Legal and trust · Privacy

Privacy policy

This policy explains the information Postdom needs to run an authorized social schedule, who receives it, and the controls available to you.

Effective
29 August 2026
Last updated
3 September 2026

Plain-language summary

The short version

01

Scope and operator

Who this policy covers

This policy applies to postdom.com, the Postdom web app, Postdom APIs and MCP tools, lifecycle emails, and the support or commercial conversations connected with those services. Blue Venture Studios Pty Ltd operates Postdom and is responsible for personal information when it decides why and how that information is used.

A workspace customer may also control personal information placed into Postdom by its members, agents, or connected accounts. In that situation, the customer is responsible for its own notices, permissions, and lawful instructions, and Postdom handles the information to provide the service.

Social networks, payment services, and other third-party products have their own privacy practices when they act independently. This policy does not replace theirs.

02

Data map

Information we handle

The information depends on how you use Postdom. We collect what is needed to create and secure a workspace, carry out authorized publishing, return evidence, bill the workspace, and operate the service.

Information categories
CategoryExamplesWhy it is needed
Account and workspaceEmail address, user ID, workspace name, role, invitations, sign-in and workspace selection state.Authenticate people, assign workspace access, and keep tenants separated.
Connected accountsPlatform, account handle, provider and platform identifiers, connection status, timezone, and authorization version.Show the correct destination and execute authorized account actions. Postdom does not ask for or store your social-network password.
Content and operationsCaptions, uploaded video, source URLs, schedules, plans, workspace briefs, agent identity and intent, approvals, account policy, publish outcomes, URLs, metrics, and webhook records.Schedule and publish customer content, enforce human authority, recover work safely, and report what happened.
BillingPlan, subscription status, Stripe customer and subscription identifiers, billing period, usage, and successful destination-publish meter records.Provide paid plans, enforce capacity, reconcile billing, and support transactions. Stripe collects payment-card details; Postdom does not store full card numbers.
Device and service activityIP address, request time, route, status, browser or device details, security and rate-limit signals, cookie choice, and diagnostic logs.Deliver, secure, troubleshoot, and improve the service.
CommunicationsMessages sent through Contact, support history, workspace notification preferences, delivery status, and the email content needed for a service notification.Respond to requests and send operational messages chosen by the workspace.
03

Sources

How information reaches Postdom

We receive information directly when you sign up, create or join a workspace, configure policy, submit content, choose a plan, change notification settings, or contact us. Workspace owners, administrators, members, and authorized agents may also provide information for the workspace.

We receive connected-account identifiers, publish outcomes, and available measurements through Zernio and the social networks you direct Postdom to use. Stripe returns subscription and usage events. Service infrastructure produces security, availability, and diagnostic records. Google Analytics and PostHog receive public-site usage data only after analytics consent.

  • We do not buy consumer data lists.
  • We do not run third-party advertising on Postdom.
  • We do not use customer content to train a general-purpose AI model.
04

Purpose and basis

Why we use information

We use information only for the purposes below or for a compatible purpose that is reasonably expected and permitted by law. Where a law requires a legal basis, the basis depends on the activity.

Purposes and legal bases
PurposeWhat this includesBasis where required
Provide the serviceAuthentication, workspaces, account connection, scheduling, publishing, outcomes, measurement, webhooks, notifications, and billing.Performing the service contract or taking requested pre-contract steps.
Keep Postdom safeAccess control, tenant isolation, rate limiting, abuse detection, fraud prevention, audit evidence, incident response, and enforcing terms.Legitimate interests in secure operations and, where applicable, legal obligations.
Support and improveResponding to requests, diagnosing failures, measuring reliability, and improving workflows and documentation.Contract performance and legitimate interests in operating a useful service.
Public-site analyticsUnderstanding consented visits, page use, and marketing-form completion through Google Analytics and PostHog.Consent. You can reject or change this choice at any time.
Comply and protectAccounting, tax, legal process, regulator requests, disputes, and protecting people, Postdom, or the public.Legal obligation and legitimate interests in establishing or defending rights.
05

Service providers

Where information is shared

Postdom shares information only as needed to provide a feature you requested, operate the service, meet a legal obligation, or complete a business transaction. The exact information sent depends on the feature. Providers may also handle limited account or technical data under their own terms when they act independently.

We may also disclose information if required by law or valid legal process, to investigate harm or misuse, with professional advisers under confidentiality, or as part of a merger, financing, reorganization, or sale subject to appropriate protections.

Current provider map
ProviderRoleInformation involved
SupabaseAuthentication and relational data infrastructure.Account identity, workspace records, operational records, and access state.
Vercel and RailwayWeb delivery, API hosting, background processing, and rate-limit infrastructure.Requests, service data needed for processing, IP addresses, and operational logs.
Cloudflare R2Private object storage and delivery for uploaded media.Video files, object identifiers, content type, size, checksum or ETag, and processing state.
ZernioConnected-account authorization, social publishing, provider outcomes, and available metrics.Connected-account identifiers, content and media needed to publish, destination settings, schedules, post identifiers, outcomes, and metrics.
Social networksThe destinations you select, such as TikTok, Instagram, and YouTube.Content, publishing settings, account authorization, and any data the destination requires or returns.
StripeCheckout, recurring subscriptions, billing portal, fraud controls, and metered overage.Contact and transaction information, plan, customer and subscription IDs, successful overage events, and payment details supplied directly to Stripe.
PostmarkLifecycle and action-required email.Recipient email, message type, limited event context, and delivery status. Open and link tracking are disabled for Postdom lifecycle email.
Google AnalyticsOptional analytics on the public website.Browser, device, page, referral, approximate location, cookie, and interaction data after consent.
PostHogOptional product analytics on the public website, hosted in the European Union. Session replay is not enabled.Browser, device, page, referral, campaign parameters, and named marketing events after consent.
06

Global processing

International data handling

Postdom and its providers may process information in Australia, the United States, the European Economic Area, and other places where the relevant provider or social network operates. Zernio states that its operation and data processing are in Europe; other providers use regional or global infrastructure.

Privacy protections can differ between countries. Where required, we use contractual, technical, and organizational safeguards for international handling. A provider may also be legally required to disclose information in the country where it operates.

07

Lifecycle

Retention and deletion

We keep information while a workspace is active and for as long as it is reasonably needed to deliver the service, maintain publishing and billing evidence, protect security, resolve disputes, and meet tax, accounting, or other legal obligations. Retention therefore varies by record type and context.

Revoking a workspace key or OAuth grant stops future access but may leave hashed identifiers and audit evidence. Disconnecting a social account stops Postdom from using that connection; Zernio and the social network apply their own deletion and retention processes to information they control. Backups and immutable security or financial records may take longer to expire or may need to be kept by law.

You can request workspace or personal-data deletion through Contact. We will verify authority, then delete or de-identify information that is no longer required, while explaining any information we must retain.

08

Control

Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, restrict, or receive personal information, object to certain processing, or withdraw consent. You may also complain to a privacy regulator. These rights can be limited where another person's rights, legal privilege, security, fraud prevention, or a legal retention duty applies.

Start with the Contact page and identify the workspace and request. We may verify your identity and workspace authority before acting. We will respond within the period required by applicable law and explain if we cannot complete all or part of a request.

Workspace administrators can update many operational settings directly. You can withdraw public-site analytics consent from Cookie settings in the footer. Withdrawing consent does not affect processing already carried out lawfully.

  • For access or correction, describe the information and the correction you believe is needed.
  • For deletion or portability, identify the workspace and whether the request covers membership, content, connected accounts, or the entire workspace.
  • For a privacy complaint, describe what happened and the outcome you want. We will investigate and respond; if you remain dissatisfied, you may contact the OAIC in Australia or the relevant authority where you live.
09

Browser storage

Cookies and analytics

The public site stores postdom_cookie_consent for up to one year so it can remember whether optional analytics were accepted or rejected. Google Analytics and PostHog do not load unless you accept, and withdrawing consent stops both. You can reopen Cookie settings from the footer and change your choice.

The authenticated app uses cookies that are necessary to maintain the Supabase sign-in session and remember the selected Postdom workspace. Disabling necessary cookies can prevent sign-in or workspace functions from working.

10

Protection

Security and incidents

Postdom uses layered access controls, workspace scoping, hashed agent credentials and OAuth tokens, provider signature checks, private media storage, rate limits, and audit records. No online service can guarantee absolute security.

Keep sign-in links, agent keys, OAuth grants, and connected devices secure. Revoke access you no longer recognize and contact us promptly if you suspect misuse. For current reporting instructions and verified boundaries, use the Security page.

11

Questions and complaints

Changes and how to contact us

We may update this policy when the service, providers, or law changes. The date at the top shows the current version. If a change materially affects how existing account information is handled, we will provide additional notice through the service or email when appropriate before the change takes effect.

Use the Contact page for privacy questions, access or correction requests, deletion requests, and complaints. Please do not send passwords, agent keys, OAuth tokens, full payment-card numbers, or unnecessary sensitive information.