Privacy Policy
Last updated September 9, 2026 · posterboysocial.com
Your business information is yours. This policy explains what Posterboy collects, why we use it, how connected social accounts and AI features work, and how you can access or delete your data.
We do not sell personal information.
posterboy Social (“posterboy,” “we,” “us”) helps small businesses create and publish social content. This policy explains what we collect, why we collect it, and how you can control your data.
1. Who this applies to
This policy covers visitors to posterboysocial.com, customers who create an account, and business owners who connect Facebook Pages or Instagram Business accounts through our product.
2. Information we collect
Account information: name, email address, workspace name, and password (stored as a salted hash — we never store plaintext passwords).
Brand & content data: onboarding answers, brand books, captions, templates, photos you upload, Studio creatives, and scheduled posts you create in the dashboard.
Connected social accounts: when you authorize Meta (Facebook/Instagram), we receive Page and Instagram Business account identifiers, display names, and access tokens required to publish on your behalf. We do not receive your personal Facebook password.
Billing information: when you subscribe, Stripe processes payment details. Posterboy stores Stripe customer and subscription identifiers and plan status — not raw card numbers.
Usage & technical data: IP address, browser type, session cookies, and basic request logs used for security, rate limiting, and debugging.
3. How we use your information
We use your data to:
- Authenticate you and keep your workspace secure
- Generate draft social content (including AI-assisted captions and images) using business context you provide or that we infer from sources you connect or approve
- Publish or schedule posts to Facebook and Instagram when you ask us to
- Store media you upload (e.g., to cloud storage) so Meta can fetch public URLs
- Process subscriptions and entitlements when billing is enabled
- Improve reliability and respond to support requests
We do not sell your personal information.
4. AI providers
To generate captions, images, and related Studio features, Posterboy may send prompts, brand context, and reference images you provide to third-party AI providers such as OpenAI, Google (Gemini / Veo), and Anthropic. Those providers process the content to return generated results. Do not include information in prompts that you are not comfortable sharing with those processors.
5. Service providers
We use infrastructure and product vendors to operate Posterboy, including hosting (Vercel), database (Neon), object storage / CDN (AWS S3 and CloudFront when configured), Redis/KV for authentication hashes and rate limiting, payments (Stripe), social publishing (Meta), error monitoring (Sentry), and the AI providers above. They process data only to provide their services to us.
6. Meta / Facebook / Instagram
posterboy uses the Meta Graph API only after you explicitly connect your accounts in Settings. Scopes we request include publishing and reading engagement data needed to operate posting features (e.g., pages_manage_posts, instagram_content_publish).
We store Page and Instagram Business tokens encrypted on our servers, scoped to your workspace and location. You can disconnect at any time in Settings, which removes those stored credentials for that location from our database.
Meta's own policies also apply to data processed on their platform. See Meta's Privacy Policy.
7. Cookies & local storage
Session cookie: we set an HTTP-only session cookie when you sign in so you stay authenticated.
OAuth state cookies: short-lived cookies used during Meta connect to prevent CSRF attacks.
Browser local storage: we cache business context, onboarding answers, and your active location selection locally so the dashboard loads quickly. You can clear this by signing out or removing site data in your browser.
We do not use third-party advertising cookies.
8. Data retention & deletion
We retain workspace data while your account is active. You may delete your account in Settings → Account → Danger zone, which removes your organization data from our database and clears your login credentials. When object storage is configured, we also attempt to delete media under your workspace storage prefix at that time. See Data deletion instructions for details.
Database backups and logs may persist for a limited period for security and legal compliance before automatic purging. Stripe may retain payment records under its policies.
9. Security
We use HTTPS, tenant-scoped database access (row-level security), rate limiting on sensitive APIs, encrypted social tokens, and hashed passwords. No system is perfectly secure — report concerns to hello@posterboysocial.com.
10. Your rights & contact
Depending on your location, you may have rights to access, correct, or delete personal data. Email hello@posterboysocial.com and we will respond within a reasonable time.
This policy may change as the product evolves. Material updates will be reflected on this page with a new “Last updated” date.
Questions: hello@posterboysocial.com · Back to home
