Privacy Policy
Last updated: June 26, 2026
1. Who We Are
Postezi is operated by ByteMind, SIA, a company registered in Latvia (Registration No. 40203626917). This Privacy Policy explains how we collect, use, store, and share your personal data when you use our Service. For questions, contact us at info@bytemind.lv.
2. Data We Collect
Account and authentication data
- Email address (used for magic link sign-in and account communications)
- API keys (stored as a SHA-256 hash and AES-256-GCM encrypted copy)
- Session tokens (JWT, expire after 30 days)
Workspace and team data
- Workspace name, slug, and settings
- Team member roles and permissions
- Default tone preferences
Connected social media accounts
- OAuth access and refresh tokens for Bluesky, LinkedIn, Threads, and X/Twitter (stored AES-256-GCM encrypted)
- Platform username and account ID
- Connection and token expiry timestamps
Content and post data
- Post content, target platforms, and scheduling information
- Media files (uploaded to Cloudflare R2; stored by original name, MIME type, and size)
- Post status, publish results, and failure reasons
GitHub integration data
- GitHub OAuth access token (encrypted) and user login
- Connected repository names and webhook secrets
- Repository event payloads (processed transiently to generate drafts; not stored long-term)
Billing data
- Subscription plan, status, and billing period
- Creem customer ID and subscription ID
- Payment information is handled entirely by Creem and is never stored on our servers
Technical and usage data
- API key usage timestamps
- Webhook endpoint URLs and event subscriptions
- Basic server logs (request path, status code, duration)
3. How We Use Your Data
- To authenticate you and maintain your session
- To publish, schedule, and manage posts on connected social media platforms on your behalf
- To generate AI-assisted content drafts from your instructions or GitHub events
- To process subscription payments and manage your billing relationship
- To send transactional emails (sign-in links, account notifications) via Resend
- To operate and improve the Service
- To comply with legal obligations
4. Legal Basis for Processing (GDPR)
If you are in the European Economic Area, we process your data under the following legal bases:
- Contract — processing necessary to provide the Service you have subscribed to
- Legitimate interests — security logging, fraud prevention, and service improvement
- Legal obligation — compliance with applicable laws
5. Third-Party Services
We share data with the following third parties only as necessary to provide the Service:
- Creem — payment processing and subscription management. Creem processes your payment card details under their own privacy policy.
- Resend — transactional email delivery (sign-in links). Your email address is shared with Resend solely to deliver emails you request.
- Cloudflare R2 — media file storage. Files you upload are stored in Cloudflare's infrastructure.
- Anthropic Claude — AI content generation. Post content and GitHub event data you submit for AI drafting is sent to Anthropic's API. Anthropic's data usage policies apply.
- Upstash QStash — task scheduling for delayed post publication. Minimal payload data (post ID, workspace ID) is transmitted.
- Social media platforms — LinkedIn, Bluesky, Threads, X/Twitter. Content and OAuth tokens are shared with these platforms as required to publish on your behalf.
We do not sell your personal data to any third party.
6. Data Retention
- Magic link tokens expire after 15 minutes
- Session tokens expire after 30 days
- Account and content data is retained for as long as your account is active
- Upon account deletion, all personal data including posts, connected accounts, workspaces, and API keys is permanently deleted from our systems
- Server logs are retained for a maximum of 90 days
7. Data Security
We implement the following technical safeguards:
- All OAuth tokens and API keys are encrypted at rest using AES-256-GCM
- API keys are additionally hashed with SHA-256 for verification
- All data in transit is protected with TLS/HTTPS
- Session cookies are set with HttpOnly and SameSite=Lax flags
Despite these measures, no system is completely secure. Please notify us immediately at info@bytemind.lv if you believe your account has been compromised.
8. Your Rights (GDPR)
If you are in the European Economic Area, you have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you
- Rectification — request correction of inaccurate data
- Erasure — request deletion of your data (you can also do this directly via Settings → Delete Account)
- Portability — request your data in a structured, machine-readable format
- Objection — object to processing based on legitimate interests
- Restriction — request that we restrict processing of your data
To exercise any of these rights, email info@bytemind.lv. We will respond within 30 days. You also have the right to lodge a complaint with the Latvian Data State Inspectorate (Datu valsts inspekcija) at www.dvi.gov.lv.
9. Cookies
We use a single session cookie (next-auth.session-token) to maintain your authenticated session. This cookie is essential for the Service to function and does not track you across third-party websites. We do not use advertising or analytics cookies.
10. Children's Privacy
The Service is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe we have inadvertently collected such data, contact us at info@bytemind.lv and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or via an in-app notice at least 14 days before they take effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
12. Contact and Data Controller
The data controller for your personal data is:
ByteMind, SIA
Registration No. 40203626917
Latvia