Back to Home

Privacy Policy

Effective Date: 25 March 2026

This policy is available in English (primary) and Turkish. In case of discrepancy, the English version prevails.

1. Introduction

Postivo (“we”, “us”, “our”) operates the Postivo application and website (“Platform”), an AI Creative Intelligence tool that helps creators analyze social media content before posting. This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and what rights you have — wherever in the world you are located. By using Postivo, you agree to the practices described in this policy.

2. Data Controller

Postivo is the data controller for personal data processed through the Platform.

Postivo

Email: privacy@postivo.app

Website: postivo.app

3. Data We Collect

3.1 Account & Identity Data

  • Email address (required for registration and login)
  • Password (stored in encrypted/hashed form — we never store plain-text passwords)
  • Name (optional profile information)

3.2 Content Data

  • Images, videos, and caption text you upload for analysis
  • Analysis results and Postivo Score outputs
  • Target audience information you enter manually

Content you upload is processed solely to generate your analysis results. We do not use your individual content to train our models without your explicit consent.

3.3 Anonymous Usage Data

After each analysis, anonymised and de-identified usage data is collected to improve Postivo's AI model. This data cannot be linked back to your identity. You may opt out in account settings.

3.4 Payment Data (Stripe)

All payment transactions are processed securely by Stripe, Inc. We never see, store, or handle your full card number, CVV, or sensitive payment credentials. We only receive:

  • Transaction ID and payment status
  • Billing email address
  • Subscription plan and payment history

Stripe is PCI-DSS Level 1 certified.

3.5 Technical & Log Data

  • IP address and approximate location (country/city level)
  • Browser type and version, operating system
  • Pages visited, features used, click behaviour
  • Error and crash reports

3.6 Cookies & Tracking Technologies

We use cookies for:

  • Essential cookies — login session management
  • Preference cookies — language and display settings
  • Analytics cookies — aggregate anonymised usage

You can manage cookies through your browser settings.

4. How We Use Your Data

4.1 Performance of Contract

  • Providing analysis results
  • Managing account and authentication
  • Processing payments

4.2 Legitimate Interests

  • Improving and securing the Platform
  • Preventing abuse and fraud
  • Service-related notifications

4.3 Consent

  • Anonymous data collection for AI improvement (opt-out available)
  • Marketing communications (opt-in only)

4.4 Legal Obligation

  • Complying with applicable laws
  • Tax regulations
  • Lawful governmental requests

5. Third-Party Data Sharing

We do not sell, rent, or share personal data for marketing purposes. Data is shared only with the following categories of recipients:

  • Stripe, Inc. — payment processing
  • AI infrastructure providers (e.g. Anthropic, Google) — generating analysis results; contractually prohibited from training their models with your data
  • Cloud hosting and storage providers — secure infrastructure for Platform operation
  • Analytics tools — aggregate, anonymised data only
  • Law enforcement — only when required by applicable law or valid legal process

6. International Data Transfers

Data may be transferred and processed outside your country of residence. Where data is transferred from the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure an adequate level of data protection.

7. Your Rights by Region

7.1 European Union & UK (GDPR / UK GDPR)

  • Right of access
  • Right to rectification
  • Right to erasure ("right to be forgotten")
  • Right to restriction of processing
  • Right to data portability
  • Right to object to processing
  • Right to withdraw consent at any time

You also have the right to lodge a complaint with your local data protection authority (e.g. the ICO in the United Kingdom). To exercise your rights, contact privacy@postivo.app.

7.2 California, USA (CCPA / CPRA)

  • Right to know what personal information is collected and how it is used
  • Right to delete personal information
  • Right to opt-out of sale of personal information (we do not sell your data)
  • Right to non-discrimination for exercising your privacy rights

Contact privacy@postivo.app to submit a request. We will respond within 45 days.

7.3 Türkiye (KVKK)

Türkiye'de yerleşik kullanıcıların 6698 sayılı Kişisel Verilerin Korunması Kanunu (KVKK) kapsamında aşağıdaki haklara sahiptir:

  • Kişisel verilerinin işlenip işlenmediğini öğrenme hakkı
  • İşlenme amacına uygun olup olmadığını öğrenme hakkı
  • Eksik veya yanlış verilerin düzeltilmesini isteme hakkı
  • Verilerin silinmesini veya yok edilmesini talep etme hakkı
  • Düzeltme ve silme işlemlerinin üçüncü taraflara bildirilmesini talep etme hakkı
  • İşlemden doğan zararın tazminini talep etme hakkı

Bu haklarınızı kullanmak için privacy@postivo.app adresine e-posta gönderebilirsiniz.

7.4 All Other Regions

Wherever you are located, you may contact us to access, correct, or delete your personal data. We will respond within 30 days.

8. Free Demo Model

Postivo offers 3 free analyses to new users. The following data practices apply to free users:

  • An email address is collected to create your account
  • Anonymised usage data is collected after each analysis
  • You may opt out of anonymous data collection in account settings without losing access to your free analyses

9. Data Security

  • All data in transit is encrypted using SSL/TLS
  • Passwords are stored using bcrypt hashing — plain-text passwords are never stored
  • Payment data is handled exclusively by Stripe (PCI-DSS Level 1 certified)
  • Server access is monitored and regularly audited

In the event of a data breach, we will notify affected users and relevant supervisory authorities within the timeframes required by applicable law (72 hours under GDPR).

10. Data Retention

  • Account data:Retained while your account is active; deleted within 30 days of a verified deletion request
  • Analysis results:Retained while your account is active
  • Payment records:Retained for 10 years in accordance with financial and tax regulations
  • Anonymous AI training data:Retained indefinitely (no personal identifiers)
  • Log data:Retained for 90 days

11. Children's Privacy

Postivo is not directed at individuals under the age of 16. We do not knowingly collect personal data from children under 16.

If you believe that a child under 16 has provided personal data to Postivo without parental consent, please contact us at privacy@postivo.app and we will take prompt steps to delete that data.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Where changes are material, we will notify you by email at least 14 days before the changes take effect.

The current version of this policy is always available at postivo.app/privacy.

13. Contact

For any privacy-related questions, requests, or complaints, please contact us:

Last updated: 25 March 2026 · © 2026 Postivo. All rights reserved.