We hold the keys to your accounts.
Your writing
It trains your profile. It does not train anything else.
Your writing shapes your profile and nothing else
The posts and samples you point us at, kept so your voice profile can be rebuilt.
The generated profile derived from source writing you provide.
Generated posts, format and quality provenance, rationale, and workflow status.
The Postiz tenant API credential is encrypted by PostLabz. Social-provider credentials remain inside Postiz and can be revoked at the social platform. We never see your social passwords.
Email, authentication identifiers via Clerk, and a billing reference. Card details live with Stripe, never with us.
Infrastructure
Small surface, boring choices, no clever parts.
Clerk, with signed JWTs
Sign-in is handled by Clerk. The API verifies RS256 JWTs against Clerk's public keys; per-user API keys are hashed, shown once, and revocable.
Tokens sealed at rest
Channel access tokens are encrypted at rest (Fernet/AES). A database read on its own cannot post anywhere.
Cloudflare in front
Traffic is served over HTTPS through Cloudflare, including the tunnel to the self-hosted Postiz instance.
Self-hosted Postiz
Scheduling runs on a Postiz instance we operate ourselves, one organization per workspace. Your social tokens are not shared with a third-party scheduler.
Stripe, with signed webhooks
Checkout and the customer portal are Stripe-hosted. Webhooks are signature-verified. We never store card numbers.
Abuse controls on by default
Expensive endpoints are rate-limited, generation is budget-capped per workspace, and production secrets are checked at startup.
Your controls
Everything here is a setting you own, not a support ticket.
Degraded and format-mismatched drafts are blocked before approval or publishing.
Recurring generation can be turned off from the calendar.
Per-user keys for the API and MCP server. Hashed, shown once, revocable from settings.
Disconnecting disables a local destination; removing the Postiz tenant connection clears its stored tenant credential.
Request account deletion
Email us to start the documented deletion process. Primary account records are removed operationally; legal records and provider logs, backups, email records, media caches, and telemetry follow the configured provider or infrastructure retention schedules; we confirm the applicable timing for each request.
The full list is in the privacy policy.
Found something? Tell us before you tell anyone else.
First response within a few working days. No legal threats for good-faith research.