Privacy Policy
What Post Array collects, why, who processes it, how long it is kept, and how to get it out or have it deleted.
Pending review by counsel before launch
What we hold
- Account and profile: your name, email, workspace membership and role.
- Social connections: the platform account identifier, its display name, its type, the granted scopes and an encrypted access token. Tokens are stored with envelope encryption and are never written to a log.
- Content and media you create, upload or import, including the rights and provenance you record with it.
- Schedules, approval decisions, publication receipts and audit events.
- Metrics retrieved from platforms about posts you published through Post Array.
- Billing references held by Polar. Post Array does not store your card details.
- Device and log data needed to operate and secure the service, redacted by default.
- Agent and API activity: which credential took which action, with an input hash rather than the input.
What we deliberately do not do
- We request only the platform scopes the features you have enabled actually need.
- We do not ingest your entire social history in order to draw a chart.
- Post content is redacted from general logs and from support tooling.
- Your content is not used to train our models or anyone models by default.
Who else processes it
The current subprocessor list is published separately and changes are announced there before they take effect.
How long we keep it
Your controls
- Download your content, receipts and analytics as JSON and CSV with a media archive.
- Disconnect one social account without deleting the workspace. Tokens are revoked at the platform and deleted here.
- Delete a project, a piece of content, a media file or the entire account.
- Cancel scheduled jobs before deleting anything, so nothing publishes after you leave.
- See and revoke active sessions, API keys, agent credentials, webhooks and platform permissions.
- Consent preferences are versioned and auditable, so you can see what you agreed to and when.
Deleting data held at a platform
Disconnecting an account in Post Array revokes the token at the platform and deletes the credential here. Content already published on a platform is governed by that platform and has to be deleted there. Where a platform requires deletion of derived data within a fixed period after revocation, we meet that period. For Google and YouTube data that period is currently 30 days.
International transfers
Hosting regions and the transfer mechanism are being finalized with counsel and will be named here, together with the safeguards that apply, before launch.
What is sent, and what happens to it
Only the text you asked us to work on, the instruction, and the project context you chose to attach. Credentials, tokens and other customers content are never in a model context.
Your content is not used to train our models. We configure providers so it is not used to train theirs.
Optional AI features can be turned off per workspace. Publishing, scheduling, approvals and analytics do not depend on them.
Contact
Contact channels will be published here before general availability. No legal or support inbox is operating during this preview.
The contracting entity, its registered address and the governing jurisdiction are an open decision and will be named here before launch.