PostCraft
Features How it works Pricing FAQ
Get the app

Legal

Privacy Policy

Last updated: 13 May 2026 · Questions? privacy@postcrafts.site

The short version

  • We collect what we need to run the app — your email, the photos you upload, the flyers we generate, and basic usage analytics.
  • We never sell your data and we don’t train third-party AI models on it.
  • You can export, delete, or stop using PostCraft any time from Account → Delete Account.

1. What we collect

Account & identity

  • Email address (the one you sign in with).
  • Full name and business name, if you set them in your profile.
  • Phone number, country, and bio, if you choose to add them.
  • An optional avatar image.

Content you create

  • Product photos you upload (stored encrypted in our object storage).
  • Flyers and captions we generate from those photos.
  • Edits you make to a saved design (price, CTA, promo, caption variant).

Technical data

  • Device platform (iOS / Android), app version, basic crash diagnostics.
  • IP address at the moment of sign-in (for fraud + brute-force protection).
  • Anonymous usage events — screens visited, features used.

Payment data

  • If you subscribe to Pro, we store the subscription state (active / cancelled / past due) and an invoice history.
  • We do not store full card numbers. Card details are tokenised by our payment provider (Paystack).

2. How we use it

  • Run the app. Sign you in, generate your flyers, deliver email codes.
  • Improve PostCraft. Aggregate analytics tell us which templates work and which screens are slow.
  • Keep you safe. Rate-limits and fraud signals protect your account from brute-force attempts.
  • Send transactional email. Sign-in codes, password resets (if you use the legacy path), and billing receipts. We don’t send marketing email unless you opt in under Notifications.

3. Who we share data with

We share the minimum data necessary with a small set of named processors:

ProcessorWhat forWhat they see
OpenAI Flyer + caption generation The product photo and product details you submit on each generate. Not retained for training.
Mailtrap Transactional email delivery Your email address and the body of each sign-in code email.
Cloudflare R2 Photo and design storage The image bytes only, encrypted at rest.
Paystack Payment processing Card details when you start checkout. We never see the card number.
Sentry Crash diagnostics Stack traces and device info. No content from your designs.

We do not sell your data, rent it, or share it with advertisers.

4. Where it’s stored

PostCraft runs on servers in the EU (Hetzner, Frankfurt). Photos and designs live in Cloudflare R2's distributed storage. If you’re outside the EU, your data is transferred to the EU under standard contractual clauses.

5. How long we keep it

  • Account data — until you delete your account, then 30 days for fraud protection, then permanently purged.
  • Designs you’ve saved — until you delete them or your account.
  • Sign-in codes (OTPs) — 10 minutes, single-use.
  • Server logs — 30 days, then deleted.

6. Your rights

You can, at any time:

  • See and edit your profile data from Account → Edit Profile.
  • Manage analytics + ad preferences from Account → Privacy.
  • Request an export of all your data (email privacy@postcrafts.site).
  • Permanently delete your account from Account → Delete Account. Your photos, designs, brand kit, and active subscription are wiped within 30 days.

If you’re in the EU or UK, the GDPR gives you a right of complaint to your local supervisory authority — but please contact us first; we’ll usually fix it within 72 hours.

7. Children

PostCraft is intended for users 16 and older. We don’t knowingly collect data from children under 16. If you believe a child has signed up, write to privacy@postcrafts.site and we’ll delete the account.

8. Changes

If we make a material change to this policy, we’ll show you a notice in the app and update the “Last updated” date at the top. Continued use after that constitutes acceptance.

9. Contact

Email privacy@postcrafts.site for anything privacy-related. We’re a small team and we read every message.

© PostCraft. Made for small businesses.
Terms Privacy Contact