Postu.io legal

Privacy Policy

Operated by: ADVITECH Consulting Korlátolt Felelősségű Társaság
Company registration number: 01-09-419640 · Tax number: 32352399-2-43 · EU VAT: HU32352399
1122 Budapest, Maros utca 25. 1. em. 1. ajtó, Hungary
Contact: info@advitech.hu · hi@postu.io

1. Overview

Last updated: September 14, 2026.

This Privacy Policy explains how Postu.io ("Postu", "we", "us", or "our") collects, uses, stores, shares, and protects information when users access Postu, connect third-party accounts, schedule content, publish content, view analytics, or use related tools.

Postu is operated by ADVITECH Consulting Korlátolt Felelősségű Társaság, company registration number 01-09-419640, tax number 32352399-2-43, EU VAT HU32352399, 1122 Budapest, Maros utca 25. 1. em. 1. ajtó, Hungary. You can contact the operator at info@advitech.hu.

2. Information We Collect

We may collect and process the following categories of information:

  • Account information, such as email address, name, password hash, organization membership, role, billing status, and account settings.
  • Connected account information, such as social profile names, user IDs, channel IDs, page IDs, workspace IDs, profile pictures, and account metadata returned by connected platforms.
  • Authorization data, such as OAuth access tokens, refresh tokens, API keys, webhook secrets, bot tokens, extension IDs, cookies, or similar credentials that are required to connect and operate a platform integration.
  • User content, such as posts, captions, descriptions, comments, titles, tags, links, thumbnails, images, videos, documents, drafts, scheduled publishing times, selected boards, pages, channels, groups, communities, or other publishing destinations.
  • Analytics and performance data, such as views, clicks, reactions, impressions, saves, comments, subscriber counts, channel statistics, post URLs, publishing status, and error messages returned by connected platforms.
  • Usage and technical data, such as IP address, browser type, device information, timestamps, logs, request metadata, feature usage, security events, and diagnostic information.
  • Support communications, such as messages, email requests, bug reports, screenshots, and information you provide when contacting us.

3. Connected Platforms and Integrations

Postu allows users to connect accounts from third-party platforms in order to publish, schedule, manage, and analyze content. Supported or planned integrations may include Telegram, X (Twitter), Mastodon, Bluesky, Nostr, Reddit, Discord, VK, LinkedIn, Instagram* Standalone, Instagram* Business, Threads*, YouTube, TikTok, Facebook*, Medium, Dev.to, WordPress, Hashnode, Pinterest, Slack, Twitch, Lemmy, Skool, Whop, Google Business Profile, Dribbble, Max messenger, Dzen, Odnoklassniki, and other services.

The exact data we access depends on the platform, the permissions shown during authorization, the account type, and the features the user chooses to use. We only request access that is needed to provide the relevant integration features.

Some integrations use OAuth. Some integrations may require an API key, bot token, webhook secret, application credential, browser extension, cookie, or other user-provided credential when the platform does not provide a standard OAuth flow for the required functionality.

4. How We Use Information

We use information to:

  • Create, authenticate, secure, and manage user accounts.
  • Connect third-party accounts at the user's request.
  • Retrieve account, page, board, channel, workspace, community, or profile information needed to display available publishing destinations.
  • Schedule, publish, update, or delete user-selected content on connected platforms when supported by the relevant platform.
  • Upload or transmit user-provided media, titles, captions, tags, descriptions, links, thumbnails, and other metadata to connected platforms.
  • Retrieve analytics, publishing status, comments, mentions, or other performance information when authorized by the user.
  • Provide previews, calendars, team workflows, automation, notifications, logs, and support.
  • Detect, prevent, and investigate abuse, spam, fraud, security incidents, platform misuse, and violations of our Terms.
  • Maintain, debug, secure, and improve Postu.
  • Comply with legal obligations and platform requirements.

4A. Legal Bases and EEA Rights

For users in the European Economic Area, ADVITECH Consulting Korlátolt Felelősségű Társaság is the data controller. Depending on the processing activity, we rely on performance of a contract, compliance with legal obligations, legitimate interests in operating and securing Postu, or consent where consent is required.

Subject to applicable law, you may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent at any time without affecting earlier lawful processing. You may also lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information or your local supervisory authority.

5. Google and YouTube API Data

Postu allows users to connect Google and YouTube accounts through Google OAuth in order to connect YouTube channels, upload videos, manage video metadata, retrieve channel information, retrieve video analytics, and connect Google Business Profile locations when those features are enabled.

When a user connects a Google or YouTube account, Postu may access:

  • Basic Google profile information, such as name, email address, and profile picture.
  • YouTube channel information, such as channel ID, title, thumbnails, custom URL, and statistics.
  • User-provided video content and metadata, such as video files, title, description, tags, thumbnail, visibility setting, and made-for-kids setting.
  • YouTube video and channel analytics, such as views, watch time, likes, comments, subscribers gained or lost, and related metrics.
  • Google Business Profile account, location, and post information when the user connects Google Business Profile.

Postu uses Google and YouTube data only to provide user-authorized features, including authentication, account connection, channel or location selection, video upload, metadata management, scheduling, publishing, and analytics display.

Postu does not sell Google user data, does not use Google user data for advertising, and does not transfer Google user data to third parties except as necessary to provide the service, comply with law, protect the service, or operate infrastructure such as hosting, storage, security, logging, and database providers.

Postu's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

6. Meta, LinkedIn, TikTok, Pinterest, and Other Platform Data

When users connect platforms such as Facebook*, Instagram*, Threads*, LinkedIn, TikTok, Pinterest, Reddit, X, Slack, Discord, Twitch, Dribbble, Whop, Telegram, Dzen, VK, or similar services, Postu may receive account identifiers, profile information, page or channel information, access tokens, publishing destinations, user-provided content, media, post status, and analytics data depending on the permissions granted.

For Dzen delivery, Postu publishes to a public Telegram relay selected by the user. The user-added @zen_sync_bot separately transfers that content to the linked Dzen channel. Postu does not receive Dzen account credentials and cannot confirm Dzen moderation or final publication.

We use this data only to perform actions authorized by the user, such as showing available pages, boards, channels, or communities, publishing content, scheduling content, retrieving analytics, or displaying publishing results.

We do not sell platform data and do not use platform data to build advertising profiles. Users remain responsible for complying with each connected platform's terms, developer policies, community guidelines, advertising policies, and content rules.

7. Browser Extension and Non-OAuth Integrations

Some integrations may use the Postu browser extension or user-provided credentials where a platform does not offer the necessary OAuth or API access. For example, a browser extension may read connection data from a platform session only after the user installs the extension, signs in to the platform, and authorizes the connection in Postu.

We use extension-based or non-OAuth credentials only to connect the requested account and perform the actions the user initiates or schedules. Users can disconnect accounts and request deletion of stored connection data at any time.

8. Data Sharing

We may share information only with the following categories of recipients:

  • Connected platforms, when needed to publish content, retrieve analytics, verify account access, or perform user-authorized actions.
  • Infrastructure and service providers that help operate Postu, such as hosting, storage, database, email, security, logging, analytics, monitoring, and payment providers.
  • Professional advisors, legal authorities, or other parties when required by law, legal process, security needs, fraud prevention, or protection of rights.
  • A successor entity in connection with a merger, acquisition, restructuring, or sale of assets, subject to appropriate safeguards.

We do not sell personal data.

9. Data Storage and Security

We store data using infrastructure providers, hosting providers, database providers, object storage, and related operational services. We use reasonable technical and organizational safeguards designed to protect personal data, credentials, tokens, and user content.

No online service can guarantee absolute security. Users should keep their account credentials secure and promptly notify us of suspected unauthorized access.

10. Data Retention

We retain personal data for as long as necessary to provide Postu, maintain connected accounts, operate scheduled content, comply with legal obligations, resolve disputes, enforce agreements, prevent abuse, and maintain security.

OAuth tokens, API keys, cookies, and similar credentials are retained while the relevant integration remains connected or as otherwise necessary to provide the service. Scheduled posts and uploaded media are retained while needed for scheduling, publishing, history, analytics, troubleshooting, or user access.

11. User Controls and Data Deletion

Users may:

  • Access and update account information.
  • Disconnect third-party accounts from Postu.
  • Delete drafts, scheduled posts, uploaded media, or other content where available.
  • Request export, correction, or deletion of personal data.
  • Revoke Postu access directly from the connected platform's security or app settings.

To request deletion, email hi@postu.io with the subject line "Data Deletion Request" from the email address associated with your Postu account. After verification, we will delete or anonymize personal data unless retention is required for legal, security, fraud prevention, accounting, or legitimate operational reasons.

12. International Data Transfers

We may process and store information in countries other than the user's country of residence. Where required, we use appropriate safeguards for cross-border data transfers.

13. Children

Postu is not intended for children under 13, and users must be at least 18 years old or the age of majority in their jurisdiction to use Postu for business or publishing purposes. We do not knowingly collect personal data from children.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Updates will be posted on this page, and the updated date will be revised. Continued use of Postu after an update means the revised policy applies.

15. Contact

For privacy questions, account deletion, platform review, or data requests, contact the operator at info@advitech.hu or the Postu support team at hi@postu.io.