Privacy Policy
Last updated: 2026-10-06
1. Who we are
Postcove (postcove.net) is operated by M. Marcos ("Postcove", "we", "us"), based in Portugal, in the European Union. For EU and EEA data protection law (GDPR), we are the data controller for the personal data described in this policy.
Contact us about privacy at [email protected]. For everything else, write to [email protected].
2. What Postcove does
Postcove publishes posts to the social media accounts you connect, at the times you choose. You can use it on postcove.net, through our API, through AI assistants connected to our MCP server, or from inside FolioPress.
3. What we collect
Waitlist. Your email address, the platforms you told us you post to, the language of the page you joined from, and where you came from (a referral or campaign tag in the link, if there was one).
Your account. Your name, email address and password. The password is stored only as a salted hash, never in plain text. If you turn on two-factor authentication, we also store its secret.
Social accounts you connect. When you connect an account (for example on Bluesky, LinkedIn, Facebook, Instagram, Threads, TikTok, YouTube, Pinterest or X), the platform gives us:
- your account's ID, username, display name and profile picture
- the access and refresh tokens that let us post for you
- which permissions you granted
You also choose a language for each account. We encrypt the tokens before storing them.
Your content. The posts you write or schedule, including:
- the versions you write for each account
- images and videos you upload
- schedules and time zones
- what each platform returned when we published: the post's ID and link, or the error
Billing. If you subscribe, our payment provider, Polar (polar.sh, merchant of record), handles your payment details. We receive your plan, subscription status and invoices, never your card number.
Technical data. Our servers log requests (IP address, browser, time, page) to keep the service secure and working. We measure visits with Plausible, a cookieless analytics tool we host ourselves. It counts visits in aggregate and does not identify you or follow you across sites.
4. Why we use it, and on what legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Running your account and publishing your posts | Contract (Art. 6(1)(b)) |
| Telling waitlist members when Postcove opens | Consent (Art. 6(1)(a)); withdraw any time |
| Service emails (password reset, failed posts, account changes) | Contract |
| Billing and accounting | Contract; legal obligation (Art. 6(1)(c)) |
| Security, abuse prevention, fixing errors | Legitimate interest (Art. 6(1)(f)) |
| Aggregate, cookieless visit statistics | Legitimate interest |
We do not sell your data, use it for advertising, or build profiles of you.
5. Data from social platforms
We use the access you grant to a platform only to do what you asked:
- show which account is connected
- check its posting limits
- publish your posts and report back whether each one went out
We don't read your feed, messages, followers or other accounts' content, and we don't use platform data to train AI models.
When you disconnect an account, we delete its tokens and ask the platform to revoke them. You can also remove Postcove's access from the platform's own settings at any time.
YouTube. Postcove uses YouTube API Services. By connecting a YouTube account you agree to the YouTube Terms of Service, and Google's use of your data is covered by the Google Privacy Policy. You can revoke Postcove's access at any time on your Google security settings page. Postcove's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Meta (Facebook, Instagram, Threads), TikTok, LinkedIn, X, Pinterest, Bluesky. We follow each platform's developer terms and use their data only as described above. How to delete your data, including from a platform's side, is on our data deletion page.
6. Who processes data for us
We use a small number of service providers (processors), under data processing agreements:
| Provider | What for | Where |
|---|---|---|
| Hetzner Online GmbH | Servers that run Postcove and store its data | Germany (EU) |
| Cloudflare, Inc. | DNS, network security and caching of public pages | Global network; EU traffic can be served from EU locations |
| Resend, Inc. | Sending our emails | United States |
| Polar Software Inc. | Payments, as merchant of record | United States |
When you publish, the content goes to the platforms you chose; from then on, their own terms and privacy policies apply to it.
7. Transfers outside the EU
Where a provider processes data outside the EU or EEA (for example in the United States), the transfer relies on the EU–US Data Privacy Framework where the provider is certified under it, or on the European Commission's Standard Contractual Clauses.
8. How long we keep it
- Waitlist: until we email you that Postcove is open, plus 6 months. Sooner if you ask.
- Your account and content: while your account exists. When you delete your account, we delete its data within 30 days.
- Tokens: deleted as soon as you disconnect the account or delete your Postcove account.
- Uploaded media: deleted 30 days after every post that uses it has been published.
- Server logs: 30 days.
- Backups: encrypted, kept up to 30 days, then overwritten.
- Billing records: as long as tax law requires (in Portugal, up to 10 years).
9. Your rights
You can ask us to access, correct, delete or export your personal data, to restrict or object to how we use it, and to withdraw consent at any time. Write to [email protected] and we'll answer within one month.
You can also complain to a data protection authority: in Portugal, the Comissão Nacional de Proteção de Dados (cnpd.pt), or the authority where you live.
10. Cookies
Postcove uses only cookies the service needs to work:
- session: keeps you signed in
- csrftoken: protects forms from cross-site forgery
- language: remembers a language you chose
We don't use advertising or tracking cookies, so there's no cookie banner.
11. Security
- All traffic is encrypted (HTTPS).
- Platform tokens are encrypted at rest.
- Passwords are hashed, and two-factor authentication is available.
- Our admin is reachable only from a private network.
No system is perfectly secure. If we learn of a breach that affects you, we'll tell you and the authorities as the law requires.
12. Children
Postcove is not meant for anyone under 16, and we don't knowingly collect their data.
13. Changes
If we change this policy, we'll update the date at the top. For significant changes, we'll also tell account holders by email before the change takes effect.