Postlume legal

Privacy Policy

This policy explains what Postlume receives, why we use it, who helps us process it, and the choices you have.

Effective and last updated: 11 September 2026

Who we are and when this policy applies

Postlume is the service name used by the operator of getpostlume.com. For the personal data described here, Postlume is the data controller unless this policy says otherwise.

This policy applies to the Postlume website, account area, creative tools, AI generation features, and optional social-platform connections. It does not govern X, Instagram, Google, or another third party's own service.

Contact us about privacy at privacy@getpostlume.com.

Personal data we collect

  • Account data: email address, authentication identifiers, profile details, account role, and sign-in records supplied through Google or email-link authentication.
  • Creative content: images, identity-kit references, logos, brand information, prompts, text, project files, documents, layers, and generated results you submit or create.
  • Service activity: generation history, selected models and presets, credit charges and refunds, feature use, timestamps, and records needed to diagnose failures.
  • Technical data: IP address, browser and device details, request logs, security events, and cookies or local storage required for sessions and preferences.
  • Connected-platform data: if you connect X or Instagram, the account identifier, handle, granted permissions, encrypted access credentials, eligible post text and media, publishing results, and related status or error information.

Where the data comes from

Most data comes directly from you. Authentication data comes from Google or Supabase Auth when you choose those sign-in methods. If you connect a social account, we receive only the data and permissions made available by that platform for the features you approve. Hosting and security providers also generate technical logs when you use the service.

Why we use data and our legal bases

PurposeTypical dataLegal basis
Provide your account and toolsAccount, content, activityPerform our contract with you
Generate and edit contentPrompts, images, brand referencesPerform our contract with you
Connect and publish to platformsConnection and selected post dataYour request and permission; contract where enabled
Protect and improve the serviceLogs, errors, aggregate activityOur legitimate interests in security and reliability
Billing and legal complianceCredits, transactions, account dataContract and applicable legal obligations

Images, faces, and AI processing

Images may contain you or other identifiable people. Postlume uses them only to provide the tools you request, such as storing a reusable identity kit, editing an image, or sending selected references to an enabled AI model. Postlume does not use facial recognition to identify people or build biometric identity profiles.

AI requests are routed through Vercel AI Gateway to the model provider selected for the job. The request may include your prompt and the image bytes needed to produce the output. Postlume does not train its own models on your content and configures gateway routing to exclude prompt-training providers where that control is available.

X and Instagram connections

Connecting a social account is optional. Postlume asks you to authorize the connection on the provider's own screen and requests only the permissions shown there. For the planned X-to-Instagram workflow, Postlume reads eligible image posts from the X account you select and publishes only the items allowed by your saved settings to the Instagram professional account you select.

Access and refresh credentials are encrypted before storage. You can withdraw access by disconnecting the account when that control is available, by revoking Postlume in the provider's settings, or by contacting us. Revocation stops future access but does not remove a post already published to a third-party service.

Who processes data for us

We share data only as needed with these categories of recipients:

  • Vercel for application hosting and AI Gateway routing.
  • Supabase for authentication and database services.
  • Cloudflare for private image and file storage.
  • Enabled AI model providers for the specific generation or editing job you request.
  • Google, X, and Meta when you choose their authentication or connected-platform features.
  • Professional advisers, authorities, or a successor to the service when disclosure is legally required or reasonably necessary.

We do not sell personal data and do not share it for cross-context behavioural advertising.

International transfers

Some service providers may process data outside your country, including outside the European Economic Area. Where data-protection law requires it, we rely on an adequacy decision, standard contractual clauses, or another lawful transfer safeguard. Contact us to request more information about safeguards relevant to your data.

How long we keep data

  • Account and creative data are kept while your account is active or until you delete the item or request account deletion, subject to limited backup, security, and legal-retention needs.
  • Social access credentials are kept only while the connection remains active and are deleted or rendered unusable after disconnection.
  • Operational and security logs are kept only for as long as reasonably needed to secure, diagnose, and operate the service.
  • Transaction and credit records may be kept for tax, accounting, fraud-prevention, and dispute purposes for the period required by law.

How we protect data

Postlume uses encrypted transport, access controls, private object storage, short-lived authorized file links, row-level database access rules, and application-level encryption for connected-platform credentials. No online service can promise absolute security. Please protect access to the email or Google account you use to sign in.

Cookies and local storage

We use cookies needed to maintain your authenticated session and save functional choices such as the sidebar state. Local storage remembers choices such as theme and tool preferences. Postlume does not currently use advertising cookies or third-party behavioural advertising trackers.

Your choices and privacy rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a copy of personal data, to object to certain processing, and to withdraw consent. Withdrawing consent does not affect processing already carried out lawfully.

Email privacy@getpostlume.com from your account email or follow our data-deletion instructions. We may need to verify that the account belongs to you. You may also complain to your local data-protection authority; in the EU, this can be the authority where you live, work, or believe an infringement occurred.

Children, changes, and contact

Postlume is not directed to children and you must be able to form a binding agreement to create an account. Do not upload a child's image unless you have the legal authority and permissions required to do so.

We may update this policy as the service changes. We will change the date above and give additional notice when a material change requires it. Questions and requests can be sent to privacy@getpostlume.com.