Postrush

Privacy policy

Last updated

This policy explains what personal data Postrush collects, why, who it is shared with, how long it is kept, and the rights you have. Postrush is a social media scheduler: you write posts, choose when they go out, and Postrush publishes them to the social accounts you connect.

Who we are

Postrush is run by Avenholm Living ApS, Gunnekær 4, 2610 Rødovre, Denmark, CVR 46742230. We are the data controller for the personal data described here. Contact us at support@postrush.app.

Data we collect

  • Account data: your name, email address and a hash of your password (we never store the password itself), whether your email is verified, and your display preferences such as theme, week start and time format.
  • Sign-in sessions: for each session we store the IP address and browser type (user agent) it was created from, so you can see and end your sessions in Settings and so we can protect accounts.
  • Security records: to slow down password guessing and abuse, we count requests per IP address and per account for a short time.
  • Workspaces and teams: workspace name, address and timezone, the members and their roles, invites (the invited email address and role), and a log of membership changes that contains ids, not names or emails.
  • Your content: posts, drafts, schedules, the per-channel versions of each post, follow-up replies or comments, revision history with who edited what, signatures, and the settings you choose per channel.
  • Media: the images and videos you upload, their original file names, sizes, dimensions and a checksum. Files are kept in private storage and are only shown to members of your workspace.
  • Notifications and email: your email notification choices per workspace, in-app notifications, and records of the emails we sent you (type and delivery status).
  • Connected social accounts: described in the next section.

We do not collect payment details. Postrush has no paid plans today.

Connected social accounts

When you connect an account on X, Instagram, Facebook or TikTok, you sign in on that platform and approve what Postrush may do. We then store:

  • the account's id on the platform, its handle, display name, profile picture address and profile link;
  • the permissions you granted and what the account can publish (for example the post length available to it);
  • the access tokens the platform gives us, encrypted (see Security). Tokens are never sent to your browser.

We use this access only to do what you ask:

  • read the connected account's own basic profile;
  • upload the media you attach to a post;
  • publish your posts, and the follow-up replies or comments you add to them, at the time you choose;
  • check that a post was published and record its id and time.

We do not read your direct messages, we do not read other people's data, and we do not use platform data for advertising. We do not sell your data, and we do not use your content or platform data to train AI models.

Postrush is not affiliated with or endorsed by X, Meta or TikTok. What you publish becomes subject to the platform's own terms and privacy policy.

How and why we use data

  • To provide Postrush (account, workspaces, scheduling, publishing, notifications, support). Legal basis: performance of our contract with you (GDPR Art. 6(1)(b)).
  • To keep Postrush secure (sessions, rate limits, the email suppression list, preventing abuse). Legal basis: our legitimate interest in protecting the service and its users (Art. 6(1)(f)).
  • To send service emails: email verification, password reset and change notices, invites, ownership changes, and post alerts (a post failed, needs your attention, or was published). You can turn post alerts off per workspace in Settings or with the one-click unsubscribe link in each alert. Account and security emails can't be turned off while you have an account.

We do not send marketing emails and we do not use tracking pixels or analytics.

Who we share data with

We use these service providers (processors), who handle data only on our instructions:

  • Cloudflare, Inc.: hosting, the database (located in Western Europe), private file storage, and forwarding of emails sent to support@postrush.app.
  • Resend, Inc.: sending our emails, from its EU region (Ireland). Resend receives your email address and the email content.

The social platforms you connect (X, Meta for Facebook and Instagram, TikTok) receive the content you publish and the requests needed to publish it. They act under their own privacy policies.

When you view connected accounts in Postrush, your browser loads their profile pictures directly from the platform's image servers, which can see your IP address.

Other members of a workspace can see your name, role and which content you edited in that workspace. We may disclose data if the law requires it.

Transfers outside the EU

Cloudflare and Resend are US companies. Your data is stored and sent from the EU where they offer it, but they may access it from outside the EU. Where that happens, the transfer is covered by the EU Standard Contractual Clauses in their data processing agreements and, where the provider is certified, the EU–US Data Privacy Framework.

Cookies and browser storage

We only use cookies that are strictly necessary for Postrush to work, so we don't ask for cookie consent:

  • __Secure-better-auth.session_token: keeps you signed in. Expires after 24 hours.
  • scheduler_media_preview: lets your browser show a private media file for 2 minutes.

Your browser's local storage remembers small layout choices, such as whether the sidebar is collapsed. It holds no personal data. We use no analytics, advertising or tracking cookies.

How long we keep data

DataHow long
Your account (name, email, password hash, preferences)Until you delete your account.
Workspaces, posts, drafts, schedules, revision history and mediaUntil you delete them or your account. Media you remove from the library is deleted from storage once no post uses it.
Records of what was published (post ids and times on each platform)Until you delete your account.
Connected-account access tokensUntil you disconnect the channel, the platform withdraws access, or you delete your account.
Sign-in sessions (with IP address and browser type)A session lasts 24 hours. The record is removed when it is cleaned up, when you sign out of it, or when you delete your account.
Security rate-limit records (IP address)Deleted after 24 hours without activity.
Email delivery recordsThe email content is cleared as soon as the email is sent or fails. The record itself is deleted after 90 days.
In-app notifications90 days.
Workspace invites90 days after the invite is accepted, cancelled or expires.
Email suppression list (an address that bounced or marked our email as spam)Kept so we never email that address again, even after the account is deleted. Ask us to remove it.
Backups of our databaseUp to 30 days. Deleted data disappears from backups within that window.

Posts you published stay on the platform after you delete them in Postrush. See how to delete your data.

Security

  • All traffic uses HTTPS.
  • Social account access tokens are encrypted at rest with AES-256-GCM, using keys kept separate from the database, and they never leave our servers.
  • Passwords are stored as hashes. Uploaded media is in private storage. It is shown only to signed-in workspace members, and handed to the platform you publish to, through short-lived links.
  • Access to workspace data is checked on every request.

No system is perfectly secure. If a breach affects your personal data, we will tell you and the authorities as the law requires.

Your rights

Under the GDPR you can ask to access, correct, delete or receive a copy of your personal data, and to restrict or object to how we use it. You can change your name and email and delete your account yourself in Settings. For anything else, email support@postrush.app from the address on your account. We answer within one month.

You can also complain to the Danish Data Protection Agency (Datatilsynet) or the authority where you live.

Age limit

Postrush is for people aged 18 or over. We don't knowingly collect data from anyone younger. If you believe a child has an account, contact us and we will delete it.

Changes to this policy

We update this policy before we change how we handle personal data, for example before adding a new service provider. We change the date at the top and, for important changes, tell you by email or in the app.