Privacy notice
Effective 27 July 2026 · Controller: PostGuild
Who is responsible
PostGuild is responsible for personal data processed by this PostGuild service. For privacy requests, contact privacy@postguild.com. If your organization operates its own PostGuild deployment, that organization is the controller for data in its deployment.
Data we process and why
- Account and session data, including name, email, hashed password credentials, IP address, user agent, and session records, to create and secure your account and provide the service.
- Content, prompts, media references, schedules, production jobs, and publishing history, to create, manage, and publish the work you request.
- Connected social-account identifiers, access credentials, and platform responses, to connect accounts and publish content. Stored access credentials are encrypted at rest.
- Configuration and limited functional interface state, such as the latest OpenMontage tab, to operate the service and remember choices you explicitly ask the application to remember.
Legal bases
We process account, content, connection, and publishing data because it is necessary to provide the service you request. We process limited security data to protect the service and users. The latest OpenMontage tab is stored locally to provide the requested remember-last-tab function; it contains no account, content, or tracking identifier.
Sharing and international transfers
Data is shared only as needed with the infrastructure, database, queue, AI, media-generation, and social-platform providers selected by the service operator or by you. Publishing content or requesting AI generation sends the necessary data to those providers under their own terms. Some providers may process data outside the EEA; the controller must use an applicable transfer mechanism where required. We do not sell personal data.
Retention
Sessions expire after 7 days. OAuth security cookies expire after 10 minutes. Functional browser state expires after 180 days. Account content and connection data are kept while the account is active and then deleted or anonymized when no longer needed, subject to security, dispute, backup, and legal-retention requirements. Platform access tokens are removed when the associated connection is deleted.
Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, or portability of your data, or object to certain processing. You may withdraw consent without affecting earlier lawful processing. Contact privacy@postguild.com to make a request. You may also complain to your local data-protection authority.
Security and changes
We use access controls, secure session cookies, encryption for stored platform credentials, and restricted OAuth security cookies. No internet service can guarantee absolute security. Material changes to this notice will be identified by an updated effective date and, where appropriate, an in-product notice.
For browser-storage details, see the cookie notice.