Privacy Policy

Last updated: 30 September 2026

This policy explains how Postmind AI Ltd collects and uses personal data when you use PostMind Studio (the Service) or visit our website, and the rights you have. Words with capitals, such as Customer, Organisation, Authorised User and Customer Content, have the meaning given in our Terms of Service.

1. Who we are

1.1 The controller of the personal data described in this policy is Postmind AI Ltd, a company registered in England and Wales under company number 17332378, with its registered office at 61 Bridge Street, Kington, Herefordshire, HR5 3DJ, United Kingdom (we, us, our).

1.2 We are not required to appoint a data protection officer and have not done so. Our privacy lead, a director of Postmind AI Ltd, is responsible for data protection. For anything about this policy or your personal data, email support@postmindai.pro or write to us at the address above.

2. When we are a controller and when we are a processor

2.1 We are the controller of personal data about the people who sign up for, use, pay for or contact us about the Service, and about visitors to our website. This policy covers that data.

2.2 Our Customers use the Service to create marketing content, and that content may include personal data about other people, for example staff who appear in videos, a person whose voice is cloned, a customer quoted in a testimonial, or people named on the Customer's website. For that Customer Content, the Customer is the controller and we are its processor: we process it only on the Customer's instructions under our Data Processing Agreement. If your personal data is in a Customer's content, please contact that Customer first; we will help them respond to you.

3. The personal data we collect

3.1 Account data: your name, email address, password (stored only as a secure hash), language preference, role in your Organisation, and whether you use two-step verification. If you choose "Continue with Google", we receive your name, email address, profile picture and Google account identifier from Google. Two-step verification secrets and backup codes are stored encrypted.

3.2 Organisation and business data: your Organisation's name and settings, the businesses you add (name, website, sector, locations, brand kit, logo and style choices), and invitations you send (the invitee's email address).

3.3 Billing data: your billing name, address, email, VAT or tax number, the Plan you chose, and your payment and invoice history. Card payments are handled by Stripe; we never receive or store your full card number. We receive from Stripe references to your customer record, subscription and payment method, the status of your payments, and a card fingerprint (a code that identifies a card without revealing its number, which we use to stop repeat free trials). Stripe's own customer portal shows and manages your card details.

3.4 Content you provide: briefs, prompts, uploaded images, video and audio, voice samples and consent recordings for voice cloning, captions, comments, approvals, and the content of your website if you ask the Service to scan it. As explained in section 2.2, we mostly process this as a processor for the Customer. For voice cloning we also keep the speaker's name, the consent statement they read and their consent recording as a record of consent.

3.5 Connected Platform data: when you connect TikTok, Instagram, Facebook, YouTube, X or LinkedIn, we receive access tokens (stored encrypted), your account or page identifier and name, and, after publishing, aggregated performance figures for the posts we published for you (such as numbers of views, likes, comments and shares). We do not read your private messages.

3.6 Outside reviewers: if a Customer shares a preview link with you, we collect the name and (optional) email address you enter and the feedback you leave.

3.7 Usage, device and security data: the IP address and browser details linked to your sign-in sessions; sign-in and security events; the actions you take in the Service (recorded in an audit log that identifies you by internal ID); rate-limit counters; and technical logs and error reports needed to keep the Service running and secure.

3.8 Communications: emails and support requests you send us, and delivery information for the emails we send you (for example whether an email was delivered or bounced).

3.9 Cookies: we use a small number of strictly necessary cookies and similar storage. We do not use advertising or analytics cookies. See our Cookie Policy.

4. How we use personal data and our lawful bases

| Purpose | Personal data | Lawful basis (UK GDPR Article 6) | | ---------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------- | | Creating and running your account and Organisation, signing you in, providing the Service and its features | Account, organisation, content, Connected Platform, usage data | Performance of our contract with the Customer; our legitimate interests in providing the Service to the Customer's Authorised Users | | Publishing to Connected Platforms and showing you performance analytics | Connected Platform data, content | Performance of contract | | Taking payment, preventing repeat free trials, invoicing and keeping accounting records | Billing data | Performance of contract; legal obligation (tax and company law); legitimate interests in preventing trial abuse | | Sending service emails (sign-in links, verification, security alerts, billing, generation and publishing notifications) | Account data, communications | Performance of contract; legitimate interests in keeping you informed about your account | | Security: preventing fraud and abuse, rate limiting, two-step verification, detecting and investigating incidents, audit logging | Usage, device and security data | Legitimate interests in keeping the Service and our Customers secure; legal obligation (security of processing) | | Content safety: automated checks of content for material that breaches our Acceptable Use Policy, human review of flagged content | Content | Legitimate interests in preventing illegal and harmful content; legal obligation where the law requires us to act | | Customer support and answering your questions | Account data, communications, content you share with support | Performance of contract; legitimate interests | | Improving and maintaining the Service, using aggregated or de-identified information | Usage data | Legitimate interests in improving the Service | | Complying with the law, responding to lawful requests, and establishing or defending legal claims | Any relevant data | Legal obligation; legitimate interests |

4.1 Where we rely on legitimate interests, we have balanced them against your rights. You can ask us for details and you have the right to object (section 9).

4.2 A voice clone and its consent recording can involve biometric data. The Customer is the controller for that processing and must obtain the speaker's explicit consent; the Service requires a consent recording, checks automatically that it contains the consent statement and the speaker's name, and does not let a voice be used until that check passes.

4.3 We do not sell personal data and we do not use it for advertising. We do not send marketing emails; notification emails about your projects can be turned off, kind by kind, with the one-click unsubscribe link in each one. Emails needed to run your account (sign-in, security and billing) cannot be turned off while you have an account. If we start sending marketing emails, we will give you a way to opt out and, where the law requires it, ask for your consent first.

5. AI processing and automated decisions

5.1 The Service sends your prompts, briefs and other Inputs to AI providers to generate scripts, images, video, voice-overs and music, to transcribe audio and to check content safety. We use these providers under business or API terms, which we select so that, as far as those terms allow, they do not use your content to train their models. We do not use Customer Content to train AI models ourselves.

5.2 We do not make decisions about individuals based solely on automated processing that have legal or similarly significant effects. Automated content-safety checks can hold a video for human review; a person at the Customer or at our company decides what happens next. Generating content with AI is not a decision about you.

6. Who we share personal data with

6.1 Service providers (sub-processors) who host, store, email, process payments or generate and check content for us, under contracts that require them to protect it. The current list, with what each receives and where, is on our Sub-processors page.

6.2 Connected Platforms such as TikTok, Meta (Instagram and Facebook), Google (YouTube and "Continue with Google"), X and LinkedIn, when you connect them and ask us to publish or read analytics. They act as independent controllers under their own privacy policies.

6.3 Other people in your Organisation: your name, email and activity are visible to other Authorised Users in the same Organisation, and your Organisation's owners and administrators can manage your membership.

6.4 Outside reviewers see only the preview a Customer chose to share and the feedback left on it.

6.5 Professional advisers, authorities and others: our lawyers, accountants and insurers; the police, courts, regulators or other authorities when the law requires or allows (for example, we report child sexual abuse material); and a buyer or successor if all or part of our business is sold, under the same protections.

7. Where your data is processed and international transfers

7.1 We host the Service and its database on servers in Helsinki, Finland (Hetzner), in the European Union. Uploaded and generated files, and encrypted backups of the database, are stored in Cloudflare R2 object storage, which runs on Cloudflare's global infrastructure: Cloudflare chooses where the data is kept, and this may be outside the UK and EEA. The encryption key that protects stored access tokens is held in AWS Key Management Service in the region we choose (London, UK, by default). Our transactional email is sent from Resend's EU (Ireland) region. The UK recognises the EU and EEA as providing adequate protection.

7.2 Some providers process data in other countries, mainly the United States (for example our AI providers, Stripe, the Connected Platforms and, for stored files, Cloudflare) and Australia (our video rendering provider). When we transfer personal data outside the UK or EEA to a country without an adequacy decision, we rely on:

  • the UK Extension to the EU–US Data Privacy Framework (the "UK–US data bridge") or the EU–US Data Privacy Framework, where the recipient is certified; or
  • the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum, or the UK International Data Transfer Agreement, included in the provider's data processing terms;

together with the additional safeguards we consider necessary. The Sub-processors page shows the location of each provider. You can ask us for more information about these safeguards at support@postmindai.pro.

8. How long we keep personal data

| Data | How long | | -------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Your account | While you have an account. If you delete it, you are signed out and cannot sign in at once, and your account data is deleted after 30 days. | | Organisation data and Customer Content | While the Organisation has a subscription. After a paid subscription ends, the Organisation stays read-only for 90 days so you can export your work, then it is scheduled for deletion and permanently deleted 30 days later. If the Organisation is deleted by its owner, deletion follows 30 days later. | | Organisations that never started a paid plan | Until the account holder deletes the account or Organisation. | | Backups | Encrypted database and file backups expire within 30 days, so deleted data leaves our backups within 30 days of leaving our live systems. | | Access tokens for Connected Platforms | Until you disconnect the platform, the platform tells us you removed our access, or the Organisation is scheduled for deletion; then they are wiped at once. | | Voice-clone consent records | For as long as the Organisation exists, including after the voice itself is deleted, as evidence of consent. The voice samples are sent to our voice provider and are not stored by us. | | Images gathered by scanning a website | With the business they belong to. If the site owner tells us the Customer did not own the site, the scanned images are deleted within 24 hours. | | Performance analytics | Hourly figures for 30 days; daily figures for 2 years. | | Audit log | 2 years. Entries identify people only by internal ID and are kept after an account or Organisation is deleted. | | Records of emails we sent | 90 days. Addresses that bounce or complain are kept on a suppression list so we do not email them again. | | Data export files | Download links expire after 7 days. | | Sign-in sessions | A session ends after 14 days without use and never lasts more than 30 days. | | Billing and tax records | As long as tax and company law requires, normally six years after the end of the financial year they relate to. | | Records of legal and takedown requests | As long as needed for our legal obligations and transparency reporting; personal details in them are removed when the Organisation concerned is deleted. | | Support emails | Up to 2 years after the conversation ends, unless we need them longer for a legal claim. | | Server logs | Overwritten automatically once they reach a fixed size, normally within a few weeks. |

9. Your rights

9.1 Under data protection law you have the right to:

  • access your personal data and receive a copy;
  • have inaccurate data corrected;
  • have your data erased in certain circumstances;
  • restrict how we use it in certain circumstances;
  • data portability: receive data you gave us in a structured, machine-readable format, or have it sent to another organisation;
  • object to processing based on legitimate interests; and
  • withdraw consent at any time where we rely on consent, without affecting earlier processing.

9.2 Much of this you can do yourself in the Service: change your details and language in your account settings, see and end your active sessions, export your Organisation's data, and delete your account. For anything else, email support@postmindai.pro. We will reply within one month, which we may extend by up to two further months for complex requests. We may need to confirm your identity first.

9.3 If a Meta (Facebook or Instagram) user removes our app or asks for their data to be deleted through Meta, we revoke the connections and wipe the related tokens and data at once.

10. Complaints

If you are unhappy with how we have used your personal data, please contact us first at support@postmindai.pro so we can try to put it right. You also have the right to complain to the Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, https://ico.org.uk. If you are in the EU, you may complain to the data protection authority where you live or work.

11. Security

We protect personal data with measures that include: encryption in transit (HTTPS) and at rest; envelope encryption of Connected Platform tokens, voice profile identifiers and customer-supplied provider keys using a key held in AWS Key Management Service; hashed passwords and optional two-step verification for all users, required for our staff; role-based access within Organisations; an audit log of significant actions; rate limits; checks against known breached passwords (we send only a partial hash, never your password); and encrypted backups. No system is completely secure, and if a breach is likely to put your rights at risk we will tell you and the ICO as the law requires.

12. Children

The Service is for businesses and is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact support@postmindai.pro and we will delete it.

13. Changes to this policy

We may update this policy from time to time. We will publish the new version here with a new "last updated" date and, if the changes are significant, tell account holders by email or in the Service before they take effect.

14. Contact

Postmind AI Ltd, 61 Bridge Street, Kington, Herefordshire, HR5 3DJ, United Kingdom. Privacy lead: a director of Postmind AI Ltd. Email: support@postmindai.pro.