Privacy policy
Postacio publishes your posts to the social platforms you connect, and builds a rolling metric history from those platforms. This page describes exactly what that means for your data - what is stored, who else touches it, how long it stays, and how to take it back.
Last updated 13 September 2026.
Who is responsible
Postacio is built and operated by Denis Dumitras, an individual trading as Postacio. That is the data controller for everything described here, and the person who answers the address below.
Questions, requests, or complaints: privacy@postacio.com. A person reads it.
What Postacio stores
Only what the product needs to do its job. There is no hidden collection, no tracking pixel, and no profile built about you.
Your account
Your email address, and a password that is hashed by our authentication provider and never visible to us. If you sign in with Google instead, we receive and store your name and profile picture URL from your Google profile alongside your email. We also keep the date your account was created.
The platforms you connect
When you connect X, Telegram, Instagram, Facebook or LinkedIn, that network issues Postacio a credential on your behalf. OAuth access and refresh tokens, plus Telegram bot tokens, are stored encrypted at rest with AES-256-GCM, using a key held outside the database, so a database copy alone does not yield a usable token. Alongside them we store the connected account’s own public identity as the platform reports it: its id, its display name or handle, its avatar URL, the permissions you granted, and when the token expires.
You can disconnect any platform at any time from the app, and revoke Postacio’s access from the platform’s own settings.
Your posts and media
The text you write, per-platform caption overrides and settings, the images and videos you upload, the cover thumbnail shown in your calendar, when a post is scheduled for, and the result of each publish attempt - including the platform’s own post id and permalink, so we can look up its metrics later. Uploaded media is stored under a key namespaced to your account and served only through short-lived signed links.
Your analytics history
This is the core of the product, so it is deliberate retention rather than incidental logging. Fresh posts are checked often, and checks slow as a post ages. Postacio asks each platform for that post’s current metrics - views, likes, comments, shares, saves, reach and impressions, plus the raw response - and writes them as a new append-only snapshot. Snapshots are never edited or overwritten; the database itself rejects an update. We do the same for the account totals each connected network makes available, such as followers, profile views, reach and impressions.
Your preferences
Your timezone, and the weekly posting slots you set per connected account. Your light or dark theme choice is kept in your browser’s local storage and never sent to us.
Billing
If you start or manage a paid subscription, Postacio stores your Stripe customer id and the subscription’s plan, price, billing interval, number of social groups billed, status, trial, renewal and cancellation dates, and whether the account has used its one free trial. We also count your published posts and AI writing actions per social group per month, to apply your plan’s allowances. Payment-card details are entered on Stripe’s pages and are not sent to or stored by Postacio.
Writing assistance
The writing assistant is optional. When you ask it to draft or revise text, Postacio sends OpenAI the text and context you supplied, your instruction, and the names of the target platforms. It does not send your social-platform tokens, billing details, media files or email address. Requests tell OpenAI not to store the generated response in its response store.
Google user data, specifically
If you sign in with Google, Postacio receives your email address, name and profile picture from your Google profile. Nothing else is requested, and the data is used only to create and display your Postacio account.
Postacio’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never transferred to anyone else, used for advertising, or used to train any model. Google’s own handling of your data is described in the Google Privacy Policy. You can remove Postacio’s access to your Google account at any time at myaccount.google.com/permissions.
Who else processes it
Postacio runs on a small set of infrastructure providers. They process your data only to provide their service to us, and nothing is sold or handed to anyone else.
- Vercel - hosts the application and serves every page and API request.
- Supabase - provides sign-in and the Postgres database where your account, posts, connections and snapshots live.
- Cloudflare R2 - stores the media files you upload until they are published.
- Sentry - error monitoring only. It receives crash reports from our servers, never from your browser: there is no Sentry code on the pages you load, no session recording, and no performance tracing. Expected hiccups such as a platform rate limit are filtered out before anything is sent.
- OpenAI - processes text only when you deliberately use the writing assistant, to return the draft or revision you requested.
- Stripe - provides subscription checkout, payment processing and the billing portal. Postacio receives subscription state, not your full card number.
The five social platforms themselves are not sub-processors - they are the destinations you are publishing to. Postacio sends them the post you wrote and the media you attached, on your instruction, and reads back the metrics for it.
What Postacio never does
- Sell your data, or share it with anyone for advertising. There are no advertisers.
- Use your content, media or metrics to train a Postacio model. The optional writing assistant sends only the text and context you choose to OpenAI when you press a writing action.
- Post anything on your behalf that you did not compose and schedule yourself.
- Read your inbox, your direct messages, or anything on a connected platform beyond the account details and the metrics for posts on that account.
Cookies
Postacio sets no analytics cookies and no advertising cookies - which is why there is no cookie banner asking you to accept any. The only cookies are the ones that keep you signed in, plus one that remembers whether you collapsed the sidebar. The pages load no third-party analytics or advertising scripts.
How long it is kept
- Snapshots and posts - posts and stored snapshot records may remain while your account exists. The analytics available in the product use a rolling 30-day window on Free and 365-day window on paid plans. Cancelling a paid plan returns the account to the Free window.
- Uploaded media - the original file is deleted about a day after every target has finished publishing. The platform keeps its own copy; we do not need ours. Cover thumbnails are kept so your calendar still shows the post.
- Everything described here - removed immediately when you delete your account.
Your rights and controls
- See and export - Settings downloads the account, content and product records Postacio currently stores for you as one JSON file. Credentials, social-platform tokens and full payment-card details are deliberately excluded.
- Delete - Settings contains a delete-account control that removes everything immediately and cannot be undone. The data-deletion page documents the steps, and what to do if you can no longer sign in.
- Correct - your email and password are editable in Settings; posts are editable until they publish. For anything else, write to us.
- Withdraw- disconnect any platform at any time. Postacio’s stored tokens for it are removed, and we ask the platform to revoke them too.
To exercise any of these, or if a request is refused and you want to challenge it, email privacy@postacio.com.
What deleting cannot reach
Two honest limits, stated plainly because finding them out later is worse.
- A post that has already been published lives on the platform you published it to, under that platform’s own rules and privacy policy. Deleting it in Postacio removes only what Postacio holds - the copy on X, Telegram, Instagram, Facebook or LinkedIn stays until you delete it there. Postacio has no ability to delete published content on any platform.
- In particular, media published to Instagram through Instagram Login cannot be retracted through the API at all - Instagram exposes no endpoint for it. It has to be removed in the Instagram app itself.
How it is kept safe
Platform tokens are encrypted with AES-256-GCM before they touch the database, and the key lives outside it. Every query the app makes is scoped to the signed-in account, so one user’s data is never reachable from another’s session. Your media is namespaced under your account id and every access is ownership-checked before a file is read. No security is absolute, and we will not pretend otherwise - but if something goes wrong that affects your data, you will hear it from us.
Changes to this policy
If what Postacio stores or who processes it changes, this page changes with it and the date at the top is updated. Material changes are announced in the app rather than made quietly.
Contact
Denis Dumitras, operating Postacio. Any privacy question, request or complaint: privacy@postacio.com.