Privacy Policy
Last updated: May 12, 2026
This privacy policy describes how PostFlip (postflip.app) collects, uses and protects your personal data, in accordance with the General Data Protection Regulation (GDPR - EU Regulation 2016/679).
1. Data controller
The data controller is the individual operator of PostFlip. For any request regarding your data, contact: hello@postflip.app
2. Data collected
2.1 Account data
When you create an account, we collect your email address and, where applicable, your name. This data is required to authenticate you and manage your subscription.
2.2 Submitted content
The LinkedIn posts you submit to PostFlip are processed by our API to generate the reformatted versions. On the free plan, content is not retained after the session. On the Pro plan, your recasts are saved to your account to build your history.
Your content is never used to train artificial intelligence models.
2.3 Payment data
Payment data (card number, etc.) is processed exclusively by Stripe, Inc. PostFlip stores no banking data. Stripe is PCI-DSS Level 1 certified.
2.4 Technical data
For the proper functioning of the service, we may process limited technical data: IP address and user agent linked to authentication sessions, browser type, pages visited and usage events (sign-in, recast launched). This data is used for security, diagnostics and service improvement.
2.5 Service emails
We send emails related to your use of the service: a welcome email, a follow-up after your first recast, and usage reminders at day 3 and day 7. These emails are sent only when the "Product and news emails" preference is enabled in your profile. Some emails remain essential to operate the service, including security, billing, payment, and quota notifications. They are sent even when non-essential emails are disabled.
3. Legal basis for processing
- Performance of the contract for the provision of the service
- Legitimate interest for security and fraud prevention
- Legal obligation for the retention of accounting data
- Consent for marketing communications, where applicable
4. Processors
PostFlip uses the following processors, all subject to GDPR compliance commitments:
- Supabase, Inc. - database hosting (AWS infrastructure, eu-west-1 region)
- Stripe, Inc. - payment processing
- Vercel, Inc. - application hosting
- Anthropic, PBC - content generation via API (your data is not used for training)
- Resend, Inc. - delivery of service emails. Data sent may include your email address, name, email content, and technical data required for delivery
- PostHog, Inc. - product analytics (loaded only after your consent)
- Google LLC - Google Analytics 4 and Google Tag Manager for audience measurement, only if configured and after your consent
5. Retention period
- Account data: kept until the account is deleted
- Pro history: kept as long as the account is active
- Billing data: 10 years (legal obligation)
- Technical logs and session data: limited to what is necessary for security, diagnostics and applicable legal obligations
6. Your GDPR rights
In accordance with the GDPR, you have the following rights over your personal data:
- Right of access to your data
- Right of rectification
- Right to erasure ("right to be forgotten")
- Right to restriction of processing
- Right to portability
- Right to object
To exercise these rights, contact hello@postflip.app. We respond within 30 days. You may also lodge a complaint with the CNIL: www.cnil.fr.
7. Cookies
PostFlip uses two categories of cookies:
Strictly necessary cookies (no consent required): authentication session and preferences (theme, language). They are essential for the service to work.
Analytics cookies and trackers (consent required): no analytics cookie or tracker is set before your explicit consent. If you accept via the cookie banner, and the relevant services are configured, we may load:
- Google Analytics 4 and Google Tag Manager (Google LLC) - traffic statistics, anonymized IP
- PostHog (PostHog, Inc.) - product usage analytics
You can withdraw your consent at any time with the "Manage cookies" button available at the bottom of every page; trackers are then disabled and the banner reappears so you can make a new choice. Google Consent Mode v2 defaults to "denied" until consent is given.
8. Transfers outside the EU
Some processors may be established outside the European Union, including Stripe, Vercel, Anthropic, Resend, Google and PostHog depending on the services enabled. Where such transfers occur, they are covered by a GDPR-recognized mechanism, such as an adequacy decision or standard contractual clauses, together with the provider's applicable safeguards.
9. Changes
We may update this policy at any time. The date of the last update is shown at the top of the page. In the event of a substantial change, you will be notified by email.