This policy explains how Vim Digital Oy (Business ID 3186318-3, Helsinki, Finland) handles personal data when you use Postapop at postapop.com and studio.postapop.com. You can reach us at hello@postapop.com.
Vim Digital Oy is the data controller for your own account: who you are, what you create, and how you use Postapop.
For messages and comments that other people send to a channel you connect, Vim Digital Oy is a data processor. The business that owns the channel is the controller: it decides why those conversations are held and what is done with them, and we handle them only on that business's instructions. If you contacted a business on Facebook, Instagram or Threads and want your data removed, ask that business first; write to us and we will help them act.
1. What we collect
- Account data. Your email address, name, and password (stored as a hash), and your workspace settings.
- Connected platform data. When you connect a social platform or design tool — including Facebook Pages, Instagram and Threads — we store the access tokens that authorization creates, your account identifiers on that platform, and the performance data the platform reports about your posts (for example impressions, saves, and clicks).
- Messages and comments from other people.If you use Postapop to read or answer the conversations on a channel you connect, we receive and store those messages and comments, the display name and platform handle of the person who wrote them, and when they were sent, and the identifiers the platform gives the person, the message and the conversation, and whether a message carried a photo or another attachment, which we need in order to reply. We do not store other people's profile pictures. Where Postapop shows one, it fetches it from the platform when you open the conversation. We hold this for the business that owns the channel, so it can reply. We do not use it for anything else, and we never use it to build profiles or to advertise.
- Content. The posts, drafts, media, notes, and source material you create or upload.
- Usage and technical data. Log data such as IP address, browser type, and actions in the service, used for security and to keep the service working.
- Support messages. What you send us when you contact us.
You need to provide account data to use the service; the rest depends on what you connect and create. We do not use automated decision-making that produces legal or similarly significant effects about you.
2. Why we process it, and on what legal basis
- To provide the service — storing your content, publishing to platforms you connect, showing you performance insights, generating AI drafts you ask for. Legal basis: performance of our contract with you (GDPR Art. 6(1)(b)).
- To keep the service secure and improve it — logs, debugging, aggregate usage analysis. Legal basis: our legitimate interest in running a secure, working product (Art. 6(1)(f)).
- To communicate with you — service messages under the contract; product news only with your consent, which you can withdraw at any time (Art. 6(1)(a)).
- To meet legal obligations — bookkeeping and responding to lawful requests (Art. 6(1)(c)).
3. AI features
When you use AI features — for example writing and checking posts and scripts, the assistant, reading your website, documents, images and Canva designs, and the topic labels and weekly summaries Postapop makes from your posts and their results — the relevant content is sent to our AI model providers to generate the result. We use providers under terms that do not permit them to use your content to train their models.
We never use data from Facebook, Instagram, Threads or YouTube to train AI models.
4. Data from connected platforms
Facebook, Instagram and Threads
When you connect a Facebook Page, an Instagram account or a Threads profile, Meta gives us access to data about that channel. We use it only to run Postapop for you:
- to show you a list of your own Pages and accounts, so you can choose which ones this workspace uses;
- to publish the posts you have written and scheduled;
- to read back how those posts performed, and show it to you in plain sentences;
- to show you the messages and comments people send to your channel, so you can answer them.
We do not sell this data. We do not combine one customer's data with another customer's. We do not use it for advertising, for building profiles of people, or to train AI models. We keep it only while you keep the channel connected, and we delete it when you disconnect or when you delete your account.
Connecting TikTok
When you authorize our native TikTok integration, we receive your TikTok account identifier, username, display name and profile picture, along with access and refresh tokens and the permissions you grant. We use these to identify the destination account and maintain the connection. Before direct publishing, we also request the account's available privacy settings, interaction permissions and video duration limit so we can apply TikTok's publishing rules.
When you choose to publish, schedule or send a video to TikTok, we process the video, caption and publishing settings you provide. We store the delivery identifier, status, timestamps and any errors returned by TikTok, together with your posting instructions. These records let us show what happened and avoid sending the same attempt twice. The native TikTok connection does not read your TikTok inbox, comments, follower list or analytics.
We send your chosen video and the metadata supported by the selected delivery method to TikTok. Sending a video to finish in TikTok delivers it to TikTok's notifications; it does not automatically save a draft or publish it. That video upload method does not transfer your caption, so the caption stays in Postapop for you to copy. TikTok processes the information it receives under its own Privacy Policy.
We use data received from TikTok only to provide and support this connection and the publishing actions you request. We do not sell it, use it for advertising or profiling, or use it to train AI models.
You can disconnect TikTok in Connections. A successful disconnect deletes the stored TikTok connection and its access and refresh tokens. If a delivery is in progress or scheduled, you may need to wait for it to finish or cancel the schedule first. Disconnecting does not remove content already sent to TikTok, your Postapop drafts, or the workspace's publishing history. Use TikTok to manage content there; contact us to request removal of retained TikTok data from Postapop, or delete the workspace that holds it.
We retain TikTok publishing records with the workspace until it is deleted or an applicable deletion request is fulfilled. Temporary media copies used for delivery are removed through our cleanup process after they are no longer needed; scheduled delivery copies are kept for the scheduled job. Copies in routine backups expire on the backup schedule. You can also revoke Postapop's access in your TikTok account settings.
Connecting YouTube
Postapop uses YouTube API Services to publish to, read numbers from, and read and answer comments on the YouTube channel you connect.
When you connect a channel we store its channel ID, title, handle and picture, the permissions you granted, and access and refresh tokens. While it stays connected we store the videos' titles and thumbnails, the numbers YouTube reports for your channel and videos, and the comments on your videos with the name and channel of each person who wrote them.
We use YouTube data only to run Postapop for you. We do not sell it, use it for advertising or profiling, or use it to train AI models. Google's Privacy Policy applies to the data Google processes.
5. Who we share data with
- Platforms you connect— we transmit your posts and read performance data at your direction. From that point the platform's own privacy policy applies. If you connect YouTube, Google's Privacy Policy applies to the data Google processes.
- Processors working for us — hosting and database infrastructure, AI model providers, and email delivery. They process data only on our instructions, under data processing agreements.
- Authorities — when the law requires it.
We do not sell personal data.
6. International transfers
Some of our processors operate outside the European Economic Area. Where they do, we rely on safeguards recognized by the GDPR — an adequacy decision such as the EU–US Data Privacy Framework, or the European Commission's Standard Contractual Clauses.
7. How long we keep data
- Account data and content: for as long as your account exists. When you delete your account, we delete them, except copies in routine backups, which are removed on their normal schedule.
- Platform access tokens: until you disconnect the platform or delete your account.
- Messages and comments from other people: while the channel stays connected, so the business can keep the conversation. They are deleted when the channel is disconnected or the account is deleted, and sooner if the business asks us to remove a conversation.
- YouTube comments: no longer than 30 days after we last saw them. Your videos' titles and thumbnails and your channel's name, handle and picture: we get them again from YouTube at least every 30 days, and we delete any we could not get again within 30 days. Numbers from YouTube: while the channel stays connected, and we check every 30 days that you still allow it. If you disconnect the channel in Postapop, YouTube data leaves Postapop within 7 days; we keep only the channel's ID on the closed connection record.
- Logs: for a short rolling period needed for security and troubleshooting.
- Records we must keep by law (for example bookkeeping): for the statutory period.
8. Delete your data
You can remove what Postapop holds about you in three ways:
- Disconnect a channel.In Connections, choose Disconnect next to a Facebook Page, Instagram account, Threads profile or other channel. Once the disconnect succeeds, we delete its stored access token. The TikTok section above explains what happens to pending deliveries and publishing history. You can also take Postapop's access to your YouTube channel away on Google's own page, at https://security.google.com/settings/security/permissions.
- Delete your account. In Settings, delete your account. We delete your workspace data, including uploads; copies in routine backups are purged on their schedule.
- Write to us. Email hello@postapop.com and we handle the request by hand.
When a request reaches us from Meta (you removed Postapop from your Facebook, Instagram or Threads settings and asked for deletion), we remove your Meta identity and every access token you granted, and we confirm with a code and a status page. Posts and statistics that belong to a workspace stay with that workspace: they are the business's records, not yours.
If you wrote to a business through Facebook, Instagram or Threads and want that conversation removed from Postapop, ask the business that owns the channel — it decides what happens to its own conversations. You can also write to us and we will pass the request on and help them carry it out.
9. Your rights
Under the GDPR you can:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data deleted;
- restrict or object to processing based on legitimate interest;
- receive your data in a portable format;
- withdraw consent at any time, where processing is based on it.
To use these rights, write to hello@postapop.com. If you think we handle your data unlawfully, you can complain to the Finnish Data Protection Ombudsman (tietosuoja.fi) or to the supervisory authority of your own EU country.
10. Security
We protect your data with technical and organizational measures appropriate to the risk: encrypted connections, access controls, row-level authorization in our database, and secrets kept out of client code. No system is perfectly secure; if a breach affects your data, we will notify you and the authorities as the law requires.
11. Cookies
Postapop uses cookies needed to sign you in and remember your preferences. See the Cookie Policy for details.
12. Children
Postapop is not directed at children. You must be at least 18 to use it.
13. Changes to this policy
We may update this policy as the service evolves. For material changes we will notify you in the service or by email. The date at the top tells you when it last changed.