Privacy Policy

How Postrun handles your information

Last updated: June 22, 2026

This Privacy Policy explains how Postrun, Inc. ("Postrun", "we", "us") handles information in connection with postrun.ai, the Postrun API, MCP, and dashboard (the "Service"). Postrun is a unified posting and advertising API that lets customers and their software (including AI agents) manage social media content and ads across third-party platforms such as Meta (Facebook, Instagram), Google, X, LinkedIn, TikTok, and YouTube (each a "Platform").

You own your data. We access and process your information, and the Platform data you connect, only to provide the features you ask us to — never to sell it, advertise against it, or train AI models on it.

1. Information we collect

  • Account & authentication data — name, email, password hash, organization/profile details, and billing identifiers you provide.
  • Connected-Platform data (via OAuth) — access/refresh tokens and the data needed to perform the actions you request: the Pages, ad accounts, and Instagram/TikTok/YouTube accounts you manage; the content you create, schedule, and publish through us; and a cached projection of results and insights (e.g. ad metrics, post status). We access this only to provide the features you invoke.
  • Usage & log data — API request metadata, IP address, timestamps, audit-log entries, and diagnostics used to operate, secure, and debug the Service.
  • Payment data — processed by Stripe. We never store full card numbers.
  • Cookies — see our Cookie Policy.

2. How we use information

To provide and operate the Service; maintain security and prevent abuse; process billing; provide support; and comply with law. We do not sell personal information, use Platform data for advertising, or use it to train AI/ML models.

3. Platform connections & authorization

When you connect a Platform account, you authorize Postrun to act on your behalf for the permissions you grant, and only for those. By connecting an account, you also agree to that Platform's own terms and privacy policy:

Data we obtain from a connected Platform is used only to provide the Service you request and is never sold or shared with third parties for their own purposes. You can revoke access at any time — disconnect in Postrun, or use the Platform's own connected-apps / security settings.

Google user data — Limited Use

Postrun's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google data only to provide or improve user-facing features that are prominent in the Service, do not transfer it except to provide or improve those features (or for security, to comply with law, or as part of a merger), do not use it for advertising, and do not allow humans to read it except with your consent, for security, to comply with law, or when the data is aggregated/anonymized.

Google Ads data

When you connect a Google Ads account, we access it through the Google Ads API only to provide the features you invoke: we read your campaign, ad group, ad, and keyword structure and their performance metrics (impressions, clicks, cost, conversions) to power reporting, and we create and manage campaigns, budgets, and related entities when you direct us to. We read this data live from Google to serve your request and do not maintain a separate synchronized copy of your Google Ads campaigns or metrics; when you disconnect the account or delete your data we revoke and delete the associated tokens (§8). Our use of Google Ads data follows the Google API Services User Data Policy, including the Limited Use requirements above — we never sell it, use it for advertising, or use it to train AI or ML models.

Google Ads conversions. If you use Google Ads offline conversion features, you direct us to send conversion data to Google on your behalf: the click identifiers you provide (Google Click ID / GCLID, GBRAID, or WBRAID) and/or the customer identifiers you supply (such as email or phone), together with the conversion's time, value, currency, order ID, and consent signals. Where you supply identifiers in plain text, we hash them (SHA-256) on our servers before transmission and do not retain them. We transmit this data to the Google Ads API and the Google Ads Data Manager API solely to record the conversions you specify; we do not sell it, use it for advertising, or use it to train AI or ML models, and its retention follows the token and log deletion rules in §8.

Meta Platform Data

We handle data obtained from Meta's APIs in accordance with the Meta Platform Terms and Developer Policies — used only for the features you authorize, deleted on request (§8), and encrypted in transit and at rest (§6).

TikTok data

We handle data obtained from TikTok for Developers products in accordance with the TikTok Developer Terms of Service and only for the scopes you authorize. We store TikTok access tokens in encrypted form, retain them only while the connection is active, and revoke and delete them when you disconnect; TikTok data is deleted on request within 30 days (§8). We never sell TikTok data, use it for advertising, or use it to train AI/ML models.

4. How we share information (service providers)

We do not sell your information. We share it only with providers that help us run the Service, limited to that purpose:

ProviderPurpose
VercelApplication hosting
SupabaseDatabase, authentication, storage
NangoOpen-source OAuth platform we self-host to store connection credentials, encrypted, on our own infrastructure
StripePayment processing
UpstashRate limiting / ephemeral cache
SvixOutbound webhook delivery
ResendTransactional email
PostHogProduct analytics

We may also disclose information to comply with law or legal process, to enforce our terms, to protect rights or safety, or in connection with a merger or acquisition.

5. Your data vs. your customers' data

You own the content you submit and the Platform data you direct us to access on behalf of your own clients. We process it solely to provide the Service on your instructions. You are responsible for having the rights and consents needed from your end users for the data and accounts you operate.

6. Data security

We encrypt data in transit (TLS 1.2+) and at rest through our infrastructure providers, restrict access on a need-to-know basis, and store OAuth credentials in encrypted form. Card data is handled by Stripe; we never store full card numbers. No method of transmission or storage is 100% secure, but we maintain reasonable safeguards appropriate to the data.

7. Data retention

We retain information for as long as your account is active or as needed to provide the Service, then delete or anonymize it within a commercially reasonable period unless a longer period is required by law.

OAuth access and refresh tokens are stored in encrypted form and retained only while the corresponding Platform connection is active. When you disconnect a Platform account — in Postrun, or through the Platform's own connected-apps settings — we revoke and delete the associated tokens. When you delete your account or make a verified deletion request, we delete your data within 30 days (§8).

8. Your choices & data deletion

You may access, correct, export, or delete your data, and withdraw consent.

To delete your data:

  1. Revoke Postrun's access from the Platform's own connected-apps/security settings (Meta, Google, TikTok, etc.) to cut off access immediately; and/or
  2. Email hello@postrun.ai with the subject "Data Deletion Request." We will confirm and, within 30 days of a verified request, delete your account and associated Platform data and provide a confirmation reference.

Deleting your Postrun data removes content, connections, and tokens from our systems. Content you already published to a Platform continues to live on that Platform — to remove it there, use the Platform directly.

9. Where we process data

We and our providers may process information in the United States and other countries where we operate.

10. Children

The Service is not directed to, and may not be used by, anyone under 18.

11. Changes

We may update this Policy; we will post the new effective date and, for material changes, provide reasonable notice.

12. Contact

Postrun, Inc. — hello@postrun.ai.