Privacy Policy
What information PostReady handles, why it is needed, where it goes and the choices available to you.
Last updated:
At a glance
Your source text is processed by AI services to fulfill generation requests. Saved projects and local drafts have different storage lifecycles. Optional page analytics requires your choice; privacy requests go to support.
1. Who handles your information
Can Özdal, operating PostReady, is responsible for personal data processed to provide the PostReady application. Contact support@postready.org with the subject “Data Privacy Request” for questions or rights requests.
This notice describes our practices; using the website does not constitute consent to every form of processing. We request a separate choice for optional analytics. Polar handles personal data for its checkout and reseller services under its own Privacy Policy.
2. Information we process
- Account information: email, account ID, profile details you provide, authentication and account security records. A connected sign-in provider may supply your name and avatar.
- Content and projects: source text, links, notes, transcripts, generated outputs, revisions, project names and brand preferences you submit or save.
- Billing and usage: plan, customer and subscription identifiers, purchase status, order and credit records, renewal dates and usage information. Checkout collects payment details directly; PostReady does not store full card numbers.
- Support and feedback: messages, attachments and diagnostic details you choose to send. Do not include passwords, payment credentials or unnecessary sensitive information.
- Technical information: requests and security logs may include IP address, browser details, timestamps, errors and accessed paths. Optional public page-view analytics and device-local event counters are described below.
3. Purposes and legal grounds
We process data you provide through forms, account activity and content requests, data returned by authentication and billing providers, and technical data generated when the Service is used.
- Providing the service: authentication, generation, saving projects, credit accounting and subscription access are necessary to perform our agreement with you.
- Security and support: proportionate fraud prevention, troubleshooting and responding to requests serve legitimate interests, subject to applicable legal conditions and your rights.
- Legal obligations: records may be needed for accounting, disputes, lawful requests and other duties imposed by law.
- Optional marketing emails: Product updates, usage tips and promotions require a separate opt-in, which is not required to create or use an account. Withdraw consent in Settings or through each marketing email’s unsubscribe link. Essential account, security and billing notifications are separate.
- Optional measurement: public page-view analytics and local event counters operate only when you enable the performance preference. You can withdraw that choice on the Cookies & Storage page.
Marketing permission records include your email address, consent status, wording and its version, language, source and consent or withdrawal time. When delivery is enabled, Resend processes recipient addresses and message content. Delivery identifiers and failure or complaint events help prevent duplicate or unwanted messages. Source materials and generated drafts are not included in marketing emails. These records are removed when your account is deleted.
Where GDPR applies, these grounds correspond to contract, legitimate interests, legal obligation and consent under Article 6. Where KVKK applies, processing must meet the relevant conditions under Articles 5 and 6; separate explicit consent is sought where required. Optional consent is not a condition of core service access.
4. AI processing and source material
Generation sends the source material, selected settings and relevant context to the configured AI generation service. Requests may use our Omni gateway and upstream model providers. When enabled, OpenJEV receives source excerpts and generated text for source evaluation and grounding checks. This processing is necessary to return the requested result.
PostReady does not use your source text or generated outputs to train its own AI models. Third-party processing and retention depend on the provider and configuration used for a request. For specific data-processing requirements, contact support.
Generated content is not automatically published to social networks by the generation flow. You decide what to export, copy and publish.
5. Service providers and disclosures
- Supabase: account authentication and cloud data storage.
- Hosting and infrastructure providers: delivery of the application, request handling and security. Vercel Web Analytics receives permitted public page views when enabled.
- AI services: the gateway, selected model providers and optional OpenJEV checks described above.
- Polar: checkout, subscriptions, purchase receipts, taxes and billing support. Polar may process data as an independent controller for these purposes.
We may disclose necessary information when required by law, to protect rights or security, or as part of a lawful business transfer with appropriate protections. We do not sell personal data or use it for cross-site behavioral advertising. Providers receive information needed for their function; this is not permission to publish your drafts.
6. International processing
Cloud, payment and AI providers may process data outside your country. The destination depends on the provider and deployed service. Where applicable, international transfers require an appropriate legal mechanism, such as an adequacy decision or contractual safeguards, and the conditions required under KVKK Article 9.
Contact support for information about the providers and transfer arrangements relevant to your use.
7. Storage, retention and security
Account records and saved cloud projects are retained to provide your account and requested features. Records needed for security, billing, legal duties or disputes may need to be retained after account closure. Backups and provider records may follow separate retention cycles; deletion from active storage does not guarantee immediate deletion from every backup.
Local drafts, versions, interface preferences and event counters may remain in your browser until you remove them. Account deletion does not remotely clear browser storage on all your devices. Export needed work before deleting local data; see the storage inventory.
We use access controls and encrypted HTTPS connections in production to help protect data. No system can guarantee absolute security. Report suspected exposure to support.
8. Cookies and optional analytics
Authentication and preference cookies support sign-in and your choices. Optional Vercel public page-view analytics requires the performance preference. Private application paths and URL query parameters are excluded from that integration. Local usage counters store event totals without source text, drafts or user identifiers.
The automatic client exception and performance collector is currently inactive. Essential server logs and information you manually send to support are separate. You can change optional preferences at any time on the Cookies & Storage page.
9. Your rights and requests
Depending on applicable law, you may request access, correction, deletion, portability, restriction of processing, or object to processing based on legitimate interests. You may withdraw optional consent without affecting lawful processing that occurred before withdrawal. Under KVKK Article 11, rights also include learning whether data is processed, its purposes and recipients, requesting notification of corrections or deletion to recipients, objecting to an adverse result arising exclusively from automated analysis, and seeking compensation for unlawful processing.
Email support from your account address and describe your request. We may verify identity proportionately. We respond within the deadline required by applicable law: ordinarily one month under GDPR (with permitted extensions explained to you), and no later than 30 days for KVKK requests. Requests are generally free; lawful exceptions may apply. Some data must be retained for legal obligations.
You may complain to the competent supervisory authority, including the Turkish Personal Data Protection Authority (KVKK), an EU supervisory authority or the UK Information Commissioner where applicable. These rights are not conditional on accepting all optional cookies.
10. Updates and contact
We publish changes with a revised date and communicate material changes where required. For privacy inquiries, contact Can Özdal at support@postready.org. For data held by Polar for its independent checkout activities, use the contact channels in Polar’s Privacy Policy.