What we collect, how we use it, who we share it with, how long we keep it, and your rights. Short version: we collect what the Service needs to run, and we don't sell, rent, or share your data for advertising.
Effective July 27, 2026
This Privacy Policy (the “Policy”) applies to postmill.ai and to the Postmill Cloud application (together, the “Service”), operated by REAA Technologies Inc (“REAA,” “we,” “us,” or “our”). It explains what personal information we collect when you use the Service, why we collect it, who we share it with, how long we keep it, and the rights you have over it. By using the Service, you consent to the data practices described in this Policy.
Up front, so you can stop reading sooner if these are your concerns:
Account information. When you register, we collect your name, email address, a hash of your password, and your organization and team memberships, roles, and settings.
Billing information. Your plan, add-on packs, invoices, and billing history. Payment-card details are entered directly with Stripe, our payment processor; REAA receives only the card brand, last four digits, and expiry needed to display your payment method.
Channel connections. When you connect a channel (a social network, chat platform, blog, or email service), we receive the OAuth access tokens needed to publish, schedule, and retrieve analytics on your behalf, plus the public profile metadata needed to display the connection (for example, the account name and avatar). Tokens are stored encrypted at rest.
AI provider keys. When you connect an AI provider, we store the API key you enter, encrypted at rest, along with your configuration (such as spend caps) and the usage metadata needed to show you spend and audit views. We never log key values.
Your content. Drafts, scheduled and published posts, campaign data, brand kits and brand-voice settings, planning notes, and the media files you upload to your library.
Product activity. Analytics snapshots retrieved from your channels, reply threads in your inbox, and audit logs of actions taken in your workspace.
Server logs. Our hosting providers maintain standard web server logs containing IP address, request path, user agent, referring URL, and timestamp.
Error telemetry. When the Service encounters an unhandled error, we send a report to Sentry that includes a stack trace, the URL the error occurred on, and basic browser/device context. Secrets and personal data are scrubbed at source before any report is captured.
We use the information we collect to:
We work with a small number of vetted third-party providers who help us run the Service, each bound by contract to use the information we share only to deliver the service for which we engaged them (see “Sub-processors” below).
At your direction, information also flows to two further groups, under your own agreements with them: the channels you connect (your content and connection tokens flow through their APIs, subject to their privacy policies) and the AI providers whose keys you connect (the prompts and content you send through them).
We may disclose your personal information, without notice, if required to do so by law, legal process, or government request, or in good-faith belief that disclosure is necessary to (a) comply with the law, (b) protect and defend our rights or property, or (c) act under exigent circumstances to protect the personal safety of our users or the public.
On the marketing Site we use Plausible Analytics, a privacy-respecting, EU-hosted, cookieless analytics service. Plausible counts unique visitors using a daily-rotating hash of IP address and user-agent (the underlying values are not retained) and records pageviews plus two custom events: trial-button clicks and contact-form submissions. No cookies are set for analytics, no advertising profiles are built, and no cross-site tracking takes place.
Inside the product, we measure aggregate feature usage to improve Postmill — likewise without advertising profiles.
The Service uses a small number of functional cookies: session cookies that keep you signed in, and short-lived CSRF tokens set during OAuth connection handshakes (deleted when the callback completes). The Service sets no advertising cookies. You can decline or delete cookies via your browser settings; signing in will not work without functional cookies.
We maintain reasonable administrative, technical, and physical safeguards designed to protect personal information from unauthorized access, use, or disclosure. Traffic to and from the Service is served over HTTPS (TLS). Channel access tokens and AI provider keys are encrypted at rest using AES-256-GCM, and access to workspace data is scoped per organization.
No data transmission over the Internet or any wireless network can be guaranteed to be 100% secure. While we take reasonable steps, you acknowledge that (a) there are security and privacy limitations inherent to the Internet that are beyond our control, and (b) the security, integrity, and privacy of any information exchanged between you and us through the Service cannot be guaranteed.
Account and workspace data is retained while your account is active. When you delete your account or request deletion, we remove your personal information and workspace content within 30 days, except for encrypted backups, which roll off within a further 30 days. Server logs roll off on our hosting providers' schedules (typically 30 days). Sentry error reports are subject to Sentry's default retention windows for our plan. Billing records are retained as required by tax and accounting law.
Regardless of where you live, you may:
We do not “sell” or “share” personal information for cross-context behavioural advertising as those terms are defined under the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act. Because we do not sell or share, there is no opt-out mechanism for us to provide — but you retain all other CCPA/CPRA rights (access, correction, deletion, portability, limit-use-of-sensitive-info, non-discrimination for exercising those rights), which you may exercise via the contact address below.
Our legal bases for processing personal information are contract (to deliver the Service you have subscribed to), legitimate interests (to operate the Service, secure it against abuse, and measure aggregate usage), and your consent where applicable. You may exercise your access, rectification, erasure, restriction, portability, and objection rights via the contact address below, and you have the right to lodge a complaint with your supervisory authority.
Subject to certain exceptions, on receipt of a verifiable request from you we will delete your personal information from our records and direct our service providers to do the same. We may decline to comply with a deletion request, or comply only in part, if it is necessary for us or our service providers to:
In the event of a security incident involving personal information, we will promptly investigate and provide notice to affected individuals and to applicable regulatory authorities in the manner and within the timeframes prescribed by applicable law.
Email we send is transactional — billing and account notices, security alerts, and product notifications you have enabled (per-category toggles are in your notification settings). We do not send marketing or promotional email blasts. If you receive an email from us that you wish to stop, use the unsubscribe link in it or email the contact address below.
You may disconnect a channel at any time from your workspace settings, or revoke Postmill's access directly from the channel's own app settings (for example, under “Authorized apps”). You may remove an AI provider key at any time, which stops all requests through it. Disconnecting does not delete data we have already received under that connection — use the deletion request flow above for that.
The Service contains links to other websites — most obviously the channels and AI providers you connect. We are not responsible for the content or privacy practices of those sites. When you follow a link off our Service, please review the privacy statement of the destination site.
REAA does not knowingly collect personally identifiable information from children under the age of 13. If you are under 13, please do not use the Service or submit any personal information. If we learn that we have inadvertently collected personal information from a child under 13, we will delete it promptly. If you are between 13 and 18, please use the Service only with the permission of a parent or guardian.
REAA is based in the United States, and several of our service providers operate worldwide. When you use the Service, your information may be processed in the United States or in another country in which one of our service providers operates. By using the Service, you acknowledge and consent to the transfer of your information to jurisdictions which may have different data protection laws than your home country.
We reserve the right to change this Policy from time to time — for example, when our services change, when our data-protection practices change, or when the law changes. When changes are significant, we will notify you (by email to the address we have on file for you, by placing a prominent notice in the Service, or both). Your continued use of the Service after such modifications constitutes (a) your acknowledgement of the modification and (b) your agreement to be bound by the modified Policy.
For questions or comments about this Policy, or to exercise any of your rights, email rick@postmill.ai. We will respond within 30 days, or sooner where required by applicable law.