Poststacks

Privacy Policy

Effective date: July 7, 2026

This Privacy Policy explains what data Poststacks collects, why, and how it's handled when you use Poststacks ("we", "us") to plan, draft, and publish content.

1. Information we collect

Account information. When you sign up, our authentication provider, Clerk, collects your name, email address, and (if you use it) your profile photo and social sign-in identifiers. We receive your Clerk user ID and profile details to associate them with your Poststacks account.

Brand and content data. Everything you create in Poststacks — brand kits, research, drafts, hooks, scripts, storyboards, notes, and scheduling data — is stored in our database (Convex) under your account.

YouTube data.If you connect a YouTube channel, we request access via Google's OAuth to read channel and video metadata (titles, descriptions, thumbnails, analytics) needed to power research, publishing, and analytics features, and to publish videos on your behalf when you ask us to. We only request the scopes we need, and you can revoke access at any time from Settings or from your Google Account permissions page. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We retain YouTube data only as long as your account is connected and active, and delete it within 30 days of disconnecting the account or closing your Poststacks account, except where retention is required by law.

Usage data. We collect basic technical data (device/browser info, pages visited, error logs) to keep the service reliable and secure.

2. AI processing

Poststacks uses AI models from OpenAI, Anthropic, and Google to generate and assist with titles, hooks, scripts, thumbnails, and other content on your behalf. When you use these features, relevant portions of your content are sent to the selected provider to produce a result, which is then stored back in your account. If you configure your own API keys (bring-your-own-key), requests go directly to that provider under its own terms. We don't use your content to train our own models, and we select providers that commit not to train on API-submitted data.

3. How we use your information

  • To operate and improve Poststacks's core features (drafting, scheduling, publishing, analytics).
  • To authenticate you and keep your account secure.
  • To communicate with you about your account, changes to the service, or support requests.
  • To diagnose and fix bugs, and to prevent abuse.

4. What we don't do

We do not sell your personal information or Your Content to third parties. We don't share it with advertisers. We share data only with the service providers described above (Clerk, Convex, Google/YouTube, OpenAI, Anthropic) strictly to operate the features you use, and with law enforcement only where legally required.

5. Data retention & deletion

We retain your account data for as long as your account is active. If you delete your account, we delete your brand, content, and connected-account data within 30 days, except for records we're required to keep for legal, security, or billing reasons. You can request an export or deletion of your data at any time by emailing us.

6. Security

We use industry-standard practices — encrypted transport, access controls, and scoped API credentials — to protect your data. No system is perfectly secure, and we can't guarantee absolute security, but we work to keep Poststacks safe.

7. Your choices

You can review, update, or delete your account information from Settings, disconnect any connected platform at any time, and request a copy or deletion of your data by contacting us below.

8. Changes to this policy

We may update this policy as Poststacks changes. Material changes will be announced in the app or by email before they take effect.

9. Contact

Questions about this policy or your data? Reach us at safarumedia@gmail.com.