Private betaSuperPost is in private beta. Buy annually and today's price is locked for your full 12 months.Lock pricing →
superpost

Privacy Policy

What we collect, why we collect it, and how to control it.

Last updated

Working draft pending review. Final legally-binding text will be published with the production launch.

Who we are

The SuperPost service is operated by the company defined in the Acceptance section of our Terms of Service at superpost.io/legal/terms ("SuperPost", "we", "us"). For personal data you provide directly to the service, that company is the data controller. Its full legal-entity details, including registered address, are available on request from privacy@superpost.io; day-to-day contact routes are in the Contact section below.

What we collect

Account data: email, name, billing address, payment method (held by Stripe).

Project data: the source you point us at. Today that is a public repository URL you connect, or a folder you upload as a zip. We read what that source exposes — code, README, release notes, commit messages — to understand what your product does. We do not install a GitHub App and we do not read private repositories, issues, or pull requests. If that changes we will update this section before it ships.

Generated content: posts, video, audio, and replies the service produces from your data.

Voice data, only if you opt in to voice cloning: the samples you record, a derived voice embedding, and the consent record authorising their use. See 'Voice cloning' below.

Usage data: events from the dashboard, CLI, and API for product analytics.

How we use it

We use your data to operate the service: to generate content, publish it to the platforms you connect, charge for subscriptions, support you, and improve the product.

We do not sell your data. We do not train third-party models on your data.

How we use your voice

If you opt in to voice cloning, your voice samples and the resulting clone are sent to ElevenLabs (our voice-synthesis subprocessor) and used to (1) generate audio for short-form video renders and any other outbound voice content you ask us to publish, and (2) — separately, only if you opt in a second time during onboarding — synthesize your cloned voice on every generated draft as part of an internal quality check that scores whether the draft sounds like you. The internal critic audio is never published; it is compared to your voice samples by an automated voice-drift score and is deleted within 24 hours unless you explicitly enable retention. You can withdraw either consent at any time from Settings → Voice; withdrawal takes effect immediately for new processing.

How we use your edits

When you edit a generated draft before publishing, we store the original and edited text in a per-workspace edit ledger and feed it into an automated learning loop that updates the prompt context, bandit weights, and persona-drift score for future drafts in your workspace. Edits never leave your workspace; they are not shared with other customers, sold, or used to train third-party foundation models. You can request deletion of your edit ledger at any time from Settings → Privacy, and it is deleted with the rest of your workspace data when you delete your account. There is no separate switch to stop edit capture while you continue editing drafts; contact support if you want capture disabled for your workspace.

How we measure post outcomes

After we publish a post on your behalf to a platform you have connected — X, TikTok, or YouTube — we poll that platform's public API at fixed intervals (1 hour, 6 hours, 24 hours, 7 days) to collect public engagement metrics (views, likes, reactions, comments, reshares, and watch-time where the platform exposes it) and store them per post. We only poll posts the engine published; we do not crawl your accounts or scrape historical content. If you have connected a GitHub repository, we also record an hourly snapshot of your repository's public star count so that we can attribute new stars to recent posts on a best-effort time-window basis. These outcomes feed an automated per-workspace learning loop that selects future hooks, formats, and post times. None of this is shared with other workspaces unless you opt in to the cross-workspace leaderboard described below.

Cross-workspace leaderboard (opt-in)

Off by default. The workspaces.public_leaderboard_opt_in flag is the source of truth, and today it is set through the API (POST /v1/workspaces/{id}/showcase, workspace admins only) or by asking support — there is no dashboard toggle yet.

Enabling it does two distinct things. Your high-performing posts enter an anonymized cross-workspace winner library that bootstraps defaults for new workspaces and powers superpost.io/leaderboard; before a post enters, we strip @handles, URLs and owner/repo slugs, and the workspace appears only as a one-way hash. Separately, the rendered media of your published posts and their C2PA provenance manifests are copied to a world-readable bucket serving superpost.io/showcase — that copy is your real content and is not anonymous.

Turning it off stops future contributions from the next collection run onward. It does not retroactively delete existing winner-pool entries or already-published showcase media. Deleting your account erases the showcase bucket along with your other data; to remove showcase media without deleting your account, email privacy@superpost.io.

The shared pool is never used to identify or contact other workspaces.

Folder uploads (R2 + workspace scope)

If you upload a zipped folder as an alternative to connecting a GitHub repository, we extract it to Cloudflare R2 object storage under a workspace-scoped prefix (workspaces/{workspace_id}/projects/{project_id}/). The R2 bucket policy denies cross-workspace reads; only members of the uploading workspace can access those objects, and access goes through a signed-URL exchange that is bound to the workspace. Uploads are retained while the workspace is active and deleted within 30 days of workspace deletion. Uploads are deleted with the rest of your workspace data when you delete your account (Settings → Privacy). Removing one specific upload while keeping the workspace is not yet self-service; contact support and we will delete it.

Who we share with

Subprocessors: cloud infrastructure, model providers, payment processing, email delivery, analytics. The full list is at superpost.io/legal/subprocessors.

Law enforcement: only when compelled by valid legal process.

Why we are allowed to use your data

Under UK/EU data protection law we need a lawful basis for each purpose. Ours:

Providing the service — running the engine, generating and publishing your content, storing your projects: performance of our contract with you.

Billing, invoicing and tax records: performance of the contract, and our legal obligations for financial record-keeping.

Account security, abuse prevention, and platform-policy enforcement: our legitimate interest in keeping the service safe and available.

Product analytics and improving generation quality for your own workspace: our legitimate interest in making the product work better. You can object; contact privacy@superpost.io.

Voice cloning, and the internal critic that synthesises your cloned voice to score drafts: your explicit consent, obtained separately for each purpose and withdrawable at any time. A voiceprint is biometric data, so consent is the only basis we rely on and we do not fall back to legitimate interest.

Including your anonymised winning posts in the cross-workspace library: your consent, given by turning the switch on. It is off by default.

Marketing email about our own product to existing customers: legitimate interest, with an unsubscribe link in every message. Any other marketing: consent.

Responding to legal process and defending legal claims: compliance with a legal obligation, and our legitimate interest in establishing or defending claims.

Where we rely on legitimate interest we have weighed it against your rights and concluded it does not override them; you can ask us for that assessment.

Where your data goes

We are based outside the EEA and most of our subprocessors are in the United States, so using the service involves transferring personal data internationally. The full list of who receives what, and where they are, is at superpost.io/legal/subprocessors.

For transfers out of the EEA, UK or Switzerland we rely on the European Commission's Standard Contractual Clauses (2021/914), with the UK International Data Transfer Addendum where the UK GDPR applies, incorporated into our contracts with each processor. Where a provider is certified under the EU-US Data Privacy Framework we may rely on that instead. We assess each transfer for the risks specific to the destination country and apply additional measures — encryption in transit and at rest, access controls, and data minimisation — regardless of the mechanism.

Some data is deliberately kept in the EU: our product analytics runs on EU-hosted infrastructure, and our consent management provider is in Denmark.

You can ask us for a copy of the transfer safeguards that apply to your data by emailing privacy@superpost.io.

Automated decisions and profiling

The service is automated by design, so it is worth being precise about what that means for you.

We build a per-workspace profile of what works — which hooks, formats, and posting times earn engagement — and an automated selection process (a multi-armed bandit) uses it to choose what to generate and when to post. In autopilot mode the engine can publish without you approving each post first, subject to the safety gates, quiet hours, and per-platform limits you configure. You can turn autopilot off, require approval for every post, or veto any individual post before it ships.

These decisions are about content, not about you: they do not determine your access to the service, your price, your creditworthiness, or anything else with a legal or similarly significant effect. On that basis we do not consider them to fall within the GDPR Article 22 restriction on solely automated decision-making. We are stating our reasoning rather than asking you to take it on trust, and this analysis is one of the items in our external counsel review — if that review disagrees, this section changes.

Suspending an account for abuse or a platform-policy breach is a decision with real consequences, so it is never fully automated: automated signals flag an account, a human decides, and you can appeal to privacy@superpost.io.

AI-generated content is separately disclosed at superpost.io/legal/ai-disclosures.

Age requirement

SuperPost is a business tool and is not directed at children. You must be at least 16 to create an account. Where local law sets a lower digital-consent age (13 in the United States under COPPA, and 13-15 in some EU member states), we still require 16 — a single higher bar is simpler to hold ourselves to than a map of exceptions.

We do not knowingly collect personal data from anyone under 16. If you believe a child has given us their data, email privacy@superpost.io and we will delete the account and its data promptly.

Your rights

You can export or delete your data from the dashboard at any time.

If you are in the EU, EEA, UK or Switzerland you have the rights to access your data, to have inaccurate data corrected, to have it erased, to restrict or object to how we use it, to receive it in a portable format, and — where we rely on your consent — to withdraw that consent at any time. Withdrawing consent does not affect processing that already happened while it was valid. Voice-clone consent is withdrawable in one action from Settings → Voice.

California residents have additional rights under the CCPA/CPRA, including to know, delete, correct, and to limit the use of sensitive personal information. We do not sell personal information and we do not share it for cross-context behavioural advertising.

We answer rights requests within one month. If a request is unusually complex we may extend that by two further months and will tell you why within the first month. We do not charge for this.

You also have the right to lodge a complaint with a data protection supervisory authority — normally the one where you live, work, or where you believe the problem occurred. In the EU, the list is at edpb.europa.eu/about-edpb/about-edpb/members_en; in the UK it is the Information Commissioner's Office at ico.org.uk. You do not need to contact us first, though we would rather you did, so we can fix it.

Contact privacy@superpost.io to exercise any of these rights.

Retention

Different categories are kept for different periods. The table below mirrors the machine-readable policy our automated pruner enforces (infra/retention/policy.yml); if the two ever disagree, that is a bug and we want to hear about it.

Account and profile — kept for the life of the account. Deleting your account starts the erasure flow: a 30-day grace window, then hard deletion.

Posts, variants and publishes — 90 days after the workspace is deleted.

Soft-deleted content (your trash) — 30 days, then hard-deleted.

Draft edits (the original/edited pairs behind per-workspace learning) — 90 days.

Raw telemetry and product events — 90 days.

Per-day published-post metrics — 3 years. De-identified monthly rollups are kept indefinitely; they no longer identify a workspace.

Post outcomes, attribution, and workspace winners/losers — 1 year.

Repository star snapshots — 90 days.

Raw voice audio — 24 hours, unless you opt in to retention. Audio for a deleted voice profile — 30 days. Voice embeddings — deleted immediately when the voice profile is deleted.

Workspace personas — kept while the workspace is active; this is configuration, not telemetry.

Support conversations — 3 years after closure.

Billing records and invoices — 7 years, as US tax law requires.

Compliance audit log — 1 year in the live system. Older entries are archived rather than destroyed, because they are the evidence that our controls worked.

Encrypted backups — 35 days, managed by our database provider.

A legal hold (litigation, a regulatory request) pauses deletion for the affected records until the hold lifts. We will tell you if one applies to your data unless we are legally barred from doing so.

Contact

Questions about this policy: privacy@superpost.io. Data Protection Officer: dpo@superpost.io.