Privacy policy
Last updated: 12 August 2026
This policy explains what Postrooster collects, why, and what your rights are. The short version: platform tokens are encrypted, we send no ads and sell nothing, and deleting your account really deletes it.
1. Who is responsible
Postrooster is the controller for the personal data described here. Contact: info@postrooster.com.
2. What we collect
Account data: your email address, name and a securely hashed password (or your Google sign-in).
Settings: timezone, language and email preferences.
Content: the posts, captions and media you create or upload, and your AI presets, prompts and generated drafts.
Connected accounts: platform handles, display names, avatars and encrypted access tokens.
Technical data: IP address, browser and security logs, and delivery status of the emails we send you.
3. What we access on connected platforms
When you connect an account we receive your basic profile for that platform (handle or page name, display name, avatar) so you can recognise the account in the composer, plus the access token that lets us publish on your behalf.
Per platform: X, Bluesky, LinkedIn and Threads, basic profile info and permission to create posts on your profile when you hit publish or a schedule fires. Facebook and Instagram, the list of Pages and linked professional accounts you manage, their basic info, and permission to publish the content you composed to them. TikTok, basic creator info, which we also use to show your allowed privacy options in the composer, and permission to upload or publish your videos. YouTube, permission to upload videos to your channel. Discord, a channel webhook you create through Discord's own consent screen, we can only post to that one channel and read nothing.
We only read what is needed to show your accounts and validate posts. We never read your feeds, messages, followers or analytics, and we never publish anything without an action you took in Postrooster.
Disconnecting a platform deletes its tokens immediately and revokes our access where the platform supports revocation. Deleting your Postrooster account removes all platform-derived data we hold.
4. Why we use it
To run Postrooster: publishing and scheduling on your behalf, showing your calendar and queue, and sending transactional email such as publish-failure alerts and reconnect warnings.
To keep the service reliable and secure, prevent abuse, and comply with legal obligations.
We do not run ads, do not track you across the web, and never sell your data.
5. Legal bases
Performing our contract with you (running the service), our legitimate interest in security and reliability, and your consent where the law requires it, which you can withdraw at any time.
6. Where your data lives
Your data is stored in EU data centers. We use a small set of processors: Supabase (database, authentication, media storage), Vercel (hosting), Resend (transactional email) and Anthropic (AI drafting, only the prompts and presets you submit when you use the AI studio). The platforms you connect receive only the content you choose to publish there.
Where a processor transfers data outside the EU, it happens under EU-approved safeguards such as Standard Contractual Clauses.
7. Platform access tokens
Access tokens for your connected platforms are encrypted at rest (AES-256-GCM) and never reach your browser. Disconnecting an account deletes its tokens immediately and revokes access at the platform where the platform supports it.
8. Retention
We keep your data while your account is active. Deleting your account immediately removes your posts, media, AI history, settings and tokens; residual copies in encrypted backups roll off within 30 days. We keep the minimal billing records the tax law requires.
9. Your rights
Under the GDPR you can access, correct, delete and export your data, and restrict or object to certain processing. Most of this works directly from your settings; for the rest, email info@postrooster.com and we respond within 30 days.
You can also complain to your data protection authority, in the Netherlands, the Autoriteit Persoonsgegevens.
10. Cookies
We only set functional cookies: your session and your language preference. No advertising or cross-site tracking cookies, so there is no cookie banner to click away.
11. Security
Encryption in transit (TLS) and at rest, row-level security on every database table, encrypted platform tokens and least-privilege access. Found a vulnerability? Tell us at info@postrooster.com and we will respond quickly.
12. Children
Postrooster is not intended for children under 16, and we do not knowingly collect their data.
13. Changes
We post updates to this policy here and note the date at the top. For material changes we notify you by email.
14. Contact
Privacy questions and requests: info@postrooster.com.
See also: Terms of service