Privacy Policy
Privacy Policy
This Privacy Policy explains how Butterknife LLC, doing business as Postmagiq, ("Company", "we", "us", "our") collects, uses, shares, and protects your information when you use our AI-powered content creation platform ("Service"). By using the Service, you consent to the practices described in this policy.
1. Information We Collect
1.1 Account Information
- Email address (required for account creation)
- Full name (optional)
- Password (stored as a secure cryptographic hash, never in plain text)
- Profile information you choose to provide
- External authentication identifiers (if using third-party login)
1.2 Content Data
- Writing samples you upload for voice learning
- Voice profiles generated from your writing samples
- Resumes or professional background information you provide for content strategy personalization, and the background profiles derived from them
- Content you create, generate, or edit within the Service
- Published posts and scheduled content
- Workflow configurations and personas
- Comments and feedback on approval workflows
1.3 Social Media Data
- OAuth access tokens (encrypted at rest)
- OAuth refresh tokens (encrypted at rest)
- Platform user identifiers (LinkedIn URN, X user ID, Threads ID)
- Platform usernames and display names
- Granted OAuth scopes
- Analytics data you import from connected platforms
1.4 Usage and Telemetry Data
- Features accessed and frequency of use
- AI model usage (which models, token counts, costs)
- Workflow execution metrics (duration, completion status)
- API requests and response times
- Error logs and diagnostic information
- Content workflow completion rates
- Posts created, scheduled, and published counts
1.5 Technical Data
- IP addresses
- Browser type and version
- Device information and operating system
- Referring URLs and pages visited
- Session duration and timestamps
- User agent strings
1.6 Billing Data
- Subscription tier and billing cycle
- Payment method type and last four digits (we do not store full card numbers)
- Billing address
- Invoice history and payment status
- Usage data for billing calculations
2. How We Use Your Information
- **Service Delivery:** To provide, operate, and maintain the Service
- **AI Processing:** To generate content, analyze writing samples, and create voice profiles
- **Social Publishing:** To publish content to your connected social media accounts
- **Analytics:** To import and display your social media performance metrics
- **Billing:** To process payments, manage subscriptions, and track usage
- **Communication:** To send transactional emails, updates, and support responses
- **Improvement:** To analyze usage patterns and improve the Service
- **Security:** To detect, prevent, and respond to security incidents and abuse
- **Legal Compliance:** To comply with legal obligations and enforce our terms
- **Audit Logging:** To maintain audit trails for security and compliance
3. AI Data Processing
**IMPORTANT AI DISCLOSURE:**
To provide AI-powered features, your content is transmitted to and processed by third-party AI providers. Please read this section carefully to understand how your data is handled.
3.1 AI Providers We Use
- **Anthropic (Claude):** Content generation and analysis
- **Google (Gemini):** Content generation and analysis
- **OpenAI (GPT):** Content generation and analysis
- **Groq:** Fast inference and audio transcription (Whisper)
- **Meta (Codex):** Content generation
- **Ollama (Local):** Optional local AI processing (data stays on your infrastructure)
3.2 Data Sent to AI Providers
- Writing samples for voice analysis
- Resume text and professional background information for content strategy analysis
- Prompts and instructions for content generation
- Existing content for revision or analysis
- Voice profile characteristics
- Context and guidance text
3.3 AI Provider Data Practices
Each AI provider has its own data retention and privacy policies. While we select providers with strong privacy practices and request that they not use your data for training:
- We cannot guarantee how third-party AI providers handle your data
- You should review each provider's privacy policy for complete details
- Data retention periods vary by provider
- Some providers may log prompts for abuse prevention
3.4 Voice Profile Data
When you upload writing samples, we analyze them to extract characteristics such as: tone, vocabulary patterns, sentence structure, signature phrases, and topics to avoid. This analysis creates a "voice profile" stored in our database to maintain consistency in AI-generated content. Writing samples and voice profiles are only shared with AI providers as needed to generate content.
3.5 Workflow Data Retention for System Improvement
To improve the quality and reliability of the Service, we store the following workflow execution data:
- Assembled prompts sent to AI providers (with raw input content replaced by internal references to reduce duplication)
- AI-generated responses received during content workflows
- User feedback provided during workflow review stages
- Workflow execution metadata (state transitions, configuration snapshots, retry events)
This data is used solely to improve the quality and reliability of the Service. We do **NOT** sell, share, or provide this workflow data to any third party. This data is tied to your account and is permanently deleted when you delete your account.
3.6 Post Edit Data
When you edit workflow-generated content, we store:
- The original (or previously edited) version of the content
- Your edited version after saving
- A computed diff (machine-readable change record) between the two versions
- An optional edit note you may provide describing what you changed and why
This data is used to analyze patterns in user corrections and improve AI writing quality, voice accuracy, and content generation over time. Edit history is tied to your account and is permanently deleted when you delete your account.
3.7 Free Tool Submissions
Our free tools (the AI-tell checker, the hook, headline, hashtag, and post generators, and the resume to LinkedIn analyzer) can be used without an account. The resume analyzer is handled differently from the others, and that difference is described at the end of this section.
When you submit text or a topic to a free tool (whether or not you are signed in), we store:
- The submitted text or topic, and the tool's result (for the checker: the verdict band and detected pattern categories; for generators: the generated output)
- A salted, one-way hash of your IP address (we do not store your raw IP address with your submission)
- Your account ID, only if you were signed in when you submitted
Submitted text is sent to our AI provider (Groq) to perform the check or generation, subject to the provider practices described in Section 3.3. We store submissions to improve the quality of the tools (for example, detection accuracy and generation prompts). We do **NOT** sell, share, or provide free-tool submissions to any third party, and we do not use them to identify you.
Because anonymous submissions are not tied to an account, they cannot be individually retrieved or deleted on request; instead, all free-tool submissions are automatically deleted after **12 months**. Do not submit text containing confidential or personal information. Submissions made while signed in are deleted when you delete your account.
**Exception: the resume to LinkedIn analyzer does not store what you submit.** Because a resume contains personal information and the tool can be used without an account, there would be no way for you to ask us to delete a stored copy later. So we do not keep one. The text you paste is held only for as long as it takes to produce the analysis, and is then discarded. It is not written to our database, not kept in any cache, and not written to our logs. It is sent to our AI provider for that single analysis, subject to Section 3.3.
We do retain the analysis the tool returns to you (the topic pillars, keywords, gaps, and post angles), together with the salted IP hash and account ID described above, on the same 12-month schedule and for the same purpose of improving the tool. The analyzer is built to exclude names, email addresses, phone numbers, and employer names from that output, and output that contains them is discarded rather than returned or stored.
This exception applies to the free, no-account analyzer at `/tools/linkedin-resume-analyzer`. If you later choose to save a resume to your account, Section 3.8 applies instead.
3.8 Resume and Professional Background Data
This section covers resumes you save to your account. It does **not** cover the free, no-account resume analyzer described at the end of Section 3.7, which stores nothing you submit.
When you are signed in, you may optionally save a resume (or paste equivalent professional background information) so that content strategies and posts can be grounded in your real experience. When you do, we:
- Extract and store the text content of your resume in our database, tied to your account
- Send that text to an AI provider (as described in Section 3.3) to derive a structured professional background profile — for example, roles, industries, skills, notable achievements, and suggested content topics
- Store the derived background profile and use it to personalize the content strategies and posts the Service generates for you
Resume data is used only to provide these features. We do **NOT** sell or share your resume or derived background profile with any third party (other than the AI processing described above), and we do not use it for advertising. Providing a resume is optional; the Service works without one.
You can view, replace, or delete your stored resume and derived background profile at any time in your account settings. Deleting removes both the resume text and the derived profile. All resume data is permanently deleted when you delete your account.
4. Social Media Integration
When you connect social media accounts to Postmagiq (including but not limited to LinkedIn, X/Twitter, Threads, TikTok, Instagram, Facebook, YouTube, Pinterest, Bluesky, Mastodon, or any other platform we may support), we collect and process data as described below. This section details exactly what data we access, how we use it, and how you can control it.
4.1 LinkedIn Integration
When you connect your LinkedIn account, we access:
- Your LinkedIn member ID and profile URL
- Your name and profile picture (for display in our interface)
- Permission to post content on your behalf (w_member_social scope)
We do NOT access: your connections, messages, email, job history, or any other profile data. Posts are only made when you explicitly click "Publish" or schedule content.
4.2 X/Twitter Integration
When you connect your X account, we access:
- Your X user ID and username
- Your display name and profile picture
- Permission to post tweets on your behalf
We do NOT access: your DMs, followers/following lists, likes, or bookmarks. Tweets are only posted when you explicitly authorize each post.
4.3 Threads Integration
When you connect your Threads account, we access:
- Your Threads user ID and username
- Your display name and profile picture
- Permission to post content on your behalf
We do NOT access: your Instagram data, DMs, followers, or any Meta account data beyond Threads.
4.4 TikTok Integration
When you connect your TikTok account, we access:
- Your TikTok user ID and username
- Your display name and profile picture
- Permission to post videos/content on your behalf
We do NOT access: your DMs, followers/following lists, liked videos, or personal viewing history. Content is only posted when you explicitly authorize each post.
4.5 Other Platform Integrations
For any other social media platform we support (Instagram, Facebook, YouTube, Pinterest, Bluesky, Mastodon, or others), we follow the same principles:
- We request only the minimum permissions necessary
- We access your user ID, username, and profile picture for identification
- We request posting permissions to publish content on your behalf
- We do NOT access private messages, contact lists, or personal data beyond what's disclosed
- Content is only posted when you explicitly authorize it
Specific permissions and data access may vary by platform based on their API capabilities. You can review the exact permissions requested during the OAuth authorization flow for each platform.
4.6 OAuth Token Security
- OAuth tokens are encrypted at rest using AES-256 encryption (PostgreSQL pgcrypto)
- Tokens are stored in a secure database with access controls
- Tokens are only decrypted server-side when needed to publish content
- Tokens are never logged, displayed, or exposed to other users
- We use refresh tokens where supported to minimize token lifetime
- Tokens are deleted immediately and permanently when you disconnect an account
4.7 User Consent and Control
- We will NEVER post to your social accounts without your explicit action
- You must click "Publish" or explicitly schedule each post
- You can preview all content before it is published
- You can cancel scheduled posts at any time before publication
- You can disconnect any social account at any time via Settings
- You can revoke our access directly from the platform's settings
4.8 Data Retention and Deletion
- OAuth tokens: Deleted immediately upon disconnection
- Profile data (name, username, ID): Deleted when you disconnect or delete your account
- Published content records: Retained for your records; content remains on platforms
- Analytics imports: Retained until you request deletion
4.9 What We Do NOT Do
- We do NOT read your private messages or DMs
- We do NOT access your connections, followers, or following lists
- We do NOT post without your explicit action
- We do NOT modify your profile or settings
- We do NOT sell your social media data
- We do NOT share your tokens with third parties
- We do NOT use your data for advertising
5. Data Sharing and Third Parties
We share your information with the following categories of third parties:
5.1 Service Providers
- **AI Providers:** Anthropic, Google, OpenAI, Groq (as described in Section 3)
- **Payment Processing:** Stripe (handles payment information)
- **Cloud Infrastructure:** Hosting and database providers
- **Email Services:** Transactional email delivery
5.2 Social Media Platforms
- LinkedIn Corporation
- X Corp. (Twitter)
- Meta Platforms (Threads)
5.3 Legal and Safety
We may disclose information when required to:
- Comply with applicable law, regulation, or legal process
- Respond to lawful requests from government authorities
- Protect our rights, privacy, safety, or property
- Investigate suspected violations of our terms
- Protect against fraud, abuse, or security threats
5.4 Business Transfers
If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any change in ownership or control of your personal information.
6. Usage Monitoring and Analytics
We collect telemetry and usage data to operate and improve the Service. This includes:
6.1 What We Track
- Feature usage patterns and frequency
- AI model costs and token usage (for billing and optimization)
- Workflow execution metrics
- Error rates and performance metrics
- API usage statistics
- Content creation and publishing rates
- Session replays of page interactions (with consent; typed text and form inputs are masked and never recorded)
6.2 Purpose of Analytics
- Accurate billing based on usage
- Service reliability and performance monitoring
- Feature development and prioritization
- Abuse detection and prevention
- Capacity planning and infrastructure optimization
6.3 Your Analytics Choices
You can opt out of non-essential analytics through your Privacy Settings. Note that some data collection is required for billing, security, and legal compliance purposes.
7. Data Security
We implement industry-standard security measures to protect your information:
- **Encryption in Transit:** All data transmitted over HTTPS/TLS 1.2+
- **Encryption at Rest:** OAuth tokens encrypted with AES-256 (pgcrypto)
- **Password Security:** Passwords hashed using bcrypt with salt
- **Access Controls:** Role-based access control for team workspaces
- **Audit Logging:** Immutable logs of significant actions
- **Infrastructure:** Hosted on secure, SOC 2 compliant infrastructure
**Note:** While we implement robust security measures, no system is completely secure. We cannot guarantee absolute security of your data.
8. Data Retention
- **Account Data:** Retained while your account is active
- **Content:** Retained until you delete it or your account
- **Resume and Background Data:** Retained until you delete it in settings or delete your account
- **Social Tokens:** Deleted immediately upon disconnection
- **Audit Logs:** Retained for 2 years for security and compliance
- **Billing Records:** Retained for 7 years as required by law
- **Deleted Accounts:** Data deleted within 30 days of account deletion, except as required for legal compliance
9. Your Rights and Choices
Depending on your location, you may have the following rights:
9.1 Access and Portability
- Request a copy of your personal data
- Export your data in a machine-readable format
9.2 Correction and Deletion
- Update or correct inaccurate information
- Delete your account and associated data
- Request deletion of specific content
9.3 Control and Opt-Out
- Disconnect social media accounts at any time
- Opt out of marketing communications
- Opt out of non-essential analytics
9.4 How to Exercise Rights
Use the Privacy Settings in your account dashboard, or contact us at [info@postmagiq.com](mailto:info@postmagiq.com). We will respond within 30 days.
10. International Data Transfers
We are based in the United States. If you access the Service from outside the US, your information will be transferred to and processed in the United States.
By using the Service, you consent to this transfer. We take steps to ensure your data receives adequate protection through:
- Standard contractual clauses with service providers
- Working with providers that maintain appropriate certifications
- Implementing technical safeguards regardless of data location
11. Regional Privacy Rights
11.1 California Residents (CCPA)
California residents have additional rights under the CCPA:
- Right to know what personal information we collect and how it's used
- Right to delete personal information
- Right to opt out of sale of personal information (we do not sell personal information)
- Right to non-discrimination for exercising privacy rights
11.2 European Economic Area (GDPR)
EEA residents have additional rights under GDPR:
- Right to access, rectification, and erasure
- Right to data portability
- Right to restrict processing
- Right to object to processing
- Right to lodge a complaint with a supervisory authority
Our legal basis for processing includes: contract performance, legitimate interests (service improvement, security), consent (where applicable), and legal compliance.
12. Children's Privacy
The Service is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If we learn that we have collected information from a child under 18, we will delete it promptly. If you believe a child has provided us with personal information, please contact us at [info@postmagiq.com](mailto:info@postmagiq.com).
13. Cookies and Tracking
We use cookies and similar technologies for:
- **Essential Cookies:** Required for authentication and security
- **Functional Cookies:** Remember your preferences and settings
- **Analytics Cookies:** Understand how you use the Service (opt-out available)
You can control cookies through your browser settings. Disabling essential cookies may prevent the Service from functioning properly.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Updating the "Last updated" date at the top
- Sending email notification for significant changes
- Displaying a notice within the Service
Your continued use of the Service after changes constitutes acceptance of the updated policy.
15. Contact Us
For questions about this Privacy Policy or to exercise your privacy rights:
**Butterknife LLC (d/b/a Postmagiq)** General Inquiries: [info@postmagiq.com](mailto:info@postmagiq.com) Support: [support@postmagiq.com](mailto:support@postmagiq.com)