— Legal
Privacy Policy
Effective date: February 5, 2026
This Privacy Policy explains what personal data PostShifted collects, how we use it, who we share it with, and the choices you have. It applies to your use of the PostShifted website and application (the “Service”).
01.Who we are
The Service is operated by PostShifted. For any privacy question or request, contact us at support@postshifted.com.
02.What we collect
We collect only what we need to provide the Service:
- Account data. Email address, name, hashed password, and optionally a profile picture (if you sign in with Google).
- Content you submit. The text you paste in for repurposing, your brand voice samples, your saved templates, and your generated outputs.
- Usage data. Number of remixes generated, formats chosen, timestamps, and basic diagnostics (errors, latency) used to keep the Service healthy.
- Billing data. If you subscribe to Pro, our payment processor Paddle handles your payment method. PostShifted only stores non-sensitive fields returned by Paddle — customer id, subscription id, status, and renewal date. We never see or store your card number.
- Cookies. A single session cookie or local-storage token to keep you signed in. We do not use third-party ad tracking.
03.How we use your data
We use your data to:
- Operate the Service and generate the outputs you requested.
- Send transactional emails such as receipts, security alerts, and product changes.
- Enforce plan limits and prevent abuse.
- Improve the product (aggregated, non-identifying analytics only).
- Comply with legal obligations.
We do not sell your personal data. We do not use your submitted content to train our own or third-party AI models.
04.Sub-processors
To provide the Service we rely on the following third parties:
- Anthropic (AI model provider) — receives the text you submit for the duration of the request in order to generate outputs.
- Paddle.com Market Limited (Merchant of Record) — handles all payment processing, tax collection, and invoicing for Pro subscriptions.
- MongoDB Atlas (managed database hosting) — stores your account, brand voices, templates, and generation history.
- Emergent (application hosting) — hosts the web and API servers.
Each sub-processor is bound by their own terms and privacy policies and processes data only as needed to deliver their portion of the Service.
05.AI providers and your content
When you request a remix, the text you submit is sent to Anthropic's Claude API for processing. Anthropic's current API terms state that API inputs and outputs are not used to train their models. We do not retain any additional copy of your input at Anthropic beyond the transient processing window.
Please avoid pasting highly sensitive personal data (medical records, government IDs, etc.) into the Service. Generative AI is not designed as a store for that kind of data.
06.Data retention
We keep your account data and generation history for as long as your account exists. When you delete your account, all associated personal data (account, brand voices, templates, history, ideas) is deleted within 30 days, except where we are legally required to retain it (e.g. financial records for tax purposes).
07.Your rights
Depending on where you live, you may have rights under laws such as the EU/UK GDPR or the California CCPA, including:
- The right to access the personal data we hold about you.
- The right to correct or update inaccurate data.
- The right to delete your data (“right to be forgotten”).
- The right to object to or restrict certain processing.
- The right to receive your data in a portable format.
- The right to withdraw consent where processing is based on consent.
To exercise any of these rights, email support@postshifted.com from the address on your account. We will respond within 30 days.
08.Security
We use industry-standard security practices: HTTPS/TLS in transit, encryption at rest via our database provider, hashed and salted passwords (bcrypt), scoped API keys, and short- lived signed tokens. No system is 100% secure — please use a strong, unique password and notify us immediately if you suspect unauthorized access.
09.International data transfers
The Service is operated globally; your data may be processed in countries other than your own, including the United States and the European Union. Where required, we rely on appropriate safeguards such as the Standard Contractual Clauses.
10.Children
The Service is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.
11.Changes to this policy
We may update this Privacy Policy occasionally. Material changes will be announced in-app or by email at least 14 days before they take effect. The “Effective date” at the top of this page always reflects the latest version.
12.Contact
Privacy questions or data-subject requests: support@postshifted.com.
See also our Terms of Service and Refund Policy.
Questions? Email support@postshifted.com.