Privacy Policy

Last updated: April 25, 2026

This is a starting template. Have it reviewed by a lawyer (and aligned with the regulations that apply to you, e.g. GDPR, CCPA) before relying on it in production.

1. Who we are

PostHandler ("we", "us") operates the content-management Service available at posthandler.com. This Privacy Policy explains what personal data we collect, how we use it, and your choices.

2. Data we collect

  • Account data: name, email address, hashed password, profile picture (if provided via Google sign-in).
  • Workspace data: workspace names, members, roles.
  • Connected platform credentials: OAuth access and refresh tokens you grant us, scoped per workspace.
  • Content you upload: videos, thumbnails, captions, tags, scheduling metadata.
  • Usage data: log entries, IP address, browser type, timestamps for diagnostics and abuse prevention.

3. How we use your data

  • operate the Service and publish content to platforms you connect;
  • authenticate you and protect your account;
  • display analytics pulled from connected platforms;
  • communicate operational notices, billing, and product updates;
  • improve the Service and prevent abuse.

4. Sharing

We share data only to operate the Service: with the third-party platforms you connect (when publishing or fetching analytics), with infrastructure providers under contract, and where required by law. We do not sell your personal data.

5. Storage and security

We store data in encrypted form at rest and in transit. Passwords are hashed with bcrypt. OAuth refresh tokens are stored encrypted and scoped to the workspace that authorized them. Access to production data is limited to staff who need it to operate the Service.

6. Retention

We retain account and workspace data for as long as your account is active. When you delete your account, we remove personal data within 30 days, except where we are required to retain it for legal, accounting, or fraud-prevention reasons.

7. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, or to object to certain processing. To exercise any of these rights, email [email protected].

8. Cookies

We use a small number of essential cookies — for example, the session cookie that keeps you signed in. We do not use third-party advertising cookies.

9. Children

The Service is not directed to children under 13, and we do not knowingly collect personal data from them.

10. International transfers

Your data may be processed in countries other than the one you live in. Where required, we put appropriate safeguards in place (such as standard contractual clauses) for cross-border transfers.

11. Changes to this policy

We may update this Policy from time to time. Material changes will be announced via the Service or by email.

12. Contact

Questions about this Policy? Email us at [email protected].