POSTFAB

PostFab Privacy Policy

Last updated: 18 July 2026 · Effective: 18 July 2026


1. Who we are

PostFab is a tool that helps people create social-media content: you give it an idea or a link, and it drafts platform-native posts for you to review and publish. This policy explains what personal data PostFab handles, why, and what rights you have.

The data controller is Tap edTech Private Limited, a company registered in India at Ground, First & Second Floors, Unit No 3, 100 Feet Road, BTM Layout Stage 2, Bengaluru, Karnataka, 560076, India ("PostFab", "we", "us"). For any privacy question or request, contact us at privacy@postfab.ai.

We serve two groups of people, and we hold different data about each:

  • Users — the people (and their agents) who sign up and use PostFab to make and publish content.
  • Creators — public social-media accounts whose public content PostFab analyzes to help Users spot what is working in their niche. Creators do not have PostFab accounts and have not signed up. We explain your rights, and how to have your data removed, in Sections 6 and 8.

2. Data we collect about Users

When you use PostFab, we collect and store:

CategoryExamplesSource
Account dataEmail address, hashed password, organization nameYou, at sign-up
Connected channelsAccess tokens / bot tokens for the social accounts you connect (e.g. a Telegram channel, an X account, a LinkedIn page), the channel name and handleYou, when you connect a channel
Content you createThe ideas, briefs, links and media you submit ("seeds"), the drafts PostFab generates for you, your schedule and calendarYou, as you use the product
Notification settingsYour Telegram chat ID if you opt into Telegram alerts, your email for alertsYou
Technical dataSession tokens, API tokens (pf_ tokens, stored hashed), basic logsAutomatically, as you use the service

We use this data to provide the service: authenticate you, generate and schedule your posts, publish to your connected channels, and alert you when something needs attention. The lawful basis is performance of our contract with you (our Terms of Service) and, for security and service-improvement, our legitimate interests.


3. Data we handle about Creators (public-content analysis)

This is the part of PostFab most people don't expect a privacy policy to cover, so we are explicit about it.

To help a User understand what content performs well in their niche, PostFab analyzes public posts from public social-media accounts. We do not access private accounts, private posts, or anything behind a login or follow-gate.

Where the data comes from:

  • Instagram — public posts and Reels, retrieved through the third-party scraping platform Apify.
  • YouTube — public videos and channel data, retrieved through the official YouTube Data API.

What we analyze and store about a Creator's public content:

CategoryExamples
Identity (as published)Public username / handle, public display name, public channel/profile title, public bio
Public post contentPost captions, video titles and descriptions, and — for Instagram — the spoken transcript of a public video
Public engagement metricsFollower/subscriber count, view/play counts, like counts, comment counts, an "outlier score" (how a post performed relative to that account's own typical numbers)
A copy of the public thumbnail image of a postStored on our servers so it can be shown to the User who is researching that niche
Derived analysisA "dossier": our software's summary of a public account's content patterns — recurring hook styles, content themes, typical posting times, and an AI-generated summary of what makes the content work

We want to be honest that the derived analysis is a form of profiling — it analyzes an account's public content to describe and predict its content strategy. We do this only on public, professional/creator content published to be seen, only to help a User make their own content, and never to make automated decisions that produce legal or similarly significant effects on the Creator.

What we do not do: we do not build dossiers on private individuals or private accounts; we do not sell Creator data; we do not combine one User's research with another's (see Section 4); we do not deliberately target or index on special-category information (health, politics, religion, sexuality, etc.); and we do not use Creator data to train our own or anyone else's AI models.

Lawful basis — legitimate interest (Article 6(1)(f) GDPR). We rely on our legitimate interest, and our Users' legitimate interest, in understanding publicly published content trends in a niche. We have carried out a written Legitimate Interest Assessment weighing this against Creators' rights. In summary: the data is public and professional in nature; we minimize what we keep and how long we keep it; each User's research is strictly isolated; and any Creator can object and have their data removed easily and for free (Section 6). The fact that content was public does not by itself make our use lawful — the legitimate-interest balancing and the removal mechanism are what make it fair, and we treat both as binding.

A short note for Creators: if your public content has been analyzed and you would rather it wasn't, you can have it removed and blocked from future analysis in one step — see Section 6. We honour these requests regardless of where you are located.

4. How Creator data is kept separated

Every piece of Creator data we store belongs to exactly one User's organization. If two different Users both research the same public account, we store two separate, isolated copies — we never pool Creator data into a shared profile across our customer base, and one User can never see another User's research. This isolation is a deliberate design choice and is described in our internal Record of Processing Activities.


5. Who we share data with (sub-processors and recipients)

We do not sell personal data. We share data only with the service providers needed to run PostFab, each bound by a data-processing agreement (or, where noted, by their standard terms):

ProviderRoleWhat they receiveLocation
ApifyScraping infrastructure for public Instagram contentOur search queries; returns public post dataEU/US (DPA + SCCs)
Anthropic (Claude API)AI analysis and content generationPublic Creator captions/transcripts for analysis; your seeds and drafts for generation. Anthropic does not train on API dataUS (DPA + SCCs)
[fal.ai]AI image/video generation engineYour seeds, prompts and any media you submit for generationUS (DPA to be confirmed)
Hetzner (planned)Server and database hostingAll stored data at restEU (Germany)
TelegramDelivery of the posts you publish and of alerts you opt intoFor publishing: the content you approve. For niche alerts you opt into: Creator public handles and post URLsCloud (standard bot terms; no DPA — see below)
[Email/SMTP provider]Sending you loud-failure and account emailsYour email address and alert content[TBD]

Telegram has no formal data-processing agreement. We limit what flows to Telegram to the minimum: for publishing, only the content you have chosen to publish; for optional niche alerts, only public handles and public post URLs. Telegram delivery of Creator identifiers happens only for alerts a User has actively switched on. Telegram's standard bot privacy policy applies: https://telegram.org/privacy-tpa

International transfers. Our company is in India; some providers are outside India and the EU. Where we transfer personal data internationally, we rely on the providers' Standard Contractual Clauses and data-processing agreements. When our EU hosting (Hetzner) is live, stored data — including Creator data and thumbnails — will reside in the EU.


6. Your rights and how to exercise them

You have rights over your personal data. How you exercise them depends on which group you are in.

If you are a Creator (your public content was analyzed and you have no PostFab account):

  • You can ask us to erase the data we hold about your public content and to block your account from any future analysis. We provide a public request page for this — no login needed: [https://postfab.app/data-removal] (the "Remove my data" page).
  • Submitting your handle or a link to your account there will: delete the stored analysis, posts, and thumbnails we hold about you across every customer that had collected them, and add you to a permanent suppression list so PostFab does not analyze your content again.
  • You can also object to our processing at any time via the same page or by emailing privacy@postfab.ai. We honour objections from Creators as a matter of course.

If you are a User (you have a PostFab account):

  • You can access, correct, export, or delete your account data. Deleting your account or organization removes your account data and cascades to the content and connected-channel data associated with it.
  • Contact privacy@postfab.ai or use the in-product account controls.

For everyone: these requests are free, and we aim to respond within one month (GDPR Article 12). You also have the right to lodge a complaint with a supervisory authority (in the EU, your local data-protection authority).


7. How long we keep data

  • Creator data is deleted when the User who collected it stops tracking that account, when the Creator requests removal, and when the User deletes their organization. We do not keep Creator data indefinitely, and we retain only what is needed to show the User useful, current niche research.
  • User account and content data is kept for as long as your account is active, and deleted when you close your account or organization.
  • Backups, where present, are cycled on a rolling basis and purged on their normal schedule after a deletion.
These retention behaviours are enforced by the removal and erasure mechanisms delivered for launch (see docs/compliance/ M2/M4). This policy states the operating practice as of the effective date above.

8. A note under India's DPDP Act

Our company is Indian, so the Digital Personal Data Protection Act, 2023 also applies to how we handle User personal data, and we handle it accordingly (notice, purpose limitation, and your rights as a Data Principal). The Act generally does not cover personal data a person has made publicly available — which is the nature of the Creator content we analyze — but we still offer Creators the removal and objection mechanism described in Section 6.


9. Security

We protect data with access controls, hashed credentials, and encrypted transport. Server-side data is hosted with a provider offering EU data-residency and audited technical/organizational measures. Where a security limitation is known and being closed, we treat it as a priority.


10. Children

PostFab is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18.

11. Changes to this policy

We may update this policy as PostFab evolves. Material changes will be reflected in the "Last updated" date, and we will notify Users of significant changes.

12. Contact

Questions, requests, or complaints: privacy@postfab.ai · Tap edTech Private Limited, Ground, First & Second Floors, Unit No 3, 100 Feet Road, BTM Layout Stage 2, Bengaluru, Karnataka, 560076, India, India.