Legal Document

Privacy Policy

Last updated: May 9, 2026  ·  Effective: May 9, 2026

By using Postfire, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please discontinue use of our services.

1. Overview

Postfire ("we", "our", or "us") is an AI-powered social media scheduling platform that allows individuals and businesses to create, schedule, and publish content across multiple social media networks. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you access or use our website, mobile applications, and related services (collectively, the "Service").

This policy applies to all users of Postfire, including free and paid subscribers, and governs all data processing activities in connection with your use of the Service. It has been drafted to comply with applicable data protection laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and the developer policies of the social media platforms we integrate with, including TikTok, LinkedIn, Meta (Facebook and Instagram), X (Twitter), and others.

2. Information We Collect

2.1 Account & Registration Data

When you register for Postfire, we collect:

  • Full name and email address
  • Password (stored as an irreversible cryptographic hash)
  • Company name and job title (optional)
  • Billing name and address
  • Payment card details (processed and tokenized by our payment processor; we never store raw card numbers)

2.2 Social Media Account Data

When you connect a social media account to Postfire, we receive and store:

  • OAuth access tokens and refresh tokens granted by the social platform
  • Your public profile information (name, profile picture, username/handle, follower counts) as provided by the platform's API
  • Page, channel, or organization identifiers for business accounts
  • Permissions scopes you have authorized Postfire to exercise on your behalf

We only request the minimum permissions necessary to deliver the scheduling and analytics features you use. Access tokens are encrypted at rest.

2.3 Content You Create

  • Post captions, hashtags, and text content
  • Images, videos, and other media files uploaded for scheduling
  • Post scheduling dates, times, and recurrence settings
  • Draft content and post templates
  • AI-generated content prompts and outputs

2.4 Usage & Technical Data

  • IP address and approximate geographic location (country/region)
  • Browser type, version, and operating system
  • Device identifiers and screen resolution
  • Pages visited, features used, clicks, and session duration
  • Error logs and crash reports
  • Referral source (how you found Postfire)

2.5 Communications Data

  • Emails or messages you send to our support team
  • Survey responses and product feedback
  • Preferences for marketing and transactional emails

3. How We Use Your Data

We use the information we collect for the following purposes, based on the stated legal basis:

3.1 Providing and Improving the Service (Contract / Legitimate Interest)

  • Authenticate your identity and maintain your account
  • Schedule and publish posts to connected social media accounts on your behalf
  • Retrieve post performance analytics and engagement metrics from social platforms
  • Generate AI-assisted content suggestions
  • Process subscription payments and manage billing
  • Send transactional emails (account creation, password reset, billing receipts)
  • Diagnose technical issues and improve platform stability

3.2 Communication (Legitimate Interest / Consent)

  • Respond to support requests and inquiries
  • Send product updates, feature announcements, and security alerts
  • Send marketing emails about new features or offers (only with your explicit consent; you may unsubscribe at any time)

3.3 Analytics & Product Development (Legitimate Interest)

  • Understand how users interact with Postfire to guide product decisions
  • Generate aggregated, anonymized usage statistics
  • Test and validate new features

3.4 Legal & Compliance (Legal Obligation)

  • Comply with applicable laws, regulations, and platform developer policies
  • Respond to lawful requests from courts or government authorities
  • Enforce our Terms of Service and protect against fraud or abuse

4. Social Media Platform Integrations

Postfire connects to third-party social media platforms via their official APIs. When you link a social account, your use of that platform's data through Postfire is also subject to that platform's own privacy policy and terms of service. Below is a summary of how we interact with each platform and what data we access.

TikTok
  • We use TikTok's Content Posting API to publish videos and photo carousels to your TikTok account.
  • We access video.publish, video.upload, and user.info.basic scopes only.
  • We do not access your TikTok messages, contacts, or private data beyond what is required to post on your behalf.
  • TikTok data is governed by the TikTok Privacy Policy and TikTok Platform Terms.
  • You may revoke Postfire's TikTok access at any time via TikTok Settings → Manage App Permissions.
LinkedIn
  • We use LinkedIn's UGC Posts API and Marketing Developer Platform to post on your behalf as a personal member or organization page administrator.
  • We request w_member_social and/or w_organization_social scopes as applicable.
  • We access your LinkedIn profile ID and page IDs to route posts correctly; we do not read your inbox, connections list, or private activity.
  • LinkedIn data is governed by the LinkedIn Privacy Policy and LinkedIn API Terms of Use.
  • You may revoke access via LinkedIn Settings → Data Privacy → Other Applications.
Facebook Instagram
  • We use the Meta Graph API to publish posts, reels, carousels, and stories to Facebook Pages and Instagram Business/Creator accounts.
  • We request permissions including pages_manage_posts, instagram_content_publish, and pages_read_engagement.
  • We access Page and account identifiers, post reach and engagement metrics, and the media objects required to schedule content.
  • We do not access personal Facebook profiles, friends lists, private messages, or any data beyond what is necessary to post and retrieve analytics on your behalf.
  • Meta data is governed by the Meta Privacy Policy and Meta Platform Terms.
  • You may revoke access via Facebook Settings → Security and Login → Apps and Websites.
X (Twitter)
  • We use the X API v2 to create tweets, threads, and media posts on your behalf.
  • We request tweet.write, tweet.read, and users.read OAuth 2.0 scopes.
  • We access your X username, user ID, and tweet engagement metrics for analytics; we do not access your direct messages or follower/following lists.
  • X data is governed by the X Privacy Policy and X Developer Agreement.
  • You may revoke access via X Settings → Security and Account Access → Apps and Sessions.

Important: Postfire never posts, modifies, or deletes content on your social accounts without your explicit instruction or a scheduled action you have set up. We will never use your social platform access for any purpose other than those disclosed in this Privacy Policy.

5. Data Sharing & Disclosure

We do not sell your personal data. We share your data only in the following limited circumstances:

5.1 Service Providers (Processors)

We engage trusted third-party vendors who process data on our behalf under strict data processing agreements:

  • Payment processing: Stripe — processes billing and subscription payments
  • Cloud infrastructure: AWS / Hetzner — hosts our servers and databases
  • Email delivery: SendGrid / AWS SES — sends transactional and marketing emails
  • Error monitoring: Sentry — captures and aggregates application errors
  • Analytics: PostHog (self-hosted) or similar privacy-respecting tools
  • AI content generation: Anthropic / OpenAI — processes AI prompt requests (no personal identifying information is sent beyond content you submit)

5.2 Social Media Platforms

When you use Postfire to publish content, your post data (text, media, scheduling metadata) is transmitted to the relevant social platform's API. This is the core function of our service and occurs only at your direction.

5.3 Legal Requirements

We may disclose your information if required to do so by law, court order, or in response to a valid request from a governmental authority, and only to the extent required.

5.4 Business Transfers

In the event of a merger, acquisition, or sale of all or substantially all of our assets, your data may be transferred to the successor entity. We will notify you via email and/or prominent notice on our website before your data is transferred and becomes subject to a different privacy policy.

5.5 With Your Consent

We may share your data with third parties not listed above when you have given us explicit consent to do so.

6. Data Retention

  • Active accounts: We retain your data for as long as your account is active or as needed to provide the Service.
  • Post content and media: Retained for the duration of your subscription plus 30 days after account deletion to allow for recovery.
  • Social account tokens: Deleted within 24 hours of you disconnecting the account or deleting your Postfire account.
  • Billing records: Retained for 7 years as required by financial regulations.
  • Server logs: Retained for up to 90 days for security and debugging purposes.
  • Anonymized analytics: May be retained indefinitely as they cannot be linked to any individual.

Upon account deletion, we will delete or anonymize all personal data within 30 days, except where we are required to retain it for legal or compliance purposes.

7. Security

We take the security of your data seriously and implement industry-standard safeguards:

  • All data in transit is encrypted using TLS 1.2 or higher (HTTPS)
  • Passwords are hashed using bcrypt with a per-user salt
  • OAuth tokens are encrypted at rest using AES-256
  • Access to production systems is restricted to authorized personnel via multi-factor authentication
  • We conduct regular security reviews and dependency audits
  • Media uploads are scanned for malware before storage

Despite our efforts, no method of transmission over the internet or electronic storage is 100% secure. In the event of a data breach that affects your personal information, we will notify you in accordance with applicable law — generally within 72 hours of becoming aware of the breach.

To report a security vulnerability, please email us at security@postfire.io. We operate a responsible disclosure program and take all reports seriously.

8. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

8.1 Rights Under GDPR (EEA/UK residents)

  • Right to access: Request a copy of the personal data we hold about you.
  • Right to rectification: Request correction of inaccurate or incomplete data.
  • Right to erasure ("right to be forgotten"): Request deletion of your personal data.
  • Right to restrict processing: Request that we limit how we use your data.
  • Right to data portability: Receive your data in a structured, machine-readable format.
  • Right to object: Object to processing based on legitimate interests or for direct marketing.
  • Right to withdraw consent: Withdraw any consent you have given at any time, without affecting the lawfulness of processing before withdrawal.

8.2 Rights Under CCPA/CPRA (California residents)

  • Right to know: Know what categories of personal information we collect, use, disclose, or sell.
  • Right to delete: Request deletion of personal information we have collected.
  • Right to opt out of sale: We do not sell personal information. No opt-out is required.
  • Right to non-discrimination: We will not discriminate against you for exercising your rights.
  • Right to correct: Request correction of inaccurate personal information.

8.3 How to Exercise Your Rights

To exercise any of the rights above, submit a request to privacy@postfire.io or use the data management tools available in your account settings. We will respond within 30 days (GDPR) or 45 days (CCPA). We may ask you to verify your identity before processing your request.

If you are an EEA resident and believe we have not addressed your concerns adequately, you have the right to lodge a complaint with your local data protection authority.

9. Cookies & Tracking Technologies

We use cookies and similar technologies to operate and improve Postfire. Here is a breakdown by category:

Category Purpose Opt-out
Strictly Necessary Session management, authentication, CSRF protection. Required for the Service to function. Cannot be disabled.
Functional Remember your preferences such as timezone, language, and UI settings. Managed in account settings.
Analytics Understand feature usage patterns to improve the product. Data is anonymized. Email us to opt out.
Marketing Used only on our public marketing pages to measure campaign effectiveness. Not used inside the app. Via cookie banner / browser settings.

You can also control cookies through your browser settings. Note that disabling strictly necessary cookies will prevent you from logging in and using the Service.

10. Children's Privacy

Postfire is not directed to children under the age of 13 (or 16 in the EEA/UK). We do not knowingly collect personal information from children under these ages. If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately at privacy@postfire.io and we will delete that information promptly.

Additionally, to use Postfire you must meet the minimum age requirements of each connected social media platform (e.g., TikTok requires users to be at least 13; LinkedIn requires users to be at least 16).

11. International Data Transfers

Postfire operates globally and your data may be transferred to and processed in countries other than the country in which you reside. These countries may have data protection laws that differ from those in your country.

For transfers of personal data from the EEA, UK, or Switzerland to countries that are not considered to provide an adequate level of data protection, we rely on the following safeguards:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • The EU-US Data Privacy Framework (where applicable)
  • Binding Corporate Rules or other recognized transfer mechanisms

You may request a copy of the relevant transfer safeguards by contacting us at privacy@postfire.io.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page
  • Send an email notification to registered users at least 14 days before the changes take effect
  • Display a prominent banner in the Postfire dashboard

For non-material changes (such as clarifications or corrections), we will update this page without separate notification. We encourage you to review this policy periodically. Your continued use of Postfire after the effective date of the updated policy constitutes your acceptance of the changes.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

General Privacy Inquiries

privacy@postfire.io

Response within 30 days

Security Vulnerabilities

security@postfire.io

Responsible disclosure program

Data Protection Officer

dpo@postfire.io

For GDPR-related requests

Mailing Address

Postfire, Inc.

123 Scheduler Lane
San Francisco, CA 94105
United States

© 2026 Postfire, Inc. All rights reserved.  ·  Privacy Policy  ·  Terms of Service  ·  Cookie Policy

We use cookies

We use essential cookies to keep you signed in, and optional analytics cookies to improve the product. We never sell your data or use advertising cookies. Cookie Policy

Cookie Preferences

Choose which cookies you allow us to use.

Strictly Necessary Always active

Session management, authentication, and CSRF protection. Cannot be disabled as the service cannot function without them.

Functional

Remember your preferences such as timezone, language, and UI settings to provide a better experience.

Analytics

Understand how features are used so we can improve the product. Data is anonymized and self-hosted — never shared with advertisers.

Cookie Policy