Privacy Policy
Effective 21 July 2026. Last updated 21 July 2026.
This notice explains what personal data PostSwarm collects, why, and what you can do about it. It is written to meet Articles 13 and 14 of the GDPR (Regulation (EU) 2016/679).
1. Who is responsible
The controller of your personal data is [FULL NAME], a sole trader registered in Poland, [STREET ADDRESS], [POSTAL CODE] [CITY], Poland, NIP [NIP]. Contact for anything in this notice, including data requests: support@postswarm.app.
We are not required to appoint a Data Protection Officer and have not appointed one. Write to the address above instead.
2. What we collect
- Account data - your name, email address and a hashed password. We never store your password in readable form.
- Your content - images you upload or import, templates, prompts, captions, rendered slideshows and schedules.
- TikTok connection - when you connect a TikTok account we store its public identifier, display name, avatar URL, and access and refresh tokens. The tokens are encrypted at rest and used only to deliver slideshows to your drafts.
- Session and security data - session tokens, and the IP address and browser user-agent recorded with each sign-in.
- Usage records - a timestamped counter row each time you generate copy, render a slideshow or push to TikTok. Used to apply plan limits and show you your usage.
- Notification data - if you turn on push notifications, the endpoint and keys your browser issues.
- Billing data - your plan, and the customer identifier our payment provider assigns you. We never see or store your card details; Stripe handles the payment and holds that data as its own controller.
- Server logs - technical records our hosting provider keeps, which include IP addresses.
3. Why we use it, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Running your account and providing the Service | Performance of a contract - Art. 6(1)(b) |
| Taking payment and applying plan limits | Performance of a contract - Art. 6(1)(b) |
| Invoicing and keeping accounting records | Legal obligation - Art. 6(1)(c) |
| Security, abuse prevention, debugging, improving the Service | Legitimate interests - Art. 6(1)(f) |
| Push notifications about your scheduled slideshows | Consent - Art. 6(1)(a), withdrawable in settings |
| Defending or bringing legal claims | Legitimate interests - Art. 6(1)(f) |
We do not sell your personal data, do not use it to train AI models, and do not use it for advertising.
4. Who we share it with
We use a small number of providers to run the Service. They process data on our instructions under data processing agreements, except where noted.
- Vercel - application hosting, image storage and server logs.
- Supabase / Neon - the managed Postgres database holding your account and content.
- Mistral AI - generates written copy. The prompts, briefs and slide text you submit are sent to it. Do not put personal or confidential information in a prompt.
- Stripe - payments. Stripe is an independent controller of the payment data you give it; see its own privacy policy.
- TikTok - receives the slideshow and caption when you or your automation push a draft to your connected account.
- Image search sources - when you search for images in the app, your search term is sent to the third-party image source. No account data goes with it.
- Browser push services - Google, Apple or Mozilla, depending on your browser, deliver notifications if you enable them.
We may also disclose data where the law requires it, or to establish or defend legal claims.
5. Transfers outside the EEA
Some of the providers above are established in the United States or process data there. Those transfers rely on the European Commission’s standard contractual clauses, on an adequacy decision such as the EU–US Data Privacy Framework where the provider is certified, or on both. Write to us for details of the safeguards in place.
6. How long we keep it
- Account and content - while your account exists, then deleted within 30 days of you deleting the account.
- TikTok tokens - until you disconnect the account or the token expires.
- Usage records - 24 months, so we can show you history and detect abuse.
- Invoices and accounting records - 5 years from the end of the tax year, as Polish law requires.
- Server logs - short-lived, per our hosting provider’s retention.
7. Your rights
Under the GDPR you can ask us to:
- give you a copy of the data we hold about you (access);
- correct anything inaccurate (rectification);
- delete your data (erasure);
- restrict how we use it, or object to processing based on our legitimate interests;
- send you, or another provider, a portable copy of the data you gave us;
- withdraw consent for push notifications at any time, without affecting what was done before.
Email support@postswarm.app and we will respond within one month. You can also delete your account yourself from your settings, and disconnect TikTok there at any time - revoking our access in your TikTok account settings works too.
If you think we have handled your data badly you can complain to the Polish supervisory authority: Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl. If you live in another EU country you may complain to your local authority instead.
8. Automated decision-making
We do not make decisions about you by automated means that produce legal or similarly significant effects. The AI in the Service drafts your content; it does not evaluate you.
9. Cookies
We set one cookie: the session cookie that keeps you signed in. It is strictly necessary, so it needs no consent - which is why you are not being asked to dismiss a banner. We use no analytics, no advertising and no third-party trackers.
10. Children
The Service is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has given us personal data, write to us and we will delete it.
11. Security
Data is encrypted in transit, passwords are hashed, TikTok tokens are encrypted at rest, and every record is scoped to the account that owns it. No system is perfectly secure; if a breach ever affects your rights we will notify you and the supervisory authority as the GDPR requires.
12. Changes
If we change this notice materially we will tell you by email or in the app before the change takes effect. The date at the top always shows the current version.
13. Contact
[FULL NAME], [STREET ADDRESS], [POSTAL CODE] [CITY], Poland · support@postswarm.app