Privacy Policy

Last updated 6 August 2026

This policy is for PostLake ("PostLake", "we", "us", "our"), based in the United Kingdom. It explains what personal data we collect when you use PostLake, why we use it, who we share it with, and the rights you have under the UK GDPR and the Data Protection Act 2018.

Who we are What we collect How & why we use it Who we share it with International transfers Retention Security Your rights YouTube Pinterest Cookies Contact

1. Who we are

PostLake is a unified social media API. For the personal data described in this policy, PostLake is the data controller. You can reach us about anything in this policy at support@postlake.dev.

When you connect your own social accounts and publish content through PostLake, we act as a data processor on your behalf for that content. You decide what is posted and where. A Data Processing Agreement (DPA) is available on request.

2. What we collect

Information you give us

Information we collect automatically

Billing data

Payments are handled by our payment providers (RevenueCat and Stripe). We receive confirmation of your plan, credits, and invoices. we never see or store your full card number.

What we access on the networks you connect

When you connect an account, we access only what the features you use require. This list is generated from what the product can actually do on each network, so it cannot fall behind the code.

Bluesky

Facebook

Instagram

LinkedIn

Pinterest

Threads

TikTok

X

YouTube

3. How & why we use it, and our lawful bases

PurposeLawful basis (UK GDPR Art. 6)
Create and run your account; publish, schedule, and report on the content you ask us toPerformance of a contract with you
Take payment and manage credits, plans, and invoicesPerformance of a contract
Secure the service, prevent abuse, debug, and keep audit logsLegitimate interests (running a safe, reliable service)
Send essential service emails (verification, password reset, billing, renewal reminders)Performance of a contract / legitimate interests
Keep financial recordsLegal obligation (UK tax/accounting law)
Any optional marketing (only if we ever add it)Your consent, which you can withdraw at any time

We do not sell your personal data, and we do not use your content to train AI models.

4. Who we share it with

We share data only with the service providers ("sub-processors") that help us run PostLake, and with the social networks you choose to connect. Each is bound to protect your data and use it only on our instructions. The current list. Including what each does and where it is located, is on our Sub-processors page.

We may also disclose data if required by law, or to protect our rights, our users, or the security of the service.

Requests from public authorities. If a government or public authority asks us for user data, we review the request's legal validity before responding, challenge requests we consider unlawful or overbroad, disclose only the minimum data necessary if we must comply, and keep a written record of every request and our response.

5. International transfers

Some of our sub-processors are based outside the UK (for example in the United States). Where personal data is transferred outside the UK, we rely on appropriate safeguards. Such as the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision. So your data receives an equivalent level of protection.

6. How long we keep it

DataRetention
Account & profileWhile your account is open, then deleted within 30 days of closure (unless we must keep it longer by law)
Connected-account tokensUntil you disconnect the account or close your account
Content (posts, media, schedules)While your account is open, or until you delete it
Billing & invoice recordsUp to 7 years, to meet UK tax and accounting obligations
Security & audit logsTypically up to 12 months

7. How we protect it

No system is perfectly secure, but we take reasonable technical and organisational measures appropriate to the risk.

8. Your rights

Under UK data protection law you have the right to:

To exercise any of these, email support@postlake.dev. We will respond within one month. You can also disconnect accounts and delete content yourself from your dashboard, or request full deletion via our data deletion page.

If you are unhappy with how we handle your data, you have the right to complain to the UK's supervisory authority, the Information Commissioner's Office (ICO). Though we'd appreciate the chance to put things right first.

9. YouTube API Services

PostLake uses YouTube API Services when you choose to connect a YouTube channel. By connecting YouTube, you also agree to be bound by the YouTube Terms of Service. Google's collection and use of data is described in the Google Privacy Policy.

When you connect YouTube, we access only the data needed to provide the features you request:

We store OAuth tokens encrypted at rest and use them only to perform those actions. We do not sell this data, do not use it to train AI models, and do not upload to channels you do not own.

In addition to disconnecting YouTube or deleting your PostLake account (see our data deletion page), you can revoke PostLake's access to your Google/YouTube data at any time from Google's security settings: https://security.google.com/settings/security/permissions. When you revoke access, we delete the related YouTube tokens and stored API data associated with that connection as soon as practicable and within 30 days.

Questions about this practice: support@postlake.dev.

10. Pinterest API

PostLake uses the Pinterest API when you choose to connect a Pinterest account. PostLake is an independent product and is not endorsed by, affiliated with, or sponsored by Pinterest. Pinterest is a trademark of Pinterest, Inc.

When you connect Pinterest, we access only the data needed to provide the features you request:

We store OAuth tokens encrypted at rest and use them only to perform those actions. We do not sell this data, do not use it to train AI models, and do not post to accounts you do not authorize. You can disconnect Pinterest from your PostLake dashboard at any time; we then delete related tokens as described in our retention table and data deletion page. Our use of information received from Pinterest APIs adheres to the Pinterest Developer and API Terms of Service and Pinterest Developer Guidelines.

11. Cookies

We use only a strictly-necessary session cookie and a functional theme-preference cookie. No advertising or cross-site tracking. Full details are in our Cookie Policy.

12. Children

PostLake is a business tool and is not directed at children. You must be at least 18 to use it. We do not knowingly collect data from anyone under 18.

13. Changes to this policy

We may update this policy from time to time. If we make material changes we'll update the date above and, where appropriate, notify you by email. Continued use of PostLake after a change means you accept the updated policy.

14. Contact

Questions, requests, or complaints about privacy? Email support@postlake.dev. PostLake, United Kingdom.