Privacy Policy

Last updated: February 18, 2026

1. Introduction

Post Architect ("we", "us", or "our") respects your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our Service. By using Post Architect, you consent to the practices described in this policy.

2. Information We Collect

Account Information

  • Email address (used for authentication and communication)
  • Password (securely hashed; we never store plaintext passwords)

Business Information

  • Product name, description, and website URL
  • Target audience, value propositions, and pain points
  • Brand voice preferences and content goals
  • Example posts and tone notes

Content Data

  • AI-generated social media posts and content plans
  • Media files you upload (images and videos)
  • Posting schedules and publishing history

Social Media Tokens

  • OAuth access tokens for Facebook and Instagram (used to publish on your behalf)
  • Connected page/account identifiers

Payment Information

Payment processing is handled entirely by Stripe. We do not store your credit card number or bank details. We only store your Stripe customer ID and subscription status.

3. How We Use Your Information

  • Service delivery: To generate content, schedule posts, and publish to your social media accounts
  • AI content generation: Your business information is sent to Anthropic's Claude API to generate social media content. This data is processed according to Anthropic's usage policies and is not used to train AI models.
  • Billing: To process subscription payments through Stripe
  • Communication: To send service-related notifications (e.g., account verification)
  • Improvement: To understand usage patterns and improve the Service

4. Third-Party Services

We use the following third-party services to operate Post Architect:

  • Supabase: Database hosting, user authentication, and file storage (hosted in the US)
  • Stripe: Payment processing and subscription management
  • Anthropic (Claude API): AI content generation
  • Meta (Facebook/Instagram): Social media publishing via authorized API access
  • Vercel: Application hosting

Each of these services has its own privacy policy governing their handling of your data.

5. Data Retention

  • Account and business data: Retained as long as your account is active
  • Generated content: Retained as long as your account is active
  • Media files: Automatically deleted from our storage 30 days after the associated post is published (the content remains on your social media platforms)
  • Posting logs: Retained for your records as long as your account is active
  • After account deletion: All data is permanently deleted within 30 days of your request

6. Data Security

We implement appropriate security measures to protect your data, including:

  • Encrypted data transmission (HTTPS/TLS)
  • Row Level Security (RLS) ensuring users can only access their own data
  • Secure password hashing
  • OAuth token encryption
  • Input validation on all API endpoints

7. Cookies

We use essential cookies only — specifically, Supabase authentication session cookies. These are strictly necessary for the Service to function and keep you logged in. We do not use tracking cookies, analytics cookies, or advertising cookies.

8. Your Rights

You have the right to:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Update or correct your personal information through the app settings
  • Deletion: Request deletion of your account and all associated data
  • Portability: Request your data in a machine-readable format
  • Revoke consent: Disconnect social media accounts at any time through the app

To exercise any of these rights, contact us at support@postarchitect.com.

9. Children's Privacy

The Service is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a new "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the updated policy.

11. Contact

If you have questions about this Privacy Policy or how we handle your data, contact us at support@postarchitect.com.