Welcome to Postora ("we," "our," or "us"). Postora is committed to protecting your personal privacy when you access or use our mobile applications, web services, AI poster creation tools, and APIs (collectively, the "Services").
This Privacy Policy explains how we collect, store, process, transfer, and safeguard your personal information when you register an account, upload graphic design elements, subscribe to premium features, or interact with our support channels.
Key Commitment: We never sell your personal data or your private design assets to third-party advertisers. Your designs remain your personal property.
2. Information We Collect
We collect information to provide, personalize, and improve the Postora platform:
Account Registration Data: Full name, email address, password hash, profile picture URL, and business category details provided during sign-up or OAuth sign-in (e.g., Google Sign-In).
User Content & Canvas Assets: Design templates, text elements, background images, custom logos, and metadata uploaded to our canvas editor.
Technical & Device Data: Mobile device model, operating system version, unique device identifier (UUID), IP address, app language, and Firebase FCM push notification tokens.
Transaction & Billing Logs: Payment confirmations, active subscription tiers, and transaction IDs processed securely through third-party payment providers.
3. How We Use Your Information
Your information is processed strictly for legitimate operational purposes:
To authenticate user sessions, maintain account security, and enforce password rules.
To store and synchronize your graphic designs across multiple mobile and web devices.
To process AI poster generation prompts using secure third-party AI model providers.
To send critical push notifications regarding account verification, security alerts, and system updates.
To respond to user support inquiries, technical tickets, and feedback.
4. Third-Party Services & Integrations
Postora integrates trusted enterprise third-party services to deliver cloud infrastructure, authentication, and push notifications:
Google Firebase: OAuth authentication verification and Firebase Cloud Messaging (FCM) push notifications.
DevTunnels & Cloudflare: Secure API gateway routing and anti-spam verification.
5. Security & Data Retention
We implement industry-standard physical, electronic, and procedural safeguards designed to protect personal data from unauthorized access, loss, or alteration. All database connections require SSL/TLS encryption.
Personal data is retained as long as your account remains active. If you delete your Postora account, all associated personal profiles and stored design elements are permanently erased within 30 days.
6. Your Rights & Choices
Depending on your location (including rights under GDPR and CCPA), you have the right to:
Request access to a copy of the personal data we store about you.
Correct or update inaccurate account information directly from your profile settings.
Request permanent deletion of your account and all associated cloud project files.
Opt out of marketing notifications and promotional emails at any time.
7. Cookies & Local Storage
Postora uses secure HTTP cookies and local storage tokens (`accessToken` and `refreshToken`) solely for authentication session management and theme preference persistence. We do not use cross-site tracking cookies.
8. Contact Us Regarding Privacy
If you have questions, concerns, or data deletion requests regarding this Privacy Policy, please contact our Data Protection Officer at:
📧 Email:privacy@postora.com 📍 Address: Postora Legal Department, Tech Park Plaza, Floor 4 ⏱️ Response Time: Within 24-48 business hours