Privacy policy
Last updated: July 2026
This explains what we do with your data. Postmstr is run from the UK, and we are the data controller for everything described here. If you want anything doing with your data — a copy, a correction, a deletion — email hello@postmstr.com.
What we collect
- Your email address, so you can log in and we can reach you about your account.
- Your password, stored scrambled (hashed). We cannot see it, and neither can anyone who reads our database.
- Your business details — business name, what you do, and anything else you fill in on your profile, such as tone of voice, your customers, or your location.
- The posts we generate, along with anything you edit, schedule or mark as published.
- Photos you upload to write posts around.
- Payment details — handled entirely by Stripe. We never see or store your card number. We keep only Stripe's reference for your customer and subscription, and whether your subscription is active.
- Your IP address, if you generate posts before making an account. We store it to limit how many free goes one visitor gets, and for nothing else. It is one row per address holding a count, not a log of what you did.
- Basic account activity — when you signed up and when you were last active.
Why we collect it
To run the service you asked us to run: to write posts for your business, keep them for you, take payment if you are on Pro, and let you log back in. Our lawful basis is performing our contract with you, and for the IP rate-limiting, our legitimate interest in stopping the free tier being abused.
We do not sell your data. We do not use it for advertising. We do not build a profile of you for anyone else's benefit.
Who we share it with
Only the companies that make the product work, and only the data each one needs:
- Anthropic — your business details and post request are sent to Claude to write the posts, along with any photo you attach. Anthropic does not use API data to train their models.
- Stripe — your email and payment details, to take payment. Stripe is the one holding your card, not us.
- Cloudinary — photos you upload, to store them.
- Resend — your email address, when we need to send you a password reset. We do not send marketing email.
- Metricool or Publer — only if you connect one yourself, and then only the posts you choose to send there.
- Render — our hosting provider, which stores the database the rest of this describes.
- Google Fonts — our pages load two fonts from Google, which means your browser tells Google your IP address when a page loads. We are looking at serving the fonts ourselves to stop that.
We would also share data if the law required it of us. We will tell you if that happens, unless we are not allowed to.
How long we keep it
Until you ask us to delete it. Your posts and business details stay while your account is open, because they are the thing you came for.
Deleting a business from your profile retires it and hides it from your account, but the underlying rows stay in our database so the posts and history attached to them are not orphaned. If you want data actually erased rather than hidden, ask us and we will erase it.
Anonymous IP rate-limiting rows are overwritten as their window rolls over and are not kept as a history.
Your rights
Under UK GDPR you can ask us to:
- Show you what we hold about you.
- Correct anything wrong — most of it you can edit yourself on your profile.
- Delete your account and everything in it.
- Send you a copy of your data in a portable format.
- Object to us processing it, or ask us to restrict what we do with it.
Email hello@postmstr.com from the address on your account and we will do it within 30 days, free of charge. There is no self-service delete button yet — the email reaches a person who does it by hand.
If you think we have handled your data badly, you can complain to the Information Commissioner's Office at ico.org.uk. We would rather you told us first so we can fix it.
Cookies
We use two, both strictly necessary, and neither of them tracks you:
- A session cookie, which keeps you logged in. It holds a signed reference to your account and nothing else. If you tick "remember me" it lasts 30 days; otherwise it disappears when you close your browser.
- A cookie that remembers you dismissed our cookie notice, so the banner does not come back every time. It lasts a year and holds the number 1.
That is the lot. No analytics, no advertising cookies, no third-party trackers, no pixels. Because both cookies are essential to something you asked for, we do not need to ask your consent for them under UK GDPR — our banner is telling you, not asking you.
Keeping it safe
Traffic is encrypted in transit, passwords are hashed, and access to the database is limited to the people running the service. No system is perfectly secure, and we will not pretend otherwise — if there is ever a breach affecting your data we will tell you and the ICO as the law requires.
Contact
Email hello@postmstr.com for anything on this page, including data requests.
See also our terms of service and fair usage page.