Privacy Policy
Who we are
PostLabz ("we", "us") operates the postlabz.com website and the PostLabz application — an AI-assisted social media content and scheduling service. You can reach us at hello@postlabz.com.
Data we collect
Account data: name, email address, and authentication identifiers provided via our sign-in provider (Clerk).
Brand data: website URLs, social handles, sample posts, and brand preferences you give us during onboarding so we can learn your voice.
Connected-channel data: PostLabz stores an encrypted Postiz tenant API credential and channel identifiers. Social-provider credentials remain within Postiz so it can publish and read analytics on your behalf. We never see your social media passwords.
Usage data: content drafts, approval decisions, publishing history, and post performance metrics.
Billing data: subscription status and identifiers. Card details are processed by Stripe; we never store them.
How we use it
To generate content drafts using your brand profile, schedule and publish posts you approve, and show available performance analytics.
To send transactional emails (approval links, digests, receipts).
To improve content quality for your account. We do not sell your data and do not use your connected-channel data for advertising.
AI processing
Text generation, embeddings, image, video, and research may use third-party providers (currently Zhipu/GLM, Fal.ai, ElevenLabs, Anthropic, and Tavily where enabled). Prompts or searches may include your brand samples, public sources, and topics. These providers process data per their own privacy terms and data-processing agreements.
Sub-processors
Hosting and infrastructure: Render, Hetzner, Supabase, Cloudflare. Authentication: Clerk. Payments: Stripe. Email: Resend. Error telemetry: Sentry where configured. Social publishing: our self-hosted Postiz instance. AI and research providers are listed above.
Retention & deletion
We keep product data while your account is active. Disconnecting a channel disables that destination; removing the Postiz tenant connection deletes its stored tenant credential. To request account deletion, email hello@postlabz.com. Primary deletion is currently an operational process, not a self-service endpoint. Generated media/cache purge and provider deletion are also operational; legal records, platform logs, backups, transactional-email records, and optional Sentry events follow their configured retention schedules and may expire after primary account data.
Security
The Postiz tenant API credential is encrypted at rest by PostLabz. Social-provider credentials are managed within Postiz. Traffic is served over HTTPS via Cloudflare, and access to production systems is restricted.
Your rights
Depending on your jurisdiction (including the GDPR), you may request access, correction, export, or deletion of your personal data, or object to processing. Contact hello@postlabz.com.
Changes
We may update this policy; material changes will be announced by email or in-app notice. Last updated: August 2026.