Privacy Policy
Effective date: June 19, 2026
Postessia ("we," "us," "our," "the Service") respects your privacy. This Privacy Policy explains what personal data we collect, why, how we use it, and your rights — under the EU General Data Protection Regulation (GDPR), India's Digital Personal Data Protection Act, 2023 (DPDP Act), and other applicable global privacy laws (e.g., CCPA/CPRA for California residents).
By using Postessia, you agree to the practices described here. If you do not agree, please do not use the Service.
1. Who We Are
Postessia is a content-generation and publishing tool for LinkedIn, operated by Harshit Tiwari (India). For all data-related queries, contact: privacy@postessia.in.
Under GDPR, Postessia acts as the Data Controller for account and billing data you give us directly, and as a Data Processor for content you generate and publish through connected platforms (e.g., LinkedIn), where the publishing platform is itself a separate controller of that content once posted.
2. What Data We Collect
| Category | Examples | Why We Collect It |
|---|---|---|
| Account data | Name, email, password (hashed), signup date | To create and secure your account |
| Billing data | Plan type, payment status, transaction ID, GST details (if applicable) | To process payments via Razorpay and meet tax/audit requirements |
| Content data | Prompts you enter, generated posts, tone/voice preferences | To generate and refine content for you |
| Usage data | Login times, feature usage, device/browser type, IP address | To improve the Service and detect abuse |
| LinkedIn connection data | OAuth tokens, basic profile info (if you connect your LinkedIn account) | To enable direct publishing/scheduling |
| Cookies & similar tech | See Cookies Policy | Authentication, analytics, preferences |
We do not knowingly collect special category data (health, religion, biometric, etc.) and ask that you avoid including such information in prompts.
3. Legal Basis for Processing (GDPR, Art. 6)
- Contract performance — to provide the Service you signed up for.
- Legitimate interest — to secure, maintain, and improve the platform.
- Consent — for optional cookies, marketing emails, and connecting third-party accounts (e.g., LinkedIn).
- Legal obligation — for tax, billing, and audit records (e.g., GST-compliant invoices via Razorpay).
4. How We Use Your Data
- Provide, operate, and maintain the Service
- Generate content based on your prompts and stored voice/tone preferences
- Process payments and issue invoices
- Send essential service emails (billing, security, policy changes)
- Send optional marketing emails (only with consent; opt out anytime)
- Improve product quality and detect fraud/abuse
- Comply with legal, tax, and regulatory obligations
We do not sell your personal data. We do not use your private prompts or content to train third-party AI models beyond what's needed to generate your output. This processing happens via our AI provider (currently Anthropic's Claude API), under their standard API data-handling terms.
5. Data Sharing — Third Parties / Sub-processors
We share data only as needed to run the Service:
| Third Party | Purpose | Data Shared |
|---|---|---|
| Supabase | Database & backend hosting | Account, content, usage data |
| Vercel | App hosting | Technical/log data |
| Razorpay | Payment processing | Billing details, transaction data |
| Anthropic (Claude API) | AI content generation | Prompts you submit (per Anthropic's API data policies) |
| LinkedIn (if connected) | Publishing/scheduling | OAuth token, basic profile, post content |
| Formspree | Waitlist/contact forms | Email, name, message content |
We require all sub-processors to maintain appropriate data protection standards. We do not share your data with advertisers.
6. International Data Transfers
Postessia is operated from India. Some sub-processors (e.g., Anthropic, Vercel) may process data outside India or the EU/EEA. Where we transfer EU personal data internationally, we rely on Standard Contractual Clauses (SCCs) or equivalent safeguards as required under GDPR Chapter V.
7. Data Retention
- Account & billing data: retained for the duration of your account plus the period required by Indian tax law (typically up to 8 years for financial records).
- Content data: retained while your account is active; deleted within 90 days of account deletion unless legally required to retain longer.
- Marketing data: retained until you withdraw consent.
8. Your Rights
If you're in the EU/EEA or UK (GDPR):
- Right to access, rectify, or erase your data
- Right to restrict or object to processing
- Right to data portability
- Right to withdraw consent at any time
- Right to lodge a complaint with your local Data Protection Authority
If you're in India (DPDP Act, 2023):
- Right to access information about your personal data and its processing
- Right to correction and erasure of your personal data
- Right to grievance redressal (see Section 10)
- Right to nominate another individual to exercise your rights in the event of death or incapacity
- Right to withdraw consent at any time, as easily as it was given
If you're in California (CCPA/CPRA):
- Right to know what personal information is collected and how it's used
- Right to delete personal information
- Right to opt out of the sale/sharing of personal information (Note: Postessia does not sell personal data)
- Right to non-discrimination for exercising your rights
To exercise any of these rights, email support@postessia.in. We will respond within the timeframe required by applicable law (typically 30 days under GDPR, and as specified under the DPDP Act once its rules are notified).
9. Data Security
We use industry-standard measures — encrypted connections (HTTPS/TLS), hashed passwords, and access-controlled databases (Supabase) — to protect your data. No system is 100% secure; we will notify affected users and relevant authorities of any data breach as required by applicable law (including the 72-hour notification requirement under GDPR Art. 33, where applicable).
10. Grievance Officer (India — DPDP Act / IT Rules)
In accordance with India's data protection and IT regulations, you may contact our Grievance Officer for any complaints regarding personal data:
Grievance Officer: Harshit Tiwari Email: support@postessia.in Response time: within 30 days
11. Children's Privacy
Postessia is not intended for individuals under 18. We do not knowingly collect data from minors. If you believe a minor has provided us data, contact us for immediate deletion.
12. Changes to This Policy
We may update this policy as the product or law evolves. Material changes will be notified via email or in-app notice at least 7 days before taking effect.
13. Contact
Questions about this policy: support@postessia.in
14. Data Processing Agreement (For Agency & Business Customers)
If you use Postessia on an Agency or Agency+ plan to create, manage, or publish content on behalf of your own clients, and that work involves processing personal data belonging to your clients or their end-users (e.g., names, contact details, or LinkedIn profile data used in content personalization), the following applies:
- Roles: You act as the Data Controller for your clients' personal data. Postessia acts as your Data Processor, processing that data solely on your documented instructions and only to provide the Service.
- DPA Required: Before processing any client/end-user personal data through Postessia on behalf of a third party, you must enter into our Data Processing Agreement (DPA), available on request at support@postessia.in. Using the Agency/Agency+ plan to process third-party personal data without an executed DPA is a breach of these Terms.
- Sub-processing: Our DPA lists the sub-processors in Section 5 above and binds them to equivalent data protection obligations.
- Your Obligations: You are responsible for obtaining any consents required from your own clients/end-users before submitting their personal data to Postessia, and for responding to data subject requests that relate to your own clients (we will assist where required by law).
- Liability: Each party remains responsible for its own compliance obligations as Controller or Processor under applicable law (GDPR Art. 28, DPDP Act, and equivalents).
This section does not apply to Solo plan users processing only their own personal content.