Legal

Privacy Policy

What personal data postyay collects, why, who processes it, how long we keep it, how we use TikTok data, and your rights under the GDPR and KVKK.

In short

  • We collect what we need to run postyay: your e-mail address, your posts and media, and the connections to the social accounts you choose.
  • We use your data to provide the Service to you. We don’t sell it, and we don’t use it for advertising.
  • Access tokens for your social accounts are encrypted, and you can disconnect them at any time.
  • Your data is stored on our servers in Germany. A few providers help us run the Service; they’re listed below.
  • Paid plans are sold by our reseller Paddle, which handles your payment details under its own privacy policy.
  • You can download a copy of your data and delete your account yourself, in Settings. See Data deletion.

Who is responsible

This policy explains how [Company legal name], [Registered address, city, country] (“postyay”, “we”), handles personal data when you use postyay.com, the postyay app and our e-mails. We are the data controller (in Türkiye: veri sorumlusu) for that data. You can reach us at [email protected].

This policy doesn’t cover the platforms you connect, such as TikTok, which have their own privacy policies.

What we collect

Account. Your e-mail address, your name if you add one, your language, your answer to the onboarding question (what you post about), and when you signed up and were last active.

Sign-in and sessions. One-time sign-in codes (stored only as a hash and valid for 10 minutes), and for each signed-in browser a session token, its IP address and its user agent.

Workspace and posts. Your workspace name and time zone, the posts you write (captions, titles and platform settings such as TikTok privacy and disclosure choices), when they’re scheduled, and each post’s delivery timeline, including the platform’s response when something fails.

Post performance. For posts we published for you, the numbers the platform reports about them — on TikTok: views, likes, comments and shares; on Bluesky: likes, reposts, replies and quotes — fetched about 1 hour, 1 day, 7 days and 30 days after publishing and kept with the post. We use them to show how your posts are doing and to suggest good times to post based on your own posts. They aren’t shared with other users, and they are deleted with the post’s workspace.

Media. The videos and photos you upload, with technical details such as file type, size, dimensions and duration. The files are stored on our own servers.

Connected accounts. For each social account you connect: its platform ID, username, display name and profile picture link, the permissions you granted, and the access tokens the platform gives us, encrypted with AES-256-GCM. See “TikTok data” below.

Support. The messages you exchange with our team, the page you wrote from, and notes our team keeps to help you. If you use our contact form, the name, e-mail address, topic and message you send (when you’re signed in, it goes into your support conversation instead).

Notifications. Your e-mail notification settings, and a record of which notices we sent you and when.

Billing. Paid plans are sold by our reseller Paddle (see “Who processes your data”). When you buy one, Paddle collects your payment details, e-mail address and country (with your postal code where tax rules need it) and, if you add them, your business name, address and tax ID. From Paddle we receive only what we need to run your plan: the plan, billing period, price, subscription status and dates, and Paddle’s customer, subscription and transaction IDs. We never receive your full card number.

Usage and technical data. A record of what happens in your account (for example, “post scheduled” or “account connected”), which powers your post timelines, helps support and shows us how postyay is used. Before our product analytics events are stored, e-mail addresses, names, captions and message text are removed from them. Our servers also keep technical logs (such as IP addresses, request paths and errors) to keep the Service secure and working.

We don’t ask for sensitive data (such as health or political views), and we don’t buy data about you from anyone.

TikTok data

When you connect a TikTok account, TikTok asks you to approve these permissions (scopes):

  • user.info.basic: your TikTok open ID, display name and profile picture, so we can show which account is connected.
  • user.info.profile: your TikTok username, so we can show it and link to your profile and posts.
  • video.publish: to publish the videos and photos you schedule directly to your TikTok profile. As part of this, we ask TikTok for your account’s current posting options (such as the privacy levels you can choose, whether comments, Duet and Stitch are available, and the longest video you can post) so the composer only offers choices that will work.
  • video.list: to read the public counts (views, likes, comments and shares) of the videos postyay published for you, so we can show how they’re doing and suggest your best times to post. We only look up videos we published for you. Accounts connected before we added this permission don’t have it: postyay shows “Reconnect to enable analytics” for them, and posting keeps working without it.

We use TikTok data only to provide the features you use in postyay: showing your connected account, publishing your posts when you ask us to, showing their status and link, and showing their performance. We send TikTok the media, caption and settings of the posts you schedule, and nothing else. We don’t read your other videos, your followers, the content of comments or your messages, and the only statistics we read are the counts above for posts we published for you. We don’t sell TikTok data, use it for advertising or share it with anyone except as described in this policy, and we don’t use it to train AI models.

You can revoke our access at any time: disconnect the account in postyay (Accounts → Disconnect), which also asks TikTok to revoke our access and erases the tokens we stored, or remove postyay in the TikTok app under Settings and privacy → Security & permissions → Apps and services permissions (menu names can vary by app version). TikTok’s own handling of your data is covered by the TikTok Privacy Policy.

How we use data, and our legal grounds

What we doLegal ground (GDPR / KVKK)
Create your account, sign you in, run your workspace, store your media and publish your postsPerforming our contract with you (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c))
Send service e-mails: sign-in codes, support replies and notices about your posts and accountsContract (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c))
Answer support, including opening your account when you need helpContract, and our legitimate interest in fixing problems (GDPR Art. 6(1)(b), (f); KVKK Art. 5(2)(c), (f))
Billing, invoices and tax recordsContract and legal obligations (GDPR Art. 6(1)(b), (c); KVKK Art. 5(2)(c), (ç))
Security, preventing abuse, server logs and records of staff accessLegitimate interests and legal obligations (GDPR Art. 6(1)(f), (c); KVKK Art. 5(2)(f), (ç))
Understanding how postyay is used, to improve itLegitimate interests (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f))

We don’t send marketing e-mails without your consent, we don’t sell personal data, and we don’t make decisions about you by automated means that have legal or similarly significant effects.

We don’t send your posts, captions or media to AI services. If we add optional AI features, we’ll update this policy and tell you before any of your content is processed by them.

Who processes your data

A few providers help us run postyay. They process data only on our instructions and under data processing terms.

ProviderWhat they doWhere
Hetzner Online GmbHHosts our servers, database and your uploaded mediaGermany (EU)
Cloudflare, Inc.DNS, content delivery and protection against attacks; all traffic to postyay.com passes through itGlobal network (US company)
ResendSends our e-mails (sign-in codes, support replies, notices)United States

Paddle (Paddle.com Market Limited, United Kingdom, and its affiliates) sells our paid plans to you as our reseller and Merchant of Record. It isn’t our processor: it processes your payment and billing data as an independent controller, under the Paddle Privacy Policy, and shares with us the subscription details listed under “Billing” above.

TikTok isn’t our processor: when we publish to TikTok for you, TikTok handles that content under its own policies. Our staff also use Anthropic’s Claude to help draft blog articles; none of your data is sent to it.

We may also disclose data when the law requires it (for example, a valid court order), to protect the rights and safety of our users or the Service, or as part of a merger or sale of the business, in which case this policy keeps applying to your data.

Staff access

Our team can see the data needed to support you: your account details, connected accounts (never their tokens), posts and their timelines, and support messages. Access to staff tools is limited to the people who run the Service.

If fixing something requires it, a staff member can open your account as you (“view as user”). Each time, the reason is recorded, you’re told in your support chat who came in and why, the session ends after one hour at most, and changing billing or disconnecting accounts is blocked. Every staff action on an account is kept in an audit log.

Cookies and local storage

We only use cookies that postyay needs to work, which is why there’s no cookie banner:

CookieWhat it doesHow long
better-auth.session_tokenKeeps you signed in30 days, renewed while you use postyay
better-auth.session_dataA short-lived copy of your session so pages load faster5 minutes
NEXT_LOCALERemembers the language you picked1 year
Cloudflare security cookies (such as __cf_bm)Tell people from bots and protect the site, when neededUp to 30 minutes

Over HTTPS, the session cookie names start with __Secure-. Your browser’s local storage also keeps a few interface preferences, such as the day your week starts; they stay on your device.

If you buy a paid plan, Paddle’s checkout may use its own cookies to take your payment and prevent fraud; see the Paddle Privacy Policy.

We don’t use advertising cookies or third-party trackers. If we measure visits to our website, we do it without cookies and only in aggregate (for example, with Cloudflare Web Analytics).

How long we keep data

  • Account, workspace, posts, media and connected accounts: while your account exists; deleted when you delete it (see Data deletion). Deleting a single post cancels it if it hasn’t gone out and hides it; its record is erased with your account.
  • Disconnected accounts: the tokens are erased the moment you disconnect. The account’s name stays on your past posts until you delete your account.
  • Sign-in codes: 10 minutes. Sessions: they expire after 30 days without use.
  • Support conversations: while your account exists, so we have the history if you write again.
  • Contact form messages sent while not signed in: kept until 12 months after we’ve dealt with them. If you have an account with the same e-mail address, they’re part of your data download and are deleted with your account.
  • Server logs: up to 30 days. Product analytics events: up to 180 days; they contain IDs, not your name, e-mail address or content.
  • Records of staff access and admin actions: kept for security and accountability; when you delete your account, the link to you is removed.
  • Billing records: the subscription details we receive from Paddle, as long as tax and accounting laws require (up to 10 years). Paddle keeps its own records under its privacy policy.
  • Database backups: our daily backups age out within 60 days, so deleted data disappears from them within that time.

Security

We use HTTPS everywhere, encrypt platform access tokens at rest (AES-256-GCM), store sign-in codes only as hashes, rate-limit sign-in attempts, and limit access to production systems to the people who run the Service. No system is perfectly secure: if a breach affects your personal data, we’ll tell you and the authorities as the law requires.

International transfers

Our servers are in Germany. Some providers (Cloudflare and Resend) process data in other countries, including the United States. For these transfers we rely on the mechanisms the law provides, such as the European Commission’s Standard Contractual Clauses or the EU–US Data Privacy Framework, and for data from Türkiye, the safeguards in Article 9 of the KVKK. Paddle is responsible for the transfers of the billing data it controls.

Your rights

Depending on where you live, you can:

  • ask what personal data we hold about you, and get a copy (you can download one yourself: Settings → Your data → Download my data);
  • correct it (you can change your name yourself in Settings);
  • have it deleted (Settings → Danger zone → Delete account; see Data deletion);
  • receive it in a portable format;
  • object to processing based on our legitimate interests, or ask us to restrict it;
  • withdraw consent where we rely on it;
  • complain to a data protection authority, for example where you live or work (in Türkiye, the Personal Data Protection Authority).

Write to [email protected] from the e-mail address on your account, or message us in the app. We answer within 30 days, free of charge.

Information notice for Türkiye (KVKK)

This section is our information notice (aydınlatma metni) under Article 10 of the Turkish Personal Data Protection Law No. 6698 (KVKK).

  • Data controller: [Company legal name], [Registered address, city, country].
  • Data we process, and why: as described in “What we collect” and “How we use data” above.
  • How we collect it: electronically, from you through the website, the app and e-mail, and from the platforms you connect.
  • Legal grounds: KVKK Article 5(2)(c) (establishing and performing a contract), (ç) (our legal obligations) and (f) (our legitimate interests), and your explicit consent where the law requires it.
  • Transfers: to the providers listed above, some of which are abroad, under Article 9 of the KVKK; to Paddle (United Kingdom), our reseller, when you buy a paid plan; and to public authorities when the law requires it.
  • Your rights under Article 11: to learn whether your data is processed and ask for information about it; to learn the purpose and whether it’s used for that purpose; to know the third parties in Türkiye or abroad it’s transferred to; to ask for it to be corrected, deleted or destroyed, and for those third parties to be told; to object to a result against you that arises only from automated analysis; and to claim compensation for damage caused by unlawful processing.

Send requests to [email protected], or by the other methods set out in the Communiqué on the Procedures and Principles of Application to the Data Controller. We answer within 30 days, free of charge.

Children

postyay isn’t meant for anyone under 18, and we don’t knowingly collect data from children. If you think a child has given us personal data, write to us and we’ll delete it.

Changes to this policy

When we change this policy, we update the date at the top. If a change is significant, we’ll tell you by e-mail or in the app before it applies.

Contact

Questions or requests about your data: [email protected], or use our contact form.

Who we are

Company
[Company legal name]
Address
[Registered address, city, country]

Questions about this page?

Write to [email protected] or message us from the chat in the app. A person on the team answers.