Legal document
Privacy Policy
Last updated: July 25, 2026
This Privacy Policy describes how PostedIn ("we", "us", "our") collects, uses, and protects your personal data in connection with your use of usepostedin.com (the "Service"). As the data controller, we operate in compliance with the EU General Data Protection Regulation (GDPR 2016/679) and other applicable data protection laws.
1. Data Controller
The controller of your personal data is:
- Name: Simple Studio Piotr Hyra
- Address: ul. Wręczycka 90, 42-133 Bieżeń, Polska
- NIP (Tax ID): 5742060804
- REGON: 365542882
- Email: [email protected]
2. Data We Collect
2.1 Account Data
When you register, we collect your name (or username), email address, and password (stored as an encrypted hash).
2.2 LinkedIn Data
If you connect your LinkedIn account via OAuth, we receive your name, LinkedIn profile ID, and access tokens needed to schedule and publish posts on your behalf. We do not collect your LinkedIn contacts or activity history.
2.3 AI-Generated Content
We store the posts generated by AI, scheduled posts, publication history, and writing styles you create so you can access and manage them.
2.4 Payment Data
Payments are handled by Stripe, Inc. We do not store your card details. We store your Stripe customer ID and subscription information (plan, status, billing dates).
2.5 Technical Data
We automatically collect IP addresses, browser type and version, device information, access logs, and cookies for security, error diagnostics, and traffic analysis.
3. Purposes and Legal Bases for Processing
- Performance of contract (Art. 6(1)(b) GDPR) – providing account services, AI generation, and post scheduling.
- Legitimate interests (Art. 6(1)(f) GDPR) – service security, fraud detection, product improvement.
- Legal obligation (Art. 6(1)(c) GDPR) – issuing invoices and maintaining tax records.
- Consent (Art. 6(1)(a) GDPR) – sending marketing communications (where you have opted in).
4. Sharing Your Data
We do not sell your personal data. We may share data with the following parties:
- Stripe, Inc. (USA) – payment processing and subscription management. Data may be transferred to the USA under Standard Contractual Clauses approved by the European Commission.
- OpenAI, LLC (USA) – AI content generation based on your inputs. Transfers are covered by Standard Contractual Clauses.
- LinkedIn Corporation (USA) – publishing scheduled posts on your behalf under your OAuth authorisation.
- Google LLC (USA) – Google Analytics 4 statistics, only after you consent, delivered first-party via Cloudflare Zaraz.
- Meta Platforms Ireland Ltd. (Ireland) – ad measurement and remarketing, only after you grant marketing consent. We send an event id and your email address as an irreversible hash (SHA-256), never the content of your posts. Legal basis: Art. 6(1)(a) GDPR (consent).
- LinkedIn Ireland Unlimited Company (Ireland) – LinkedIn ad measurement, only after you grant marketing consent, with the same data scope. Legal basis: Art. 6(1)(a) GDPR (consent).
- Cloudflare, Inc. (USA) – CDN, security, and delivery of analytics tooling (Zaraz).
- Infrastructure providers – hosting and database services located in the EU or subject to appropriate safeguards.
All sub-processors are required to process data only on our behalf and in accordance with our instructions.
5. International Data Transfers
Ad measurement is carried out by entities in the European Economic Area (Meta Platforms Ireland, LinkedIn Ireland), which may transfer data to their US parent companies under their own transfer mechanisms. Your data may also be transferred to the United States in connection with Stripe, OpenAI, and LinkedIn services. We apply appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914).
6. Data Retention
- Account data – for the duration of your account; deleted upon request or 90 days after account deletion.
- Payment records and invoices – 5 years, as required by Polish tax law.
- Generated posts and writing styles – until account deletion or upon request.
- Technical logs – up to 90 days.
7. Your Rights (GDPR)
As a data subject, you have the following rights:
- Access – request a copy of the data we hold about you.
- Rectification – correct inaccurate or incomplete data.
- Erasure – request deletion of your data (subject to legal obligations).
- Restriction – request that we pause processing in certain circumstances.
- Portability – receive your data in a structured, machine-readable format.
- Objection – object to processing based on legitimate interests.
- Withdrawal of consent – withdraw consent at any time without affecting prior processing.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with the Polish supervisory authority, the Urząd Ochrony Danych Osobowych (UODO), at uodo.gov.pl, or with the data protection authority in your country of residence.
8. Cookies
We use necessary cookies (session, login, security) and, only after you give consent, analytics cookies (Google Analytics 4 delivered via Cloudflare Zaraz) and marketing cookies (Meta Pixel, LinkedIn Insight Tag). Marketing consent also covers server-side measurement: without it we send no events to Meta or LinkedIn at all, and withdrawing it stops the sending immediately. We collect consent through a banner on your first visit. You can change or withdraw it at any time by opening your cookie settings. For a full list of cookies, their retention and information about data transfers, see our Cookie Policy.
9. Security
We use TLS/HTTPS encryption for all traffic, bcrypt password hashing, and secure token storage. Access to personal data is restricted to those who need it. Despite our precautions, no system is 100% immune to breaches.
10. Children
The Service is not directed at individuals under 16 years of age. We do not knowingly collect data from children. If you believe a child has provided us with data, please contact us for immediate deletion.
11. Changes to This Policy
We may update this Policy from time to time. For material changes, we will notify you by email or via a prominent notice within the Service at least 14 days before the change takes effect. Continued use of the Service after that date constitutes acceptance of the updated Policy.
12. Contact
For any questions about this Privacy Policy or your personal data:
- Email: [email protected]