MyPostFlow
Home›Privacy Policy

Privacy Policy

Version 1.0Effective: June 10, 2026

This Policy explains which personal data MyPostFlow collects, what for, who we share it with, and how you exercise your rights. It was written to comply with the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA).

1. Data we collect and why

We collect only what’s needed to run the service:

Account data

Email and name. Purpose: to create and identify your account, authenticate access, and communicate with you. Legal basis (GDPR): performance of the contract.

Usage data

Records of your generations and product events (for example, which features you use and when). Purpose: to provide the service, track credit usage, improve the platform, and prevent abuse. Legal basis (GDPR): performance of the contract and legitimate interest.

Content you submit for generation

The prompts, text, and images you submit are sent to the AI providers listed below solely to produce your requested output. Purpose: to deliver the core generation feature. Legal basis (GDPR): performance of the contract.

Payment data

Payments are processed by Stripe, our payment processor. We do not store your card datain our systems — Stripe handles it directly. We keep only what’s needed to link a purchase to your account (such as transaction identifiers). Purpose: to process credit and plan purchases. Legal basis (GDPR): performance of the contract and legal obligations.

Cookies and analytics

We use analytics tools (Google Analytics 4 and PostHog) to understand product usage. These scripts are only loaded with your consent via the cookie banner, and Google Analytics is configured with IP anonymization. Legal basis (GDPR): consent.

Error logs

We record technical errors (via Sentry) to diagnose and fix problems. Purpose: security and stability of the service. Legal basis (GDPR): legitimate interest.

2. Who we share with (processors)

To function, MyPostFlow relies on providers that process data on our behalf (processors / service providers), each with a specific purpose:

  • Google — AI text and image generation;
  • OpenAI — AI image generation;
  • Stripe — payment processing;
  • Vercel and Supabase — hosting and database infrastructure;
  • Resend — transactional email delivery.

We do not sell your personal data, and we do not share it for cross-context behavioral advertising. Sharing is limited to what’s necessary to provide the service and to meet legal obligations.

3. International data transfers

MyPostFlow operates from the United States, and some of the processors above are located in the U.S. or other countries. When we transfer personal data out of the European Economic Area or the United Kingdom, we rely on an appropriate safeguard — such as the European Commission’s Standard Contractual Clauses or an adequacy decision — so your data keeps a comparable level of protection.

4. How long we keep it

We keep your data while your account is active and for as long as needed to fulfill the purposes above and legal obligations (for example, tax and accounting). Once your account is closed, we delete or anonymize the data we no longer need to retain, subject to any legal hold.

5. Your rights (GDPR)

If you are in the EEA or the UK, you can at any time:

  • access the personal data we hold about you;
  • correct incomplete, inaccurate, or outdated data;
  • request deletion of data we no longer have a reason to keep;
  • request restriction of, or object to, certain processing;
  • request portability of your data in a machine-readable format;
  • withdraw consent (for example, by declining analytics cookies).

To exercise these rights, use our support channel under the “Personal data” category, or write to hello@mypostflow.app. We respond within 30 (thirty) days. You also have the right to lodge a complaint with your local data protection authority.

6. California privacy rights (CCPA/CPRA)

If you are a California resident, you have the right to:

  • know what personal information we collect, use, and disclose;
  • request access to, or deletion of, your personal information;
  • correct inaccurate personal information;
  • opt out of the “sale” or “sharing” of your personal information; and
  • not be discriminated against for exercising any of these rights.

Do Not Sell or Share My Personal Information. MyPostFlow does not sell your personal information, and does not share it for cross-context behavioral advertising. You can also decline analytics cookies at any time through the cookie banner. To make any California request, email hello@mypostflow.app.

7. Security

We apply technical and organizational measures to protect your data, such as access control, encryption in transit, and per-user isolation. No system is 100% immune to incidents, but we work to reduce risks and respond quickly if something happens.

8. Contact

For any privacy question or request — including matters that would fall to a Data Protection Officer under the GDPR — contact us at hello@mypostflow.app or through our support channel.

9. Changes to this Policy

We may update this Policy. Significant changes will be reflected in the version and effective date at the top of this page and, where applicable, communicated through official channels.

Terms of UsePrivacy PolicyRefunds and Cancellationcontato@mypostflow.com
© 2026 MyPostFlow