Privacy Policy
Last updated: 26 August 2026
This Privacy Policy explains how POST-BASE ("POST-BASE", "we", "us") collects, uses, and protects your information when you use our website at post-base.com and our cross-posting application (the "Service").
1. Information we collect
We collect the following categories of information:
- Account information — your name, email address, and the social accounts you connect.
- Content you create — post text, uploaded images/videos, captions, schedules, and templates.
- Usage data — how you interact with the Service, device and browser type, and log data.
- Payment information — handled entirely by our payment provider (see Section 4). We do not store your full card details.
- Cookies & local storage — used to keep you signed in and to store your drafts and settings locally in your browser.
2. How we use your information
- To provide, operate, and maintain the Service (scheduling and cross-posting to your connected platforms).
- To generate AI captions, images, and videos that you request.
- To process payments and subscriptions.
- To communicate with you about your account, security, and updates.
- To improve the Service and prevent fraud or abuse.
3. AI & third-party processors
To deliver certain features, content you submit may be sent to trusted third-party processors strictly to perform the requested task:
- OpenAI — to generate AI captions from your prompt or link.
- fal.ai — to generate AI images and videos from your prompt.
- Supabase — to store your posts and generated media.
- Netlify — to host the Service.
- Post for Me — the publishing aggregator behind most platform connections (Instagram, TikTok, TikTok Business, Facebook, YouTube, LinkedIn, Pinterest). You authorize those platforms through Post for Me's hosted OAuth screen, and Post for Me — not POST-BASE — holds the resulting platform access credentials. We keep only a lightweight mirror of each connection (platform, handle, display name, profile photo URL, and Post for Me's account id) — never a credential. Your post text and media are sent to Post for Me so it can publish them to the accounts you selected.
- Sentry — error tracking, so we can diagnose failures in the app and on our servers (see Section 3.1).
- PostHog — product analytics, so we can see which features are used (see Section 3.1).
- Google Drive — only if you use the optional "Import from Drive" feature (see Section 3.2).
These providers process data on our behalf under their own security and privacy commitments. API keys are held only on our servers and are never exposed to your browser.
POST-BASE's AI features are powered by third-party models (OpenAI and fal.ai). POST-BASE is an independent product and is not affiliated with, sponsored by, or endorsed by OpenAI or fal.ai.
3.1 Error tracking & product analytics (Sentry, PostHog)
When these tools are enabled, we send them your pseudonymous account identifier only — the random user id issued by Supabase — together with the error details or the name of a product event (for example "post created" or "account connected"). We do not send your name, email address, post text, captions, or media to Sentry or PostHog, and browser error reporting runs with automatic personal-data collection switched off. Both tools are optional: if they are not configured, their code is never loaded and nothing is sent to them at all.
3.2 Google Drive import (optional)
If you use "Import from Drive", you sign in with Google in your browser and pick individual files in the Google Picker. We request only the narrow drive.file scope, which grants access to the files you explicitly select — never to your whole Drive. The short-lived Google access token stays in that browser tab and is never sent to, or stored on, our servers; we hold no Google refresh token and no listing of your Drive. Your browser reads each selected file and uploads it directly to Post for Me for publishing, and a small thumbnail is sent to OpenAI so it can draft a caption.
4. Payments (Creem)
Our order process and payments are conducted by our online reseller and Merchant of Record, Creem (operated by Armitage Labs OÜ, Estonia). Creem handles your payment, billing, invoicing, and related customer queries, and may collect billing details (name, billing address, payment method, and tax/VAT information) in accordance with its own privacy policy, available on the Creem website (creem.io).
5. Cookies and local storage
We use essential cookies and browser local storage to keep the application working — for example, to remember your session, drafts, connected accounts, and preferences. You can clear this data at any time from your browser settings; doing so may sign you out and remove unsynced drafts.
6. Data retention
We retain your information for as long as your account is active or as needed to provide the Service. You may request deletion of your account and associated data at any time by contacting us.
7. Your rights
Depending on your location (including under the GDPR and CCPA), you may have the right to access, correct, export, restrict, or delete your personal data, and to object to certain processing. To exercise these rights, email info@post-base.com.
8. Data security
We use industry-standard measures to protect your data, including encryption in transit (HTTPS) and server-side handling of all third-party credentials. No method of transmission is 100% secure, but we work to protect your information.
9. International transfers
Your information may be processed in countries other than your own. Where required, we rely on appropriate safeguards for such transfers.
10. Children
The Service is not directed to children under 16, and we do not knowingly collect their data.
11. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date above reflects the latest revision. Continued use of the Service after changes constitutes acceptance.
12. Contact
Questions about this policy? Email us at info@post-base.com.