Privacy Policy
Last updated: November 27, 2025
Effective date: November 27, 2025
This Privacy Policy describes how Nazar Verhun ("we", "us", "our") collects, uses, and protects your personal information when you use the Posti AI mobile application and website (collectively, the "Service"). We are committed to protecting your privacy and ensuring transparency about our data practices.
1. Information We Collect
1.1 Information You Provide
- Account information: name and email address from Apple Sign In
- Content data: topics, ideas, generated content, and edits you make
- Personalization data (optional, only with your consent): content preferences, writing style, and topic preferences
- Feedback and correspondence you send to us
1.2 Information Collected Automatically
- Device model, operating system version, and app version
- Usage data: features used, content generation requests, session duration
- App performance data and crash reports
1.3 Information We Do NOT Collect
- Location data
- Contacts or photos (unless you explicitly upload)
- Microphone recordings (voice is processed on-device only)
- Browsing history or data from other apps
2. How We Use Your Information
- Authenticate your account via Apple Sign In
- Generate AI content based on your inputs
- Save and sync your content across sessions
- Process subscription payments
- Improve our Service and develop new features
- Personalize your experience (with your consent)
- Send important service updates and respond to support requests
- Comply with legal obligations
3. Voice Data
Voice input is processed entirely on your device using iOS native speech recognition. Audio recordings are not transmitted to our servers or any third party. Only the resulting text transcription is sent to our backend for content generation.
4. AI Content Generation
When you generate content, your text input is sent to OpenAI's API for processing. Important details about how OpenAI handles your data:
- OpenAI does NOT store your data from API calls
- OpenAI does NOT use your data to train their models
- Data is processed and immediately discarded
5. How We Share Your Information
We do NOT sell, rent, or trade your personal information to third parties for marketing purposes. We share data with the following trusted service providers solely to operate the Service:
- Apple (USA) — Authentication and payments
- OpenAI (USA) — AI content generation
- Appwrite (Germany, EU) — Data storage
- RevenueCat (USA) — Subscription management
- Amplitude (Germany, EU) — Anonymous analytics (no IDFA)
We may also disclose information if required by law, regulation, or legal process, or to protect our rights and safety.
6. Data Storage and Security
Your data is stored on:
- Appwrite servers in Germany (EU): account information, saved content
- Amplitude servers in the EU: anonymous analytics data
- Your device: cached content and preferences
We implement industry-standard security measures including encryption in transit (HTTPS/TLS), encryption at rest, secure authentication via Apple Sign In, regular security audits, and access controls.
7. Data Retention
- Active accounts: data retained while your account is active
- Deleted accounts: all data deleted immediately upon account deletion
- Subscription data: retained as required by tax and legal obligations
8. Analytics and Tracking
We use Amplitude Analytics (hosted in Germany, EU, GDPR-compliant) to understand app usage and improve features. Amplitude collects anonymous usage events, device type, OS version, app version, and session duration. Amplitude does NOT collect IDFA, IP addresses, carrier information, precise location, or any cross-app tracking data.
Our website uses Google Analytics (GA4, measurement ID: G-E0XZFMDSFZ) to analyze website traffic and improve the user experience.
10. Your Rights
- Access: view your data in the app or request a complete data export
- Delete: delete individual content or your entire account (Settings > Delete Account)
- Export: request a portable copy of your data
- Opt-out: disable personalization at any time in Settings
- Withdraw consent: withdraw consent for data processing at any time
Account deletion is immediate and permanent. All your data will be erased and cannot be recovered.
11. GDPR Rights (EU Users)
If you are in the European Economic Area, you have additional rights under GDPR: right to access, rectification, erasure ("right to be forgotten"), restrict processing, data portability, object to processing, and withdraw consent. Contact legal@posti-ai.com with subject "GDPR Request". You also have the right to lodge a complaint with a supervisory authority in your country of residence.
12. California Privacy Rights (CCPA)
California residents have additional rights: right to know, right to delete, right to opt-out, and right to non-discrimination. We do NOT sell personal information as defined by CCPA. Contact legal@posti-ai.com with subject "CCPA Request".
13. Children's Privacy
Posti AI is not intended for children under 13. We do not knowingly collect personal information from children under 13. Users between 13 and 18 must have parental or guardian consent. If you believe a child under 13 has provided us with personal information, please contact us immediately and we will delete such information promptly.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page and in the app, effective immediately upon posting. We will notify you via email or in-app notification for material changes.
15. Contact Us
If you have questions about this Privacy Policy, please contact us:
- Email: legal@posti-ai.com
- Support: /support
- Website: https://posti-ai.com
Response time: we aim to respond to all privacy-related inquiries within 30 days.