Legal

Privacy Policy

Last updated September 2, 2026

1. Who we are and what PostGranny does

PostGranny is a cloud-based content creation and social media management platform. Depending on your plan and settings, the Service may allow you to create, edit, draft, schedule, and publish content; use AI-assisted writing and planning tools; store knowledge sources; build link-in-bio mini-sites; collaborate in shared workspaces; view analytics; and manage campaigns and creative workflows.

We process information to provide these features, maintain security, improve the Service, and comply with applicable law.

  • Create, edit, draft, schedule, and publish content to connected social media accounts
  • Use AI-assisted writing, brainstorming, analytics chat, image generation, and content planning tools
  • Store knowledge sources (text notes, documents, URLs, video references) to inform AI-assisted content
  • Build and publish link-in-bio mini-sites
  • Collaborate with teammates, clients, and approvers in shared workspaces
  • View analytics for connected channels and published mini-sites
  • Manage campaigns, drafts, assets, topical maps, Instagram flows, and related creative workflows

2. Information we collect

We collect information in several ways: information you provide directly, information generated through your use of the Service, information from connected third-party accounts, and limited technical information from your device or browser.

2.1 Account and authentication information

When you register or sign in, we may collect:

  • Email address
  • Password (stored using industry-standard hashing through our authentication provider; we do not store your password in plain text)
  • Name and profile details supplied through email/password signup or third-party sign-in (such as Google)
  • Authentication session data required to keep you signed in
  • Onboarding preferences and completion status
  • If you sign in with Google, we receive basic profile information permitted by Google's OAuth process, such as your name, email address, and profile picture, according to your Google account settings and the permissions you grant

2.2 Profile, workspace, and team information

To personalize the Service and support collaboration, we may collect:

  • Display name, headline, bio, location, website, company, role, and similar profile fields
  • Workspace names and settings
  • Team membership, roles, invitations, and client/brand organization data
  • Content preferences such as topics, goals, audience, industries, skills, and posting interests you choose to provide during onboarding or in settings

2.3 Content you create, upload, or store

We store content you add to the Service, which may include:

  • Post drafts, captions, comments, polls, hashtags, and scheduling details
  • Media files and assets (images, videos, PDFs, and other uploads)
  • Knowledge Hub entries, including text notes, uploaded documents, scraped or summarized web content, and video/transcript references
  • Chat messages and AI conversation history within the Service
  • Topical maps, campaigns, content ideas, approval records, and editorial notes
  • Mini-site configuration, including display name, bio, avatar, links, social icons, themes, featured cards, and published page content
  • Some of this content may include personal information if you choose to include it. You are responsible for ensuring you have the right to upload and process any content you provide

2.4 Connected social media and third-party account information

If you choose to connect external accounts, we may collect and store:

  • Account identifiers, usernames, display names, profile URLs, and avatars
  • OAuth access tokens, refresh tokens, token expiry information, granted scopes, and related authorization metadata
  • Page, channel, board, or profile lists available through the connected platform
  • Publishing destinations you select (for example, a Facebook Page, Discord channel, Telegram chat, Pinterest board, or LinkedIn profile/page)
  • Analytics and performance metrics made available to us by connected platforms when you use analytics features
  • Subscription or account tier indicators where a platform exposes them (for example, certain X/Twitter account types)
  • Supported integrations may include Meta platforms (Instagram, Facebook, Threads), LinkedIn, X (Twitter), Bluesky, Pinterest, Discord, Telegram, YouTube, and Canva — depending on availability in your account and region
  • We only connect accounts when you initiate the connection and authorize the requested permissions
  • For Telegram, connection may involve phone-number-based authentication handled through Telegram's official API flow
  • For Bluesky, connection may use an app password or equivalent credential you provide according to Bluesky's settings
  • We do not ask for your main social network passwords except where a platform explicitly requires an app-specific password or similar credential that you voluntarily provide

2.5 Published and public information

If you publish a link-in-bio mini-site through PostGranny, the content you choose to publish (such as your display name, bio, avatar, links, and featured items) becomes publicly accessible at your chosen public URL.

Visitors to published mini-sites are not required to sign in. We may record anonymous or pseudonymous interaction events for analytics available to the site owner, such as page views and link clicks.

2.6 Billing, subscription, and usage information

If you subscribe to a paid plan or use metered features, we may collect:

  • Selected plan, trial status, billing interval, and subscription state
  • AI credit balances, usage counts, and feature consumption records
  • Payment-related identifiers when billing is enabled (for example, customer ID and invoice metadata processed by our payment provider)
  • Payment card details, when collected, are generally processed directly by our payment processor rather than stored by us in full

2.7 Technical, device, and usage information

When you use the Service, we may automatically collect:

  • IP address
  • Browser type, device type, operating system, and language settings
  • Pages viewed, features used, timestamps, and error logs
  • Referring URLs and basic interaction data needed to operate and secure the Service
  • Rate-limiting and abuse-prevention signals
  • Some draft or UI state may be stored locally in your browser (for example, composer working state or selected workspace) to improve performance and continuity between sessions

2.8 Cookies and similar technologies

We use cookies and similar storage mechanisms for essential Service functions, including keeping you signed in, securing OAuth flows when connecting external accounts, remembering workspace or UI preferences where applicable, and protecting against cross-site request forgery and invalid authorization attempts during third-party login flows.

OAuth-related cookies are generally short-lived and used only to complete secure account connection flows.

3. How we use your information

We use collected information to:

  • Provide, operate, maintain, and improve the Service
  • Authenticate users and manage accounts, teams, and workspaces
  • Connect, validate, refresh, and use authorized third-party account tokens so you can publish, schedule, and analyze content
  • Generate AI-assisted drafts, suggestions, summaries, images, topical maps, alt text, and analytics insights based on your inputs and connected data
  • Store, sync, display, schedule, and publish content at your direction
  • Provide collaboration features such as invites, approvals, comments, and shared workspaces
  • Measure feature usage, enforce plan limits, and manage AI credits
  • Provide customer support and respond to requests
  • Monitor, detect, prevent, and address fraud, abuse, security incidents, and violations of our terms
  • Comply with legal obligations and enforce our agreements
  • We process your content and connected account data only as needed to deliver the features you choose to use. Publishing to a social network occurs only when you (or an authorized teammate acting within your workspace permissions) take an action to publish or schedule content

4. AI processing and automated features

PostGranny includes AI-powered features. When you use them, relevant portions of your input may be sent to third-party AI or media-generation providers to produce responses or assets. Depending on the feature, this may include chat prompts and conversation history, draft post text and composer context, Knowledge Hub excerpts, analytics summaries formatted for AI chat, image generation prompts, and topical map generation inputs.

We apply safeguards intended to reduce misuse, such as filtering certain prompt injection patterns and redacting values that resemble secrets before content is sent to AI providers. No automated system is perfect, and you should avoid uploading highly sensitive personal data, credentials, or confidential business secrets into AI features unless you accept the associated risk.

AI outputs may be inaccurate, incomplete, or inappropriate. You are responsible for reviewing content before publishing.

5. How we share information

We do not sell your personal information. We share information only in the limited circumstances below.

5.1 Service providers and infrastructure partners

We use trusted third parties to help operate the Service, such as:

  • Cloud hosting and deployment providers
  • Database, authentication, and file storage providers
  • AI model providers used for chat, mapping, analysis, and related features
  • Image generation infrastructure providers
  • Payment processors (when billing is enabled)
  • Email or notification providers, if used for account or team communication
  • These providers process information on our behalf under contractual or technical arrangements intended to protect your data and limit use to providing services to us

5.2 Social media and publishing platforms

When you connect an account or publish content, we share the minimum information necessary with the relevant platform APIs to perform the action you request. This may include post text, media files, metadata, and authorization tokens.

Each third-party platform has its own privacy policy governing how it handles data once received.

5.3 Team members and collaborators

If you use team, client, or approval features, information within a workspace may be visible to other members according to their role and permissions. Do not invite users who should not have access to your workspace content.

6. Public content and your responsibilities

You control much of the information processed through PostGranny. Please note:

  • Published mini-sites are public by design
  • Social posts become subject to the privacy policies and terms of the destination platform once published
  • You must have rights to any content, images, trademarks, and personal data you upload or publish
  • If you process personal data about others (for example, client information or audience data), you are responsible for having a lawful basis to do so
  • Do not store passwords, API keys, or authentication secrets in free-text fields, knowledge sources, or drafts

7. Data retention

We retain information for as long as reasonably necessary to provide the Service, maintain business and audit records, resolve disputes and enforce agreements, and meet legal, tax, accounting, or compliance requirements.

When you delete your account or workspace through available settings, we will take reasonable steps to delete or anonymize associated personal information, subject to legal retention requirements and backup cycles.

  • Account data is kept while your account remains active
  • Workspace content remains until you delete it or delete the workspace
  • OAuth tokens remain until you disconnect the account or they expire and are no longer needed
  • Usage and billing records may be retained for accounting and fraud-prevention purposes
  • Backups and logs may persist for a limited period after deletion

8. Security

We use administrative, technical, and organizational measures designed to protect information, including access controls, encrypted transport (HTTPS), authenticated access to user accounts, and restricted handling of OAuth tokens on the server side.

No method of transmission or storage is completely secure. You are responsible for maintaining the confidentiality of your login credentials and for using strong, unique passwords. Notify us promptly if you believe your account has been compromised.

9. International data transfers

PostGranny may process and store information in countries other than where you live, including countries where our service providers operate. Those countries may have data protection laws different from those in your jurisdiction.

Where required, we rely on appropriate safeguards for cross-border transfers, such as contractual protections with service providers.

10. Your rights and choices

Depending on your location, you may have rights regarding your personal information, which may include the right to access, correct, delete, export, or restrict processing, object to certain processing, withdraw consent where processing is based on consent, and lodge a complaint with a supervisory authority.

To exercise privacy rights not available in the product UI, contact us using the details in Section 16. We may need to verify your identity before responding.

  • Updating account and profile settings
  • Disconnecting social accounts
  • Deleting workspaces, drafts, assets, or knowledge items
  • Deleting your account where that option is available in settings
  • Choosing not to connect optional integrations

11. California privacy notice

If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA), as amended by the CPRA, including the right to know, delete, and correct personal information, and the right to opt out of certain sharing that qualifies as a "sale" or "sharing" for cross-context behavioral advertising.

PostGranny does not sell personal information for money. We do not use the Service to deliver third-party behavioral advertising based on cross-site tracking of users.

You may submit a verifiable request by contacting us at the address below. We will not discriminate against you for exercising your privacy rights.

12. European Economic Area, United Kingdom, and Switzerland

If you are located in the EEA, UK, or Switzerland, our legal bases for processing personal data may include performance of a contract with you, your consent where required, legitimate interests in operating, securing, and improving the Service balanced against your rights, and compliance with legal obligations.

You may have the right to access, rectify, erase, restrict, or port your personal data, and to object to certain processing. You may also withdraw consent at any time where processing is consent-based, without affecting the lawfulness of prior processing.

13. Children's privacy

The Service is not directed to children under 13 years of age (or the minimum age required in your jurisdiction), and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.

14. Third-party links and services

The Service may contain links to third-party websites, platforms, or services. This Privacy Policy does not apply to those third parties. Their collection and use of information is governed by their own policies. Review the privacy terms of any platform you connect or visit.

15. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in the Service, legal requirements, or our practices. When we make material changes, we will provide notice through the Service, by email, or by other reasonable means.

The "Last updated" date at the top indicates when this Privacy Policy was most recently revised. Continued use of the Service after an update becomes effective means you accept the revised policy.

16. Contact us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, contact us at:

PostGranny — Email: support@postgranny.com — Website: https://app.postgranny.com

For data protection inquiries from users in the EEA/UK, you may also contact us at the same address with the subject line "Data Protection Request."

17. Summary of key points for users

What you should know at a glance:

  • PostGranny helps you create, manage, schedule, and publish social content, use AI tools, and build link-in-bio pages
  • We collect account details, workspace content, connected account tokens, usage data, and content you upload or generate
  • We use service providers for hosting, authentication, storage, AI, image generation, and payments
  • When you publish or connect an account, necessary data is sent to the relevant social platform
  • AI features process your prompts and selected content to generate outputs; review outputs before publishing
  • Published mini-sites are public
  • You can update settings, disconnect accounts, delete content, and request account deletion where available
  • We do not sell your personal information
  • Keep credentials secure and do not upload secrets into the Service
  • Thank you for trusting PostGranny with your creative workflow

This page is provided for product transparency. It is not legal advice. If you need counsel for your situation, please contact a qualified attorney.