This policy covers the Postfox product, at app.postfox.ai, and this website, postfox.ai, with its free tools. Sections 1 to 12 describe the product as it works today; section 13 describes this website.
1. Who we are
Postfox is run by Benoît Rossignol, an entrepreneur individuel (sole trader) registered in France, trading as BR Media, SIREN 789 477 726, 123 Avenue Henri Ginoux, 92120 Montrouge, France (“Postfox”, “we”). Questions about this policy or your data: hello@postfox.ai.
2. What Postfox is, and who decides what
Postfox writes LinkedIn posts for a company’s employees, in each employee’s own words and voice. Every post is approved by the person whose name goes on it before anything is published; nothing is ever published without them.
- For its campaigns, your company is the controller and Postfox its processor. Your company decides to use Postfox, invites its people, and gives us what its posts start from: what the company does, who it sells to, and the briefs and documents of its campaigns. That, and each employee’s data used to write, approve and publish the posts of its campaigns, we process only on your company’s instructions, under a standard data processing agreement, available on request.
- Postfox is the controller of account, billing and security data: your account (your name, your email, how you sign in), your company’s billing and invoices, and what keeps the service working and safe (error logs, the check records in section 3).
- Posts you write for yourself, outside a campaign, stay yours: we keep them only to write, hold and publish them for you, and your company cannot see them. Postfox is the controller of them, as of your account.
- What you give us about your work, your settings and your rules is used only to write your posts, and your company does not read it (section 4).
3. What we collect
About your company: its name; the context it gives us (what it does, who it sells to, its guidelines); its campaigns (title, brief, attached documents, who was included) and the posts produced for them; its billing details and invoices; and where it came from: the campaign tags of the link that first brought the person who created it (which campaign it was), the page they arrived on and when, and, only with advertising on, the identifier Google Ads put on the link of the ad they clicked (section 6).
About each employee who joins:
- your name and work email, from your invitation or your sign-in;
- your LinkedIn profile photo, as the web address LinkedIn gives us for it when you connect (we keep no copy of the picture). It is shown next to your name, to you and to the people at your company. We keep it until you disconnect LinkedIn or delete your account;
- your LinkedIn access token, which lets a post you approved publish under your name at the time you chose. We never hold your LinkedIn password;
- what you gave us about how you write: an answer about your recent work, any posts of your own you chose to paste, the settings you chose (emojis, hashtags, sign-off, length, language, who you talk to) and any rules you set;
- your posting times;
- the posts written for you, whether you approved, edited or said “Not this time” to each one, and what you changed. We never ask why you said no, and keep no reason.
- anything you later tell us about your week;
- the images and documents you add to a post: the file, its name, its size, the description you give it and, for a document, its title. Before a photo leaves your browser, it is drawn again, which removes its location and the other details a camera records in it. You are responsible for having the right to publish what you add, photos of other people included;
- a record of each check we run on a post before you see it: the post as checked, the material it was checked against and what the check found, kept so that a wrong check can be explained.
About people invited by email: the address, what the inviter said they do, who invited them and when, and what became of the email (sent, delivered, bounced, reported as spam).
What we do not collect. We do not read your LinkedIn: not your messages, connections, feed or anyone else’s posts. The permissions we ask LinkedIn for are your identity: name, photo and email; and permission to publish posts as you, which cannot read your feed or messages (LinkedIn’s names for them: openid, profile, email and w_member_social). A file you add to a post is sent to LinkedIn only when that post is published, under your name, at the time you chose.
4. Who can see what
| You | Your company’s admins | Postfox | |
|---|---|---|---|
| Posts written for you | Yes | Once you approve one. Before that, only that it exists and is not approved yet (or was not included); once the campaign is over, "Not this time" if it did not go out, the same whether you said no or did not answer | Yes |
| Whether you said no to a post | Yes | No. Once a campaign ends, how many people passed, whenever that number can't point at anyone; never who | Yes |
| The other versions of a post | Yes | No | Yes |
| Posts you write for yourself | Yes | No | Yes |
| Images and documents on a post written for you | Yes | Once you approve the post, as with its words | Yes |
| Images and documents on posts you write for yourself | Yes | No | Yes |
| What you told us about your work, and what you tell us about your week | Yes | No | Yes |
| Your writing profile and your rules | Yes | No | Yes |
| Your posting times | Yes | Only whether you have any | Yes |
What you tell us about your work is not read by your company unless you approve a post built from it. Your company’s admins cannot approve, change or publish a post for you. This is enforced by our database, not only by our screens.
The person who runs Postfox accesses your data only to run the service, answer you, and investigate a failure.
5. Why we use it
- To run the service you or your company signed up for: writing posts from your own material, asking for your approval, publishing what you approved at the time you chose, and sending the emails that go with it (invitations, approvals, reminders). Legal basis: the contract for the service (GDPR, article 6(1)(b)).
- To keep it working and secure: error logs, the check records above, and preventing abuse. Legal basis: our legitimate interest in a service that works and is safe (article 6(1)(f)).
- To understand how the product is used, with product analytics and masked session recordings (section 8). Where we ask first, only if you accept them. Legal basis: your consent (article 6(1)(a)). Elsewhere they run until you turn them off.
- To learn which of our campaigns bring companies to Postfox, from the campaign tags of the link a company’s creator arrived with. Legal basis: our legitimate interest in knowing what brings us customers (article 6(1)(f)). Telling Google Ads that one of our ads led to a signup, a first campaign or a first payment happens only with advertising on: where we ask first, only if that person accepted it (legal basis: their consent, article 6(1)(a)); elsewhere, until they turn it off or their browser sends Global Privacy Control.
- To issue your company’s invoices and keep them. Legal basis: our legal obligation to keep accounts (article 6(1)(c)).
The posts are drafted by a language model (section 6). No decision with a legal or similarly significant effect on you is made automatically: every post waits for your approval.
6. Who processes it for us
Where data leaves the European Union, it goes on one of two footings the European Commission provides: the EU-US Data Privacy Framework, for US companies that take part in it, or the Commission’s standard contractual clauses, written into the provider’s data processing agreement. Each provider’s is given below, as its own documents and the official Data Privacy Framework list stated them on 25 September 2026.
- Supabase: the application and its database, hosted on AWS in Paris. The database is encrypted at rest. Our contract is with Supabase Pte. Ltd, in Singapore, under the standard contractual clauses in its data processing agreement, which also govern any access from outside the EU, for support for instance. It also stores the images and documents you add to a post, in the same place.
- Vercel: serves the web application. Vercel Inc., in the United States, takes part in the Data Privacy Framework.
- Anthropic: the language models that write the posts. Text sent to them is not used to train their models. Our contract is with Anthropic Ireland, Limited, and its data processing agreement includes the standard contractual clauses. Anthropic stores the text in the United States and may process it in other countries.
- Resend: sends our emails, and stores them in the United States. Resend (Plus Five Five, Inc.) takes part in the Data Privacy Framework, and its data processing agreement includes the standard contractual clauses as well.
- PostHog: product analytics and masked session recordings, with measurement on (section 8): usage events (which page, which action) and recordings of how the pages are used, tied to a pseudonymous identifier. In a recording, every piece of text on the page and everything you type shows as asterisks, so PostHog receives no name, no email and nothing you write; the page addresses it receives have their access keys removed. PostHog, Inc., in the United States, takes part in the Data Privacy Framework.
- Google Analytics: only with measurement on: when your account is created, when your company launches a campaign, and when it first pays (or that payment is refunded), we tell Google Analytics, under the random identifier from postfox.ai’s cookies or, if you came straight to the product, an identifier made from your account’s own identifier, never from your email. It receives that identifier, the time, for a campaign how many people it includes, and for a payment the amount and currency; never your name, your email or anything you write, and no advertising signal. Our contract is with Google Ireland Limited; Google LLC, in the United States, takes part in the Data Privacy Framework.
- Google Ads: only with advertising on (which counts only with measurement, and stays off when your browser sends Global Privacy Control) and if you arrived from one of our Google ads: when you create your account, and when the company you created launches its first campaign and first pays, PostHog tells Google Ads that the ad led to it. Google Ads receives the identifier it put on the ad’s link, the time and, for the payment, the amount and currency; never your name, your email or anything you write. Withdrawing advertising stops it: your choice reaches your account the next time you open the product. Our contract is with Google Ireland Limited; Google LLC, in the United States, takes part in the Data Privacy Framework.
- LinkedIn: publishes the posts you approve, on your behalf, with their images or document, which it receives only when the post goes out.
- Slack: only if your company connects it, to ask you for approval by direct message. The messages are held in your company’s own Slack workspace, under your company’s agreement with Slack; Slack’s US company is covered by the Data Privacy Framework through Salesforce’s participation.
- Stripe: billing and invoices. Our contract is with Stripe Payments Europe, Limited, in Ireland; what it passes to Stripe, LLC in the United States is covered by the Data Privacy Framework, with the standard contractual clauses as a fallback.
The images and documents you add go to nobody else: not to Anthropic (the language models never see them), not to PostHog (recordings show them blank), and not to Resend or Slack (their messages only say how many there are).
We will update this list before it changes.
7. How long we keep it
- Your account data: for as long as your account exists. Deleting your account removes your profile, your writing profile, what you told us about your work, your times, your posts, the images and documents on them, the check records of those posts, the invitations sent to your address, and your address from our log of the emails we sent you. Our log of your sign-ins (your email address, and sometimes your name and the internet address you signed in from) is kept 30 days after the deletion, for security, and then deleted.
- Images and documents on a post: kept while the post is waiting or booked, and deleted 30 days after it is published (LinkedIn keeps its own copy, as part of your post), after you say “Not this time” to it, or after it is skipped. On a post you wrote and then deleted, they go when you delete it for good, or 30 days after you deleted it, whichever comes first.
- Check records: 90 days after their post is finished (published, “Not this time” or dropped); while a post is waiting or booked, its record stays.
- An email invitation nobody accepts: deleted, with the address in it, 30 days after it expires; our log of each invitation email, 44 days after sending. If an invitation bounced or was reported as spam, we keep only a one-way fingerprint of the address so that we never email it again.
- Error logs: kept to investigate failures; if you delete your account, your identifier is removed from them.
- Your company’s data: until your company asks us to delete it. If the last person in a company deletes their account, the company goes with them.
- Invoices: ten years, as French law requires of accounting records.
- Backups: none yet. On our current plan the database keeps no automated backup: point-in-time recovery is off and no daily copy is kept. We move to daily backups, kept seven days, before any company’s employees start using Postfox, and this line will then say so.
Posts already published on LinkedIn belong to your LinkedIn account and are not ours to remove.
8. Cookies and analytics in the product
The product uses the cookies needed to keep you signed in. In the European Economic Area, the United Kingdom and Switzerland, and wherever we cannot tell the country, product analytics and masked session recordings (PostHog) run only if you accept them in the product’s cookie banner, which asks before anything starts. Elsewhere there is no banner: they run until you turn them off in “Your privacy choices”, and a browser that sends the Global Privacy Control signal keeps advertising off. Our host reads the country of your connection to decide, and it is not kept. The same choice covers postfox.ai and app.postfox.ai: made on either, the latest one applies to both. With measurement on, your signup, your company’s campaign launches and its first payment are counted in Google Analytics; with advertising on too, Google Ads learns which of our ads led to them, as section 6 says. You can change your choice at any time from “Your privacy choices” in the product, or in its Settings, under Security. This website asks the same way: see section 13 and our Cookie Policy.
9. Your rights
Under the GDPR you can ask to access your data, correct it, delete it, receive a copy of it, restrict or object to its use, and withdraw a consent you gave. You can delete your account from your settings; for anything else, write to hello@postfox.ai and we will answer within one month. A copy of your data includes the check records of your posts, which are copies of your own material even though no screen shows them. You can also complain to the CNIL (www.cnil.fr) or your own data protection authority.
10. Security
Everything travels over TLS; the database is encrypted at rest; access to each person’s data is limited by rules in the database itself. No change to the database structure runs until a full export of it has been taken, restored and compared.
11. Children
Postfox is a service for companies and their employees, not for anyone under 16.
12. Changes
If this policy changes in a way that matters, we will say so in the product before it takes effect, and update the date above.
13. This website (postfox.ai)
This website presents Postfox and offers free tools; it has its own small backend, separate from the product’s. What it does with your data today:
- Hosting. Vercel serves this website and receives each request, with your IP address. Vercel Inc., in the United States, takes part in the Data Privacy Framework.
- Who is asked first. Visitors from the European Economic Area, the United Kingdom and Switzerland, and anyone whose country we cannot tell, see a banner with three choices of the same weight: Accept all, Refuse all and Customize. Until they choose, no analytics or advertising script loads and nothing is sent to Google or PostHog. Everyone else sees no banner: measurement and advertising are on until they turn them off in “Your privacy choices”, at the bottom of every page, and a browser that sends the Global Privacy Control signal keeps advertising off. Vercel reads the country of the connection to decide; it is not kept. A choice is kept in a
cookie_consentcookie, and its advertising part in acookie_advertisingcookie, each for 12 months and shared with app.postfox.ai. - Google Analytics 4. With measurement on: the pages you view and how you use them, with your browser, your device and an approximate location, under a random identifier kept in its cookies (
_ga,_ga_*) for 13 months. Its advertising features stay off unless advertising is on too, and Google signals are always off. Google keeps the events tied to that identifier for at most 14 months. Our contract is with Google Ireland Limited; Google LLC, in the United States, takes part in the Data Privacy Framework. - Where you came from. With measurement on: the campaign tags of the link that first brought you (such as which campaign it was), the page you arrived on and when, kept in a
pf_utmcookie for 90 days and shared with app.postfox.ai, so that if you create an account there, your company records where it came from (section 3). With advertising on too, the identifier Google Ads adds to the link of an ad you click is kept in apf_clickcookie for 90 days, so that Google Ads can learn that the ad led to an account, a first campaign or a first payment (section 6). Withdrawing removes both cookies. - PostHog. With measurement on: page views and events, recordings of your visit in which every piece of text on the page and everything you type shows as asterisks, heatmaps of where the page is clicked, how fast pages load, and errors they run into. Its identifier is kept in your browser for 12 months and shared with app.postfox.ai. PostHog, Inc., in the United States, takes part in the Data Privacy Framework.
- Cloudflare Turnstile. On the three free tools that write with AI, and on /admin, a page for our own team: Cloudflare’s security check reads signals such as your IP address and your browser to tell a person from a bot, and sets no cookie on postfox.ai. Cloudflare, Inc., in the United States, takes part in the Data Privacy Framework.
- The free tools’ daily counters. Four tools count your uses of the day in your browser’s local storage, to apply their daily free limit; the count is never sent to us.
- The “There’s An AI For That” badge. An image stored on postfox.ai and a plain link: nothing loads from their site, and no cookie is set, unless you click it.
- The free tools. What you paste into a tool is sent to this website’s backend and to Anthropic to produce the result, and it is not kept, with one exception: when the AI’s answer cannot be read, up to 500 characters of that answer, which can quote what you pasted, are kept in our error records and emailed to us, and the answer appears in the backend’s logs, so we can fix the problem. For each use we record which tool ran, what it cost, how long it took and whether it worked, with your IP address and the country and city ipapi.co gives for it; your IP address also limits how often the tools can be used, and that count is deleted after two days. These usage records have no automatic deletion yet: we delete yours on request. The backend is a Supabase project, under the same contract with Supabase Pte. Ltd as in section 6; Anthropic is described there too.
- Errors. When the backend fails, the error is logged, sometimes with the IP address of the request, and emailed to us through Resend.
We rely on our legitimate interest to run the free tools, to protect them from abuse and to fix errors, and, where we ask first, on your consent for the analytics and advertising you accept; elsewhere they run until you turn them off. Your rights are those of section 9.