01Who we are
Postlift is a tool for drafting, scheduling and publishing posts on X. It is operated by Postlift [legal entity name], [street and number, postal code, city, country] (“we”, “us”, “our”). We are the controller of the personal data described in this policy.
Privacy questions, requests and complaints: privacy@postlift.io.
02Data we collect
We collect the following categories of personal data:
- Waitlist data. Your email address, how you found us (source and referrer page) and when you joined, stored when you submit the waitlist form.
- Account data. Your email address, sign-in method, display name and avatar if provided by your sign-in provider, session records (IP address and browser/device details), and one-time sign-in tokens, which we store only as hashes.
- Connected X account data. Your X user ID, handle and public profile data, and the OAuth access and refresh tokens needed to publish on your behalf. Tokens are encrypted at rest.
- Content and publishing data. Drafts, scheduled posts, threads, uploaded images with alt text, plus publishing results and error logs.
- Usage and technical data. IP address, device and browser information, request and error logs, and an audit log of important actions on your account.
- Communications. Emails and messages you send to our support.
We do not intentionally collect special categories of data, and we do not sell your personal data.
03How and why we use your data
We use personal data only where we have a legal basis under the GDPR:
| Purpose | Legal basis |
|---|---|
| Providing the service: your account, the composer, scheduling and publishing to X. | Performance of our contract with you (Art. 6(1)(b)) |
| Managing the waitlist, sending invitations and honouring the founding price. | Steps before entering a contract and our legitimate interest in running the waitlist (Art. 6(1)(b) and (f)) |
| Service and security emails: sign-in links, errors, important changes. | Contract and legal obligations (Art. 6(1)(b) and (c)) |
| Product updates and marketing, which you can opt out of at any time. | Consent where required, otherwise legitimate interest (Art. 6(1)(a) or (f)) |
| Security, fraud and abuse prevention, rate limiting. | Legitimate interest (Art. 6(1)(f)) |
| Improving the product using aggregated, de-identified usage data. | Legitimate interest (Art. 6(1)(f)) |
| Complying with law and enforcing our Terms. | Legal obligation and legitimate interest (Art. 6(1)(c) and (f)) |
Where we rely on legitimate interests, we balance them against your rights and freedoms. You can object at any time — see Your rights below.
06International transfers
We aim to keep data in the EU where possible, but some providers may process data in the United States and other countries. When data leaves the EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision.
07How long we keep data
- Waitlist: until you are invited and create an account, or until you ask us to delete your entry. Inactive entries are reviewed after 24 months.
- Account data: while your account is active; after deletion most data is removed within 30 days.
- X tokens: until you disconnect X or delete your account.
- Posts and media: until you delete them, then removed from backups within 90 days.
- Logs: request and error logs for 30 days; security audit logs for 12 months.
- Billing records: as long as tax and accounting law requires.
08Security
We protect data with encryption in transit, encryption of X OAuth tokens at rest, access controls, rate limiting and least-privilege access to production systems. No method of storage or transmission is completely secure. If a breach affects you, we will notify you and the competent authority as required by law.
09Your rights
If you are in the EEA or the UK, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase data where we no longer have a lawful reason to keep it.
- Restrict processing while a request is being resolved.
- Port data you provided, in a machine-readable format.
- Object to processing based on legitimate interests.
- Withdraw consent at any time, without affecting processing done before withdrawal.
We do not make decisions with legal effects based solely on automated processing. To exercise a right, email privacy@postlift.io. You can also lodge a complaint with your local supervisory authority — in Poland, the President of the Personal Data Protection Office (UODO).
10Children
The service is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with data, contact us and we will delete it.
11Changes to this policy
We may update this policy as the service evolves. We will post the new version here and update the date at the top. For material changes we will notify you by email or in the app before they take effect.
12Contact
Controller: Postlift [legal entity name], [street and number, postal code, city, country]. Email: privacy@postlift.io.