Information we collect
When you sign up for Postavya we collect your name, email address and authentication credentials through Firebase Authentication. If you connect social media accounts, we store encrypted access tokens and the minimum profile information needed to publish content on your behalf.
We collect content you generate through our AI tools, including drafts, approved posts, brand profiles, project settings, campaigns, funnels, schedules, memory and notifications. This data is stored in Firestore and is yours — we do not use it to train AI models.
How we use your information
We use your information solely to provide and improve the Postavya service: authenticating you, generating content in line with your project memory, publishing to your connected accounts after your approval, sending notifications about drafts and publish outcomes, and maintaining your account and workspace.
We use usage data — generation counts, images delivered, video seconds and infrastructure events — to enforce plan entitlements, operate a transparent usage ledger, and provide support.
AI providers and BYOK keys
On the Managed AI plan, your prompts and brand data are sent from Postavya’s secure backend to Postavya-managed Google AI. On the BYOK plan, they are sent from the same backend to the provider you configured (Gemini, OpenAI or OpenRouter) using your own key.
BYOK keys are submitted only to authenticated, App Check-protected Firebase Functions over HTTPS, encrypted using Cloud KMS envelope encryption with tenant-bound context, and never returned to the client, written to Firestore in plaintext, bundled into the app, logged or sent to unrelated providers.
Social platform tokens
Social access and refresh tokens are server-only and isolated by workspace, project and account. Tokens are never exposed to the client or included in generation audit records, analytics or logs.
You can revoke a social connection at any time from your dashboard. Expired or revoked connections move to a reconnect-required state.
Google and YouTube connection
Postavya uses YouTube API Services to let you connect a YouTube channel and publish videos you approve. When you choose to connect through Google, Postavya asks permission to identify channels you manage and to upload to the channel you select.
Postavya accesses and stores only the channel name, channel identifier, custom channel link when available, the permissions you granted, and encrypted connection tokens. We use this information only to show your available channels, keep the connection working, and upload your selected video with the title, description, visibility and made-for-kids setting you choose. Postavya does not access your Google password, delete YouTube content, sell Google user data, or use it for advertising.
Connection credentials are encrypted before storage, kept only on protected servers, and isolated by workspace. They are never returned to your browser or written to logs. Our encryption keys are regularly rotated through a controlled security process. Protecting customer credentials and data is a core Postavya priority.
You can disconnect YouTube in Postavya to delete the stored connection and OAuth credentials. You can also revoke Postavya through Google Account permissions. You may request deletion of associated stored data through the dashboard or by contacting us; deletion is completed as soon as possible and within seven calendar days. Deleting data stored by Postavya does not delete content already stored by YouTube.
Postavya’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Use of YouTube is also governed by the YouTube Terms of Service and the Google Privacy Policy.
Data sharing
We never sell your personal data. We share data only with:
Google (Firebase) for infrastructure — hosting, database, authentication, AI generation, storage, messaging and functions.
Social platforms you explicitly authorize — to publish content on your behalf after your approval.
AI providers you configure — to generate content based on your prompts and brand data.
Data security
All data is encrypted in transit and at rest. Social access tokens and BYOK keys are encrypted per tenant using Cloud KMS envelope encryption. Firestore security rules restrict access to workspace members and callable Firebase Functions enforce workspace authorization server-side.
App Check protects callable Functions. Authentication and workspace authorization remain mandatory even when App Check is satisfied.
Multi-tenant isolation
Every client query and callable operation authorizes the active workspace and project. Cross-tenant reads, writes, token use, scheduling and notifications are impossible by design. Server-side adapters perform their own authorization because server libraries bypass Firestore rules.
Data retention
Unapproved drafts in suggested or discarded status are automatically deleted after 30 days, together with their generated or uploaded media. All stored post images and videos are automatically deleted after 365 days, even when the post record remains. Download any media you need to keep before that period ends.
Other workspace data is retained while your workspace exists. Recursively deleting a project permanently removes its brand profiles, posts, campaigns, funnels, schedules and memory. Deleting your account permanently removes all associated data from our systems.
Generation audit records — provider, model, inputs, output, usage and status — are retained for support and reconciliation. Secrets and authorization headers are never part of audit records.
Your rights
You can export, modify or delete your data at any time through your dashboard settings. You can revoke social connections and delete BYOK credentials. Deleting a credential requires replacing or disabling every route that references it.
For privacy-related inquiries, contact us at the email listed below.
Children’s privacy
Postavya is not intended for individuals under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us and we will delete it.
International data transfers
Postavya runs on Google Cloud and Firebase. Your data may be processed in Google Cloud regions as configured. By using Postavya you consent to these transfers in accordance with this policy.
Changes to this policy
We may update this Privacy Policy from time to time. We will update the "Last updated" date above when we do. Continued use after changes constitutes acceptance of the updated policy.
Contact
For privacy-related inquiries, contact us at support@postavya.com or through our contact page.