Security

We hold the keys to your accounts.

That is a serious thing to hand over, so this page says exactly what is stored, where it runs, who can reach it, and what happens when you leave.
Encrypted
Postiz tenant credential at rest
TLS
all traffic via Cloudflare
No pooling
your writing trains only your profile
On request
documented account-deletion process
01

Your writing

It trains your profile. It does not train anything else.

The model commitment

Your writing shapes your profile and nothing else

·Your posts, samples and rejections are scoped to your workspace and are never pooled with another customer's.
·Drafting calls hosted language models with your brand samples as context, per each provider's data-processing terms.
·We do not sell or license your content. Only the service providers listed in our Privacy Policy process the data needed for their configured task.
What we store
Source writing

The posts and samples you point us at, kept so your voice profile can be rebuilt.

Voice profile

The generated profile derived from source writing you provide.

Drafts

Generated posts, format and quality provenance, rationale, and workflow status.

Publishing credential

The Postiz tenant API credential is encrypted by PostLabz. Social-provider credentials remain inside Postiz and can be revoked at the social platform. We never see your social passwords.

Account basics

Email, authentication identifiers via Clerk, and a billing reference. Card details live with Stripe, never with us.

02

Infrastructure

Small surface, boring choices, no clever parts.

Auth

Clerk, with signed JWTs

Sign-in is handled by Clerk. The API verifies RS256 JWTs against Clerk's public keys; per-user API keys are hashed, shown once, and revocable.

Encryption

Tokens sealed at rest

Channel access tokens are encrypted at rest (Fernet/AES). A database read on its own cannot post anywhere.

Edge

Cloudflare in front

Traffic is served over HTTPS through Cloudflare, including the tunnel to the self-hosted Postiz instance.

Publishing

Self-hosted Postiz

Scheduling runs on a Postiz instance we operate ourselves, one organization per workspace. Your social tokens are not shared with a third-party scheduler.

Payments

Stripe, with signed webhooks

Checkout and the customer portal are Stripe-hosted. Webhooks are signature-verified. We never store card numbers.

Rate limits

Abuse controls on by default

Expensive endpoints are rate-limited, generation is budget-capped per workspace, and production secrets are checked at startup.

03

Your controls

Everything here is a setting you own, not a support ticket.

Workspace · Security settings
Publication gate

Degraded and format-mismatched drafts are blocked before approval or publishing.

ON
Scheduled generation

Recurring generation can be turned off from the calendar.

OFF
API keys

Per-user keys for the API and MCP server. Hashed, shown once, revocable from settings.

OPTIONAL
Channel disconnection

Disconnecting disables a local destination; removing the Postiz tenant connection clears its stored tenant credential.

ANYTIME
Leaving

Request account deletion

Email us to start the documented deletion process. Primary account records are removed operationally; legal records and provider logs, backups, email records, media caches, and telemetry follow the configured provider or infrastructure retention schedules; we confirm the applicable timing for each request.

hello@postlabz.com
Subprocessors
·Clerk — authentication
·Stripe — payments
·Resend — transactional email
·Cloudflare — DNS and edge
·AI providers (Zhipu/GLM, Fal.ai, ElevenLabs, Anthropic) — content generation

The full list is in the privacy policy.

Responsible disclosure

Found something? Tell us before you tell anyone else.

First response within a few working days. No legal threats for good-faith research.

Report a vulnerability
hello@postlabz.com