Who we are and when this policy applies
Postomatic is an AI-powered content operating system for organic growth, operated from Melbourne, Victoria, Australia. This policy applies when you visit postomatic.co, create or use an account at app.postomatic.co, join an account or brand workspace, connect a third-party service, or communicate with us.
In this policy, “Postomatic”, “we”, “us”, and “our” refer to the operator of the Postomatic service. “Customer” means the person or organisation responsible for an account. “User” means anyone authorised to use that account.
Questions or privacy requests can be sent to support@postomatic.co.
Information we collect
Depending on how you use Postomatic, we may collect:
- Account information: name, email address, authentication records, account membership, roles, invitations, active brand, and security events.
- Billing information: Stripe customer, subscription, plan, invoice, payment-status, cancellation, and entitlement records. Postomatic does not store full payment-card numbers.
- Brand and content information: websites, brand profiles, products, offers, evidence, source files, customer language, content plans, drafts, images, publishing settings, editorial decisions, and performance history provided or authorised by a Customer.
- Connected-service information: authorised account/property identifiers, encrypted access and refresh tokens, connection status, scopes, and data returned by Google, CMS platforms, analytics services, or publishing destinations.
- Usage and technical information: IP address, browser/device details, session and security cookies, pages/actions used, timestamps, errors, workflow events, audit records, and support communications.
- Public and licensed research: public website content, search results, and market information gathered to provide requested content-intelligence features.
Please do not provide sensitive personal information, confidential third-party material, or personal data that is not reasonably necessary for the service.
How we collect information
We collect information:
- directly from you when you register, configure a brand, upload material, or contact us;
- from account owners and administrators who invite or manage you;
- from services you choose to connect and authorise;
- automatically when the service records sessions, security, usage, and workflow events; and
- from public websites and approved research sources when you ask Postomatic to learn a brand or market.
If you connect an integration on behalf of an organisation, you confirm you have authority to give Postomatic access to that organisation’s account and data.
How we use information
We use information where reasonably necessary to:
- create, authenticate, secure, and administer accounts and brand workspaces;
- learn approved brand context and maintain evidence-backed Brand Brain records;
- identify customer questions, search demand, competitors, and content opportunities;
- research, plan, create, review, schedule, publish, update, and measure content;
- import Search Console and Analytics results and use them to improve future decisions;
- process subscriptions, invoices, entitlements, cancellations, and payment failures;
- deliver authentication, invitation, operational, billing, and support messages;
- detect abuse, investigate errors, recover interrupted work, and keep immutable audit evidence;
- comply with legal obligations and enforce our Terms; and
- improve Postomatic using aggregated, de-identified, or account-authorised feedback and usage signals.
We do not sell personal information or connected Google user data. We do not use Google user data for targeted advertising, credit decisions, surveillance, or unrelated purposes.
Google account, Search Console, and Analytics data
Google Sign-In may provide your name, email address, profile identifier, and basic profile information so Postomatic can authenticate your account. If you separately connect Google Search Console or Google Analytics, Postomatic requests only the permissions shown during authorisation and needed for the feature you select.
Search Console data may include sites/properties, search queries, pages, countries, devices, dates, clicks, impressions, click-through rate, and average position. Analytics data may include properties, streams, page/path dimensions, traffic and engagement measures, and configured events. We use this information to show performance, map existing demand and content, identify opportunities, evaluate published work, and inform future content and refresh decisions for the connected brand.
Authorisation tokens are encrypted at rest. Users with suitable permissions can disconnect Google integrations in Postomatic, and you can also revoke access through your Google Account. Disconnecting stops new imports; retained records are handled under the retention and deletion section below.
Postomatic’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
AI processing and automated workflows
Postomatic uses AI and search/research providers to deliver features such as extraction, classification, market analysis, opportunity scoring, article generation, image creation, quality review, correction, and editorial assistance. Relevant brand material, approved evidence, public research, content, instructions, and limited performance context may be sent to those providers to produce the requested result.
Postomatic stores generated results, provenance, review findings, cost/usage records, and audit evidence so work can be explained, resumed, corrected, and reproduced safely. We apply technical and contractual safeguards appropriate to each provider, but third-party providers operate under their own terms and privacy commitments.
Automated decisions determine routine content operations within the Customer’s configured plan and safeguards. Material blockers and unsafe conditions are surfaced for review. You can contact us if you believe an automated process has produced an incorrect or harmful outcome.
Storage and overseas processing
Postomatic operates from Australia and uses cloud services that may store or process information in Australia, the United States, and other countries where our providers or their subprocessors operate. Provider locations can change as services evolve.
We take reasonable steps to use reputable providers, restrict access, encrypt sensitive integration credentials, and apply contractual and technical safeguards. Privacy and data protection laws in another country may differ from Australian law.
Retention, disconnection, and deletion
We retain information while an account is active and for as long as reasonably necessary to provide the service, maintain security and audit evidence, resolve disputes, meet legal and tax obligations, recover from failures, and enforce agreements. Different records have different retention periods.
Disconnecting an integration stops future access but does not automatically erase imported metrics, generated content, publication history, invoices, security logs, or audit records. An account owner can request account closure and deletion. We will delete or de-identify information when it is no longer required, subject to legal obligations, backups, fraud and security needs, and records that must remain with other account members.
Backup copies may remain until overwritten through normal retention cycles. Where a legal hold applies, relevant information may be retained until the hold ends.
Security and data incidents
We use access controls, workspace and brand isolation, encryption for integration credentials, signed webhooks, audit logs, provider-scoped permissions, backups, and operational monitoring designed to protect information. No system is completely secure, and you are responsible for protecting account credentials and promptly removing users who no longer need access.
We investigate suspected incidents and will notify affected people and regulators where required by applicable law, including Australia’s Notifiable Data Breaches scheme when it applies.
Access, correction, complaints, and choices
Depending on your location and relationship with Postomatic, you may have rights to access, correct, export, object to, restrict, or delete personal information, or withdraw consent. Account owners and administrators can manage much of their workspace information directly.
Send a request or privacy complaint to support@postomatic.co. Include enough detail for us to verify your identity, identify the relevant account, and understand the request. We will respond within a reasonable period and explain if a request cannot be completed.
If you are not satisfied with our response and Australian privacy law applies, you may contact the Office of the Australian Information Commissioner.
Changes to this policy
We may update this policy when Postomatic’s features, providers, or legal obligations change. We will publish the revised policy with a new “Last updated” date and provide additional notice where a material change affects how we use personal information or connected Google data.