Skip to content
SocialMint
FeaturesDemoPricingFAQLog inStart free

Privacy Policy

Last updated: September 9, 2026

This policy explains how Postial handles personal data when you visit our website, use an account, or review a client post.

Our Data Processing Agreement, including processing details, security measures and providers, is available online. Workspace owners can accept it in legal settings.

Who is responsible

productivity-boost.com Betriebs UG (haftungsbeschränkt) & Co. KG, Reichenbergerstr. 2, 94036 Passau, Germany, is the controller for account administration, billing, security, and website operation. Contact: info@productivity-boost.com. See our Impressum for company representation and registration details.

When an agency uploads client content and manages approvals, we process that content on its documented instructions. The agency determines the purposes and lawful basis, either as controller or on behalf of its own client. Our data processing agreement governs that processing. If your agency sent you an approval link, contact it about the content or its use of your data; we help it respond to requests.

We have not appointed a data protection officer. Please direct privacy questions to the contact email above.

Data we use and why

DataPurposeLegal basis for processing we control
Account email, name, workspace membership, and account settingsCreate accounts, manage access, and provide the subscriptionArticle 6(1)(b) GDPR for an individual contracting with us; Article 6(1)(f) for business contacts and team members, to administer the customer relationship
Name, email, and profile picture, if you choose Google sign-inAuthenticate you using Google sign-in; we do not request access to Gmail, contacts, or other Google contentThe same account-administration bases above
Subscription, invoice and payment status, billing contact/address, tax information, Stripe customer and transaction referencesTake payments, administer subscriptions, and maintain accounting recordsArticle 6(1)(b), or Article 6(1)(f) for business contacts; Article 6(1)(c) for tax and accounting duties
IP address, request time, requested path, browser information, response status, and relevant account reference in server logsDiagnose faults, prevent abuse, and protect accessArticle 6(1)(f): our interest in a secure, functioning service
Session identifiers and session recordsKeep you signed in and protect your sessionArticle 6(1)(b), or Article 6(1)(f) for team access
Support messages and related account informationAnswer your questions and resolve problemsArticle 6(1)(b), or Article 6(1)(f) for business contacts

We also process drafts, media, brand and connected-account identifiers, schedules, approval decisions and comments, publishing results, and retry/error history on the customer's instructions. Reviewers can respond without creating an account; their responses are associated with the review link and post. Technical request data is still processed for security. Do not include confidential information in a review comment unless the agency needs it.

For API and n8n use, we process credentials and request metadata needed to authenticate requests and carry out the customer's workflow. Data sent to a separate n8n installation is also subject to that installation's operator and configuration.

Providing the information needed for an account or paid subscription is necessary to supply that service. Optional profile information is not required beyond the authentication method's needs. We do not use automated decision-making with legal or similarly significant effects, or profile people for advertising.

Social-network access tokens

When you connect a social account, the network supplies access tokens and, where applicable, refresh tokens. We store tokens encrypted and use them only to deliver the publishing service you request, including maintaining authorization and checking the result of a publishing attempt. We do not use them to browse unrelated private messages or for advertising.

You can revoke Postial's access in the network's settings. Disconnecting an account stops future publishing through that connection and removes its active tokens. Content already published remains on the network until you remove it there. Anyone with a review link may be able to view or respond to its post; share links only with intended reviewers.

Cookies and tracking

Postial uses only technically necessary authentication, session, security and workspace-selection cookies. They support sign-in, session security and your selected workspace. We use no advertising pixels, behavioral analytics, or cross-site tracking. Blocking session cookies can prevent sign-in. Necessary device storage is based on § 25(2)(2) TDDDG; the associated personal-data processing follows the bases described above.

Session cookies are first-party cookies on the Postial domain. Auth.js uses __Secure-authjs.session-token on HTTPS (authjs.session-token in local HTTP development); sessions expire after 30 days unless renewed. Necessary first-party authentication cookies include __Host-authjs.csrf-token and __Secure-authjs.callback-url (browser-session lifetime), plus __Secure-authjs.pkce.code_verifier and __Secure-authjs.state (up to 15 minutes during Google sign-in). Local HTTP development omits the secure prefixes. These cookies protect login requests and remember the callback destination; they are not used for tracking.

Providers and other recipients

The provider and recipient list is the same as DPA Annex 3: Hetzner, Stripe, optional Google sign-in, customer-connected social networks and customer-selected Slack, Discord or Mattermost alert destinations. These recipients have different roles; not every independent recipient acts as our subprocessor.

  • Hetzner hosts Postial's application data in Germany and processes hosted data on our instructions under a data processing agreement.
  • Stripe handles checkout, subscription billing, and payments. Payment details are entered directly into Stripe; Postial does not store full card numbers or card security codes. Stripe acts as a processor for activities performed on our instructions and as an independent controller for its own purposes, including regulatory compliance and fraud prevention. See Stripe's Privacy Policy and data processing agreement.
  • Google handles optional Google sign-in and receives login-related technical data. Its own processing is explained in Google's Privacy Policy.
  • Connected networks receive the content, media, and account information needed to publish your posts. Currently these are Bluesky, Mastodon and Telegram. X, Threads, LinkedIn and Instagram/Facebook are in preparation, subject to platform approval without a confirmed date. The relevant provider includes your selected Mastodon server or Bluesky service provider. Their own privacy rules apply to data they receive and posts they host.
  • Customer-selected Slack, Discord or Mattermost incoming webhooks receive event notices and post links when a workspace owner configures them in Notification settings. We process destination URLs and signing secrets encrypted, on the customer’s instructions. Alerts do not include scheduled post bodies or client comments and may continue after subscription access expires. The customer chooses the destination, its audience and permissions; that provider’s terms, retention and international processing apply. No email or Telegram notification delivery is included.
  • Authorized personnel can access data where necessary to operate the service or provide support. We may disclose necessary records to professional advisers or authorities when required by law or needed to establish or defend legal claims.

We do not sell personal data or share it with advertisers.

Where data is processed

Our application data is hosted with Hetzner in Germany. This does not mean every recipient processes data only in Germany or the EU: Stripe, Google, and connected social-network providers may process data internationally.

Where we arrange a transfer outside the EEA, it must have a lawful transfer mechanism, such as a relevant adequacy decision or EU Standard Contractual Clauses with any necessary supplementary safeguards. Ask us for information about the applicable safeguards or a copy, with confidential information redacted where necessary.

The application, database, media, and backups run on our own infrastructure at Hetzner in Germany (Falkenstein/Nuremberg). Stripe Payments Europe, Limited (Ireland) provides payment services and may transfer data to Stripe, LLC in the United States. US transfers use EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. Google and connected networks may also process data outside the EEA under the applicable transfer safeguards described above.

Retention and deletion

We retain account data while the account is active and as needed to close it. Customer content and approval/publishing history are retained according to the customer's instructions and the data processing agreement. Cancellation of a subscription does not by itself request immediate account deletion. Use Workspace settings for owner export, ownership transfer and workspace deletion, or Account settings for your own account deletion. You can also request deletion at our contact email.

The application container logs rotate by size: three files of up to 10 MB, not a fixed 30-day period. A time-based retention period for proxy and build logs has not been verified. Account data remains until deletion, including after trial expiry or cancellation. Owners can export data, transfer ownership or delete their workspace in Workspace settings. Export downloads JSON containing brands, credential-free channel metadata, posts, targets, approvals, history and members. It includes media URLs, but not image bytes, external network copies, channel credentials, API/webhook secrets or approval capabilities. Keep exports private. Workspace deletion cancels its Stripe subscription immediately without proration and deletes its content and integrations; if cancellation fails, data is not deleted and the owner must retry the pending deletion in settings; it does not delete members’ accounts. Users can delete their account in Account settings after transferring or deleting any workspace where they are the last owner. Shared posts and media remain with an anonymous creator, and the account email is removed from stored histories. You can also contact info@productivity-boost.com.

Records needed for German tax and commercial accounting are retained for the statutory period applying to their category. Necessary evidence may also be retained for legal claims or binding preservation duties, with access restricted to that purpose. We delete or anonymize data when the applicable purpose and retention duty end. Deletion from Postial does not delete a post already held by a social network or records another controller must retain independently.

Your rights

Subject to the GDPR's conditions, you can request access, correction, erasure, restriction, and data portability. You can object to processing based on legitimate interests for reasons relating to your situation. If we rely on consent, you can withdraw it at any time without affecting earlier lawful processing.

Email info@productivity-boost.com. We may request proportionate identity verification. We normally respond within one month; if a lawful extension is necessary, we explain why within that first month. You can complain to a supervisory authority, including the Bavarian State Office for Data Protection Supervision (BayLDA), or the authority where you live or work.

Security, children, and changes

We use encrypted transport and encrypted token storage, and limit access to operational needs. No service can eliminate every security risk. Postial is intended for professional agency and freelance use, not for children. Contact us if a child has provided account data.

We update this policy when our processing changes and revise the date above. We notify account holders of material changes before they take effect where applicable. A policy update does not replace consent when consent is legally required.

Network launch waitlist

If you select “Notify me”, we store your email, chosen network, signup time and source page to send one notification when that network becomes available, based on your consent (Article 6(1)(a) GDPR). A keyed hash of your IP address helps limit abusive registrations (Article 6(1)(f), our interest in preventing abuse); we do not store the raw IP in the waitlist. No email is sent on signup; email confirmation will be added before launch notifications are enabled. This is not a newsletter. Withdraw consent or request deletion at info@productivity-boost.com. We delete the waitlist entry after the launch notification or when you withdraw. If a network is abandoned, we delete its entries.

Cookies, media and operational retention

We use authentication/session and security cookies. The HttpOnly sm_ws workspace preference cookie lasts up to one year; it grants no access without a valid session and membership. Uploaded image URLs are public bearer links: anyone with the URL can view the image. New origin responses use private/no-store caching. Deleted images return Gone; copies already downloaded or cached under our previous one-year policy cannot be recalled.

The daily maintenance job removes unused images after 30 days, webhook deliveries after 30 days, notifications after 90 days, rate windows expired for one day, invitations consumed/revoked/expired for 30 days, and OAuth states expired for one day. Post and approval history remains until the post or workspace is deleted. Deletion events without names/emails last 90 days; random image and workspace deletion identifiers and timestamps remain to prevent reused links and late billing events from restoring access.

Host database backups rotate to the latest two successful dumps per database. Pre-release dumps are kept through release acceptance. Deleted data may remain in these restricted backups until rotation or manual release-archive cleanup; completed erasures must be repeated before a restore returns to service. No offsite copy of the host application database has been verified.

SocialMint

Social scheduling and client approvals for agencies.

Made in Passau, Germany

FeaturesInteractive demoPricingRoadmapHelp centerAPI docs
ImpressumPrivacy PolicyTerms of ServiceData Processing AgreementContact
CompareHootsuite alternative for agenciesPostiz alternative

© 2026 productivity-boost.com Betriebs UG (haftungsbeschränkt) & Co. KG