Privacy Policy
Postly (“the Service”) helps you generate marketing content and publish it to social media accounts that you choose to connect. This policy explains what data we collect, why, and how you can remove it.
Information we collect
- Account details. Your email address, an optional display name, and a securely hashed password. We never store your password in readable form.
- Social account credentials. When you connect a platform such as Pinterest, we store the access token (and refresh token, if provided) that the platform issues, together with basic account information such as your username, account ID, and the boards or pages available to you. We ask only for the permissions needed to publish content and list your destinations.
- Content you create. The prompts you submit (theme, product name, description, tone, destination URL), the copy and images generated from them, and a record of each publish attempt including its status, the post ID returned by the platform, and any error message.
- Usage measurement. We count page views and visits using Vercel Web Analytics. It records the page visited, referrer, country, and the general device and browser type. It does not use cookies, does not follow you to other sites, and does not build a profile of you.
We do not collect payment details, and we do not use advertising or cross-site tracking cookies. The only cookie we set is the one required to keep you signed in.
How we use your information
- To authenticate you and keep your session active.
- To generate content at your request and publish it to the accounts you connected.
- To show your posting history and report errors returned by a platform.
- To keep the Service secure and diagnose failures.
We do not sell your personal data, and we do not use your content to train machine-learning models.
Third-party services
To provide the Service, the prompts you submit are sent to the providers below. Only the text needed to generate your content is sent — never your credentials.
- The AI provider you configure (Groq, OpenAI, Google Gemini or Anthropic) — generates the written copy.
- Pollinations.ai — generates the images.
- The social platform you connect (for example Pinterest) — receives the post you asked us to publish, on your behalf.
- Neon (database hosting, United States) and Vercel (application hosting) — store and run the Service.
- Vercel Web Analytics — counts page views. Cookieless, and it receives no account data.
Data retention and deletion
- Disconnect a platform at any time from the Connections page. This deletes the stored access token for that account immediately.
- Delete your account by contacting us at chentaymane234@gmail.com. We remove your user record, all connected-account tokens, and your posting history. Content already published to a social platform must be deleted on that platform, since we cannot remove it for you after publishing.
Revoking Postly’s access from within a platform’s own settings (for example Pinterest’s connected-apps page) also invalidates the token we hold.
Security
Passwords are hashed with bcrypt. Access tokens are stored server-side and are never exposed to your browser. All traffic is served over HTTPS, and database connections are encrypted with TLS. Each user’s data is scoped to their own account.
No system is perfectly secure. If you believe your account has been compromised, contact us at chentaymane234@gmail.com.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, or to object to its processing. Contact us at chentaymane234@gmail.comand we will respond within 30 days.
Children
The Service is not directed to anyone under 16, and we do not knowingly collect their data.
Changes to this policy
If we make material changes, we will update the date at the top of this page and, where appropriate, notify you by email.
Contact
Questions or requests: chentaymane234@gmail.com