postclaw
Who It's ForHow It WorksPowered ByPricingAffiliates

PostClaw

Your AI social media manager powered by OpenClaw

admin@postclaw.io

Product

  • Pricing
  • Blog
  • Affiliates

Legal

  • Privacy Policy
  • Terms of Service

© 2026 PostClaw. All rights reserved.

OpenClawPowered by Zernio

Privacy Policy

Last updated: February 24, 2026

1. Introduction

PostClaw ("we", "us", or "our") respects your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our Service at postclaw.io. We are committed to complying with the General Data Protection Regulation (GDPR) and applicable French and EU data protection laws.

2. Data Controller

PostClaw is the data controller for the personal data processed through the Service. For any questions or requests regarding your data, contact us at hello@postclaw.io.

3. Data We Collect

3.1 Account Information

  • Email address (provided at registration or via Google OAuth)
  • Name (if provided or obtained via Google OAuth)
  • Profile picture (if obtained via Google OAuth)

3.2 Payment Information

  • Stripe customer ID and subscription details (subscription status, billing period)
  • We do not store your credit card number or full payment details — these are handled entirely by Stripe

3.3 Social Media Account Data

  • Platform account identifiers and usernames for connected accounts (Twitter/X, LinkedIn, Bluesky, Threads)
  • OAuth tokens used to post on your behalf (stored securely by our social media integration provider)

3.4 Chat Data

  • Messages exchanged with your AI social media manager (processed in your isolated instance and not stored by us beyond the session)

3.5 Usage Data

  • Analytics data collected via PostHog (page views, feature usage)
  • Bot status and service health metrics

4. How We Use Your Data

We use your personal data for the following purposes:

  • Provide the Service: operate your AI bot, publish content to your social accounts, manage your subscription
  • Authentication: verify your identity and manage your account
  • Payment processing: manage billing and subscriptions through Stripe
  • Communication: send transactional emails (account confirmation, password reset, subscription updates)
  • Service improvement: analyze usage patterns to improve the Service (anonymized analytics)
  • Support: respond to your requests and provide customer support

5. Legal Basis

Under the GDPR, we process your data based on the following legal grounds:

  • Contract performance: processing necessary to provide the Service you subscribed to (Article 6(1)(b))
  • Legitimate interest: analytics and service improvement, fraud prevention (Article 6(1)(f))
  • Legal obligation: tax and accounting requirements (Article 6(1)(c))
  • Consent: marketing communications, if applicable (Article 6(1)(a))

6. Third-Party Processors

We share your data with the following third-party processors, each acting under data processing agreements:

  • Stripe — payment processing (USA, EU Standard Contractual Clauses)
  • Supabase — database hosting (PostgreSQL)
  • Fly.io — container hosting for your AI social media manager (Europe)
  • Zernio (zernio.com) — social media posting (OAuth tokens and post data)
  • Moonshot (Kimi K2.5) — AI language model for content generation
  • Resend — transactional email delivery
  • PostHog — product analytics
  • Vercel — web application hosting

We do not sell your personal data to third parties.

7. Data Isolation and Security

We take security seriously and implement the following measures:

  • Per-user isolation: each subscriber receives a dedicated, isolated bot container — your data and conversations are not shared with other users
  • Scoped API keys: your social media access is limited to your own accounts via profile-scoped API keys
  • Encrypted connections: all data in transit is encrypted via TLS/HTTPS
  • Secure credential storage: bot tokens and API keys are stored as encrypted environment variables
  • Access controls: only authorized personnel have access to production systems

8. Data Retention

  • Account data: retained while your account is active and for up to 30 days after deletion
  • Payment records: retained as required by tax and accounting laws (up to 10 years)
  • Bot conversations: processed in real-time within your isolated container and not permanently stored by PostClaw
  • Analytics data: retained in anonymized form

When you cancel your subscription, your AI social media manager and associated data (social account connections) are deleted at the end of your billing period.

9. Your Rights (GDPR)

Under the GDPR, you have the following rights:

  • Right of access: request a copy of your personal data
  • Right to rectification: correct inaccurate or incomplete data
  • Right to erasure: request deletion of your personal data
  • Right to restrict processing: limit how we use your data
  • Right to data portability: receive your data in a structured, machine-readable format
  • Right to object: object to processing based on legitimate interest
  • Right to withdraw consent: where processing is based on consent, you can withdraw it at any time

To exercise any of these rights, contact us at hello@postclaw.io. We will respond within 30 days. You also have the right to lodge a complaint with the French data protection authority (CNIL) or your local supervisory authority.

10. International Data Transfers

Some of our third-party processors are located outside the European Economic Area (EEA). Where data is transferred outside the EEA, we ensure appropriate safeguards are in place, including EU Standard Contractual Clauses or adequacy decisions, in compliance with GDPR Chapter V.

11. Cookies

We use essential cookies required for authentication and session management. We also use analytics cookies (PostHog) to understand how the Service is used. You can manage cookie preferences through your browser settings. Essential cookies cannot be disabled as they are necessary for the Service to function.

12. Children's Privacy

The Service is not intended for anyone under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service at least 30 days before they take effect. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.

14. Contact Us

If you have any questions about this Privacy Policy or your personal data, please contact us at hello@postclaw.io.