Back to home
Privacy & data handling

Privacy Policy

This policy explains how Postlore handles account information, workspace data, publishing activity, and analytics signals across the platform.

Effective May 28, 2026

Overview

This Privacy Policy applies to Postlore, a social media publishing and intelligence application ("Postlore", "the Application", "we", "us", or "our"), operated by BlocWeave and available at postlore.com. It explains how we collect, use, store, and protect information when you visit our website, create an account, connect social platforms, publish content, or use analytics and AI-powered features.

We aim to collect only the information required to provide, secure, improve, and support the Postlore application. We do not sell personal information, and we handle workspace and account data in line with the expectations of a professional SaaS product.

Information We Collect

  • Account information such as your name, email address, login credentials, and profile details.
  • Workspace information such as brand settings, publishing preferences, billing region, connected platforms, and team configuration.
  • Content data such as drafts, captions, media references, scheduled posts, generated variants, hashtags, and workflow history.
  • Analytics data such as impressions, engagement, clicks, reach, posting times, and other performance signals returned by connected publishing providers.
  • Technical data such as IP address, browser type, device information, session logs, cookies, and product usage events.
  • Billing and transaction metadata required to process subscriptions through providers such as Stripe or Paystack. Payment card details are handled by the payment processor and are not stored directly by Postlore.

How We Use Information

  • To create and manage accounts, workspaces, subscriptions, and access permissions.
  • To publish, schedule, analyze, and optimize social content across connected platforms.
  • To generate AI-assisted content suggestions, best-time recommendations, and performance summaries.
  • To maintain platform security, prevent abuse, diagnose issues, and enforce our terms.
  • To communicate important service updates, billing notices, onboarding information, and support responses.
  • To improve the quality, reliability, and relevance of the Postlore product experience.

AI and Platform Data

Postlore uses workspace data, content inputs, and performance signals to generate recommendations and platform-adapted outputs. These features are designed to help users draft, refine, and learn from their content performance.

Where third-party AI or infrastructure providers are used, data may be processed by those providers strictly for service delivery, subject to contractual and technical controls. Users remain responsible for reviewing content before publication.

Sharing of Information

We share information only where necessary to operate the service, comply with legal obligations, protect rights and security, or complete transactions you request.

  • Infrastructure and hosting providers that help us deliver the application.
  • Authentication, analytics, and queueing providers that support core product functionality.
  • Payment processors such as Stripe and Paystack for subscription and checkout operations.
  • Publishing and analytics partners used to connect your social accounts and retrieve post performance data.
  • Design tool integrations such as Canva, where you choose to connect your Canva account from within Postlore. If you use the Canva integration, Postlore stores OAuth access and refresh tokens on your behalf to authenticate API requests. These tokens are deleted immediately when you disconnect the integration. Exported design images are stored in Postlore's media storage and subject to this policy. Your use of the Canva editor is also subject to Canva's own Privacy Policy.
  • Professional advisers or regulators where disclosure is legally required or reasonably necessary.

Third-Party Platform Integrations

Postlore allows you to connect social media accounts from third-party platforms including YouTube (Google), LinkedIn, TikTok, X (Twitter), Instagram, Telegram, and others. When you connect a platform, Postlore stores OAuth access and refresh tokens on your behalf, encrypted at rest, to authenticate publishing and analytics requests. These tokens are deleted immediately when you disconnect the integration.

Postlore collects only the data necessary to perform the actions you request — publishing content, reading post performance, and displaying account information. We do not use platform data to train AI models and we do not share platform data with third parties beyond what is necessary to operate the service.

  • YouTube and Google: Postlore uses YouTube Data API services to publish videos, retrieve video metadata, and fetch channel performance analytics. Your use of YouTube features is also subject to the YouTube Terms of Service (youtube.com/t/terms) and Google's Privacy Policy (policies.google.com/privacy). Postlore's use of data obtained via Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. YouTube data is not used to train AI models or shared with advertisers.
  • LinkedIn: Postlore uses the LinkedIn API to publish posts and retrieve basic profile information (name, email, and account identifier via OpenID Connect) required to identify your connected account. LinkedIn data is not used beyond the publishing and account-display purposes described in this policy.
  • TikTok: Postlore uses the TikTok API to publish photos, videos, and captions to your TikTok account. Postlore accesses only the permissions necessary to complete the actions you request and does not retain TikTok content data beyond what is needed for publishing confirmation.
  • X (Twitter): Postlore uses the X (Twitter) API to publish posts and retrieve basic account information. OAuth tokens are stored encrypted and deleted on disconnect.
  • Other platforms: Telegram, Instagram, Google Business Profile, Facebook, and other connected platforms are handled under the same principles — tokens are encrypted, used only to fulfill your publishing requests, and deleted on disconnect.

Data Retention

We retain information for as long as reasonably necessary to provide the service, maintain business records, resolve disputes, enforce agreements, and meet legal obligations. Retention periods may vary depending on the type of data, account status, and operational requirements.

If you close your account, we may delete or anonymize certain information after a reasonable retention period, except where storage is required for security, financial, tax, fraud-prevention, or legal compliance purposes.

Security

We use reasonable administrative, technical, and organizational safeguards to protect data from unauthorized access, misuse, loss, or disclosure. No system can be guaranteed completely secure, but we design Postlore with security, least-privilege access, and responsible infrastructure practices in mind.

Your Choices and Rights

You may update account and workspace information from within the product where those controls are available. You may disconnect integrations, manage billing settings, and control team access based on your plan and permissions. You may disable cookies in your browser, though some parts of the service may not function properly without them.

If you are located in the European Economic Area, United Kingdom, or another jurisdiction with applicable data protection law, you may have additional rights regarding your personal information, including:

  • Right of access — you may request a copy of the personal information we hold about you.
  • Right to rectification — you may request correction of inaccurate or incomplete information.
  • Right to erasure — you may request deletion of your personal information where we have no legitimate reason to continue processing it.
  • Right to restriction — you may request that we limit how we use your data in certain circumstances.
  • Right to data portability — you may request a machine-readable copy of personal information you have provided to us.
  • Right to object — you may object to processing based on legitimate interests or for direct marketing purposes.
  • Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

Legal Basis for Processing (EEA and UK Users)

Where the GDPR or UK GDPR applies, we process personal information on the following legal bases: performance of a contract (to provide the service you have signed up for), legitimate interests (to operate and improve the platform, prevent fraud, and ensure security), compliance with legal obligations, and consent where explicitly requested.

To exercise any of your rights or to raise a data protection concern, contact us at hello@postlore.com. We will respond within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority.

International Use

Postlore may serve users in multiple countries. By using the platform, you understand that your information may be processed in jurisdictions where we or our service providers operate, subject to appropriate protections and contractual safeguards where required.

Policy Updates

We may update this Privacy Policy from time to time to reflect changes in the product, legal requirements, or operational practices. When changes are material, we will update the effective date and take reasonable steps to provide notice through the website, the app, or email where appropriate.

Questions

Need clarification from the Postlore team?

If you have questions about these terms, privacy practices, or platform usage, contact us at hello@postlore.com and we will respond as promptly as we can.

Contact legal support