This Privacy Policy describes how Post Machine("Post Machine," "we," "us," or "our") collects, uses, shares, and protects information when you visit postmachine.co, apply for our founding cohort, create an account, or use our services (collectively, the "Service").
By using the Service, you agree to this Privacy Policy. If you do not agree, please do not use the Service.
1. Who we are
Post Machine is a software service that helps businesses turn proven ad formats into scheduled social content. For privacy questions or requests, contact us at emailforaffiliatestuff@gmail.com.
2. Information we collect
We collect information in the following categories:
Account and authentication. When you sign in, we collect your email address and create a user identifier through Supabase Auth. We use email magic links (one-time passwords); we do not store passwords.
Early access waitlist. If you join from our landing page or sign-in gate, we collect your email to notify you when access opens.
Founding cohort applications.If you apply on our landing page, we collect your email, business type, posting frequency, website URL, a short "why now" response, and your IP address (for spam prevention and rate limiting). We may also record a honeypot field used only for bot detection.
Membership and billing. If you purchase a plan, we store membership status, Stripe customer and subscription identifiers, checkout session references, and payment-related metadata. Payment card details are collected and processed directly by Stripe; we do not store full card numbers on our servers.
Brand and workspace data. When you use the product, you may provide brand names, website URLs, handles, voice samples, audience descriptions, offer details, uploaded images, audio for transcription, and other business content you choose to submit.
Generated and scheduled content. We store posts, images, videos, captions, KEEP/KILL decisions, and scheduling data you create or approve in the Service.
API keys (Bring Your Own Keys plans). If you connect your own provider accounts, we store encrypted copies of API keys (OpenAI, BytePlus, Sora, PostForMe, and similar) so we can run generations on your behalf. Keys are encrypted at rest and used only server-side.
Technical and usage data. We collect server logs, request metadata, and internal product metrics (for example, generation and scheduling events). These metrics are designed not to include free-text personal content. We do not currently use third-party advertising or behavioral analytics cookies.
3. How we use information
- Provide, operate, and improve the Service
- Authenticate you and maintain your account
- Evaluate founding cohort applications and communicate about your application
- Process payments, subscriptions, and credit purchases
- Generate, render, and schedule content at your direction
- Connect to third-party publishing tools you authorize (such as PostForMe)
- Prevent abuse, spam, and fraud
- Comply with legal obligations and enforce our Terms of Service
- Respond to support requests
4. Legal bases (EEA/UK users)
If you are in the European Economic Area or United Kingdom, we process personal data on these bases:
- Contract: to provide the Service you request
- Legitimate interests: to secure the Service, prevent abuse, and improve product reliability, balanced against your rights
- Consent: where required, such as for optional analytics (none are active today) or where you explicitly agree when applying
- Legal obligation: where we must retain or disclose data under applicable law
5. How we share information
We do not sell your personal information. We share information only as described below:
- Service providers (processors) that help us run the Service, including:
- Supabase (authentication, database, file storage)
- Stripe (payments and billing)
- Vercel (hosting and scheduled jobs)
- OpenAI (text, image, audio transcription, and video generation when enabled)
- BytePlus / Seedance (AI video generation when enabled)
- PostForMe (social account connection and publishing)
- Remotion (server-side video rendering)
- Google Fonts (typography delivery via Next.js)
- Calendly (optional concierge onboarding booking links)
- Google Sheets (optional application collection via a webhook you configure)
- AI processing: Content you submit may be sent to AI providers to generate outputs you request. Do not submit information you are not authorized to share with these providers.
- Legal and safety: When required by law, to protect rights and safety, or to investigate abuse.
- Business transfers: In connection with a merger, acquisition, or asset sale, subject to continued protection of your data.
6. Cookies, local storage, and similar technologies
We use the following technologies:
Essential cookies. Supabase authentication cookies maintain your signed-in session. A short-lived HttpOnly cookie (postmachine_invitation_return) may store your invitation return path during checkout sign-in. These are necessary for the Service to function.
Local storage (browser). We store draft workspace state, onboarding flags, lineup preferences, and buffered internal metrics on your device to improve performance and preserve your work between sessions. Keys include qm-brand, qm-offer-kit, qm-week-lineup, and similar prefixes, plus your cookie consent choice.
Analytics cookies. We do not currently deploy third-party analytics or advertising trackers. If we add them in the future, we will request consent where required before loading non-essential trackers.
You can manage cookie preferences using our cookie banner. You can also clear cookies and local storage in your browser settings, though doing so may sign you out or remove unsaved drafts.
7. Data retention
- Active accounts: We retain account and workspace data while your account is active and as needed to provide the Service.
- Founding applications: Accepted applicants move under the customer retention policy. Declined or withdrawn application personal data is retained for up to 180 days after the founding cohort application period closes, then deleted in ordinary course unless a longer period is required by law.
- Billing records: Retained as required for tax, accounting, and dispute resolution.
- Deletion requests: You may request deletion as described in Section 9.
8. International transfers
We and our service providers may process data in the United States and other countries. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms offered by our processors.
9. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to certain processing of your personal data, and to data portability. California residents may have additional rights under the CCPA/CPRA, including the right to know, delete, and opt out of sale or sharing (we do not sell personal information).
To exercise these rights, email emailforaffiliatestuff@gmail.com. We may need to verify your identity. You may also lodge a complaint with your local data protection authority.
10. Security
We use administrative, technical, and organizational measures designed to protect your information, including encryption of API keys at rest, access controls, and row-level security in our database. No method of transmission or storage is completely secure.
11. Children
The Service is not directed to children under 16 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and update the "Last updated" date. Material changes may also be communicated by email or in-product notice where appropriate.
13. Contact
Questions about this Privacy Policy or our data practices: emailforaffiliatestuff@gmail.com. See also our Terms of Service.