Privacy Policy

Last updated: June 11, 2026

1. Who we are

Postlia ("Postlia", "we", "us", "our") provides the social media publishing and analytics service available at postlia.com (the "Service"). Postlia acts as the data controller for the personal data described in this policy.

You can reach us for any privacy matter at support@postlia.com. This policy explains what personal data we collect, why we collect it, how long we keep it, who we share it with, and the rights you have over it.

This policy applies to the Service, including our free tools, the dashboard, and our integrations with third-party social platforms (LinkedIn, Bluesky, X, Instagram via the Meta Graph API, and TikTok via the TikTok Content Posting API).

2. Personal data we collect

We collect only the data needed to operate the Service:

  • Account data — your email address (and name/avatar if you sign in with Google), used to create and identify your account.
  • Social account credentials — when you connect a social account, we store the OAuth access token (and refresh token, where the platform issues one) needed to publish on your behalf. For Bluesky, this is the app password you generate in your Bluesky settings. These credentials are encrypted at rest with AES-256-GCM before being stored.
  • Connected profile data — the public account identifier, username, and display name returned by the platform during authorization (for example your TikTok username or Instagram account ID), so we can show which account is connected and publish to the correct profile.
  • Content data — the text, media files, and scheduling details of posts you create, schedule, or publish through Postlia, together with their delivery status (published, scheduled, or failed), so you can review your post history.
  • Usage and technical data — your IP address (used for rate limiting and abuse prevention on our free tools and APIs) and basic request logs collected by our hosting providers (Vercel and Supabase) for security and reliability. We also use Vercel Web Analytics, a cookieless analytics service that records anonymous, aggregated page-view statistics; it does not identify you or track you across sites.
  • Payment data — if you purchase a paid plan, payment is processed by our payment provider (e.g. Stripe or Lemon Squeezy). We never see or store your full card details; we store only your subscription status, plan, and the provider's customer/subscription identifiers.

We do not collect data from your social accounts beyond what is listed above. In particular, we do not read your timeline, followers, direct messages, contacts, or any other account content.

3. How and why we use your data (purposes & legal bases)

Under the EU/UK General Data Protection Regulation (GDPR), we rely on the following legal bases:

  • To provide the Service (Art. 6(1)(b) — contract): authenticating you, connecting your social accounts, publishing and scheduling the posts you explicitly initiate, showing your post history and analytics, and managing your subscription.
  • To secure the Service (Art. 6(1)(f) — legitimate interests): rate limiting, fraud and abuse prevention, debugging, and keeping the Service available and safe.
  • To communicate with you (Art. 6(1)(b) and (f)): sending sign-in emails (magic links, password resets) and important service announcements. We do not send marketing emails.
  • To comply with legal obligations (Art. 6(1)(c)): tax and accounting requirements related to paid subscriptions.

We do not use your data for advertising, we do not build advertising profiles, and we do not sell or rent personal data to anyone.

4. Platform data (TikTok, Meta/Instagram, LinkedIn, X, Bluesky)

When you connect a social platform, we access only the permissions (scopes) you grant during the platform's consent screen, and we use that access exclusively to (a) publish the content you create in Postlia to the account you choose, and (b) display your connected account's username/display name inside the Service.

Specifically for TikTok: we use the TikTok Content Posting API solely to upload and publish the videos and captions you explicitly submit, and the basic profile fields (username, display name, avatar) to identify the connected account. We do not access your followers, likes, comments, messages, or watch history. We never use TikTok platform data for advertising or profiling, never sell it, and never share it with third parties except the processors listed in section 6.

Specifically for Instagram (Meta Graph API): we use the granted permissions only to publish the content you create and to retrieve your basic profile (username and account ID). Our use of Meta platform data adheres to the Meta Platform Terms.

Our use of data received from each platform complies with that platform's developer terms, including the TikTok Developer Terms of Service and Community Guidelines. You can revoke Postlia's access at any time from the platform's own security settings, or by disconnecting the account inside Postlia — disconnecting immediately and permanently deletes the stored credentials for that platform.

5. How long we keep data (retention)

  • Social account credentials — kept until you disconnect the account or delete your Postlia account, at which point they are deleted immediately.
  • Post history and media — kept while your account is active so you can review it; deleted within 30 days of account deletion.
  • Account data (email) — kept while your account exists; deleted within 30 days of account deletion.
  • Rate-limiting/abuse logs (IP addresses) — automatically expire within 30 days.
  • Billing records — kept for the period required by tax and accounting law.

6. Who we share data with (processors)

We share personal data only with the service providers (processors) needed to run Postlia, under data processing agreements:

  • Supabase (database, authentication, file storage) — hosted on AWS in the US-East region.
  • Vercel (application hosting and content delivery).
  • Resend (transactional email — sign-in links and password resets sent from noreply@postlia.com).
  • Anthropic (AI features — when you use an AI tool such as the caption generator, the text you submit is sent to the Anthropic API to generate the result; it is not used to train models).
  • Our payment provider (e.g. Stripe or Lemon Squeezy) — subscription billing.
  • The social platforms you connect (LinkedIn, Bluesky, X, Meta/Instagram, TikTok) — to deliver the posts you initiate.

We do not share, sell, or rent personal data to data brokers, advertisers, or any other third parties.

7. International transfers

Our infrastructure providers store data in the United States (Supabase/AWS US-East; Vercel's global network). Where personal data of EU/UK residents is transferred outside the EEA/UK, we rely on the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework certifications of our providers.

8. Security

All traffic to and from the Service is encrypted in transit with TLS. Social access tokens and app passwords are encrypted at rest with AES-256-GCM using keys held outside the database, in addition to the disk-level encryption provided by our hosting providers.

Database access is protected by row-level security, so your data is only readable by your own authenticated session. Webhooks and internal endpoints are authenticated with signed secrets. We follow the principle of least privilege for all platform permissions we request.

No system is perfectly secure; if we become aware of a personal data breach affecting you, we will notify you and the competent supervisory authority as required by law.

9. Your rights

Depending on where you live (including under the GDPR and the California Consumer Privacy Act), you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — delete your account and all associated data ("right to be forgotten").
  • Portability — receive your data in a structured, machine-readable format.
  • Restriction & objection — limit or object to certain processing.
  • Withdraw consent — at any time, where processing is based on consent (e.g. by disconnecting a social account).
  • Non-discrimination — we will never penalize you for exercising your rights.

To exercise any of these rights, email support@postlia.com — we respond within 30 days. You also have the right to lodge a complaint with your local data protection authority. If you are in the EU, this is the supervisory authority of your member state.

10. Data deletion

Disconnect a social account — from Settings in your dashboard at any time; this immediately deletes the stored credentials and access tokens for that platform.

Revoke access at the platform — you can also revoke Postlia's access from your LinkedIn, X, Instagram/Facebook, or TikTok account security settings, or by deleting the app password in your Bluesky settings.

Delete your account — email support@postlia.com from your account email and we will delete your account and all associated data within 30 days, except billing records we must keep by law.

11. Cookies

Postlia uses only strictly necessary, first-party cookies: the authentication session cookies set by Supabase Auth that keep you signed in. Your light/dark theme and cookie-banner choice are stored in your browser's local storage. We do not use advertising or cross-site tracking cookies. Page-view statistics are collected by Vercel Web Analytics, which is cookieless and anonymous (see section 2).

12. Children

The Service is not directed at children and may not be used by anyone under 16 years of age (or the higher minimum age required by the social platforms you connect). We do not knowingly collect personal data from children; if you believe a child has provided us personal data, contact support@postlia.com and we will delete it.

13. Changes to this policy

We may update this policy as the product evolves. We will post the updated version on this page with a new "Last updated" date, and for material changes we will notify you by email before they take effect.

14. Contact

For any question, concern, or request about this policy or your personal data, contact us at support@postlia.com.

Questions or privacy requests? Email us at support@postlia.com