Privacy Policy

Last updated: 2026-07-21

TL;DR

Posting Machine turns company context into founder-led LinkedIn content and helps you operate the workflow around publishing and engagement. We process the information you provide, the accounts you choose to connect, and the work we create for you. We do not sell your personal data, use your private content for advertising, or use it to train public AI models.

Scope

This Privacy Policy applies to Posting Machine's website, application, integrations, AI-assisted features, onboarding, support, and related managed services (the “Service”). It explains how Posting Machine collects, uses, discloses, retains, and protects personal data and customer content.

If we process personal data solely on behalf of your company under a signed data-processing or service agreement, that agreement also applies and controls if it conflicts with this Policy.

Information we collect

  • Account and contact information: your name, email address, profile image, sign-in identity, company, role, timezone, and communications with us.
  • Onboarding and founder context: photos, profile summaries, company information, founder memory, writing samples, strategy, preferences, files, links, and other materials you send by email, upload, paste, or ask us to import.
  • Connected-account information: account and workspace identifiers, profile details, authorization tokens, connection status, and the content made available through Slack, LinkedIn, Attio, Granola, Plaud, Telegram, an MCP client, or another integration you choose to connect.
  • Company signals and source material: selected Slack threads and files, meeting notes and call-recording transcripts, product updates, customer context, public webpages, pasted text, and other material you deliberately capture or import into the Service.
  • LinkedIn and public research data: public profiles, posts, company information, source citations, follower and audience information, post performance, comments, reactions, connection status, and inbox or message data when you enable a feature that needs it.
  • Content and workflow data: source metadata, extracted evidence, drafts, images, edits, approvals, schedules, published posts, suggested or sent engagement actions, feedback, and research or AI outputs created through the Service.
  • Billing and support information: agreed plans, service periods, invoice status, payment-related identifiers, support requests, and records of our business relationship. Card and bank details are collected and processed by our payment provider rather than stored by Posting Machine.
  • Usage and technical information: pages and features used, actions taken, approximate location derived from IP address, browser and device information, referral data, cookies, diagnostics, and security logs.

How we collect information

We collect information:

  • directly from you and your organization;
  • from accounts and data sources you choose to connect or authorize;
  • from public sources when you ask us to research a founder, company, market, or post; and
  • automatically when you use the website or application, such as through logs, cookies, and product analytics.

How we use information

  • Provide onboarding, account setup, support, and the features you request.
  • Organize company and founder context, extract evidence, create drafts and images, conduct research, and suggest engagement actions.
  • Schedule, publish, or send actions that you approve or authorize through clearly described automation settings.
  • Measure post outcomes, identify relevant engagement, and improve recommendations for your account.
  • Process invoices, administer the customer relationship, and communicate about the Service.
  • Operate, secure, troubleshoot, analyze, and improve the Service.
  • Comply with law, enforce our agreements, and protect our users, connected platforms, and the Service.

We do not sell or rent personal data, share it with third parties for their own advertising, or use private customer content to train our own or public AI models.

AI processing

When you request an AI-assisted feature, relevant instructions and source material may be sent to OpenRouter and an underlying model provider to generate the requested result. We limit the material sent to what the feature needs. Provider handling and retention can vary by model and are subject to the provider's applicable policies and the privacy controls available through OpenRouter.

AI output may be inaccurate. We keep prompts, outputs, and related run information when needed to show your work, operate the feature, diagnose failures, and maintain an audit trail for your account.

Services that process information for us

We use service providers to operate Posting Machine. The providers used for a particular customer depend on the features and integrations they enable. Key providers include:

  • Convex — application database, file storage, server functions, and authentication infrastructure.
  • Google — account sign-in and, where authorized, connected Google services.
  • Slack — selected thread, file, and workspace capture when you install the Slack integration.
  • Unipile — LinkedIn account connection, publishing, analytics, engagement, messaging, and connection actions.
  • Attio, Granola, and Plaud — meeting-note, recording, and transcript ingestion when you connect or authorize those sources.
  • OpenRouter and underlying model providers — AI inference for generation, extraction, analysis, and research.
  • Bright Data — collection of public LinkedIn, founder, post, and company information used for authorized research features.
  • Vercel — website and application hosting.
  • PostHog — product analytics and diagnostics.
  • Stripe — invoices, payment processing, and billing records.
  • Resend and communications providers — transactional email, notifications, onboarding, and support.
  • Telegram and other messaging providers — only when you enable a messaging-based Posting Machine experience.

These providers may process information in countries other than yours. They process information under their agreements with us or the terms that apply when you connect their service, as well as applicable law.

When we disclose information

We disclose information only as needed:

  • to the service providers described above;
  • to connected services and recipients when you direct us to publish, send, import, export, or otherwise perform an action;
  • to authorized members of your organization or operators helping deliver your agreed service;
  • when required by law or reasonably necessary to protect rights, safety, security, and the integrity of the Service; or
  • as part of a financing, acquisition, reorganization, or sale of all or part of the business, subject to appropriate confidentiality protections.

Cookies and analytics

We use essential cookies for sign-in, security, and core product behavior. We also use analytics to understand website traffic and product usage. You can control non-essential cookies through your browser and any consent controls we make available, but blocking essential cookies may prevent parts of the Service from working.

Data retention

We retain account information and customer content while your account or service relationship is active and for as long as reasonably needed to provide the Service, keep agreed records, resolve disputes, maintain security, and comply with law. Different records may have different retention periods.

Disconnecting an integration removes or disables its active access credentials. You may ask us to delete your account and user-scoped content; we aim to complete account deletion requests within 30 days unless we must retain specific records for legal, billing, security, or dispute-resolution purposes. Residual copies may remain temporarily in backups and logs until they age out under normal retention cycles.

Security and incident response

We use reasonable administrative, technical, and organizational safeguards designed to protect information, including access controls, scoped integration permissions, protected credentials, and service-provider security measures. No method of storage or transmission is completely secure.

If we identify a data breach, we will investigate, limit further exposure, and notify affected customers, individuals, or authorities when applicable law requires it.

International data transfers

Posting Machine and its providers may process information outside your country. Where required, we use contractual and other measures intended to provide protection comparable to applicable data protection requirements. Contact us if you need information about transfers relevant to your account.

Your choices and rights

Depending on where you live, you may have rights to access, correct, export, delete, restrict, or object to certain processing of your personal data, and to withdraw consent where processing relies on consent. You may also have the right to complain to a data protection authority.

  • Update available account and content information through the Service.
  • Disconnect integrations to stop new collection from those sources.
  • Email us to request access, correction, export, or deletion, or to withdraw consent.
  • Unsubscribe from non-essential email using the link in the message or by contacting us.

We may need to verify your identity and authority before completing a request. Some rights are subject to legal exceptions, and withdrawing consent may prevent us from providing features that require the affected data.

Children

The Service is intended for business users and is not directed to children under 18. We do not knowingly collect personal data from a child through the Service. Contact us if you believe a child has provided personal data to us.

Changes to this Policy

We will post updates here and change the “last updated” date. If a change materially affects how we use personal data, we will provide reasonable notice through the Service or by email when practical.

Contact

Questions, complaints, or requests concerning privacy or data protection: founders@postingmachine.ai.