This policy explains how Vim Digital Oy (Business ID 3186318-3, Helsinki, Finland) handles personal data when you use Postapop at postapop.com and studio.postapop.com. You can reach us at hello@postapop.com.
Vim Digital Oy is the data controller for your own account: who you are, what you create, and how you use Postapop.
For messages and comments that other people send to a channel you connect, Vim Digital Oy is a data processor. The business that owns the channel is the controller: it decides why those conversations are held and what is done with them, and we handle them only on that business's instructions. If you contacted a business on Facebook, Instagram or Threads and want your data removed, ask that business first; write to us and we will help them act.
1. What we collect
- Account data. Your email address, name, and password (stored as a hash), and your workspace settings.
- Connected platform data. When you connect a social platform or design tool — including Facebook Pages, Instagram and Threads — we store the access tokens that authorization creates, your account identifiers on that platform, and the performance data the platform reports about your posts (for example impressions, saves, and clicks).
- Messages and comments from other people. If you use Postapop to read or answer the conversations on a channel you connect, we receive and store those messages and comments, the display name and platform handle of the person who wrote them, and when they were sent, and the identifiers the platform gives the person, the message and the conversation, and whether a message carried a photo or another attachment, which we need in order to reply. We hold this for the business that owns the channel, so it can reply. We do not use it for anything else, and we never use it to build profiles or to advertise.
- Content. The posts, drafts, media, notes, and source material you create or upload.
- Usage and technical data. Log data such as IP address, browser type, and actions in the service, used for security and to keep the service working.
- Support messages. What you send us when you contact us.
You need to provide account data to use the service; the rest depends on what you connect and create. We do not use automated decision-making that produces legal or similarly significant effects about you.
2. Why we process it, and on what legal basis
- To provide the service — storing your content, publishing to platforms you connect, showing you performance insights, generating AI drafts you ask for. Legal basis: performance of our contract with you (GDPR Art. 6(1)(b)).
- To keep the service secure and improve it — logs, debugging, aggregate usage analysis. Legal basis: our legitimate interest in running a secure, working product (Art. 6(1)(f)).
- To communicate with you — service messages under the contract; product news only with your consent, which you can withdraw at any time (Art. 6(1)(a)).
- To meet legal obligations — bookkeeping and responding to lawful requests (Art. 6(1)(c)).
3. AI features
When you use AI drafting, the relevant content is sent to our AI model providers to generate the result. We use providers under terms that do not permit them to use your content to train their models.
We never use data from Facebook, Instagram or Threads to train AI models.
4. Data from Facebook, Instagram and Threads
When you connect a Facebook Page, an Instagram account or a Threads profile, Meta gives us access to data about that channel. We use it only to run Postapop for you:
- to show you a list of your own Pages and accounts, so you can choose which ones this workspace uses;
- to publish the posts you have written and scheduled;
- to read back how those posts performed, and show it to you in plain sentences;
- to show you the messages and comments people send to your channel, so you can answer them.
We do not sell this data. We do not combine one customer's data with another customer's. We do not use it for advertising, for building profiles of people, or to train AI models. We keep it only while you keep the channel connected, and we delete it when you disconnect or when you delete your account.
5. Who we share data with
- Platforms you connect— we transmit your posts and read performance data at your direction. From that point the platform's own privacy policy applies. If you connect YouTube, Google's Privacy Policy applies to the data Google processes.
- Processors working for us — hosting and database infrastructure, AI model providers, and email delivery. They process data only on our instructions, under data processing agreements.
- Authorities — when the law requires it.
We do not sell personal data.
6. International transfers
Some of our processors operate outside the European Economic Area. Where they do, we rely on safeguards recognized by the GDPR — an adequacy decision such as the EU–US Data Privacy Framework, or the European Commission's Standard Contractual Clauses.
7. How long we keep data
- Account data and content: for as long as your account exists. When you delete your account, we delete them, except copies in routine backups, which are removed on their normal schedule.
- Platform access tokens: until you disconnect the platform or delete your account.
- Messages and comments from other people: while the channel stays connected, so the business can keep the conversation. They are deleted when the channel is disconnected or the account is deleted, and sooner if the business asks us to remove a conversation.
- Logs: for a short rolling period needed for security and troubleshooting.
- Records we must keep by law (for example bookkeeping): for the statutory period.
8. Delete your data
You can remove what Postapop holds about you in three ways:
- Disconnect a channel. In Connections, choose Disconnect next to a Facebook Page, Instagram account, Threads profile or other channel. We delete the access token for it at once.
- Delete your account. In Settings, delete your account. We delete your workspace data, including uploads; copies in routine backups are purged on their schedule.
- Write to us. Email hello@postapop.com and we handle the request by hand.
When a request reaches us from Meta (you removed Postapop from your Facebook, Instagram or Threads settings and asked for deletion), we remove your Meta identity and every access token you granted, and we confirm with a code and a status page. Posts and statistics that belong to a workspace stay with that workspace: they are the business's records, not yours.
If you wrote to a business through Facebook, Instagram or Threads and want that conversation removed from Postapop, ask the business that owns the channel — it decides what happens to its own conversations. You can also write to us and we will pass the request on and help them carry it out.
9. Your rights
Under the GDPR you can:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data deleted;
- restrict or object to processing based on legitimate interest;
- receive your data in a portable format;
- withdraw consent at any time, where processing is based on it.
To use these rights, write to hello@postapop.com. If you think we handle your data unlawfully, you can complain to the Finnish Data Protection Ombudsman (tietosuoja.fi) or to the supervisory authority of your own EU country.
10. Security
We protect your data with technical and organizational measures appropriate to the risk: encrypted connections, access controls, row-level authorization in our database, and secrets kept out of client code. No system is perfectly secure; if a breach affects your data, we will notify you and the authorities as the law requires.
11. Cookies
Postapop uses cookies needed to sign you in and remember your preferences. See the Cookie Policy for details.
12. Children
Postapop is not directed at children. You must be at least 18 to use it.
13. Changes to this policy
We may update this policy as the service evolves. For material changes we will notify you in the service or by email. The date at the top tells you when it last changed.