On this page
- We don't sell your data or show you ads.
- No analytics or ad trackers. The only cookies keep you signed in.
- Your API keys and WordPress password are encrypted before we store them.
- What you submit goes to the AI provider you choose, using your key.
01What we collect
- Account details. Your email address and, if you add it, your name. If you sign in with Google, we get your name, email, and profile picture from Google. Passwords are stored hashed by our sign-in provider, so we never see them. If you add a passkey, we keep its public key and the name you gave it.
- Connections. Your WordPress site address, username, and application password, and any API keys you add for Google, OpenAI, or Anthropic. The password and keys are encrypted before we store them.
- Preferences. The model, language, tone, publishing status, post type, and categories you choose, plus any templates you write.
- What you submit. The links you paste, like YouTube videos, Instagram posts, and web pages, and any text you paste in directly.
- What we generate. The posts we write for you, their titles and SEO details, and a history of each job, including its status, any errors, and a link to the published post.
- Technical data. Our hosting and database providers keep standard logs, such as IP address, browser type, and request times. We use them to keep PostFusion secure and to fix problems.
02How we use it
We use your data to:
- Run PostFusion: read your sources, write posts with the model you picked, and publish them to your site
- Keep your account secure and prevent abuse
- Answer you when you contact support, and figure out why a job failed
- Tell you about important changes to the service or to this policy
We don't sell your data, we don't use it for ads, and we don't train AI models on it.
03Your content and AI providers
When you create a post, we send the text from your source, your template, and your settings to the AI provider you picked, using your API key. The provider handles it under its own terms and privacy policy, as part of your account with them.
Providers treat that data differently. Paid API plans generally don't train on it, but some free tiers do, including Google's free Gemini API tier. If that matters to you, check your provider's terms.
06How we protect it
Your WordPress application password and API keys are encrypted with AES-256-GCM before they're stored, and only decrypted on our servers when a job needs them. Everything travels over HTTPS, and access to production data is limited.
No system is perfectly secure. If a breach affects your data, we'll tell you without undue delay. Because PostFusion uses a WordPress application password rather than your real login, you can revoke it from WordPress at any time.
07How long we keep it
We keep your data while your account is open. You can delete posts from your history whenever you want. If you ask us to delete your account, we'll erase your data within 30 days, except anything the law requires us to keep. Backups roll over on their normal schedule.
Deleting your account doesn't remove posts from your WordPress site, or anything your AI provider keeps under its own policy.
08Your choices and rights
You can edit your name in your profile, change your connections and preferences in Settings, and delete jobs from your history. For anything else, email support@postfusion.com and ask us to:
- Send you a copy of the personal data we hold about you
- Correct anything that's wrong
- Delete your account and its data
- Export your data in a common format
Depending on where you live, including the EU, the UK, and California, laws like the GDPR and CCPA may give you more rights, such as objecting to some kinds of processing or complaining to your local data protection authority. We'll reply to requests within 30 days.
We process your data because we need it to provide the service you signed up for, for legitimate interests like security, and where the law requires it.
09Where your data is processed
PostFusion and the services it uses may process data in the United States and other countries. When data leaves your country, we rely on the safeguards our providers offer, such as standard contractual clauses where they apply.
10Children
PostFusion isn't meant for anyone under 18, and we don't knowingly collect data from children. If you think a child has given us personal data, let us know and we'll delete it.
11Changes to this policy
If we change how we handle your data, we'll update this page and the date at the top. For significant changes, we'll let you know by email or in the app before they apply. This policy works alongside our Terms of Service.
12Contact
PostFusion Inc. is responsible for your data. For questions or requests about your privacy, email support@postfusion.com.
