Postsie← Back to postsie.com

Legal

Privacy Policy

Effective date: 21 August 2026. Last updated: 3 September 2026.

1. Who controls your data

UAB Gildium is the data controller for Postsie. Company code 307192563; registered address Polocko g. 17-113, LT-01205 Vilnius, Lithuania. Privacy questions and requests may be sent to privacy@postsie.com.

2. Data we collect

Account and security data — collected for every account:

  • Account identity, email address, and hashed password.
  • For optional Google sign-in, Google openid, email, and profile identity data.
  • Sessions and security records used to authenticate and protect accounts.
  • Support messages, operational logs, product events, and audit records used for support, security, and service reliability.

Feature-dependent data — each category below is collected only when you connect the relevant account or use the relevant feature. Comment features, the unified inbox, and TikTok account support are planned features that are not yet available; the categories that depend on them are not collected until those features are released and you use them:

  • Encrypted OAuth credentials for the Facebook Pages and Instagram professional accounts you connect, and for TikTok accounts when TikTok support becomes available.
  • Connected-account metadata, content, media, and insights, including post-level and account-level engagement and analytics data.
  • Comments on your connected accounts’ content, including commenter identity as provided by the platform, when you use comment features (planned; not yet available).
  • Messages sent to and from your connected accounts when you use the unified inbox (planned; not yet available): message content and attachments, participant identifiers provided by the platform, and message timestamps and status.
  • Your captions, drafts, uploads, schedules, and preferences.
  • Page Guides, suggestions, AI outputs, AI usage records, and basic analytics.
  • Subscription and invoice references without card details. Stripe, not Postsie, handles card details.

Meta permissions. To provide these functions Postsie requests the following permissions through Facebook Login for Business: public_profile and email (to identify you); pages_show_list and business_management (to list the Facebook Pages and Instagram professional accounts you can connect); pages_read_engagement and read_insights (Page content, media, and insights); pages_manage_posts (scheduling and publishing to Pages); instagram_basic (Instagram account profile and media); instagram_content_publish (publishing to Instagram); and instagram_manage_insights(Instagram insights). Permissions for reading comments or for sending and receiving messages — such as pages_read_user_content, instagram_manage_comments, pages_messaging, and instagram_manage_messages— are not requested until the planned comment and unified inbox features are released.

3. How we use data

We use the relevant data to:

  • Authenticate accounts and maintain sessions.
  • Connect to the platforms you authorise, and retrieve, display, analyse, schedule, and publish content at your direction.
  • Analyse your connected accounts’ content, insights, and engagement on an ongoing basis to produce suggestions, such as recommended posting times and topics.
  • Display comments and messages from your connected accounts and send the replies you compose, once the planned comment and unified inbox features become available.
  • Provide requested AI features and billing.
  • Provide support, secure the service, and keep Postsie reliable.
  • Meet legal obligations and maintain required records.

Postsie does not sell personal data, does not use connected-platform data for advertising, and does not use your content, messages, or platform data to train AI models.

Separately from connected-account data, Postsie’s own marketing on postsie.com uses Google Analytics and the Meta Pixel and Meta Conversions API described in section 6, only with your cookie consent, to measure site traffic and whether our advertising leads to sign-ups. That measurement never uses data obtained from your connected Facebook, Instagram, or (when available) TikTok accounts.

4. Legal bases

Where the GDPR applies, we process personal data on the following legal bases:

  • Contract: performance of a contract, and steps taken at your request before a contract (Article 6(1)(b)) — operating your account, the features you use, and billing;
  • Legitimate interests: our legitimate interests (Article 6(1)(f)) — proportionate security, fraud prevention, service reliability, support, and product improvement, balanced against your rights;
  • Consent: your consent (Article 6(1)(a)) where law requires it — for example non-essential cookies; consent can be withdrawn at any time;
  • Legal obligation: compliance with legal obligations (Article 6(1)(c)) — for example accounting and tax records.

5. AI processing

While an account is connected, Postsie analyses its content, insights, and engagement on an ongoing basis to produce suggestions such as recommended posting times and topics. This analysis is part of the service and does not generate text on your behalf.

AI-generated text — such as captions, drafts, and reply suggestions — is produced only when you request it. Relevant customer content and connected-account data can be sent to Anthropic only when you request such an AI-assisted feature. Anthropic processes that information to return the requested AI result. AI text generation is never applied to your data automatically; it runs only on your request.

6. Providers and sharing

Data is shared only as needed for the requested service, security, support, billing, legal obligations, or the limited provider purposes below. Provider names do not imply endorsement.

  • Meta: authorised access to Facebook Pages and Instagram professional accounts, including relevant metadata, content, media, insights, credentials, and publishing activity directed by the customer, and — once the planned comment and unified inbox features become available — comments, messages, and messaging activity directed by the customer.
  • TikTok (planned; not yet available): once TikTok support becomes available, authorised access to connected TikTok accounts, including relevant metadata, content, media, insights, comments and messages where TikTok makes them available, credentials, and publishing activity directed by the customer.
  • Google: optional identity sign-in. Google identity data is accessed only after optional sign-in authorisation, used to authenticate and maintain your account, stored with your account record, shared only with infrastructure and security providers needed to operate that account, and deleted through the account-deletion process subject to the retention rules below.
  • Google Analytics: aggregated site-usage measurement on the marketing site, only with your cookie consent; if you decline, Google Analytics receives at most limited, cookieless, aggregated signals that do not identify you. See the Cookie Policy.
  • Meta (advertising measurement): on postsie.com only, and only with your cookie consent, the Meta Pixel sets the _fbp and _fbc cookies and reports your page views to Meta. If you start a sign-up while you have given that consent, Postsie also sends Meta a hashed (SHA-256) form of the email address you entered, together with your IP address, browser user agent, and those cookie values, through the Meta Conversions API, so we can measure whether our Meta advertising leads to sign-ups. Meta processes this under its own terms. This is separate from, and never combined with, the connected-account access described in the Meta entry above. See the Cookie Policy.
  • Anthropic: relevant customer content and connected-account data for AI features the customer requests.
  • Stripe: subscription and payment processing, including subscription and invoice references; card details remain with Stripe.
  • Amazon SES: transactional account and service email delivery.
  • Laravel Cloud: application infrastructure used to host and operate the service, located in the European Union.
  • Laravel Nightwatch: application monitoring used to keep the service reliable and secure. It receives operational logs, error and performance events, and request metadata, which can include IP addresses and account identifiers.

7. Messages — special handling (planned feature)

The unified inbox is a planned feature that is not yet available. This section applies once it becomes available and you use it. Message data from the unified inbox is used only to display conversations to you and to send the replies you direct. Postsie honours platform deletion signals: when a participant deletes a message on a connected platform and the platform notifies Postsie, Postsie deletes its stored copy of that message. Message threads are retained while the connection is active and are deleted when you disconnect the account or delete your account, subject to the general deletion timeline in section 9.

8. International transfers

Postsie’s application infrastructure and primary database are hosted in the European Union. Some providers — such as Anthropic, Meta, Google, Stripe, and Laravel Nightwatch — may process data in the United States or other countries outside the EEA. Where personal data is transferred outside the EEA or the UK, we rely on: the EU–US Data Privacy Framework (including the UK Extension and the Swiss–US framework, as applicable) for providers certified under it; and otherwise the European Commission’s Standard Contractual Clauses, together with the UK Addendum or International Data Transfer Agreement for UK transfers, supplemented by technical and organisational measures such as encryption. You can request information about the safeguard applying to a specific provider via privacy@postsie.com.

9. Retention and deletion

When applicable data exists and a verified deletion request is approved, the technical deletion sequence is:

  • Access is disabled, sessions are invalidated, Meta credentials are revoked, subscription cancellation is initiated, and queued work is stopped immediately. Connected-provider OAuth tokens are included in that immediate revocation step.
  • The process removes active database rows and media — including any stored messages and comments, once those planned features are available — within 24 hours.
  • It removes object-storage remnants within 7 days, and expires export archives within 7 days.
  • It expires encrypted backups within 30 days.
  • Postsie may retain anonymised product and audit data for 13 months.
  • Postsie retains financial and accounting records for 10 years, as required by Lithuanian accounting law.

10. Your rights

Depending on applicable law, you may have rights of access, correction, portability, deletion, restriction, objection, and consent withdrawal where consent applies. A copy of your data is available through the export function in your account settings, where available, or on request through the process in section 11; export archives expire 7 days after delivery. You may also complain to the competent data-protection regulator; in Lithuania this is the State Data Protection Inspectorate (VDAI). Available rights and any lawful exceptions depend on applicable law.

11. Requests and identity verification

Send a rights request to privacy@postsie.com. We aim to acknowledge emailed privacy requests within five business days and to respond to verified requests within one month, unless applicable law permits an extension and we tell you.

We may use proportionate identity verification to protect the requester and other customers. We will never ask for your password, OAuth token, or card number as verification.

12. Cookies and security

Postsie uses essential cookies plus, only with your consent, Google Analytics and Meta Pixel cookies on the marketing site. The Cookie Policy (postsie.com/legal/cookies) describes their purposes, your consent choices, and how to change them.

Security practices include encryption — including encryption of stored OAuth credentials — access controls, and sensitive-value redaction where appropriate. No security measure eliminates every risk, and we do not promise absolute security.

13. Children, changes, and contact

Postsie is for people aged 18 or over and is not directed to children. We will provide appropriate notice of material policy changes. Contact privacy@postsie.com with privacy questions.

Legal documents

  • Terms of Service
  • Privacy Policy
  • Data Deletion Instructions
  • Refund and Cancellation Policy
  • Acceptable Use Policy
  • Cookie Policy
© 2026 Postsie. All Rights Reserved.
Terms of ServicePrivacy PolicyData Deletion InstructionsRefund and Cancellation PolicyAcceptable Use PolicyCookie PolicyCookie settings