Privacy Policy

PostChute — Policy version: [VERSION] — Last updated: [DATE] — Effective from: [DATE]

1. Who we are

PostChute is operated by Rebecca Brown, a sole trader trading as "PostChute" in the United Kingdom. Our contact address is Level One, Basecamp Liverpool, 49 Jamaica Street, Liverpool, L1 0AH.

As a sole trader, Rebecca Brown is personally the data controller responsible for your personal data under UK GDPR.

We are registered with the Information Commissioner's Office (ICO) under registration number ZC166256.

For privacy-related questions: data@postchute.com

In this policy, "we", "us", and "our" refer to Rebecca Brown trading as PostChute. "You" and "your" refer to the person using PostChute.

2. What this policy covers

This policy explains what personal data we collect when you use PostChute, why we collect it, how long we keep it, who we share it with, and what rights you have over it.

PostChute connects your Notion workspace to your WordPress site using AI agents (via an AI API you choose and provide — currently Anthropic or OpenAI) to draft, optimise, and publish blog content. The decision to publish, the destination, and the schedule remain under your control.

3. If you join the waitlist

This section applies to you before you have a PostChute account — that is, while you are on our waitlist. Once you accept a beta invitation and create an account, you become an app user, and the rest of this policy (sections 4 onwards) applies to you instead. See section 3g.

3a. What we collect and why

WhatWhyLegal basis
Email addressTo add you to the PostChute waitlist and email you about your position on it and about the public launchConsent — you asked us to keep you informed
Sign-up date and sourceRecorded automatically by our email provider as evidence that you consentedLegal obligation — UK GDPR requires us to demonstrate consent
The content of any reply you send to our qualifying email (see 3b)To assess whether PostChute is a fit for you and when to offer you a placeConsent — you choose whether to reply

We collect nothing else at the waitlist stage. You do not need an account, a password, or any third-party credentials to join the waitlist.

Why consent and not contract. Unlike an account holder, you have not entered into any contract with us — you have simply asked to be kept informed. UK GDPR requires consent as the lawful basis for that. Because the messages are sent by email, the Privacy and Electronic Communications Regulations (PECR) also require your consent for them. You give that consent when you submit your email address on our waitlist form, which clearly states what you are signing up for and links to this policy.

3b. The qualifying email and your reply

Shortly after you join the waitlist, we send you one email confirming we have received your details and asking whether PostChute currently fits your setup (Notion, WordPress, and your own AI provider API key). Replying is entirely optional and helps us decide when to offer you a place. If you reply, your message is delivered to our inbox and we process it only for that purpose. We do not ask for, or need, any sensitive information in your reply.

3c. What we will and will not send you

We will email you only to:

  • confirm your details and ask the qualifying question described in 3b;
  • tell you about your position on the waitlist, including when a beta place becomes available to you (your invitation); and
  • announce the public launch.

We will not use your email address for any other marketing, and we will never share it with anyone else for their marketing.

3d. Your choices and withdrawing consent

Because we rely on your consent, you are in control of what you receive. Our emails give you two options:

  • Stop the qualifying emails but stay on the waitlist. You will no longer receive the qualifying series, but you remain on the waitlist and will still be told about the public launch.
  • Unsubscribe completely. This removes you from the waitlist entirely and stops all emails from us.

You can also contact us at data@postchute.com to be removed at any time. Withdrawing your consent does not affect the lawfulness of anything we did before you withdrew it.

3e. Who we share waitlist data with

We do not sell your data. We use the following processors to operate the waitlist, each under a Data Processing Agreement (DPA):

ProcessorWhat dataWhyLocation
Mailjet (Sinch)Email address; sign-up date and sourceTo store the waitlist and send you the emails described aboveEU — hosted on Google Cloud Platform in Frankfurt (Germany) and Saint-Ghislain (Belgium) (we have accepted Mailjet's DPA)
Cloudflare, Inc.Email address (in transit)Our waitlist form is received by a Cloudflare service that passes your email to Mailjet; your email is not stored on CloudflareGlobal edge network, in transit only (we have accepted Cloudflare's DPA, which includes international transfer safeguards)
Mailgun (Sinch)The content of any reply you send to our qualifying emailTo receive your reply and forward it to our mailboxEU (we have accepted Mailgun's DPA)
Google (Google Workspace)The content of any reply you send to our qualifying emailTo receive and store your reply in our mailboxUnited States (Google Workspace Data Processing Amendment and international transfer terms accepted)

3f. How long we keep it

We keep your waitlist data until the earlier of:

  • you unsubscribing or asking us to remove you; or
  • 6 months after the public launch, after which we delete any waitlist contacts who have not become account holders.

Replies to our qualifying email are kept only for as long as you remain on the waitlist, and are deleted when you leave it or when you become an account holder.

3g. When you become an app user

If you accept a beta invitation and create an account, you stop being a waitlist contact and become a PostChute app user. From that point, the rest of this policy governs how we handle your data, and the lawful basis for your account data becomes Contract (see section 4 onwards) rather than consent.

4. The data we collect, why, and our legal basis

4a. Account credentials

WhatWhyLegal basis
Email addressTo identify your account, send transactional emails, allow sign-inContract
Password (hashed — we never see it)To authenticate youContract

4b. Display name

WhatWhyLegal basis
Display name (optional)To address you in the app and emailsContract

4c. Third-party service credentials

WhatWhyLegal basis
Notion access tokenTo read your Notion database on your behalfContract
WordPress API URL and application passwordTo publish content to your WordPress siteContract
Anthropic API key (if you use Anthropic as your AI provider)To generate content using Claude AIContract
OpenAI API key (if you use OpenAI as your AI provider)To generate content using OpenAI modelsContract
Google Gemini API key (optional — only if you enable AI image generation)To generate featured images for your postsContract
Tavily API key (optional — only if you enable web research during quality checks)To search the web for current information used to fact-check and refresh your postsContract

All credentials are encrypted at rest (AES-256-GCM) with the encryption key held separately. Credentials are decrypted only when a pipeline run needs them. Credential values are never included in data exports, logs, or API responses.

4d. Pipeline run history

WhatWhyLegal basis
Run status, timestamps, error messagesDashboard history, service monitoring, anonymised aggregate statisticsLegitimate interests — statistics are aggregated and anonymised so no individual can be identified

Our balancing assessment: We have considered whether our use of pipeline run history for aggregate marketing statistics could be overridden by your interests. We believe it cannot, because: (a) the statistics we publish cannot identify any individual user; (b) the data used is operational in nature (counts and timestamps, not content); and (c) you would reasonably expect a software product to track whether its own pipelines succeed or fail. Run records are linked to your account for 30 days only; after that they are detached and anonymised into aggregate counts that cannot identify you (see section 9).

4e. Privacy consent record

WhatWhyLegal basis
Timestamp of policy acceptance at sign-upAudit trail demonstrating informed consentLegal obligation

4f. Support chat conversations

WhatWhyLegal basis
The content of messages you send in the in-app support chatTo generate a relevant response to your question using AILegitimate interests — providing effective support for PostChute users
Conversation turn count and timestamps, not message contentTo enforce fair-use rate limits and manage service costsLegitimate interests — protecting service integrity

The support chat is available to signed-in users. It works only from our help documentation and what you type — it has no access to your account data, your credentials, or your content. Your messages are processed in memory to generate a reply and are never written to our database or linked to your account. The chat history you see exists only in your browser and disappears when you close the chat.

Support chat messages are sent to Anthropic via PostChute's own Claude API account to generate a response — Anthropic processes them on our behalf (see section 7). PostChute does not store support chat message content after your browser session ends. Please don't include personal data in your messages that isn't needed to answer your question — for anything account-specific, email data@postchute.com instead.

5. Data we do not collect

  • The content of your Notion pages beyond what is needed to process and publish them
  • Any data from your WordPress site beyond a successful publish confirmation (status code and post URL)
  • Location data
  • Any data from your device beyond standard web server access logs

Support chat messages are transiently processed while you use the chat, but are not stored by PostChute after the session ends.

Content belonging to other people. The Notion pages you process may include personal data about people other than you (for example, a name mentioned in a draft post). During a pipeline run we handle that content only transiently, on your instructions, for the sole purpose of drafting, refining, and publishing your post. We do not store it beyond what the run needs, and we do not use it for any other purpose. You remain the data controller for the content you choose to process and publish.

6. Server logs, cookies, and browser storage

Our servers automatically generate access logs (IP address, browser type, pages visited, timestamps). We use these logs to monitor for errors and security issues.

We retain server logs for 30 days, after which they are automatically deleted. We consider this period proportionate for security monitoring and error diagnosis.

Cookies and browser storage. When you sign in to PostChute, a session token is stored in your browser so that you stay signed in as you move around the app. This is strictly necessary for the service to function — without it, you would have to sign in again on every page. Because it is strictly necessary, it does not require your consent under PECR, but we tell you about it here for transparency. We do not use advertising cookies, analytics cookies, or any other tracking technologies.

7. Who we share your data with, and where it goes

We do not sell your personal data. We use the following data processors under Data Processing Agreements:

ProcessorWhat dataWhyLocation
Supabase Inc.All data in section 4Database and authenticationEU (DPA accepted)
Google Cloud PlatformServer logs; application runtimeCloud hostingEU — europe-west2 (DPA accepted)
Anthropic, PBCSupport chat message content for the duration of a support session only (not stored by us)AI inference for support chat responsesUnited States (we use Anthropic's commercial terms, which include data processing and international transfer safeguards)
Mailgun (Sinch)Your email address and the content of transactional emails (e.g. account invitations and privacy-policy update notices)To send you service emails about your accountEU (we have accepted Mailgun's DPA)

When you connect to Notion, WordPress, your chosen AI provider, or the optional image-generation and web-research services described below, your credentials are transmitted directly to those services to authenticate requests made on your behalf. Those services are independent data controllers for the data you hold with them, and are subject to their own privacy policies. We encourage you to read them:

International transfers

Data we hold about you. The data described in section 4 is stored with our processors in the EU (see the table above). UK law recognises the EU/EEA as providing adequate protection for personal data, so no additional transfer safeguards are required. For waitlist data, the transfers involved (including to Google in the United States) and the safeguards covering them are set out in section 3e.

Support chat conversations. Messages you send to the support chat are processed by Anthropic in the United States, as our processor, under the commercial terms referred to in the table above.

Content sent to services you connect. Anthropic, OpenAI, Google, and Tavily are United States companies. When a pipeline run uses your chosen AI provider, the content of the post being prepared is transmitted to that provider, using the API key you supplied, and is handled under that provider's own terms and privacy policy (linked above). This can include Research Pack notes, linked Notion-page content, supported attachments, and public-page extracts that you choose to add to a post. PostChute handles this material only for the active run and does not store extracted research in its run history. If you enable the optional features, an image-generation prompt for your post is sent to Google's Gemini API, and public URLs in a Research Pack are sent to Tavily for extraction — each using the API key you supplied. These optional features are off unless you provide the relevant key, and you can stop using any of these services at any time by removing its key. Similarly, where your published posts go depends on where your WordPress site is hosted, which is under your control.

8. Your rights

Under UK GDPR, you have the following rights. You can exercise any of these by contacting us at data@postchute.com.

Right of access. You can request a copy of the personal data we hold about you. We provide a self-service data export in your account settings (Account → Download my data). The export contains all personal data we hold, excluding credential values (see section 4c).

Right to erasure. You can delete your account at any time from your account settings (Account → Delete account). Deletion is permanent and removes all data associated with your account from our active systems. This cannot be undone. Two things to be aware of:

  • Server logs may retain your IP address for up to 30 days after deletion (see section 6).
  • We retain a minimal, non-identifying record of the deletion itself (timestamp and an internal reference) so that we can demonstrate, if asked, that we honoured your request. This record contains no email address, name, or other personal data that could identify you. See section 9 for the retention period.

Right to rectification. You can update your display name and email address at any time from your account settings.

Right to data portability. Your data export (described under Right of access above) is provided in JSON format, which is machine-readable and can be imported into other systems.

Right to object. You have the right to object to any processing we base on legitimate interests. At present, that means our use of pipeline run history (see section 4d), including its use in anonymised aggregate marketing statistics, and the support chat (see section 4f) — though the simplest way to object to the support chat is just not to use it. To exercise this right, contact us at data@postchute.com. As with all rights requests, we will respond within one calendar month (see below).

Right to restrict processing. In certain circumstances, you can ask us to restrict the processing of your data while a dispute is resolved.

Automated decision-making. We do not make any solely automated decisions about you that have legal or similarly significant effects. PostChute's AI features generate and refine blog content under your direction — they do not make decisions about you as a person.

Right to complain to us. You have the right to complain directly to us if you believe we have not handled your personal data properly. You can complain by emailing data@postchute.com, or by any other means that reaches us. We will acknowledge your complaint within 30 days, look into it without undue delay, keep you informed of our progress, and tell you the outcome. Complaining to us first is often the quickest way to resolve a problem, but it never removes or delays your right to go to the ICO (below).

Right to lodge a complaint with the ICO. If you believe we have handled your data unlawfully, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

We aim to respond to all rights requests within one calendar month of receipt, as required by UK GDPR. In rare cases involving particularly complex requests, we may extend this period by up to two further months — if we need to do so, we will tell you within the first month and explain why.

9. How long we keep your data

DataRetention period
Account credentials, display name, third-party credentialsFor the lifetime of your account; deleted immediately on account deletion
Pipeline run history30 days in identifiable form. After 30 days, run records are detached from your account and anonymised, leaving only an aggregate count that cannot be linked back to you. Anonymised aggregates are not personal data and may be kept indefinitely
Privacy consent timestamp6 years after consent or account closure (Limitation Act 1980)
Account deletion record6 years after deletion (non-identifying: timestamp and internal reference only)
Support chat messagesNot stored by us — processed in memory only and discarded once the reply is sent. Chat history exists only in your browser until you close the chat
Server logs30 days, then automatically deleted

10. Security

  • All data transmitted over HTTPS (TLS)
  • Third-party credentials encrypted at rest; encryption key held separately
  • Row-level security enforced in the database — each user can only access their own data
  • Account deletion requires password confirmation

If you discover a security vulnerability, contact us immediately at security@postchute.com.

11. Children

PostChute is not intended for anyone under 18. This is because the third-party AI services used by PostChute (Anthropic and OpenAI) have their own age requirements, and our service depends on them. If you believe we have collected data from a minor, contact data@postchute.com and we will delete it immediately.

12. How you accept this policy

You accept this Privacy Policy when you create an account. The consent checkbox on the sign-up page is empty by default — you must actively tick it. The exact timestamp is recorded in your account record.

13. Changes to this policy

When we make a material change affecting your rights, we will notify you by email and ask for your acceptance before you continue. For minor changes (typos, clarifications), we update the document and date without requiring re-acceptance.

14. Contact

Rebecca Brown, trading as PostChute
Level One, Basecamp Liverpool, 49 Jamaica Street, Liverpool, L1 0AH
Email: data@postchute.com
ICO registration: ZC166256