Privacy Policy

Last updated: 29 August 2026

Postmaxx ("we", "us") adapts proven short-form carousel structures into ready-to-post marketing content for your app, site, or SaaS. This page explains what we collect, why, and your rights. We aim to collect as little personal data as possible.

1. Information we collect

Account information

When you sign in with Google, we receive your email address, name, and profile picture. We use this to identify your account, send important service emails, and display your name in the app.

Product profile

If you save a product profile (your app, site, or SaaS URL, plus its name, description, audience, and brand color), we store it and send it to our AI model with each generation so the output describes your product accurately. If you use URL import, we fetch the public page at the URL you provide.

Generated content

We store the text plan (slide copy, captions, and hashtags) and the stock photographs chosen for posts you create so you can revisit them, export Reels, and use daily publishing. Photographs come from a curated library of licensed stock images; none are AI-generated. Final composited slide files for manual downloads are rendered in your browser. When you use daily publishing, final slides are rendered by our service and sent to the publishing provider and your connected social account.

Connected social accounts

If you connect Instagram, our publishing provider handles the account authorization. We store the provider profile identifier, your publishing queue, delivery status, and provider response data needed to schedule posts, prevent duplicates, and show whether each post succeeded.

Post performance

For posts we published for you, we retrieve and store the numbers the platform reports — views, likes, comments, shares, and saves — together with the post's link. These are shown to you on your own analytics view, and they are used to improve the posts we generate for your account: a source structure or visual style that earned saves and shares is chosen more often for you. This never crosses between accounts. Your results are not used to generate anyone else's posts, and you are never shown anyone else's numbers.

Payment data

Payments are processed by Stripe. We never see or store your full card details. We retain a Stripe customer ID, subscription status, and any legacy credit balance needed to manage your account.

Cookies

We use a single HttpOnly session cookie (tg_session) to keep you signed in, and a cookie that lasts 30 days (tg_anon) if you generate a preview post before creating an account, so the free preview cannot be taken repeatedly. We do not use third-party advertising or tracking cookies.

Usage analytics

We measure how the site is used with our own first-party analytics. No third-party analytics service is involved and no data leaves our systems. Analytics sets no cookie of any kind.

For each visit we record the pages viewed, how long the tab was actively in the foreground, which product actions occurred (for example importing a product link or generating a post), the referring website, the country your request arrived from, and whether the device is a phone or a desktop.

We do not store your IP address or your browser's user-agent string. To tell one visitor from another we store an irreversible hash derived from them together with a secret and the current date. Because the date is part of the hash, it changes every day and cannot be used to recognise you over time or across other websites.

If your browser sends a Do Not Track or Global Privacy Control signal, we collect nothing at all.

2. How we use your information

We do not use your content to train AI models. We do not sell your data to anyone, ever.

3. Third parties we share data with

4. Data retention

Generated content, publishing queues, and delivery records stay in your account until you request deletion or close your account. Sessions expire after 30 days of inactivity. Analytics records are deleted automatically: individual visit actions after 90 days, visit summaries after 180 days. The one-way hash that limits free preview posts to one per visitor is deleted after 30 days. If you joined the waitlist, we keep your email until you ask us to remove it. Stripe records are retained as required by law (typically 7 years).

5. Your rights

You can:

If you are in the EU, UK, or California, you have additional rights under GDPR / UK GDPR / CCPA, including the right to object to processing and the right to lodge a complaint with your local supervisory authority.

6. Security

Sessions are HttpOnly and rotated regularly. Passwords are never stored — sign-in is delegated to Google. All traffic is HTTPS. We follow industry-standard practices but cannot guarantee absolute security.

7. Children

Postmaxx is not intended for anyone under 16. We do not knowingly collect data from children.

8. Changes

If we materially change this policy, we will update the "Last updated" date and, where appropriate, notify you by email.

9. Contact

Questions about this policy or your data? Email hyperfixlabs@gmail.com.