PostBakery

Privacy Policy

Last updated: 30 June 2026

This Privacy Policy explains how PostBakery ("PostBakery", "we", "us", or "our") collects, uses, shares, and protects your personal data when you use our website at postbakery.aiand our related services (the "Service"). We are committed to processing personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Bulgarian data-protection law.

1. Who we are (Data Controller)

The data controller responsible for your personal data is:

  • [Company Name] EOOD
  • Registered in the Republic of Bulgaria, UIC (ЕИК): [Registration No.]
  • Registered address: [Registered address]
  • Contact for privacy matters: privacy@postbakery.ai

2. What data we collect

2.1 Account data

When you create an account we collect your email address and a securely hashed version of your password. We never store your password in plain text.

2.2 Brand and project data

To generate on-brand content we process the information you provide about your brand: project names, brand voice descriptions, website URLs, uploaded screenshots, extracted color palettes, and the prompts you write. We also store the images and captions we generate for you.

2.3 Data from connected Meta accounts (Facebook & Instagram)

If you choose to connect a Facebook Page or Instagram Business account in order to publish posts, we access and store only the data needed to provide that feature:

  • The Facebook Page ID and name, and the Instagram Business account ID and username, that you select.
  • Access tokens issued by Meta, which are encrypted at rest and used solely to publish content you explicitly create and approve.
  • The granted permission scopes (for example instagram_content_publish, pages_manage_posts).

We request these permissions through Meta's official Login flow and use them only to publish the posts you generate in PostBakery to the accounts you connect. We do not read your private messages, we do not post without your action, and we do not use Meta Platform Data for advertising or profiling.

2.4 Payment data

Paid subscriptions are processed by Stripe. We do not collect or store your full card number. We receive from Stripe a customer identifier, subscription status, and limited billing metadata needed to manage your plan.

2.5 Usage and device data

We collect basic usage analytics (pages visited, features used, and product events such as sign-up or post generation) through PostHog, along with technical data such as IP address and browser type. This helps us operate, secure, and improve the Service.

3. How we use your data and our legal bases

PurposeLegal basis (GDPR Art. 6)
Providing the Service (accounts, generation, publishing)Performance of a contract
Processing payments and managing subscriptionsPerformance of a contract
Securing the Service and preventing abuseLegitimate interests
Product analytics and improvementLegitimate interests / consent where required
Complying with legal and accounting obligationsLegal obligation

4. Third parties and sub-processors

We share data only with service providers who process it on our behalf and under contract:

  • Meta Platforms — to publish content to your connected Facebook and Instagram accounts.
  • Anthropic and OpenAI — to generate captions and images from your prompts and brand inputs.
  • Stripe — payment processing.
  • Amazon Web Services / CloudFront — hosting and media storage and delivery.
  • PostHog — product analytics.

We do not sell your personal data, and we do not share Meta Platform Data with any party except as needed to deliver the publishing feature you requested.

5. International transfers

Some of our sub-processors are located outside the European Economic Area. Where data is transferred internationally, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

6. Data retention

We keep your account and content data for as long as your account is active. Meta access tokens are retained only while a connection is active; when you disconnect an account or delete your PostBakery account, the related tokens and connection data are deleted. Certain records (such as invoices) may be retained longer where required by law. See our Data Deletion page for details.

7. Security

We use industry-standard measures including encryption in transit (TLS), encryption of access tokens at rest, hashed passwords, and access controls. No method of transmission or storage is completely secure, but we work to protect your data and to limit access to it.

8. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict, and port your personal data, and to object to certain processing. You may exercise these rights at any time by emailing privacy@postbakery.ai. You also have the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection (КЗЛД) or your local supervisory authority.

9. Deleting your data

You can delete your account and all associated data from within the application, by email, or — for data we accessed through Meta — by removing PostBakery from your Facebook settings, which triggers automatic deletion on our side. Full instructions are on our Data Deletion page.

10. Children

The Service is not directed to individuals under 16, and we do not knowingly collect their personal data.

11. Changes to this policy

We may update this Privacy Policy from time to time. We will revise the "Last updated" date above and, where changes are material, provide additional notice.

12. Contact us

For any privacy question or request, contact us at privacy@postbakery.ai.

PostBakery

Fresh-baked, on-brand Instagram posts in seconds.

Product

  • Pricing
  • Log in
  • Get started

Legal

  • Privacy Policy
  • Terms of Service
  • Data Deletion

© 2026 PostBakery. All rights reserved.

Baked with care in Bulgaria.