Legal · Privacy

Privacy Policy

PostyrX holds two quite different kinds of personal data: yours, because you signed up, and your visitors', because they clicked a link you posted. This policy separates them, because the second group never agreed to anything and the obligations are not the same.

Effective 16 September 2026

1.What this covers

This policy covers the PostyrX website, the application, the API and the MCP server. It describes what we collect, why we collect it, who processes it on our behalf, and what you can make us do about it.

Where you use PostyrX to publish for a brand, you are the controller of the data you bring — your knowledge sources, your customers’ conversions — and we process it on your instructions. For your own account, we are the controller.

2.What we collect about you

CategoryWhat it isWhy
Account identityEmail address, name, username, avatar URL, time zone, and the Clerk user ID that identifies you to our authentication provider.To give you an account, sign you in, and evaluate anything scheduled "Monday 07:00" in your own zone rather than UTC.
Sign-in credentialsNone. Clerk holds your password or social sign-in. PostyrX stores no password for any account created through Clerk.Authentication is delegated, so a breach of our database does not expose a credential.
Billing detailsYour plan, billing email, tax ID if you give one, and the Stripe customer and payment-method identifiers. Invoice records: period, amounts, status, attempt count and failure code.To charge you, show you what you were charged, and retry a failed payment.
Connected platform accountsOAuth access and refresh tokens, encrypted at rest; the scopes you granted; and the profile the platform returns — its user ID, username, display name, profile picture and account type.To publish on your behalf to the accounts you connected, and to tell you when a token has expired before a post fails.
Your content and your BrainDrafts, variants, media you upload or we generate, and everything you connect as a knowledge source — repositories, crawled pages, uploaded files, pasted text — stored as documents, passages and embeddings.To draft posts that cite your own material instead of guessing, and to publish them once you approve.
UsageWhen you were last active, and what the agent did on your behalf.To run the product, and to show you what happened in a week.

We never see your card. Payment details go to Stripe directly; what we store is the identifier Stripe gives us and the history of what was charged.

Your platform tokens are encrypted at rest and used only to publish what you approved, to the accounts you connected. We do not read your inbox, your direct messages, or anything the granted scopes do not cover.

3.What we collect about people who click your links

Attribution is the point of the product: it tells you which post earned money. That means recording something about the people who clicked. Here is exactly what, and what we refuse to record.

CategoryWhat it isWhy
A first-party visitor identifierA random ID in a cookie named px_vid, set on the link domain when someone follows a tracked link. It lasts 365 days and is scoped to one brand — the same browser following two different brands’ links gets two unrelated IDs.To join a click to a purchase without profiling anyone across the web. It is not a fingerprint and it is not shared with an ad network.
A salted hash of the IP address — or nothingWe never store a raw IP address. We store a salted SHA-256 of it, and when no salt is configured on the deployment we store nothing at all and the column stays empty.To tell two visitors apart. An unsalted hash of an IP address is reversible in minutes, so it is not treated as anonymisation here.
A salted hash of an email address — or nothingWhen a sale is reported to us, an email may be used to match it to an earlier click. It is hashed the same way and, again, is not stored at all when no salt is configured. The match is confined to one brand.To attribute a purchase to the post that caused it when the buyer switched device between the click and the payment.
Request contextBrowser user-agent string, referring URL, and a two-letter country code.To report which platform a click came from and to discard obvious bot traffic.
Conversion recordsThe value and currency of a reported sale, when it happened, and the reference the reporting system gave it.To show a customer what their posts earned, and — on the Partner plan — to calculate the revenue share they are invoiced.

No raw IP address and no raw email address is stored in these tables. Both are salted hashes, and when a deployment has no salt configured they are not written at all — the column stays empty and the click is still counted. An unsalted hash of an IP address can be reversed in minutes, so we do not treat one as anonymisation.

We do not build cross-site profiles, and we do not sell or share this data for advertising. The visitor identifier is first-party, scoped to a single brand, and not joined to any advertising network. The same browser following two brands’ links is two unrelated records.

If you use PostyrX to publish, telling your own visitors about this is your responsibility as the controller of that data — including any consent banner your jurisdiction requires before a cookie is set.

4.How AI models are used

Drafts are written by a language model against passages retrieved from your own connected sources. That means the text of those passages, and your prompts, are sent to the model provider named in section 6.

Figures are never generated. Numbers, prices and logos in generated images are rendered from templates using your real data; the generative model only ever receives the prompt for a backdrop, and a prompt containing a digit is refused before it reaches a provider.

We do not use your content to train models of our own. We use these providers through their commercial APIs, and rely on the terms attached to those APIs regarding training on submitted data — if you need a specific contractual assurance on that point for your own compliance, ask us and we will show you what the current terms say rather than paraphrase them here.

6.Who else processes it

PostyrX runs on other people’s infrastructure. These are the services that handle personal data on our behalf:

ServiceRoleWhat reaches it
ClerkAuthenticationEmail, name, credentials, session
StripePaymentsBilling email, payment method, charge history
NeonDatabase (PostgreSQL)Everything PostyrX stores
RenderApplication hostingEverything in transit through the API
VercelWeb hostingRequests to the website and app
CloudinaryMedia storageImages and video you upload or generate
AnthropicLanguage modelsPrompts and the passages a draft cites
Voyage AIEmbeddingsText from your connected sources
ResendTransactional emailYour email address and the message
PostHogProduct analyticsWhich screens are used, identified by brand — never your name, email, IP address, post content or revenue figures
Generative media providersImages and video, when usedThe prompt only — never your figures, prices or logos, which are rendered from templates
The platforms you connectPublishingThe post, its media, and the token you granted — Meta, Google, LinkedIn, X and Reddit as applicable

Some of these process data outside your country, including in the United States. Where that applies to data protected by UK or EU law, the transfer relies on the standard contractual clauses in that provider’s terms.

We do not sell personal data. We have never sold personal data. If that ever changes this page changes first, and you would be told before it took effect.

7.How long we keep it

  • Account data — for as long as you have an account, and then removed on deletion.
  • Content, media and your Brain — until you delete them, or until your account is deleted.
  • Clicks, visitors and conversions — kept while they are useful for attribution and reporting, and removed with the brand they belong to.
  • Invoice and payment records — for as long as tax and accounting law requires, which is longer than your account may last.
  • Backups — on a rolling cycle, at most 30 days. Deleted data is never restored into service from a backup.

8.What you can make us do

Depending on where you live, you have some or all of these rights. We honour all of them for everyone, rather than checking your jurisdiction first.

  • Access — a copy of what we hold about you.
  • Correction — fix anything inaccurate.
  • Deletion — remove your account and its data. See the deletion page for exactly what goes and what is kept.
  • Portability — your content in a machine-readable form.
  • Objection and restriction — tell us to stop a particular use.
  • Withdraw consent — where consent is what we relied on.
  • Complain to a regulator — in the UK the ICO, in the EU your national authority. We would rather you came to us first, but you do not have to.

Write to privacy@postyrx.com from the address on the account. We answer within 30 days.

A request about a visitor, rather than about you. If someone asks you to delete their data and they are in your attribution records, forward it — we can find them by the identifier in their cookie. We cannot find them by email alone unless a hashed match already exists, because we hold no reversible copy of an email address.

9.How it is protected

  • Every brand is separated in the database itself, by row-level security that the application cannot bypass — not by a filter in application code that a query could forget.
  • Platform OAuth tokens are encrypted at rest.
  • Credentials are held by our authentication provider; PostyrX stores no password.
  • Traffic is TLS-encrypted in transit.
  • IP and email values in attribution are salted hashes, or are not stored.

No system is perfect. If a breach affects your personal data we will tell you and the relevant regulator, within the time the law allows and without waiting to have a complete picture first.

10.Google and YouTube data

PostyrX uses YouTube API Services. When you connect a YouTube channel you sign in with Google and grant PostyrX two permissions: to upload videos to that channel and set their thumbnails (youtube.upload), and to read your channel and the videos on it (youtube.readonly). Google then gives us the channel’s ID, title and thumbnail, and an access token that we encrypt at rest.

Neither permission lets PostyrX delete, rate or comment on anything. Google does not grant those under the two above, so it is enforced by Google rather than promised by us.

What we do with it. We upload the videos you approved, at the time you scheduled them; we set the title, description, tags, thumbnail and privacy status on those uploads; and we read their processing status so you can see whether the upload succeeded. You choose who can see each video, and whether it is made for kids; PostyrX never chooses either for you — a video with no answer to both is not uploaded. We do not read, rate, comment on or delete videos that were not uploaded through PostyrX, and we do not use any of this data for advertising, sell it, share it beyond the sub-processors in section 6, or use it to train models.

Nothing from YouTube reaches an AI model. No data received from the YouTube Data API is transmitted to any AI or machine learning service, including the model providers listed in section 6. Engagement counts are read by our own deterministic statistical code to work out which hour of the week your posts do best, and that recommended hour is the only thing derived from them that goes any further; no YouTube field, identifier or value is included in any prompt, embedding or other model input, and none of it is used to develop, improve or train any model.

PostyrX’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

How long we keep it, and how to end it. The token and channel details are held until you disconnect the channel in PostyrX or delete your account, and the channel details are refreshed each time we check the connection. Disconnecting deletes our copy; to make Google invalidate the token itself, remove PostyrX on the Google security settings page. Videos already published stay on your channel until you remove them there. The full deletion route is on the data deletion page. On disconnection or account deletion the stored token and channel details are removed within 30 days, and sooner in practice; backups age out on a 30-day rolling cycle.

By connecting a YouTube channel you also agree to be bound by the YouTube Terms of Service. Google’s handling of your data is described in the Google Privacy Policy.

11.Children

PostyrX is a business tool and is not for children. We do not knowingly collect data from anyone under 16. If you believe a child’s data has reached us, write to us and we will remove it.

12.Changes to this policy

When this policy changes materially we will update the effective date and tell account holders by email before the change takes effect. Continuing to use PostyrX after that means you accept the new version.

Who operates PostyrX

PostyrX is a product of Synll Labs. The registered company details and postal address for this notice have not been published yet. Until they are, write to the address below and we will answer.

Privacy and data requests: privacy@postyrx.com

Everything else: contact@postyrx.com