Privacy Policy
Last updated: 19 August 2026
This Privacy Policy explains how Casiva Limited ("we", "us", "the Company"), the operator of posting-app.com (the "Service"), collects, uses, stores and protects personal data. We are the data controller for the purposes of the EU General Data Protection Regulation (GDPR) where it applies.
1. Who we are
Casiva Limited, Suite 2, 260 Main Street, Gibraltar, GX11 1AA, Company No. 125406. Contact for privacy matters: privacy@posting-app.com.
2. Data we collect
- Account data — name, email address and password (stored hashed) of the users who register.
- Connected social accounts — when you connect a Facebook Page, Instagram, Threads or TikTok account, we store the account identifier, display name, avatar, the permissions (scopes) you grant, and the access/refresh tokens needed to act on your behalf. Tokens are encrypted at rest and are never displayed or shared.
- Content you create — the posts, captions, media and schedules you submit for publishing.
- Performance metrics — engagement and reach figures we retrieve from the platforms' official insights for the posts you publish through us.
- Billing data — subscription status handled by our payment processor (Paddle). We do not store full card details.
- Technical data — logs and error reports for security and reliability.
3. Data obtained from Meta and TikTok platforms
With your explicit authorisation via official OAuth, we access data from the Facebook, Instagram, Threads and TikTok APIs strictly to provide the Service:
- Your account/page identity and the permissions you grant, to connect the account.
- Publishing endpoints, to post the content you schedule.
- Insights/metrics endpoints, to build your reports.
We use this platform data only to operate the features you use. We do not sell your platform-derived data, and we do not use it for advertising. Our use of information received from these APIs adheres to the respective Platform Terms and Developer Policies. You can revoke our access at any time from the platform's own settings, or by contacting us.
4. How we use your data
- To publish your scheduled content and manage your connected accounts.
- To generate your performance reports.
- To provide AI drafting features you choose to use.
- To operate billing, support, security and legal compliance.
Legal bases (GDPR) are: performance of our contract with you, your consent (for connecting accounts and optional features), and our legitimate interests in securing and improving the Service.
5. Aggregated, anonymised benchmarks
We may produce aggregated, anonymised benchmarks by industry sector (for example, average engagement patterns across hospitality businesses) and make these available as a feature or product. These benchmarks are computed only from pooled data across multiple businesses and are subject to a minimum-number-of-businesses threshold and safeguards designed so that no individual business's data can be identified or reconstructed from a benchmark. We never sell or disclose an individual customer's data to third parties.
6. Sharing and processors
We share data only with service providers who process it on our behalf under contract: Supabase (managed database, EU region), Cloudflare (hosting and media delivery), Paddle (payments, Merchant of Record), Sentry (error monitoring), and the AI providers you choose to use for generation. We disclose data if required by law.
7. Storage, location and retention
Data is stored on infrastructure in the European Union. We keep your data for as long as your account is active. When you delete your account or a connected account, we delete the associated tokens and data as described in our Data Deletion Instructions. Technical logs are retained for a limited period for security.
8. Your rights
Under GDPR you have the right to access, rectify, erase, restrict or object to processing of your personal data, and to data portability. To exercise any right, email privacy@posting-app.com. You may also lodge a complaint with your local data protection authority.
9. Security
Access tokens are encrypted at rest, secrets are kept out of logs, access is isolated per customer, and administrative access requires two-factor authentication.
10. Changes
We may update this policy; material changes will be posted on this page with a new "last updated" date.
11. Contact
Casiva Limited — privacy@posting-app.com.