Effective date: March 16, 2026
PostEngine AI Solutions (“PostEngine”, “we”, “us”) operates the postengine.co platform. PostEngine is a user-assistive workflow platform. Every publishing action happens on your authorization and stays under your control — your approval of an individual post, or a standing instruction you give and can withdraw at any time.
This Privacy Policy explains what information we collect, why we collect it, how we use and protect it, and what choices you have. It applies to all users of the PostEngine web application and related services.
When you create an account we collect your name, email address, and password. Passwords are salted and hashed before storage—we never store them in plain text.
If you choose to connect your LinkedIn account, we access profile information and content metrics through LinkedIn’s official API, limited to the OAuth scopes you explicitly grant. We do not access your private messages, connections list, or any data outside the granted scopes.
We request the following LinkedIn OAuth scopes:
Drafts, ideas, brand voice settings, publishing preferences, approval decisions, and scheduling choices you create within the platform are stored to provide the service.
When you use AI-assisted features, your brand profile and content context are sent to the AI providers we work with — OpenAI, Anthropic (Claude) and Google (Gemini) — to generate text and images. Which one handles a request depends on the feature and on which provider is available at the time; a request that fails with one is retried with another. We do not use your content to train AI models. Requests are processed in real time; a provider may hold part of a request in a short-lived cache so a repeated request is faster and cheaper, and nothing is kept after that.
We collect anonymized usage patterns (pages visited, features used, performance timings) to improve the service. We do not use third-party analytics trackers or advertising pixels.
We do not sell your personal information. We do not use your data for advertising. We do not share it with third parties for their marketing purposes.
We process your data based on:
Your data is hosted on DigitalOcean cloud infrastructure in the NYC region within secured private networks. LinkedIn access tokens are encrypted with AES-256-GCM before storage. All connections to the platform use TLS encryption. We apply the principle of least privilege to all internal access controls.
While we implement industry-standard safeguards, no system is completely immune to risk. If we become aware of a personal data breach, we will notify the competent supervisory authority within 72 hours of becoming aware of it, which is what Article 33 of the GDPR requires. Where the breach is likely to put your rights at high risk, we will tell you without undue delay, which is the standard Article 34 sets, and we will do it through an in-app notification, the only channel this product delivers on today. We do not quote you a fixed deadline, because the Regulation sets none here and a deadline nothing can keep is worse than none.
We share data with the following categories of service providers, strictly as needed to operate the platform:
We do not share your data with data brokers, advertising networks, or any other third parties beyond what is described above. For a complete list of sub-processors and our data processing terms, see our Data Processing Agreement.
We retain your data for as long as your account is active. Upon account deletion via Settings → Danger Zone, PostEngine will: (a) ask LinkedIn to revoke your access token immediately, and tell you if LinkedIn refuses rather than report success, (b) schedule your account for deletion and keep it recoverable for 30 days — you can cancel it yourself at any point in that window by signing back in and pressing Cancel deletion on the screen that appears — signing in on its own does not cancel it — and no request to us is needed, (c) permanently delete all personal data after 30 days. Cancelling restores your account and its data, but not your LinkedIn connection: revoking that token is one-way, so you will need to reconnect LinkedIn. Specific retention periods:
You may also export a full copy of your data before deletion via the same Settings → Danger Zone page (see Article 20, GDPR — right to data portability).
Depending on your jurisdiction, you may have the right to:
To exercise any of these rights, contact us at our support address. We will respond within 30 days.
We use essential cookies for authentication, CSRF protection, and locale preferences. Optional analytics cookies may be used to understand usage patterns. On your first visit, you will be prompted to accept or reject non-essential cookies. Your choice is stored for 365 days and can be changed at any time via Settings → Privacy. We do not use third-party advertising cookies or fingerprinting techniques.
If you are a California resident, the California Consumer Privacy Act (as amended by CPRA) grants you additional rights:
To exercise these rights, contact us at the email address listed in Section 13. We will verify your identity before processing your request and respond within 45 days.
Our infrastructure is hosted in DigitalOcean's NYC region (United States). If you access the service from outside the US, your data will be transferred internationally. We rely on industry-standard contractual safeguards (including Standard Contractual Clauses where applicable) to protect data during such transfers.
PostEngine is not directed at individuals under the age of 16. We do not knowingly collect personal information from children. If we learn that we have inadvertently collected data from a child, we will delete it promptly.
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via in-app notification or email at least 14 days before the changes take effect. Continued use of the Service after the effective date constitutes acceptance of the revised policy.
For privacy-related questions, concerns, or requests, contact us at our support address.
See also: Terms of Service · Data Processing Agreement · Support Center · Contact Us