Translation for convenience. The legally binding version of this document is the German one. In case of any discrepancy, the German text prevails. German statutes keep their German short title and citation style, for example § 19 UStG or § 356 Abs. 4 und 5 BGB: a citation is an address, not a sentence to translate. Read the German version.
Privacy Policy
1. Controller
The controller for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) is:
Stefan Kern
Kleinsachsenheimer Str. 36
74343 Sachsenheim
Germany
E-mail: hello@postd.ai
2. What data we process, and what for
Account and sign-in: To set up and manage your user account, we process your e-mail address. You sign in with a magic link or a password. You can use the free Light version without an account, and then no data is created here.
Profile data: If you provide them, we process your name, display name, Instagram handle, date of birth, phone number, billing address and profile picture.
Connected social media accounts: If you connect an Instagram professional account to postd, we store that account's ID, its public account name, the account type and an access token issued by Meta. The token is stored encrypted in a separate vault, never reaches your browser and can only be read by our server functions. We use it for exactly three things: publishing posts on your behalf, loading your existing posts for the feed preview, and reading the metrics of your own posts. We do not read direct messages, and we never reply to anything in your name. You can disconnect the account at any time in your account settings, and we delete the token immediately. If instead you remove postd in your Instagram settings, Meta tells us and we delete it just the same.
Saved projects: We store what you create in the tool (projects, drafts) so you can open it again and keep working.
Contract and billing data: For the paid versions we process your entitlements and your subscription status.
Local storage: We use your browser's localStorage for your settings. Your current draft, and any images you load into the feed preview just to look at them, are stored in your browser's IndexedDB. All of this data stays on your device; we do not transmit it.
Errors and usage: So that we can find bugs and improve the service, we record technical events: which function was used, for example an export, a new project or a question to our help, as well as program errors with the error message, file and line, page and a coarse browser label. If you are signed in, these entries belong to your account, otherwise to no person. We do not transmit the contents of your posts; for questions to our help we count only the number of characters, not the text.
Problem reports: If you report a problem to us through the form, we process your text, your email address if you provide one, and the technical environment: page, browser, window size, language and the most recent error messages from your browser. The form shows you everything that is sent along before you submit.
Visit statistics: We count page views on our website, which sections of a page were seen, the time spent, the scroll depth, the device category and the origin, meaning only the domain of the referring page plus campaign parameters from the link. We use no cookies for this and store nothing on your device. To tell visitors apart we derive a non-reversible checksum from the IP address, the browser identification and a key that changes daily; we do not store the IP address itself. Recognising anyone beyond a single day is therefore ruled out. We respect a “Do Not Track” signal from your browser.
Notes on shared links: Anyone who receives a share link from you can leave a note on an individual slide without signing in. For this we process the name that person enters themselves and their text. So that they can withdraw their own note again, we store a random identifier in their browser’s localStorage; it is not linked to any person, we do not evaluate it, and it only leaves the device as a value to compare against. We use the IP address transiently as an abuse brake and do not store it. As the creator of the link you are notified about new notes by email; you can delete them at any time and turn them off entirely for a link.
3. Legal bases
We process your data to perform the contract with you or to take steps prior to entering into a contract (Art. 6(1)(b) GDPR). Where we process data for technical operation, for security and to improve the service, we rely on our legitimate interests (Art. 6(1)(f) GDPR).
4. Recipients and processors
Supabase: For hosting, database and authentication we use Supabase as a processor. Processing takes place in the United Kingdom (London region). The legal basis for this transfer is the European Commission's adequacy decision for the United Kingdom, which confirms a level of data protection comparable to the EU.
Stripe: Payments are handled by Stripe Payments Europe, Ltd. (Ireland) as our contractual partner. As part of payment processing, data may be transferred to affiliated Stripe companies in the USA (Stripe, Inc.), for example for technical processing and fraud prevention. That transfer is based on the standard contractual clauses of the European Commission or on the EU-US Data Privacy Framework. Your payment data itself is processed directly by Stripe and held there, not with us.
Netlify: We use Netlify, Inc. (USA) for static hosting and delivery through a content delivery network. This involves processing IP addresses and server log data, among other things. The transfer to the USA is based on the standard contractual clauses of the European Commission or on the EU-US Data Privacy Framework.
Resend: For internal notification emails to us as the operator, for example on purchase or cancellation, for the confirmation to you when you report a bug via the form and give us your email address, and for the notification to you when someone leaves a note on a link you shared, we use the email service Resend (USA). The transfer to the USA is based on the European Commission’s standard contractual clauses and/or the EU-US Data Privacy Framework.
5. How long we store data
We store your data for as long as we need it for the purposes named above, at most for as long as your user account exists.
Measurement data: We delete usage events after 180 days, error data after 90 days and visit statistics after 400 days. We treat problem reports like correspondence: we delete them once they are resolved and no longer needed.
After the contract ends: When your subscription or contract ends, the projects you saved in the cloud stay available for another seven days so you can export them without rushing. After that we delete them, together with any existing share links.
Shared preview links: When you create a share link, we store a copy of the slides as images for it, plus an editable copy of the draft so that authorised viewers can take it over into their own account. Font files from your own brand kit are not included. We delete both copies automatically when the link expires: seven days after creation on the Free plan, after 30 days with a subscription or Lifetime. If you revoke a link yourself before then, the preview stops working immediately and we delete the copy at the next cleanup run. When your contract ends, we delete existing share links together with your projects, even if their own period is still running.
Notes: Notes that viewers leave on a shared link are deleted together with that link, so at the latest when it expires. If you turn notes off for a link, they are no longer visible to viewers; that alone does not delete them, which you can do individually.
Access to connected accounts: We store the access token of a connected Instagram account for as long as the connection exists. If you disconnect it in your account, we delete it immediately. If you request deletion of your data through Instagram, we delete the connection, the token and the metrics stored with it in full, and give you a confirmation code you can use to look the process up.
Rendered post files: When you schedule a post, your browser renders the slides into an image or video file and stores it in private storage so Instagram can fetch it at the scheduled time. 30 days after a post has been published or has finally failed, we delete these files. Files whose post no longer exists are deleted on the next cleanup run.
After you delete your account: If you delete your account, we erase your data without delay and in full, including projects, uploaded images, profile data and share links. This does not cover data we have to keep because of statutory retention obligations, such as invoice data under commercial and tax law. Payment data is held by Stripe and subject to their retention periods.
6. Your rights
You have the right of access, rectification, erasure, restriction of processing and data portability, and a right to object to processing. An informal message to the contact details above is enough. You can also delete your account yourself at any time in the Account area.
7. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, your place of work or the place of the alleged infringement.