Privacy Policy

Last updated September 29, 2026

What this covers

This policy explains what data Postfalcon collects when you use the service at postfalcon.co, why we collect it, who we share it with, and how you can control it. It applies to visitors, trial users, and paying customers alike.

Data we collect

Account information: your email address, a bcrypt hash of your password (never the password itself), and — if you sign in with Google — your Google account id and email, which we use to match or create your account instead of storing a password at all.

Connected social accounts: when you connect a platform (Mastodon, Bluesky, Facebook, Instagram, Threads, Telegram, YouTube, TikTok, Pinterest, or LinkedIn), we store the OAuth access token (and refresh token, where the platform issues one) needed to publish on your behalf, along with the account's display name and platform-assigned id. We request only the minimum permissions each platform requires for posting and, where available, reading back engagement metrics — never permissions to read your DMs, contacts, or unrelated account data.

Content you create: post text, uploaded media (images/video), schedules, and recurrence settings for the posts you compose.

Billing: subscription plan and status. Card details are handled entirely by Stripe — we never see or store your card number.

Usage & security logs: IP address, user agent, and timestamps for page visits and authentication events (login, password reset, etc.), plus coarse product usage events (e.g. "created a post") used to understand which features get used.

How we use it

  • To publish your scheduled posts to the platforms you've connected, at the times you set.
  • To process payments and manage your subscription.
  • To send transactional email: verification, password resets, and security notices.
  • To keep your account secure (detecting suspicious login activity, enforcing sessions).
  • To understand aggregate usage trends and improve the product.

We do not sell your data, and we do not use it for advertising — Postfalcon has no ad integrations of any kind.

Who we share it with

We share data only where it's needed to run the service:

  • The platforms you connect — only the post content, media, and schedule you explicitly create get sent to Mastodon, Bluesky, Meta (Facebook/Instagram/Threads), Telegram, Google (YouTube), TikTok, Pinterest, or LinkedIn, whichever you've linked.
  • Stripe, for billing and payment processing.
  • Our email provider, to deliver transactional email on our behalf.

Site traffic analytics run on Umami, which we self-host — it is not a third-party analytics vendor, collects no cookies, and reports only aggregate, anonymized traffic data (pages viewed, referrers) back to us.

We never sell or rent your data to anyone.

How long we keep it

  • Uploaded media for posted, failed, or canceled posts is deleted after 30 days; the post's text and history are kept regardless.
  • Page-visit and login/security logs are kept for 90 days.
  • Aggregate product usage events are kept for up to a year.

Deleting your account (below) removes your account data outright rather than waiting out these windows.

Your controls

  • Disconnect any social account at any time from Accounts — this immediately revokes our stored token for it.
  • Export or inspect your own data at any time via the REST API.
  • Change your password or delete your account entirely from Settings.

Security

Passwords are hashed with bcrypt and never stored in plain text. All traffic is served over HTTPS. Platform access tokens are stored server-side and are never exposed to your browser. Every state-changing request is protected against cross-site request forgery.

Children

Postfalcon is not directed at, and is not knowingly used by, anyone under 16.

Changes to this policy

If this policy changes, we'll update the date at the top of this page.

Contact

Questions about this policy or your data? Email admin@postfalcon.co.