PostroAI
Privacy

Privacy Policy

Here is everything we do with your data, without hedging: what we collect, why we collect it, who we share it with, and how long we keep it.

Last updated: 18 de agosto de 2026

01The short version, in three sentences

If you only read this part

We collect the minimum the product needs to work: your account details, your brand data, and the files you upload so posts can be generated. We do not sell any data to anyone, and we do not use your material to advertise anything without your permission. You can ask for access, correction or deletion of your data at any time, straight through our contact email.

This policy follows Brazil’s General Personal Data Protection Law (Law 13.709/2018, the LGPD) and the Brazilian Internet Civil Framework (Law 12.965/2014).

02Who is responsible for your data

The controller of the personal data processed at PostroAI is [PREENCHER: razão social], company registration (CNPJ) [PREENCHER: CNPJ], with registered office at [PREENCHER: endereço completo]. That company decides how and why your data is processed, and it is the one you talk to in order to exercise any right.

03What we collect, and what for

We split this by origin, because each group of data has a different purpose and a different destination.

Account and sign-up data

  • Name, email and password. To create and identify your account, allow sign-in, and talk to you about the service. The password is stored in hashed form and is not readable by us.
  • Payment data. Payment happens on a page hosted by a specialist payment provider, and that is where you enter whatever is needed to pay. All that leaves this platform is the plan you chose. What comes back is the transaction record the provider sends us: amount, payment method, status, dates and, for card payments, the card brand and the last digits, so you can recognise the charge and so we can handle refunds. The full card number, expiry date and security code never pass through our servers and are not stored by us.
  • Tax identifier, when the payment provider asks for it. PostroAI has no field for a CPF, a CNPJ, a phone number or an address: none of that is requested by this platform and none of it is kept in your account. If the provider collects any of it on its own payment page, the confirmation notice it sends us may carry it along, and that notice is stored exactly as received, unaltered, because it is the record of the transaction. It is not copied into your account and is not used for anything else.

Your brand and business data

  • Business name, sector, target audience, tone of voice, colours, description of products and services. This is what allows the AI to generate a post that looks like yours rather than a generic one.
  • Logo and visual identity files. To apply your brand to the material that is generated.
  • Photos and images you upload. To serve as reference or as the basis of the generated artwork. If those photos contain identifiable people, they are third-party personal data, and you are the one responsible for holding permission to use their image.
  • Past captions, when you upload them. So the platform can learn your way of writing, on the plans that offer that feature.

Data generated by use

  • Generated posts: images, captions, hashtags and calendars. They stay saved in your account so you can reuse them, download them again, and so the anti-repetition mechanism knows what has already been created.
  • Usage counters. How many creations you made in the cycle, to enforce your plan’s quota.
  • Access logs. IP address, date and time of requests, and basic browser information, kept for security, fraud prevention and compliance with Article 15 of the Brazilian Internet Civil Framework.
  • Technical error records. When something fails, we record what happened so it can be fixed.

Contact data before sign-up

If you write to us before having an account, through the contact page or by email, we collect your email address and whatever you write, purely to answer what you asked. If you ask to receive product news, every email of that kind carries an unsubscribe link.

What we do not do

We do not sell, rent or hand over your data to third parties for commercial purposes. We do not build an advertising profile of you. We do not use your material as an example, a portfolio piece or promotional material for PostroAI without your express and specific permission.

04Why we are allowed to process it

The LGPD requires every processing activity to have a legal basis. Ours are these, named as the Brazilian statute names them:

  • Performance of the contract (art. 7, V): account, brand, uploaded files, post generation, quotas and billing. Without that data the service simply does not work.
  • Compliance with a legal obligation (art. 7, II): the transaction record received from the payment provider, and retention of access logs.
  • Legitimate interest (art. 7, IX): security, fraud and abuse prevention, and improving the product from aggregated data that identifies nobody.
  • Consent (art. 7, I): marketing communications and use of your material as a public example. Consent can be withdrawn whenever you like.

05Who we share it with

For the product to work, some data has to pass through companies that work for us. Under the LGPD they are called processors. They may only use the data to carry out the task we hired them for, under contract and a duty of confidentiality. Described here by category:

  • Artificial intelligence providers. They receive the generation instructions, your brand data and the files needed to produce the image and the text. There is no other possible route: without sending the instruction, there is no generated post. These providers are contracted on business terms, with a contractual commitment not to use your content to train models.
  • Cloud infrastructure and file storage providers. They host the application, the database and your account’s images.
  • Payment provider. Hosts the page where you pay, processes the charge by Pix and by card, and tells us when the payment is confirmed, cancelled or refunded.
  • The provider of our contact mailbox. It is how we read and answer whatever you write to our contact address. The platform sends no automated email today: every notice about your account appears inside the product itself.
  • Public authorities. Only upon a court order or a valid legal request, and strictly within what is required.

If the company ever goes through a merger, acquisition or corporate reorganisation, data may be transferred to the successor, which is bound to respect this same policy. You will be told beforehand.

06International transfers

Part of the infrastructure and of the artificial intelligence providers sits outside Brazil, which means some data is processed abroad. When that happens, we require contractual protection guarantees from suppliers equivalent to those of the LGPD, under Article 33 of that law.

07How long we keep it

  • Account and brand data: for as long as your account exists. After closure, we delete or anonymise it within 30 days.
  • Uploaded files and generated posts: for as long as your account exists, and for up to 30 days after closure. That window exists in case you change your mind and want the account back. After that, the content is deleted for good. Download whatever you want to keep before closing.
  • Tax and billing data: 5 years after the last transaction, as required by Brazilian tax law and by the Brazilian Consumer Protection Code.
  • Access logs: 6 months, under Article 15 of the Brazilian Internet Civil Framework, extendable by court order.
  • Email address of someone who wrote to us without an account: until you ask for it to be deleted.

We may keep data for longer where there is ongoing judicial or administrative proceedings requiring its preservation, and only for as long as that need lasts.

08Cookies and sessions

PostroAI uses a single cookie, the session one, which keeps you signed in. We use no audience analytics tools and no third-party trackers: there is no social network pixel and no advertising cookie on the site.

Every detail, including its name, lifetime and how to disable it, is in the Cookie Policy.

09Security

We take technical and administrative measures to protect your data: encrypted traffic between your browser and the platform, passwords stored with a hashing algorithm, a session cookie that page scripts cannot read, internal access restricted to those who need it, and monitoring of suspicious activity.

No system is completely immune. If a security incident occurs with a relevant risk to your rights, we will notify you and the Brazilian National Data Protection Authority within a reasonable period, telling you what happened, which data was affected and what we are doing, as Article 48 of the LGPD requires.

Found a security flaw? Write to ola@postroai.com. We genuinely appreciate it.

10Your rights

You can request confirmation of processing, access, correction, anonymisation, portability, deletion, information about sharing, and withdrawal of consent. We explain each one, with the steps to ask and the response deadline, on the Data subject rights (LGPD) page.

11Children and teenagers

PostroAI is intended for people over 18 and does not knowingly collect data from children or teenagers. If we identify an account created by a minor without their guardians’ permission, we will delete the data. If you are a guardian and suspect this, tell us at ola@postroai.com.

12Changes to this policy

This policy may be updated when the product changes or when the law requires it. Relevant changes are communicated by a notice inside the platform, on your first visit after the change. The date at the top of the page always indicates the latest version.

13Data Protection Officer and contact

The officer responsible for personal data processing (DPO), provided for in Article 41 of the LGPD, is [PREENCHER: nome do encarregado (DPO)].

For any privacy matter (a question, a request or a complaint), write to ola@postroai.com with “LGPD” as the subject. We answer every request, and the deadlines are explained on the data subject rights page.

If you are not satisfied with our answer, you have the right to complain to the Brazilian National Data Protection Authority (ANPD), at gov.br/anpd.

Still have a question?

Write to us at ola@postroai.com and we will answer plainly. If you prefer, have a look at the frequently asked questions too.

Política de Privacidade · PostroAI