Privacy Policy
Last updated: September 10, 2026 • Compliant with GDPR, UK GDPR, KVKK, and CCPA standards.
Payment Data & Merchant of Record Notice
PostReady does not store, handle, or process sensitive credit card, debit card, or banking numbers on our servers. All transactions are securely conducted by our online reseller and Merchant of Record, Paddle.com. Paddle is PCI-DSS Level 1 certified and operates as an independent data controller for payment operations.
1. Introduction
At PostReady (“PostReady”, “we”, “us”, or “our”), we take your privacy and data protection seriously. This Privacy Policy outlines how we collect, use, disclose, and safeguard personal information when you access our content repurposing platform at postready.org.
By using PostReady, you consent to the data practices described in this policy. If you do not agree with any terms of this policy, please discontinue use of our service immediately.
2. Information We Collect
We collect information in the following categories:
When you create an account, we collect your email address, display name, and avatar URL if authenticated via OAuth providers (such as Google).
Text, links, draft notes, or transcripts you submit to the Studio for transformation, as well as the resulting generated threads, posts, and summaries.
IP address, approximate country location (used for localized currency and tax calculation), browser user-agent, operating system, and generation activity logs.
Authentication session cookies and browser localStorage keys to retain your dark/light theme, UI language, and recent generation history.
3. How We Use Information
We utilize collected information for the following legitimate purposes:
- Service Delivery: Processing your source text into multi-channel social media and newsletter formats.
- Account Administration: Managing subscription statuses, credit allocations, and profile preferences.
- Security & Abuse Prevention: Detecting fraudulent account creation, automated bot spam, and API rate limit abuse.
- Customer Support: Diagnosing errors, resolving technical tickets, and answering questions sent to support.
- Compliance: Fulfilling our legal, regulatory, and taxation obligations in partnership with Paddle.com.
4. AI Prompt Processing & Model Privacy
PostReady routes editorial transformation requests through enterprise API endpoints provided by leading artificial intelligence providers (such as Anthropic, OpenAI, Deepseek, or Google Vertex AI).
Strict Zero-Training Policy:
Our agreements with AI infrastructure partners explicitly stipulate that your submitted inputs, source materials, and generated outputs are NOT used to train, retrain, or improve foundational AI models. Your proprietary writing, transcripts, and confidential research remain entirely your own.
5. Payment Processing & Paddle.com
When you upgrade to a paid tier (such as Starter, Pro, or Agency) or purchase credit add-ons, your payment is processed directly by Paddle.com Market Ltd (“Paddle”).
Paddle acts as the Merchant of Record. Under this model:
- Paddle collects your payment information, billing address, and country details.
- PostReady only receives non-sensitive confirmation tokens, such as your subscription ID, tier name, active status, and billing cycle.
- Paddle securely stores payment methods and performs automated recurring renewals under industry-standard PCI-DSS Level 1 compliance.
6. Cookies & Tracking Technologies
We use strictly necessary cookies to maintain secure authenticated sessions and retain basic user interface preferences (such as light/dark mode and language settings). We do not engage in cross-site tracking, third-party advertising networks, or data brokerage.
We utilize privacy-friendly analytics (such as Vercel Analytics) that aggregate traffic data without setting persistent tracking cookies or harvesting personal identifying information.
7. Your Data Subject Rights (GDPR / UK GDPR / KVKK / CCPA)
Regardless of where you reside, we respect your fundamental privacy rights. Under applicable data privacy laws, you are entitled to:
- Right of Access: Request a full copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete personal information.
- Right to Erasure (“Right to be Forgotten”): Request the permanent deletion of your account, history, and associated personal records.
- Right to Data Portability: Obtain your stored data in a structured, commonly used, and machine-readable format (JSON).
- Right to Restrict or Object to Processing: Limit or object to how we process specific data categories.
To exercise any of these rights, please email us directly at support@postready.org. We process all validated data subject requests within 30 calendar days at no cost to you.
8. Data Retention & Security
We implement robust administrative, technical, and physical safeguards designed to protect personal data against accidental, unlawful, or unauthorized destruction, loss, alteration, access, or disclosure. All data transmissions occur over encrypted HTTPS/TLS channels.
We retain your account profile and usage data for as long as your account remains active. If you delete your account or request data erasure, your records are permanently purged from active databases within 30 days.
9. Contact & Data Protection Officer
For any questions, requests, or concerns regarding our privacy practices or this Privacy Policy, please contact our privacy compliance team:
Email: support@postready.org
Subject Line: “Data Privacy Request”
Response SLA: Inquiries are addressed within 24 to 48 business hours.