Data Protection & Privacy

Privacy Policy

Last Updated: July 26, 2026

1. Overview & Commitment

At PostFlow, we take your privacy and data security seriously. This Privacy Policy explains how we collect, use, encrypt, and safeguard your personal information when you access our AI blog automation platform.

2. Information We Collect

  • Account Information: Your name, work email address, and workspace name provided during signup.
  • Encrypted CMS Credentials: Application passwords for WordPress, Ghost, or Webflow. All credentials are encrypted using AES-256 encryption before being saved to our database.
  • Connected Site Data: Domain names, focus keywords, sitemap URLs, and publishing schedules.
  • Usage & Performance Metrics: Anonymous logs regarding publishing queue success, job retries, and API performance.

3. AI Model Data Policy (No Training Guarantee)

🔒 Our AI Promise: We do NOT sell your data to third parties, nor do we train public AI models on your private articles or CMS content.

When PostFlow rewrites content or generates images via AI models (Claude, OpenAI GPT-4, DALL-E, Flux), data is passed solely via zero-retention API endpoints to produce your requested posts.

4. How We Protect Your Data

We employ industry-standard technical and organizational security measures to protect your information:

  • AES-256 Encryption for stored site passwords and webhooks.
  • TLS 1.3 Encryption for all data in transit between your browser, our API, and your CMS.
  • Isolated Job Queues per domain to ensure data isolation.

5. Your Privacy Rights (GDPR & CCPA)

Depending on your location, you have rights to access, correct, export, or delete your personal data. You may request full account and workspace data deletion at any time by contacting our Data Protection Officer at privacy@postflow.com.

6. Contact Our Privacy Team

PostFlow Privacy & Data Protection Officer
Address: PostFlow Inc. 100 Technology Plaza, San Francisco, CA