Who we are and when this policy applies
Postlume is the service name used by the operator of getpostlume.com. For the personal data described here, Postlume is the data controller unless this policy says otherwise.
This policy applies to the Postlume website, account area, creative tools, AI generation features, and optional social-platform connections. It does not govern X, Instagram, Google, or another third party's own service.
Contact us about privacy at privacy@getpostlume.com.
Personal data we collect
- Account data: email address, authentication identifiers, profile details, account role, and sign-in records supplied through Google or email-link authentication.
- Creative content: images, identity-kit references, logos, brand information, prompts, text, project files, documents, layers, and generated results you submit or create.
- Service activity: generation history, selected models and presets, credit charges and refunds, feature use, timestamps, and records needed to diagnose failures.
- Technical data: IP address, browser and device details, request logs, security events, and cookies or local storage required for sessions and preferences.
- Connected-platform data: if you connect X or Instagram, the account identifier, handle, granted permissions, encrypted access credentials, eligible post text and media, publishing results, and related status or error information.
Where the data comes from
Most data comes directly from you. Authentication data comes from Google or Supabase Auth when you choose those sign-in methods. If you connect a social account, we receive only the data and permissions made available by that platform for the features you approve. Hosting and security providers also generate technical logs when you use the service.
Why we use data and our legal bases
| Purpose | Typical data | Legal basis |
|---|---|---|
| Provide your account and tools | Account, content, activity | Perform our contract with you |
| Generate and edit content | Prompts, images, brand references | Perform our contract with you |
| Connect and publish to platforms | Connection and selected post data | Your request and permission; contract where enabled |
| Protect and improve the service | Logs, errors, aggregate activity | Our legitimate interests in security and reliability |
| Billing and legal compliance | Credits, transactions, account data | Contract and applicable legal obligations |
Images, faces, and AI processing
Images may contain you or other identifiable people. Postlume uses them only to provide the tools you request, such as storing a reusable identity kit, editing an image, or sending selected references to an enabled AI model. Postlume does not use facial recognition to identify people or build biometric identity profiles.
AI requests are routed through Vercel AI Gateway to the model provider selected for the job. The request may include your prompt and the image bytes needed to produce the output. Postlume does not train its own models on your content and configures gateway routing to exclude prompt-training providers where that control is available.
International transfers
Some service providers may process data outside your country, including outside the European Economic Area. Where data-protection law requires it, we rely on an adequacy decision, standard contractual clauses, or another lawful transfer safeguard. Contact us to request more information about safeguards relevant to your data.
How long we keep data
- Account and creative data are kept while your account is active or until you delete the item or request account deletion, subject to limited backup, security, and legal-retention needs.
- Social access credentials are kept only while the connection remains active and are deleted or rendered unusable after disconnection.
- Operational and security logs are kept only for as long as reasonably needed to secure, diagnose, and operate the service.
- Transaction and credit records may be kept for tax, accounting, fraud-prevention, and dispute purposes for the period required by law.
How we protect data
Postlume uses encrypted transport, access controls, private object storage, short-lived authorized file links, row-level database access rules, and application-level encryption for connected-platform credentials. No online service can promise absolute security. Please protect access to the email or Google account you use to sign in.
Your choices and privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a copy of personal data, to object to certain processing, and to withdraw consent. Withdrawing consent does not affect processing already carried out lawfully.
Email privacy@getpostlume.com from your account email or follow our data-deletion instructions. We may need to verify that the account belongs to you. You may also complain to your local data-protection authority; in the EU, this can be the authority where you live, work, or believe an infringement occurred.
Children, changes, and contact
Postlume is not directed to children and you must be able to form a binding agreement to create an account. Do not upload a child's image unless you have the legal authority and permissions required to do so.
We may update this policy as the service changes. We will change the date above and give additional notice when a material change requires it. Questions and requests can be sent to privacy@getpostlume.com.
X and Instagram connections
Connecting a social account is optional. Postlume asks you to authorize the connection on the provider's own screen and requests only the permissions shown there. For the planned X-to-Instagram workflow, Postlume reads eligible image posts from the X account you select and publishes only the items allowed by your saved settings to the Instagram professional account you select.
Access and refresh credentials are encrypted before storage. You can withdraw access by disconnecting the account when that control is available, by revoking Postlume in the provider's settings, or by contacting us. Revocation stops future access but does not remove a post already published to a third-party service.