Privacy Policy
Last updated: May 9, 2026 · Effective: May 9, 2026
By using Postfire, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please discontinue use of our services.
1. Overview
Postfire ("we", "our", or "us") is an AI-powered social media scheduling platform that allows individuals and businesses to create, schedule, and publish content across multiple social media networks. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you access or use our website, mobile applications, and related services (collectively, the "Service").
This policy applies to all users of Postfire, including free and paid subscribers, and governs all data processing activities in connection with your use of the Service. It has been drafted to comply with applicable data protection laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and the developer policies of the social media platforms we integrate with, including TikTok, LinkedIn, Meta (Facebook and Instagram), X (Twitter), and others.
2. Information We Collect
2.1 Account & Registration Data
When you register for Postfire, we collect:
- Full name and email address
- Password (stored as an irreversible cryptographic hash)
- Company name and job title (optional)
- Billing name and address
- Payment card details (processed and tokenized by our payment processor; we never store raw card numbers)
2.2 Social Media Account Data
When you connect a social media account to Postfire, we receive and store:
- OAuth access tokens and refresh tokens granted by the social platform
- Your public profile information (name, profile picture, username/handle, follower counts) as provided by the platform's API
- Page, channel, or organization identifiers for business accounts
- Permissions scopes you have authorized Postfire to exercise on your behalf
We only request the minimum permissions necessary to deliver the scheduling and analytics features you use. Access tokens are encrypted at rest.
2.3 Content You Create
- Post captions, hashtags, and text content
- Images, videos, and other media files uploaded for scheduling
- Post scheduling dates, times, and recurrence settings
- Draft content and post templates
- AI-generated content prompts and outputs
2.4 Usage & Technical Data
- IP address and approximate geographic location (country/region)
- Browser type, version, and operating system
- Device identifiers and screen resolution
- Pages visited, features used, clicks, and session duration
- Error logs and crash reports
- Referral source (how you found Postfire)
2.5 Communications Data
- Emails or messages you send to our support team
- Survey responses and product feedback
- Preferences for marketing and transactional emails
3. How We Use Your Data
We use the information we collect for the following purposes, based on the stated legal basis:
3.1 Providing and Improving the Service (Contract / Legitimate Interest)
- Authenticate your identity and maintain your account
- Schedule and publish posts to connected social media accounts on your behalf
- Retrieve post performance analytics and engagement metrics from social platforms
- Generate AI-assisted content suggestions
- Process subscription payments and manage billing
- Send transactional emails (account creation, password reset, billing receipts)
- Diagnose technical issues and improve platform stability
3.2 Communication (Legitimate Interest / Consent)
- Respond to support requests and inquiries
- Send product updates, feature announcements, and security alerts
- Send marketing emails about new features or offers (only with your explicit consent; you may unsubscribe at any time)
3.3 Analytics & Product Development (Legitimate Interest)
- Understand how users interact with Postfire to guide product decisions
- Generate aggregated, anonymized usage statistics
- Test and validate new features
3.4 Legal & Compliance (Legal Obligation)
- Comply with applicable laws, regulations, and platform developer policies
- Respond to lawful requests from courts or government authorities
- Enforce our Terms of Service and protect against fraud or abuse
5. Data Sharing & Disclosure
We do not sell your personal data. We share your data only in the following limited circumstances:
5.1 Service Providers (Processors)
We engage trusted third-party vendors who process data on our behalf under strict data processing agreements:
- Payment processing: Stripe — processes billing and subscription payments
- Cloud infrastructure: AWS / Hetzner — hosts our servers and databases
- Email delivery: SendGrid / AWS SES — sends transactional and marketing emails
- Error monitoring: Sentry — captures and aggregates application errors
- Analytics: PostHog (self-hosted) or similar privacy-respecting tools
- AI content generation: Anthropic / OpenAI — processes AI prompt requests (no personal identifying information is sent beyond content you submit)
5.2 Social Media Platforms
When you use Postfire to publish content, your post data (text, media, scheduling metadata) is transmitted to the relevant social platform's API. This is the core function of our service and occurs only at your direction.
5.3 Legal Requirements
We may disclose your information if required to do so by law, court order, or in response to a valid request from a governmental authority, and only to the extent required.
5.4 Business Transfers
In the event of a merger, acquisition, or sale of all or substantially all of our assets, your data may be transferred to the successor entity. We will notify you via email and/or prominent notice on our website before your data is transferred and becomes subject to a different privacy policy.
5.5 With Your Consent
We may share your data with third parties not listed above when you have given us explicit consent to do so.
6. Data Retention
- Active accounts: We retain your data for as long as your account is active or as needed to provide the Service.
- Post content and media: Retained for the duration of your subscription plus 30 days after account deletion to allow for recovery.
- Social account tokens: Deleted within 24 hours of you disconnecting the account or deleting your Postfire account.
- Billing records: Retained for 7 years as required by financial regulations.
- Server logs: Retained for up to 90 days for security and debugging purposes.
- Anonymized analytics: May be retained indefinitely as they cannot be linked to any individual.
Upon account deletion, we will delete or anonymize all personal data within 30 days, except where we are required to retain it for legal or compliance purposes.
7. Security
We take the security of your data seriously and implement industry-standard safeguards:
- All data in transit is encrypted using TLS 1.2 or higher (HTTPS)
- Passwords are hashed using bcrypt with a per-user salt
- OAuth tokens are encrypted at rest using AES-256
- Access to production systems is restricted to authorized personnel via multi-factor authentication
- We conduct regular security reviews and dependency audits
- Media uploads are scanned for malware before storage
Despite our efforts, no method of transmission over the internet or electronic storage is 100% secure. In the event of a data breach that affects your personal information, we will notify you in accordance with applicable law — generally within 72 hours of becoming aware of the breach.
To report a security vulnerability, please email us at security@postfire.io. We operate a responsible disclosure program and take all reports seriously.
8. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
8.1 Rights Under GDPR (EEA/UK residents)
- Right to access: Request a copy of the personal data we hold about you.
- Right to rectification: Request correction of inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): Request deletion of your personal data.
- Right to restrict processing: Request that we limit how we use your data.
- Right to data portability: Receive your data in a structured, machine-readable format.
- Right to object: Object to processing based on legitimate interests or for direct marketing.
- Right to withdraw consent: Withdraw any consent you have given at any time, without affecting the lawfulness of processing before withdrawal.
8.2 Rights Under CCPA/CPRA (California residents)
- Right to know: Know what categories of personal information we collect, use, disclose, or sell.
- Right to delete: Request deletion of personal information we have collected.
- Right to opt out of sale: We do not sell personal information. No opt-out is required.
- Right to non-discrimination: We will not discriminate against you for exercising your rights.
- Right to correct: Request correction of inaccurate personal information.
8.3 How to Exercise Your Rights
To exercise any of the rights above, submit a request to privacy@postfire.io or use the data management tools available in your account settings. We will respond within 30 days (GDPR) or 45 days (CCPA). We may ask you to verify your identity before processing your request.
If you are an EEA resident and believe we have not addressed your concerns adequately, you have the right to lodge a complaint with your local data protection authority.
10. Children's Privacy
Postfire is not directed to children under the age of 13 (or 16 in the EEA/UK). We do not knowingly collect personal information from children under these ages. If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately at privacy@postfire.io and we will delete that information promptly.
Additionally, to use Postfire you must meet the minimum age requirements of each connected social media platform (e.g., TikTok requires users to be at least 13; LinkedIn requires users to be at least 16).
11. International Data Transfers
Postfire operates globally and your data may be transferred to and processed in countries other than the country in which you reside. These countries may have data protection laws that differ from those in your country.
For transfers of personal data from the EEA, UK, or Switzerland to countries that are not considered to provide an adequate level of data protection, we rely on the following safeguards:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- The EU-US Data Privacy Framework (where applicable)
- Binding Corporate Rules or other recognized transfer mechanisms
You may request a copy of the relevant transfer safeguards by contacting us at privacy@postfire.io.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the "Last updated" date at the top of this page
- Send an email notification to registered users at least 14 days before the changes take effect
- Display a prominent banner in the Postfire dashboard
For non-material changes (such as clarifications or corrections), we will update this page without separate notification. We encourage you to review this policy periodically. Your continued use of Postfire after the effective date of the updated policy constitutes your acceptance of the changes.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Mailing Address
Postfire, Inc.
123 Scheduler Lane
San Francisco, CA 94105
United States
© 2026 Postfire, Inc. All rights reserved. · Privacy Policy · Terms of Service · Cookie Policy
4. Social Media Platform Integrations
Postfire connects to third-party social media platforms via their official APIs. When you link a social account, your use of that platform's data through Postfire is also subject to that platform's own privacy policy and terms of service. Below is a summary of how we interact with each platform and what data we access.
video.publish,video.upload, anduser.info.basicscopes only.w_member_socialand/orw_organization_socialscopes as applicable.pages_manage_posts,instagram_content_publish, andpages_read_engagement.tweet.write,tweet.read, andusers.readOAuth 2.0 scopes.Important: Postfire never posts, modifies, or deletes content on your social accounts without your explicit instruction or a scheduled action you have set up. We will never use your social platform access for any purpose other than those disclosed in this Privacy Policy.