LEGAL

Privacy Policy

What we collect, how we use it, who we share it with, how long we keep it, and your rights. Short version: we collect what the Service needs to run, and we don't sell, rent, or share your data for advertising.

Effective July 27, 2026

About this Policy

This Privacy Policy (the “Policy”) applies to postmill.ai and to the Postmill Cloud application (together, the “Service”), operated by REAA Technologies Inc (“REAA,” “we,” “us,” or “our”). It explains what personal information we collect when you use the Service, why we collect it, who we share it with, how long we keep it, and the rights you have over it. By using the Service, you consent to the data practices described in this Policy.

What we do not do

Up front, so you can stop reading sooner if these are your concerns:

  • We do not sell, rent, or lease your personal information to anyone.
  • We do not share your information with advertisers, ad networks, data brokers, or marketing-automation vendors.
  • We do not load advertising pixels, remarketing tags, or cross-site trackers on the Site.
  • We do not collect biometric data.
  • We do not see or store your full payment-card number — payments are handled by Stripe.
  • We do not use the content from your connected channels, or your AI provider keys, for anything other than providing the Service to you.

What we collect

Account information. When you register, we collect your name, email address, a hash of your password, and your organization and team memberships, roles, and settings.

Billing information. Your plan, add-on packs, invoices, and billing history. Payment-card details are entered directly with Stripe, our payment processor; REAA receives only the card brand, last four digits, and expiry needed to display your payment method.

Channel connections. When you connect a channel (a social network, chat platform, blog, or email service), we receive the OAuth access tokens needed to publish, schedule, and retrieve analytics on your behalf, plus the public profile metadata needed to display the connection (for example, the account name and avatar). Tokens are stored encrypted at rest.

AI provider keys. When you connect an AI provider, we store the API key you enter, encrypted at rest, along with your configuration (such as spend caps) and the usage metadata needed to show you spend and audit views. We never log key values.

Your content. Drafts, scheduled and published posts, campaign data, brand kits and brand-voice settings, planning notes, and the media files you upload to your library.

Product activity. Analytics snapshots retrieved from your channels, reply threads in your inbox, and audit logs of actions taken in your workspace.

Server logs. Our hosting providers maintain standard web server logs containing IP address, request path, user agent, referring URL, and timestamp.

Error telemetry. When the Service encounters an unhandled error, we send a report to Sentry that includes a stack trace, the URL the error occurred on, and basic browser/device context. Secrets and personal data are scrubbed at source before any report is captured.

How we use your information

We use the information we collect to:

  • operate the Service — publish and schedule your content at your direction, retrieve your analytics, and deliver your replies;
  • send your prompts and content to the AI providers whose keys you have connected, so their models can do the work you ask of them;
  • send transactional email (confirmations, billing notices, security alerts) and product notifications you have enabled (for example, a post published or failed);
  • detect and prevent abuse, fraud, and security incidents;
  • diagnose and fix bugs and operational errors;
  • measure aggregate product usage so we can improve the Service;
  • comply with applicable laws, regulations, legal process, and government requests.

Who we share information with

We work with a small number of vetted third-party providers who help us run the Service, each bound by contract to use the information we share only to deliver the service for which we engaged them (see “Sub-processors” below).

At your direction, information also flows to two further groups, under your own agreements with them: the channels you connect (your content and connection tokens flow through their APIs, subject to their privacy policies) and the AI providers whose keys you connect (the prompts and content you send through them).

We may disclose your personal information, without notice, if required to do so by law, legal process, or government request, or in good-faith belief that disclosure is necessary to (a) comply with the law, (b) protect and defend our rights or property, or (c) act under exigent circumstances to protect the personal safety of our users or the public.

Sub-processors

  • Stripe — processes payments and manages the billing portal. Sees your payment method and billing details; we never see your full card number.
  • Resend — sends transactional email on our behalf. Sees the recipient address and the message we send.
  • Sentry — receives scrubbed error reports; sees IP, user-agent, and any data captured in the error context.
  • Cloud infrastructure providers — host the application and database; see IP address and request metadata as part of normal hosting.

Analytics

On the marketing Site we use Plausible Analytics, a privacy-respecting, EU-hosted, cookieless analytics service. Plausible counts unique visitors using a daily-rotating hash of IP address and user-agent (the underlying values are not retained) and records pageviews plus two custom events: trial-button clicks and contact-form submissions. No cookies are set for analytics, no advertising profiles are built, and no cross-site tracking takes place.

Inside the product, we measure aggregate feature usage to improve Postmill — likewise without advertising profiles.

Cookies

The Service uses a small number of functional cookies: session cookies that keep you signed in, and short-lived CSRF tokens set during OAuth connection handshakes (deleted when the callback completes). The Service sets no advertising cookies. You can decline or delete cookies via your browser settings; signing in will not work without functional cookies.

Security

We maintain reasonable administrative, technical, and physical safeguards designed to protect personal information from unauthorized access, use, or disclosure. Traffic to and from the Service is served over HTTPS (TLS). Channel access tokens and AI provider keys are encrypted at rest using AES-256-GCM, and access to workspace data is scoped per organization.

No data transmission over the Internet or any wireless network can be guaranteed to be 100% secure. While we take reasonable steps, you acknowledge that (a) there are security and privacy limitations inherent to the Internet that are beyond our control, and (b) the security, integrity, and privacy of any information exchanged between you and us through the Service cannot be guaranteed.

Data retention

Account and workspace data is retained while your account is active. When you delete your account or request deletion, we remove your personal information and workspace content within 30 days, except for encrypted backups, which roll off within a further 30 days. Server logs roll off on our hosting providers' schedules (typically 30 days). Sentry error reports are subject to Sentry's default retention windows for our plan. Billing records are retained as required by tax and accounting law.

Your rights

Regardless of where you live, you may:

  • request access to the personal information we hold about you;
  • request correction of inaccurate information;
  • request deletion of your personal information;
  • object to or request restriction of certain uses (including any use you believe is unfair);
  • export a copy of the personal information you have provided to us in a portable format.

California residents (CCPA/CPRA)

We do not “sell” or “share” personal information for cross-context behavioural advertising as those terms are defined under the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act. Because we do not sell or share, there is no opt-out mechanism for us to provide — but you retain all other CCPA/CPRA rights (access, correction, deletion, portability, limit-use-of-sensitive-info, non-discrimination for exercising those rights), which you may exercise via the contact address below.

EU/EEA/UK residents (GDPR/UK GDPR)

Our legal bases for processing personal information are contract (to deliver the Service you have subscribed to), legitimate interests (to operate the Service, secure it against abuse, and measure aggregate usage), and your consent where applicable. You may exercise your access, rectification, erasure, restriction, portability, and objection rights via the contact address below, and you have the right to lodge a complaint with your supervisory authority.

Right to deletion — exceptions

Subject to certain exceptions, on receipt of a verifiable request from you we will delete your personal information from our records and direct our service providers to do the same. We may decline to comply with a deletion request, or comply only in part, if it is necessary for us or our service providers to:

  • complete a transaction for which the personal information was collected or perform a contract between you and us;
  • detect security incidents; protect against malicious, deceptive, fraudulent, or illegal activity; or prosecute those responsible for such activity;
  • debug to identify and repair errors that impair existing intended functionality;
  • exercise free speech, ensure the right of another consumer to exercise free speech, or exercise another right provided for by law;
  • enable solely internal uses reasonably aligned with the context in which you provided the information;
  • comply with an existing legal obligation; or
  • otherwise use your personal information internally in a lawful manner that is compatible with the context in which you provided it.

Breach notification

In the event of a security incident involving personal information, we will promptly investigate and provide notice to affected individuals and to applicable regulatory authorities in the manner and within the timeframes prescribed by applicable law.

Email communications

Email we send is transactional — billing and account notices, security alerts, and product notifications you have enabled (per-category toggles are in your notification settings). We do not send marketing or promotional email blasts. If you receive an email from us that you wish to stop, use the unsubscribe link in it or email the contact address below.

Disconnecting channels and AI providers

You may disconnect a channel at any time from your workspace settings, or revoke Postmill's access directly from the channel's own app settings (for example, under “Authorized apps”). You may remove an AI provider key at any time, which stops all requests through it. Disconnecting does not delete data we have already received under that connection — use the deletion request flow above for that.

Links to other sites

The Service contains links to other websites — most obviously the channels and AI providers you connect. We are not responsible for the content or privacy practices of those sites. When you follow a link off our Service, please review the privacy statement of the destination site.

Children

REAA does not knowingly collect personally identifiable information from children under the age of 13. If you are under 13, please do not use the Service or submit any personal information. If we learn that we have inadvertently collected personal information from a child under 13, we will delete it promptly. If you are between 13 and 18, please use the Service only with the permission of a parent or guardian.

International transfers

REAA is based in the United States, and several of our service providers operate worldwide. When you use the Service, your information may be processed in the United States or in another country in which one of our service providers operates. By using the Service, you acknowledge and consent to the transfer of your information to jurisdictions which may have different data protection laws than your home country.

Changes to this Policy

We reserve the right to change this Policy from time to time — for example, when our services change, when our data-protection practices change, or when the law changes. When changes are significant, we will notify you (by email to the address we have on file for you, by placing a prominent notice in the Service, or both). Your continued use of the Service after such modifications constitutes (a) your acknowledgement of the modification and (b) your agreement to be bound by the modified Policy.

Contact

For questions or comments about this Policy, or to exercise any of your rights, email rick@postmill.ai. We will respond within 30 days, or sooner where required by applicable law.