Legal
Privacy Policy
Last updated 6 August 2026
This policy is for PostLake ("PostLake", "we", "us", "our"), based in the United Kingdom. It explains what personal data we collect when you use PostLake, why we use it, who we share it with, and the rights you have under the UK GDPR and the Data Protection Act 2018.
1. Who we are
PostLake is a unified social media API. For the personal data described in this policy, PostLake is the data controller. You can reach us about anything in this policy at support@postlake.dev.
When you connect your own social accounts and publish content through PostLake, we act as a data processor on your behalf for that content. You decide what is posted and where. A Data Processing Agreement (DPA) is available on request.
2. What we collect
Information you give us
- Account details: your email address, and (optionally) your name. If you sign up with a password we store it only as a salted hash, never in plain text. If you sign in with GitHub or Google we store your provider ID and email.
- Connected social accounts: when you link a network (e.g. X, LinkedIn, Instagram), we store the access tokens needed to act on your behalf. These are encrypted at rest and used only to perform the actions you request.
- Content: the posts, captions, media, and schedules you create to publish to your networks.
- Support & correspondence: anything you send us by email.
Information we collect automatically
- Technical & usage data: IP address, request logs, timestamps, and basic device/browser information, used to run and secure the service.
- Cookies: a strictly-necessary session cookie and a functional theme-preference cookie. See our Cookie Policy. We do not use advertising or third-party tracking cookies.
Billing data
Payments are handled by our payment providers (RevenueCat and Stripe). We receive confirmation of your plan, credits, and invoices. we never see or store your full card number.
What we access on the networks you connect
When you connect an account, we access only what the features you use require. This list is generated from what the product can actually do on each network, so it cannot fall behind the code.
Bluesky
- your account identity on that network (so we can show you which account is connected);
- permission to publish posts you create, to your own account, on your explicit request;
- public statistics for posts you published through PostLake (such as views, likes and comments) for your analytics;
- permission to post a first comment on something you published, when you ask us to;
- permission to reply to comments people leave, on your behalf and only when you ask us to;
- permission to delete something you published through PostLake, when you ask us to;
- recent activity on your account (such as likes, replies, mentions and new followers) so you can see and respond to it;
- comments people leave on things you published, so you can read and reply to them in PostLake;
- the list of accounts that follow you, so you can see your audience;
- the list of accounts you follow;
- permission to update your profile (display name, bio, avatar and banner) when you ask us to;
- permission to like, repost, follow, block or mute on your behalf, only when you ask us to;
- your direct messages on that network, so you can read and reply to them in PostLake;
- your account identity on that network (so we can show you which account is connected);
- permission to publish posts you create, to your own account, on your explicit request;
- public statistics for posts you published through PostLake (such as views, likes and comments) for your analytics;
- permission to post a first comment on something you published, when you ask us to;
- permission to reply to comments people leave, on your behalf and only when you ask us to;
- permission to delete something you published through PostLake, when you ask us to;
- comments people leave on things you published, so you can read and reply to them in PostLake;
- permission to like, repost, follow, block or mute on your behalf, only when you ask us to;
- your account identity on that network (so we can show you which account is connected);
- permission to publish posts you create, to your own account, on your explicit request;
- public statistics for posts you published through PostLake (such as views, likes and comments) for your analytics;
- your account identity on that network (so we can show you which account is connected);
- permission to publish posts you create, to your own account, on your explicit request;
- public statistics for posts you published through PostLake (such as views, likes and comments) for your analytics;
- permission to post a first comment on something you published, when you ask us to;
- permission to reply to comments people leave, on your behalf and only when you ask us to;
- permission to delete something you published through PostLake, when you ask us to;
- permission to like, repost, follow, block or mute on your behalf, only when you ask us to;
- your account identity on that network (so we can show you which account is connected);
- permission to publish posts you create, to your own account, on your explicit request;
- public statistics for posts you published through PostLake (such as views, likes and comments) for your analytics;
- permission to delete something you published through PostLake, when you ask us to;
- the list of accounts that follow you, so you can see your audience;
- permission to like, repost, follow, block or mute on your behalf, only when you ask us to;
Threads
- your account identity on that network (so we can show you which account is connected);
- permission to publish posts you create, to your own account, on your explicit request;
- public statistics for posts you published through PostLake (such as views, likes and comments) for your analytics;
- permission to post a first comment on something you published, when you ask us to;
- permission to reply to comments people leave, on your behalf and only when you ask us to;
- comments people leave on things you published, so you can read and reply to them in PostLake;
TikTok
- your account identity on that network (so we can show you which account is connected);
- permission to publish posts you create, to your own account, on your explicit request;
- public statistics for posts you published through PostLake (such as views, likes and comments) for your analytics;
X
- your account identity on that network (so we can show you which account is connected);
- permission to publish posts you create, to your own account, on your explicit request;
- public statistics for posts you published through PostLake (such as views, likes and comments) for your analytics;
- permission to post a first comment on something you published, when you ask us to;
- permission to reply to comments people leave, on your behalf and only when you ask us to;
- permission to delete something you published through PostLake, when you ask us to;
- recent activity on your account (such as likes, replies, mentions and new followers) so you can see and respond to it;
- comments people leave on things you published, so you can read and reply to them in PostLake;
- the list of accounts that follow you, so you can see your audience;
- your direct messages on that network, so you can read and reply to them in PostLake;
YouTube
- your account identity on that network (so we can show you which account is connected);
- permission to publish posts you create, to your own account, on your explicit request;
- public statistics for posts you published through PostLake (such as views, likes and comments) for your analytics;
- permission to post a first comment on something you published, when you ask us to;
- permission to reply to comments people leave, on your behalf and only when you ask us to;
- permission to delete something you published through PostLake, when you ask us to;
- recent activity on your account (such as likes, replies, mentions and new followers) so you can see and respond to it;
- comments people leave on things you published, so you can read and reply to them in PostLake;
- the list of accounts that follow you, so you can see your audience;
3. How & why we use it, and our lawful bases
| Purpose | Lawful basis (UK GDPR Art. 6) |
|---|---|
| Create and run your account; publish, schedule, and report on the content you ask us to | Performance of a contract with you |
| Take payment and manage credits, plans, and invoices | Performance of a contract |
| Secure the service, prevent abuse, debug, and keep audit logs | Legitimate interests (running a safe, reliable service) |
| Send essential service emails (verification, password reset, billing, renewal reminders) | Performance of a contract / legitimate interests |
| Keep financial records | Legal obligation (UK tax/accounting law) |
| Any optional marketing (only if we ever add it) | Your consent, which you can withdraw at any time |
We do not sell your personal data, and we do not use your content to train AI models.
4. Who we share it with
We share data only with the service providers ("sub-processors") that help us run PostLake, and with the social networks you choose to connect. Each is bound to protect your data and use it only on our instructions. The current list. Including what each does and where it is located, is on our Sub-processors page.
We may also disclose data if required by law, or to protect our rights, our users, or the security of the service.
Requests from public authorities. If a government or public authority asks us for user data, we review the request's legal validity before responding, challenge requests we consider unlawful or overbroad, disclose only the minimum data necessary if we must comply, and keep a written record of every request and our response.
5. International transfers
Some of our sub-processors are based outside the UK (for example in the United States). Where personal data is transferred outside the UK, we rely on appropriate safeguards. Such as the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision. So your data receives an equivalent level of protection.
6. How long we keep it
| Data | Retention |
|---|---|
| Account & profile | While your account is open, then deleted within 30 days of closure (unless we must keep it longer by law) |
| Connected-account tokens | Until you disconnect the account or close your account |
| Content (posts, media, schedules) | While your account is open, or until you delete it |
| Billing & invoice records | Up to 7 years, to meet UK tax and accounting obligations |
| Security & audit logs | Typically up to 12 months |
7. How we protect it
- All traffic is encrypted in transit (TLS/HTTPS).
- Connected-account tokens and other secrets are encrypted at rest (AES-GCM).
- Passwords are stored only as salted hashes; API and session tokens are stored hashed.
- Access to production systems is limited and audit-logged.
No system is perfectly secure, but we take reasonable technical and organisational measures appropriate to the risk.
8. Your rights
Under UK data protection law you have the right to:
- Access the personal data we hold about you;
- Rectify data that is inaccurate or incomplete;
- Erase your data ("right to be forgotten");
- Restrict or object to certain processing;
- Portability: receive your data in a portable format;
- Withdraw consent at any time, where we rely on it.
To exercise any of these, email support@postlake.dev. We will respond within one month. You can also disconnect accounts and delete content yourself from your dashboard, or request full deletion via our data deletion page.
If you are unhappy with how we handle your data, you have the right to complain to the UK's supervisory authority, the Information Commissioner's Office (ICO). Though we'd appreciate the chance to put things right first.
9. YouTube API Services
PostLake uses YouTube API Services when you choose to connect a YouTube channel. By connecting YouTube, you also agree to be bound by the YouTube Terms of Service. Google's collection and use of data is described in the Google Privacy Policy.
When you connect YouTube, we access only the data needed to provide the features you request:
- your account identity on that network (so we can show you which account is connected);
- permission to publish posts you create, to your own account, on your explicit request;
- public statistics for posts you published through PostLake (such as views, likes and comments) for your analytics;
- permission to post a first comment on something you published, when you ask us to;
- permission to reply to comments people leave, on your behalf and only when you ask us to;
- permission to delete something you published through PostLake, when you ask us to;
- recent activity on your account (such as likes, replies, mentions and new followers) so you can see and respond to it;
- comments people leave on things you published, so you can read and reply to them in PostLake;
- the list of accounts that follow you, so you can see your audience;
We store OAuth tokens encrypted at rest and use them only to perform those actions. We do not sell this data, do not use it to train AI models, and do not upload to channels you do not own.
In addition to disconnecting YouTube or deleting your PostLake account (see our data deletion page), you can revoke PostLake's access to your Google/YouTube data at any time from Google's security settings: https://security.google.com/settings/security/permissions. When you revoke access, we delete the related YouTube tokens and stored API data associated with that connection as soon as practicable and within 30 days.
Questions about this practice: support@postlake.dev.
10. Pinterest API
PostLake uses the Pinterest API when you choose to connect a Pinterest account. PostLake is an independent product and is not endorsed by, affiliated with, or sponsored by Pinterest. Pinterest is a trademark of Pinterest, Inc.
When you connect Pinterest, we access only the data needed to provide the features you request:
- your Pinterest account identity (so we can show which account is connected);
- permission to create Pins and related media on your boards, on your explicit request;
- board list / board ids needed to publish where you choose;
- public performance metrics for Pins you published through PostLake, for analytics.
We store OAuth tokens encrypted at rest and use them only to perform those actions. We do not sell this data, do not use it to train AI models, and do not post to accounts you do not authorize. You can disconnect Pinterest from your PostLake dashboard at any time; we then delete related tokens as described in our retention table and data deletion page. Our use of information received from Pinterest APIs adheres to the Pinterest Developer and API Terms of Service and Pinterest Developer Guidelines.
11. Cookies
We use only a strictly-necessary session cookie and a functional theme-preference cookie. No advertising or cross-site tracking. Full details are in our Cookie Policy.
12. Children
PostLake is a business tool and is not directed at children. You must be at least 18 to use it. We do not knowingly collect data from anyone under 18.
13. Changes to this policy
We may update this policy from time to time. If we make material changes we'll update the date above and, where appropriate, notify you by email. Continued use of PostLake after a change means you accept the updated policy.
14. Contact
Questions, requests, or complaints about privacy? Email support@postlake.dev. PostLake, United Kingdom.