Legal and trust · Privacy

Privacy policy

This policy explains the information Postdom needs to read your website, write posts for your approval, and publish what is approved, who receives it, and the controls available to you.

Effective
29 August 2026
Last updated
6 October 2026

Plain-language summary

The short version

01

Scope and operator

Who this policy covers

This policy applies to postdom.com, the Postdom web app (including the website preview you can run before signing up), Postdom APIs and MCP tools, lifecycle emails, and the support or commercial conversations connected with those services. Blue Venture Studios Pty Ltd operates Postdom and is responsible for personal information when it decides why and how that information is used.

A workspace customer may also control personal information placed into Postdom by its members, agents, or connected accounts. In that situation, the customer is responsible for its own notices, permissions, and lawful instructions, and Postdom handles the information to provide the service.

Social networks, payment services, and other third-party products have their own privacy practices when they act independently. This policy does not replace theirs.

02

Data map

Information we handle

The information depends on how you use Postdom. We collect what is needed to create and secure a workspace, read your website and write posts from it, carry out authorized publishing, return evidence, bill the workspace, and operate the service.

Information categories
CategoryExamplesWhy it is needed
Account and workspaceEmail address, user ID, workspace name, role, invitations, sign-in and workspace selection state.Authenticate people, assign workspace access, and keep tenants separated.
Connected accountsPlatform, account handle, provider and platform identifiers, connection status, timezone, and authorization version.Show the correct destination and execute authorized account actions. Postdom does not ask for or store your social-network password.
Content and operationsCaptions, uploaded video, source URLs, schedules, plans, workspace briefs, agent identity and intent, approvals, account policy, publish outcomes, URLs, metrics, and webhook records.Schedule and publish customer content, enforce human authority, recover work safely, and report what happened.
Derived from uploaded mediaTranscripts of the audio, text read from sampled video frames, embeddings (numeric representations of the content), a low-resolution copy of the video, measured media properties such as duration, dimensions, language, and length, and per-publish result summaries.Show a workspace what has worked for it and inform its own posts. This material stays in the workspace it came from and is never shown to another customer.
Website and Brand BrainPublic pages Postdom reads from the website you give it, including your blog articles, and what it derives from them: a business summary, products and services, audience, tone, logo, colours, fonts, images, and the page each fact came from. Website pages can include names and details of people.Write posts and videos that fit your business, and check posts against what your own website says.
Posts and review decisionsPosts, captions, slides, and videos Postdom writes, the reason shown with each post, your approvals, edits, and rejections with any reasons you give, your Mention your business setting, and the preferences Postdom learns from those decisions.Show you posts, publish only what is approved, and shape later posts for your workspace from what you approve, edit, and reject.
Competitor inspirationNames, websites, and public social handles of competitors you add or accept; recent public posts from those accounts (caption, format, public engagement counts, date, and link); and titles and short summaries of their public blog posts. These posts are written by other people and businesses.Suggest topics and formats for your posts, and check that a post does not copy another account's post. Posts are kept for up to 90 days after they are fetched.
Website preview before sign-upThe website address you enter, what Postdom reads from it, the brand preview and post made from it, a keyed hash of your IP address, and a hash of a browser cookie that links the preview to your browser.Show you the preview, limit abuse, and let you keep the preview if you sign up.
BillingPlan, subscription status, Stripe customer and subscription identifiers, billing period, usage, and successful destination-publish meter records.Provide paid plans, enforce capacity, reconcile billing, and support transactions. Stripe collects payment-card details; Postdom does not store full card numbers.
Device and service activityIP address, request time, route, status, browser or device details, security and rate-limit signals, the result of the Cloudflare Turnstile check on the website preview, and diagnostic logs.Deliver, secure, troubleshoot, and improve the service.
CommunicationsMessages sent through Contact, support history, workspace notification preferences, delivery status, activation and onboarding email sent when you sign up, and the email content needed for a service notification.Respond to requests, send operational messages chosen by the workspace, and send a limited series of activation and onboarding email to help a new sign-up finish setup, with an unsubscribe option in every message.
03

Sources

How information reaches Postdom

We receive information directly when you sign up, create or join a workspace, configure policy, submit content, choose a plan, change notification settings, or contact us. Workspace owners, administrators, members, and authorized agents may also provide information for the workspace.

When you give Postdom a website, before or after signing up, Postdom reads public pages from it, including blog articles, and follows the site's robots.txt. When you add or accept a competitor, Postdom reads that business's public website and receives recent public posts from its social accounts through ScrapeCreators. Video posts use stock footage found by searching Pexels and Pixabay.

We receive connected-account identifiers, publish outcomes, and available measurements through Zernio and the social networks you direct Postdom to use. Stripe returns subscription and usage events. Service infrastructure produces security, availability, and diagnostic records. Cookieless Ahrefs Web Analytics receives limited public-site usage data; it is the only analytics on the public website and it sets no cookie.

When you follow a sign-up link on the public website, the link carries the first postdom.com page you visited, the page you signed up from, the referring website's domain, and any campaign tags in the address. Postdom keeps these with your new account and workspace, together with any outreach link or Made with Postdom page that led to the sign-up.

  • We do not buy consumer data lists.
  • We do not run third-party advertising on Postdom.
  • We do not use customer content to train a general-purpose AI model.
04

Purpose and basis

Why we use information

We use information only for the purposes below or for a compatible purpose that is reasonably expected and permitted by law. Where a law requires a legal basis, the basis depends on the activity.

Purposes and legal bases
PurposeWhat this includesBasis where required
Provide the serviceAuthentication, workspaces, reading your website, writing posts and videos, account connection, scheduling, publishing, outcomes, measurement, webhooks, notifications, and billing.Performing the service contract or taking requested pre-contract steps.
Learn from review decisionsUsing your approvals, edits, and rejections, and the reasons you give, to change what later posts in your workspace say and how they look.Performing the service contract.
Website preview before sign-upReading the website you enter, showing a brand preview and a post, limiting how many previews one address can start, and letting you keep the preview if you sign up.Taking steps you request before a contract, and legitimate interests in preventing abuse of a free preview.
Competitor inspirationReading recent public posts and blog titles from competitors you add or accept, to suggest topics and formats and to check that posts do not copy them.Legitimate interests, yours and ours, in writing posts informed by public activity in your market, limited to public posts kept for up to 90 days.
Activation and onboarding emailA limited series of email sent to a new sign-up to help finish setting up a workspace, connect an account, and start publishing.Legitimate interests in helping a new sign-up finish setup, with an opt-out offered at sign-up and in every message.
Keep Postdom safeAccess control, tenant isolation, rate limiting, bot checks on the website preview, abuse detection, fraud prevention, audit evidence, incident response, and enforcing terms.Legitimate interests in secure operations and, where applicable, legal obligations.
Support and improveResponding to requests, diagnosing failures, measuring reliability, and improving workflows and documentation.Contract performance and legitimate interests in operating a useful service.
Sign-up sourceRecording which page, referring website, campaign, outreach link, or Made with Postdom page led to a new sign-up, to see which of our marketing brings sign-ups.Legitimate interests in measuring our own marketing, limited to these details and not used for advertising.
Public-site analyticsUnderstanding visits, page use, and marketing-form completion through cookieless Ahrefs Web Analytics.Legitimate interests in aggregate, cookieless measurement through Ahrefs, which stores nothing in your browser and discards raw IP addresses.
Comply and protectAccounting, tax, legal process, regulator requests, disputes, and protecting people, Postdom, or the public.Legal obligation and legitimate interests in establishing or defending rights.
05

Service providers

Where information is shared

Postdom shares information only as needed to provide a feature you requested, operate the service, meet a legal obligation, or complete a business transaction. The exact information sent depends on the feature. Providers may also handle limited account or technical data under their own terms when they act independently.

We may also disclose information if required by law or valid legal process, to investigate harm or misuse, with professional advisers under confidentiality, or as part of a merger, financing, reorganization, or sale subject to appropriate protections.

Current provider map
ProviderRoleInformation involved
SupabaseAuthentication and relational data infrastructure.Account identity, workspace records, operational records, and access state.
Vercel and RailwayWeb delivery, API hosting, background processing, and rate-limit infrastructure.Requests, service data needed for processing, IP addresses, and operational logs.
Cloudflare R2Private object storage and delivery for uploaded media and for the images and videos used in posts.Video files, images read from your website, post images and videos, object identifiers, content type, size, checksum or ETag, and processing state.
AI model provider: OpenAIReading your website, writing posts, captions, and video scripts, answering in Chat, checking stock footage frames, and producing transcripts, frame text, and embeddings for the workspace's own analysis, under a data-processing agreement.Website text and images, Brand Brain details, prompts and instructions, posts, short excerpts of competitor posts, and stock footage preview frames. The audio track and sampled frames from uploaded video. We use providers that contractually do not train on customer content.
fal.aiAI media models for video posts: voiceover, background music, and short video clips, including clips animated from an image on your website. Some models on fal.ai are made by other companies, such as ElevenLabs for voice and music.Video script text, prompts, and images from your website or brand kit.
Pexels and PixabayStock video libraries searched for footage in video posts.Search terms written from a post's script. They do not receive your account details.
ScrapeCreatorsFetches recent public posts from the social accounts of competitors you add or accept.Those competitors' public social handles. It returns their public posts.
Cloudflare TurnstileBot check on the website preview before sign-up.IP address, browser and device signals, and the result of the check. Cloudflare runs the check in your browser.
ZernioConnected-account authorization, social publishing, provider outcomes, and available metrics.Connected-account identifiers, content and media needed to publish, destination settings, schedules, post identifiers, outcomes, and metrics.
Social networksThe destinations you select, such as TikTok, Instagram, and YouTube.Content, publishing settings, account authorization, and any data the destination requires or returns.
StripeCheckout, recurring subscriptions, billing portal, fraud controls, and metered overage.Contact and transaction information, plan, customer and subscription IDs, successful overage events, and payment details supplied directly to Stripe.
PostmarkLifecycle and action-required email, including the email that tells you your first posts are ready.Recipient email, message type, limited event context, and delivery status. Open and link tracking are disabled for Postdom lifecycle email.
Ahrefs Web AnalyticsCookieless analytics on the public website, and the only analytics there. Ahrefs does not use cookies and discards raw IP addresses without storing them.Page URL, referral, browser and device, language, approximate city and country, and page, link, and form interactions.
06

Global processing

International data handling

Postdom and its providers may process information in Australia, the United States, the European Economic Area, and other places where the relevant provider or social network operates. Zernio states that its operation and data processing are in Europe; other providers use regional or global infrastructure.

Privacy protections can differ between countries. Where required, we use contractual, technical, and organizational safeguards for international handling. A provider may also be legally required to disclose information in the country where it operates.

07

Lifecycle

Retention and deletion

We keep information while a workspace is active and for as long as it is reasonably needed to deliver the service, maintain publishing and billing evidence, protect security, resolve disputes, and meet tax, accounting, or other legal obligations. Retention therefore varies by record type and context.

Material derived from uploaded media — transcripts, frame text, embeddings, the low-resolution copy, measured media properties, and per-publish result summaries — is kept while the workspace exists, and for 12 months after cancellation with an export offered first; the low-resolution copy is kept for 30 days on Free. It can be deleted at any time from your workspace settings, or by asking us by email. Metric values a platform reports are kept only as long as that platform's developer terms allow, and are then reduced to Postdom's own summaries. Media uploaded and never published expires after 14 days.

Website readings, the Brand Brain, posts, videos, and the preferences learned from your review decisions are kept while the workspace exists and are deleted with the workspace, subject to the backup and legal exceptions below. Competitor posts are kept for up to 90 days after they are fetched, and a competitor's posts and blog titles are deleted when you remove that competitor or the workspace is deleted. A website preview that is not kept by signing up is deleted after 7 days, and the hashed IP address and cookie hash recorded for any preview are deleted after 7 days.

Revoking a workspace key or OAuth grant stops future access but may leave hashed identifiers and audit evidence. Disconnecting a social account stops Postdom from using that connection; Zernio and the social network apply their own deletion and retention processes to information they control. Backups and immutable security or financial records may take longer to expire or may need to be kept by law.

You can request workspace or personal-data deletion through Contact. We will verify authority, then delete or de-identify information that is no longer required, while explaining any information we must retain.

08

Control

Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, restrict, or receive personal information, object to certain processing, or withdraw consent. You may also complain to a privacy regulator. These rights can be limited where another person's rights, legal privilege, security, fraud prevention, or a legal retention duty applies.

Start with the Contact page and identify the workspace and request. We may verify your identity and workspace authority before acting. We will respond within the period required by applicable law and explain if we cannot complete all or part of a request.

Workspace administrators can update many operational settings directly. The public website asks for no analytics consent because its only analytics, Ahrefs Web Analytics, sets no cookie and stores nothing in your browser; you can object to that measurement by contacting us. Withdrawing consent does not affect processing already carried out lawfully.

  • For access or correction, describe the information and the correction you believe is needed.
  • For deletion or portability, identify the workspace and whether the request covers membership, content, connected accounts, or the entire workspace.
  • For a privacy complaint, describe what happened and the outcome you want. We will investigate and respond; if you remain dissatisfied, you may contact the OAIC in Australia or the relevant authority where you live.
  • For activation and onboarding email, use the unsubscribe link included in every message; it works without signing in and applies immediately.
09

Browser storage

Cookies and analytics

The public site sets no analytics or advertising cookies and shows no cookie banner. Its only analytics, Ahrefs Web Analytics, is cookieless: it stores nothing in your browser and discards raw IP addresses. A consent cookie set by this site before 23 September 2026 is no longer read and expires on its own within a year. The sign-up source described above travels in the sign-up link itself; the public site uses no cookie or browser storage for it.

The authenticated app uses cookies that are necessary to maintain the Supabase sign-in session and remember the selected Postdom workspace. Disabling necessary cookies can prevent sign-in or workspace functions from working.

If you sign up from a Made with Postdom page, the app sets a cookie that remembers which page it was for 30 days.

The website preview before sign-up sets one necessary cookie that links the preview to the browser that started it. It lasts up to 14 days and cannot be read by the page's scripts. The preview page also loads Cloudflare Turnstile, which checks that the visitor is a person and not an automated program. Turnstile collects browser and device signals for that check and is covered by Cloudflare's own privacy policy.

10

Protection

Security and incidents

Postdom uses layered access controls, workspace scoping, hashed agent credentials and OAuth tokens, provider signature checks, private media storage, rate limits, and audit records. No online service can guarantee absolute security.

Keep sign-in links, agent keys, OAuth grants, and connected devices secure. Revoke access you no longer recognize and contact us promptly if you suspect misuse. For current reporting instructions and verified boundaries, use the Security page.

11

Questions and complaints

Changes and how to contact us

We may update this policy when the service, providers, or law changes. The date at the top shows the current version. If a change materially affects how existing account information is handled, we will provide additional notice through the service or email when appropriate before the change takes effect.

Use the Contact page for privacy questions, access or correction requests, deletion requests, and complaints. Please do not send passwords, agent keys, OAuth tokens, full payment-card numbers, or unnecessary sensitive information.