Effective date: June 5, 2026
Privacy Policy
Your privacy matters. This policy explains what data PostBuzz collects, how we use it, and your rights.
1. Who We Are
PostBuzz is operated by PostBuzz LLC (“we”, “us”, “our”), a social media management platform located at 100 N Howard St #7024, Spokane, WA 99201, United States. For data protection purposes, PostBuzz LLC is the data controller for personal data processed through the Service. PostBuzz acts as a data processor for social content you manage or publish through the platform. Queries about your personal data should be directed to support@postbuzz.ai.
2. Data We Collect
2.1 Account and Identity Data
When you create an account we collect your name, email address, profile picture (if provided), and authentication credentials managed by our identity provider (Clerk). If you sign in via an organisation, we also associate your account with that organisation. We may also collect browser type, device info, and IP address for security purposes.
2.2 Workspace and Content Data
We store content you create within the Service, including campaign briefs, AI-generated drafts, scheduled posts, published posts, images, and associated metadata. This data is scoped to your workspace and organisation.
2.3 LinkedIn Profile Data (Personal Brand Reports)
If you choose to generate a Personal Brand Report, you will be asked to provide your LinkedIn profile URL and give explicit consent. We will then retrieve your publicly accessible LinkedIn profile information (name, headline, about section, experience, recent posts) from LinkedIn via a third-party data provider (Apify). This data is processed solely to generate your brand voice document. Raw scraped payload data is automatically purged once your brand voice has been created, or within 30 days of report creation. You may delete your brand voice and the underlying report at any time from your organisation settings, which triggers irreversible deletion of associated data.
2.4 Connected Social Media Account Tokens
To publish content on your behalf, we store OAuth access tokens for the social media accounts you connect. Tokens are encrypted at rest using AES-256-GCM and are never returned in API responses or logged. We access your social accounts only to perform actions you explicitly authorise (publishing posts, retrieving analytics). You can revoke access at any time using your connected platform's OAuth settings.
2.5 AI Processing (Google Gemini)
When you use AI-powered features (content generation, brand voice creation), your prompts and campaign context are sent to our AI subprocessor — Google (Gemini models) — solely for the purpose of generating your requested content. We do not use this data for training AI models. The provider is contractually bound to our data protection standards. See Section 4 for the full subprocessor list.
2.6 Usage and Analytics Data
We collect information about how you use the Service, including feature interactions, error logs, and performance metrics. This is used to improve the Service and diagnose issues. We use PostHog for product analytics (configured to respect Do Not Track signals) and Sentry for error monitoring.
2.7 Payment Data
Payment card details are processed directly by Stripe. We do not store card numbers. We retain billing records (amounts, dates, subscription status) necessary to manage your subscription and comply with financial regulations.
3. How We Use Your Data
We process your personal data to:
- Provide, operate, and improve the Service;
- Authenticate your identity and maintain account security;
- Process and publish content to connected social media platforms on your explicit instruction;
- Generate AI-powered content and brand voice documents (with your consent where required);
- Send transactional emails (account creation, workflow notifications, billing) via Resend;
- Investigate abuse, enforce our Terms of Service, and comply with legal obligations;
- Conduct aggregate, anonymised analytics to understand product usage.
Our legal bases under the GDPR are: contract performance (providing the Service), legitimate interests (product improvement, security), and consent (LinkedIn profile data collection for Personal Brand Reports, Google OAuth scope authorisation).
4. Subprocessors
We use the following third-party subprocessors to deliver the Service. Each has been assessed for data protection compliance:
| Subprocessor | Purpose | Location |
|---|---|---|
| Clerk | Authentication and user identity | USA |
| Supabase | Managed PostgreSQL database hosting | USA / EU |
| Google (Gemini) | AI content generation | USA |
| Apify | LinkedIn profile data retrieval (with explicit consent) | Czech Republic / USA |
| Stripe | Payment processing and subscription billing | USA |
| Resend | Transactional email delivery | USA |
| Vercel | Application hosting and edge infrastructure | USA / Global CDN |
| Sentry | Error monitoring and diagnostics | USA |
| PostHog | Product analytics (anonymised usage) | USA / EU |
| Upstash | Redis cache and rate limiting | USA / EU |
| Cloudflare | CDN, DDoS protection, and R2 object storage | USA / Global |
5. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. Specific retention periods:
- Account data — retained until account deletion plus 30 days for backup purge cycles;
- LinkedIn scrape payload (raw) — deleted automatically once brand voice generation is complete, or within 30 days of report creation;
- Published post records — retained for the lifetime of your workspace to support analytics continuity;
- Billing records — retained for 7 years as required by financial regulations;
- Error and audit logs — retained for 90 days;
- Inactive accounts — after 24 months of inactivity (no login or service usage) we may delete account data.
6. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access — request a copy of the personal data we hold about you. You can export your data directly from the app (Settings → Export My Data), which produces a structured JSON file;
- Rectification — request correction of inaccurate data. Profile fields can be updated directly in Settings;
- Erasure — request deletion of your personal data. Account deletion can be initiated by contacting support@postbuzz.ai. We will hard-delete your record (including personal brand reports) within 30 days;
- Restriction — request that we restrict processing of your data in certain circumstances;
- Portability — receive your data in a structured, machine-readable format (use the in-app export);
- Objection — object to processing based on legitimate interests;
- Withdraw consent — where processing is based on consent (e.g. LinkedIn data, Google OAuth), you may withdraw consent at any time by deleting your Personal Brand Report in Org Settings, or revoking OAuth access via the platform's own settings.
To exercise any of these rights, contact us at support@postbuzz.ai. We will respond within 30 days.
7. Google API Services Disclosure
PostBuzz integrates with Google APIs, including YouTube, for secure sign-in and publishing capabilities. We comply with the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google API data for advertising or resale. It is used only to provide user-facing features you have explicitly enabled.
8. International Data Transfers
We and our subprocessors are based in or transfer data to the United States and other jurisdictions. By using our services, you consent to the processing and transfer of your personal data to the United States. For users in the EEA, UK, or Switzerland, where required by applicable law, we rely on Standard Contractual Clauses (SCCs) or other approved mechanisms for international data transfers.
9. Security
We implement technical and organisational measures to protect your personal data, including TLS encryption in transit, AES-256-GCM encryption for OAuth tokens at rest, role-based access controls, application-layer workspace isolation that scopes every data access to your organisation, and regular security monitoring. No security measure is perfect; we will notify you of any breach that is required to be reported under applicable law.
10. Cookies and Tracking
We use session cookies and localStorage for authentication and user preferences. We do not use third-party advertising cookies. PostHog analytics is configured to respect Do Not Track signals and uses anonymised identifiers where possible. You can control cookie behaviour through your browser settings.
11. Children's Privacy
The Service is not directed at children under 13. We do not knowingly collect personal data from anyone under 13 without verifiable parental consent. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
12. Third-Party Sharing
We do not sell or share your personal data with third parties for advertising purposes. We engage subprocessors (listed in Section 4) who are contractually bound to meet our data security standards. You may request a full list of our authorised subprocessors by emailing support@postbuzz.ai.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you by email or by a notice in the app at least 14 days before material changes take effect. The current version is always available at https://postbuzz.ai/privacy.
14. Contact and Complaints
For privacy-related enquiries, contact us at support@postbuzz.ai. If you are in the EEA and believe we have not addressed your concern, you have the right to lodge a complaint with your local data protection supervisory authority.
PostBuzz LLC
100 N Howard St #7024, Spokane, WA 99201, United States
© 2026 PostBuzz LLC. All rights reserved.