Postfin
Privacy Policy
Effective August 24, 2026 · Last updated August 24, 2026
This Privacy Policy explains how Postfin (“Postfin,” “we,” “us,” or “our”) collects, uses, stores, and shares information when you visit postfin.ai, create an account, generate short-form content, connect social accounts, or otherwise use the Postfin service (the “Service”).
Postfin is an AI-powered social media automation platform. You give us a product link or a brief; we can generate slideshows or talking-head videos, captions, and a posting plan; and we can schedule and publish to the Instagram, TikTok, YouTube, Facebook, X, Threads, Pinterest, LinkedIn, and other accounts you connect. This policy is written to match how the product actually works — not a generic template.
By using the Service, you agree to this Policy. If you do not agree, do not use Postfin. Our Terms of Service cover your contract with us, including credits, content, and posting.
1. Who this policy applies to
This Policy applies to:
- visitors to the marketing site at postfin.ai;
- people who create an account with email and password or Sign in with Google;
- people who use the dashboard, calendar, connectors, analytics, products, recents, profile, onboarding, or Add post tools; and
- people whose information appears in a product page, brief, caption, upload, or connected social account that you submit to Postfin.
The Service is intended for people 18 or older who are using Postfin for a brand or business. We do not knowingly collect personal information from children.
2. Information we collect
2.1 Account and sign-in
When you create an account or log in, we collect:
- Email address and a password if you sign up with email. Passwords are stored as a salted scrypt hash. We do not store your password in plaintext.
-
If you use Sign in with Google, we receive your Google
account email, Google’s unique user identifier (
sub), and whether the email is verified. We use this only to create or recognize your Postfin account. Google sign-in is separate from YouTube publishing OAuth. - An operator or admin role if the Service is configured that way (for example, an operator email or admin password used to open the operator workspace).
- Your credit balance and timestamps for when the account was created.
New self-serve accounts start with 0 credits. Credits are deducted when you generate content. Manual Add post uploads do not spend generation credits. Paid plans (including a Starter plan shown as $19 per month for 5,000 credits, and Growth and Scale plans shown during onboarding) may grant credits when billing is enabled. We do not currently process card payments ourselves; if we add a payment processor, we will update this Policy with the processor’s name and the data they receive.
2.2 Session and security
-
After you log in we set an HttpOnly session cookie
(
session), path/, SameSite=Lax, Secure when the site is served over HTTPS, lasting 30 days. Session records live in server memory. A server restart ends open sessions and you will need to log in again. - We rate-limit failed logins by IP address (8 attempts per 15 minutes) to reduce password guessing.
- We may log IP address, user agent, timestamps, and error messages in application logs for security, debugging, and uptime.
We do not use advertising cookies or sell your personal information. The marketing and login pages load a Google Fonts stylesheet (Newsreader / Press Start 2P on the homepage) from Google’s servers, which may receive your IP address as a normal web request.
2.3 Product, brand, and workspace content
To generate and schedule posts we collect what you give us, including:
- Product URLs and written briefs;
- information we scrape from a product page you submit (title, description, images, and related public page content) so the video and captions can match the real product — including software or app screenshots when that is the product;
- generation settings (style, tone, angle, captions, preferred video model, schedule, platforms);
- scripts, concepts, and captions we generate or you edit;
- files you upload through Add post (video such as MP4, MOV, or WebM, and images such as JPEG, PNG, or WebP, subject to size limits);
- calendar slots, posting times, and whether a job should auto-post.
Workspaces are isolated per user. Your jobs, products, and connected accounts are stored against your user id so other customers cannot see them in the dashboard.
2.4 Connected social accounts
When you connect a platform from Connectors, we receive OAuth tokens and profile identifiers needed to publish and (where the platform allows) read performance. That typically includes:
- access tokens and, where issued, refresh tokens;
- token expiry;
- the platform’s account id and display name;
- the time the account was connected.
Platforms we can support, depending on which ones are enabled for your workspace, include TikTok, Instagram, YouTube, Facebook, X, Threads, Pinterest, and LinkedIn. Connecting an account authorizes Postfin to post as that account and, where implemented, to pull metrics such as views, likes, comments, shares, saves, impressions, reach, and follower counts.
Those platforms have their own privacy policies. Their rules apply to anything published through your connected accounts.
2.5 Generated media and analytics
-
Rendered videos, stills, and audio are stored so you can review them and
so platforms can fetch a file at publish time. Media under
/ugc-mediais served without a Postfin login because Instagram and similar platforms retrieve the file from a public URL when publishing. Anyone who knows or is given that URL may be able to access the file. - We store post status, platform post ids, errors, and scheduled or posted times.
- We store performance snapshots (views, likes, comments, shares, saves, impressions, reach, and related fields) and account-level follower metrics when a platform provides them.
2.6 Information we do not collect as a default
- We do not require a government ID to sign up.
- We do not run third-party advertising pixels on the Service today.
- We do not sell personal information, and we do not share it for cross-context behavioral advertising.
- We do not use your product photos as an image-to-video input in a way that replaces a real speaker still with a catalog thumbnail. Talking-head UGC is generated from a speaker frame and a spoken line you (or the planner) supply.
3. How we use information
We use the information above to:
- create and authenticate your account;
- isolate your workspace and credit balance;
- scrape a product page you submit and generate scripts, captions, stills, slideshows, and videos (UGC talking-head, scenic comedy, Lego-style, app slideshow, before & after, and related formats);
- schedule posts and publish to accounts you connected;
- show Recents, Calendar, Analytics, Products, and Profile;
- deduct credits for generations and enforce plan limits;
- prevent abuse, rate-limit logins, and keep the Service running;
- respond to you if you contact us;
- improve the product and fix failures (including failed renders);
- comply with law and enforce our Terms.
Spoken lines in talking-head videos are written as first-person UGC to an audience. We instruct generation not to make medical or cure claims. You are still responsible for reviewing every caption and video before it goes live.
4. AI and subprocessors
Postfin does not run every model on our own GPUs. To provide the Service we send necessary prompts, scripts, product context, reference images, and similar inputs to subprocessors, including:
- OpenAI — planning, scripts, captions, text-to-speech, and related language or image tasks when an OpenAI key is configured;
- fal.ai — image and video generation (including image edits for a first-frame speaker still, and image-to-video or text-to-video models). fal.ai may call a webhook on our servers when a render finishes;
- HeyGen — optional avatar video when that provider is configured for a job;
- Google — Sign in with Google, and YouTube APIs if you connect YouTube;
- Meta (Instagram, Facebook, Threads) — OAuth, publishing, and a webhook handshake those apps require;
- TikTok, X, Pinterest, LinkedIn and other platforms you connect — OAuth and publishing APIs;
- Hosting and database providers that run postfin.ai (currently including Railway-style hosting and PostgreSQL). Logs, media files, and database rows live on that infrastructure.
Those providers process data according to their own terms and privacy policies. We send them only what is needed to complete the request. Model providers may use inputs as described in their customer agreements; we do not use your workspace as an advertising audience.
Talking-head clips typically show a synthetic UGC-style person, not a scan of a specific private individual you did not provide. Do not upload photos of real people unless you have the rights and consents required to use them in ads and social posts.
5. When we share information
We share information only as needed to operate Postfin:
- With platforms you connect — captions, media URLs or files, titles, and the tokens required to post or read metrics;
- With AI and infrastructure vendors listed above;
- With the public — anything you publish to a social account is public or audience-limited according to that platform, including TikTok privacy levels the platform enforces (for example self-only vs public, depending on TikTok’s audit status and settings);
- If required by law, or to protect Postfin, our users, or the public;
- In a business transfer — if we sell, merge, or reorganize, information may move with the Service, still under this Policy or a successor notice.
We do not sell your personal information.
6. Cookies and similar technology
The only first-party cookie Postfin sets for the app is the session cookie described above. It is required to keep you logged in. If you block it, you cannot use the dashboard.
Third parties (Google Fonts, Google OAuth, connected social networks) may set their own cookies when you interact with their services. We do not control those cookies.
7. Retention
We keep information for as long as your account is active and as needed to:
- provide the calendar, recents, analytics, and media library;
- retry or finish a generation or publish job;
- maintain security logs for a reasonable period;
- meet legal, tax, or dispute needs if billing is later enabled.
There is no in-app “delete account” button today. To request deletion of your account, generated media, connected-token records, and related workspace data, email hello@postfin.ai. We will delete or de-identify personal data we control, except where we must retain it (for example, to complete a legal obligation or resolve abuse). Content already posted to TikTok, Instagram, or other platforms remains under those platforms until you delete it there. Unpublishing from Postfin does not automatically erase a live post on every network.
Session records expire after 30 days or when the server restarts. Short-lived OAuth CSRF state is discarded after it is used or times out.
8. Security
We hash passwords with scrypt, mark the session cookie HttpOnly, isolate customer data by user id, and limit login attempts by IP. Hosting uses HTTPS when the public URL is HTTPS. No method of transmission or storage is 100% secure. You are responsible for your password and for who can access your email or Google account. Disconnect social accounts you no longer want Postfin to use.
9. Your choices and rights
You can:
- edit captions, briefs, and jobs in the dashboard before they go live;
- disconnect a social account from Connectors;
- sign out (this clears the session cookie);
- choose not to submit a product URL or upload a file;
- email hello@postfin.ai to access, correct, or delete personal information we hold, or to ask questions about this Policy.
Depending on where you live (including the EEA, UK, and certain U.S. states), you may have rights to access, correct, delete, port, or restrict processing of personal data, and to opt out of “sale” or “sharing” as those terms are defined by law. We do not sell personal information. We will not discriminate against you for exercising privacy rights. Authorized agents may submit requests where the law allows, with proof of authority.
If you are in the EEA or UK, our processing is generally based on: performing the contract (providing the Service you signed up for), legitimate interests (security, product improvement, preventing abuse), and consent where we ask for it (for example, connecting a social account).
10. International processing
Postfin is operated from the United States. If you use the Service from another country, your information is processed in the United States and in any country where our vendors (OpenAI, fal.ai, HeyGen, Google, Meta, and hosting providers) operate. Those countries may have different data protection laws than your own.
11. Automated generation
Scripts, images, and videos are produced automatically using third-party models. That is the core of the product. You can review and edit before publishing. Credits are deducted automatically when a generation runs. These automations are not used to deny you housing, credit, or employment.
12. Third-party sites and product pages
If you ask Postfin to scrape a product URL, we fetch that page the way a browser would. The site you point us at has its own terms and privacy policy. Do not submit URLs you are not allowed to use. Links on postfin.ai (including brand marks on the login page used as social proof) are not an endorsement, and those brands are not our customers unless they sign up.
13. Do Not Track
There is no consistent industry standard for Do Not Track signals. Our session cookie is required for the logged-in app. We do not use it to follow you across unrelated third-party websites for advertising.
14. Changes
We may update this Policy as the product changes (for example, when card billing, a new platform, or a new model vendor goes live). We will change the “Last updated” date above and, for material changes, provide additional notice in the product or by email when we have an email on file. Continued use after an update means you accept the revised Policy.
15. Contact
Questions about privacy, access, or deletion: hello@postfin.ai.
Postfin · postfin.ai
Related: Terms of Service