Privacy Policy
1. Who we are
PostChute is operated by Rebecca Brown, a sole trader trading as "PostChute" in the United Kingdom. Our contact address is Level One, Basecamp Liverpool, 49 Jamaica Street, Liverpool, L1 0AH.
As a sole trader, Rebecca Brown is personally the data controller responsible for your personal data under UK GDPR.
We are registered with the Information Commissioner's Office (ICO) under registration number ZC166256.
For privacy-related questions: data@postchute.com
In this policy, "we", "us", and "our" refer to Rebecca Brown trading as PostChute. "You" and "your" refer to the person using PostChute.
2. What this policy covers
This policy explains what personal data we collect when you use PostChute, why we collect it, how long we keep it, who we share it with, and what rights you have over it.
PostChute connects your Notion workspace to your WordPress site using AI agents (via an AI API you choose and provide — currently Anthropic or OpenAI) to draft, optimise, and publish blog content. The decision to publish, the destination, and the schedule remain under your control.
3. If you join the waitlist
This section applies to you before you have a PostChute account — that is, while you are on our waitlist. Once you accept a beta invitation and create an account, you become an app user, and the rest of this policy (sections 4 onwards) applies to you instead. See section 3g.
3a. What we collect and why
| What | Why | Legal basis |
|---|---|---|
| Email address | To add you to the PostChute waitlist and email you about your position on it and about the public launch | Consent — you asked us to keep you informed |
| Sign-up date and source | Recorded automatically by our email provider as evidence that you consented | Legal obligation — UK GDPR requires us to demonstrate consent |
| The content of any reply you send to our qualifying email (see 3b) | To assess whether PostChute is a fit for you and when to offer you a place | Consent — you choose whether to reply |
We collect nothing else at the waitlist stage. You do not need an account, a password, or any third-party credentials to join the waitlist.
Why consent and not contract. Unlike an account holder, you have not entered into any contract with us — you have simply asked to be kept informed. UK GDPR requires consent as the lawful basis for that. Because the messages are sent by email, the Privacy and Electronic Communications Regulations (PECR) also require your consent for them. You give that consent when you submit your email address on our waitlist form, which clearly states what you are signing up for and links to this policy.
3b. The qualifying email and your reply
Shortly after you join the waitlist, we send you one email confirming we have received your details and asking whether PostChute currently fits your setup (Notion, WordPress, and your own AI provider API key). Replying is entirely optional and helps us decide when to offer you a place. If you reply, your message is delivered to our inbox and we process it only for that purpose. We do not ask for, or need, any sensitive information in your reply.
3c. What we will and will not send you
We will email you only to:
- confirm your details and ask the qualifying question described in 3b;
- tell you about your position on the waitlist, including when a beta place becomes available to you (your invitation); and
- announce the public launch.
We will not use your email address for any other marketing, and we will never share it with anyone else for their marketing.
3d. Your choices and withdrawing consent
Because we rely on your consent, you are in control of what you receive. Our emails give you two options:
- Stop the qualifying emails but stay on the waitlist. You will no longer receive the qualifying series, but you remain on the waitlist and will still be told about the public launch.
- Unsubscribe completely. This removes you from the waitlist entirely and stops all emails from us.
You can also contact us at data@postchute.com to be removed at any time. Withdrawing your consent does not affect the lawfulness of anything we did before you withdrew it.
3e. Who we share waitlist data with
We do not sell your data. We use the following processors to operate the waitlist, each under a Data Processing Agreement (DPA):
| Processor | What data | Why | Location |
|---|---|---|---|
| Mailjet (Sinch) | Email address; sign-up date and source | To store the waitlist and send you the emails described above | EU — hosted on Google Cloud Platform in Frankfurt (Germany) and Saint-Ghislain (Belgium) (we have accepted Mailjet's DPA) |
| Cloudflare, Inc. | Email address (in transit) | Our waitlist form is received by a Cloudflare service that passes your email to Mailjet; your email is not stored on Cloudflare | Global edge network, in transit only (we have accepted Cloudflare's DPA, which includes international transfer safeguards) |
| Mailgun (Sinch) | The content of any reply you send to our qualifying email | To receive your reply and forward it to our mailbox | EU (we have accepted Mailgun's DPA) |
| Google (Google Workspace) | The content of any reply you send to our qualifying email | To receive and store your reply in our mailbox | United States (Google Workspace Data Processing Amendment and international transfer terms accepted) |
3f. How long we keep it
We keep your waitlist data until the earlier of:
- you unsubscribing or asking us to remove you; or
- 6 months after the public launch, after which we delete any waitlist contacts who have not become account holders.
Replies to our qualifying email are kept only for as long as you remain on the waitlist, and are deleted when you leave it or when you become an account holder.
3g. When you become an app user
If you accept a beta invitation and create an account, you stop being a waitlist contact and become a PostChute app user. From that point, the rest of this policy governs how we handle your data, and the lawful basis for your account data becomes Contract (see section 4 onwards) rather than consent.
4. The data we collect, why, and our legal basis
4a. Account credentials
| What | Why | Legal basis |
|---|---|---|
| Email address | To identify your account, send transactional emails, allow sign-in | Contract |
| Password (hashed — we never see it) | To authenticate you | Contract |
4b. Display name
| What | Why | Legal basis |
|---|---|---|
| Display name (optional) | To address you in the app and emails | Contract |
4c. Third-party service credentials
| What | Why | Legal basis |
|---|---|---|
| Notion access token | To read your Notion database on your behalf | Contract |
| WordPress API URL and application password | To publish content to your WordPress site | Contract |
| Anthropic API key (if you use Anthropic as your AI provider) | To generate content using Claude AI | Contract |
| OpenAI API key (if you use OpenAI as your AI provider) | To generate content using OpenAI models | Contract |
| Google Gemini API key (optional — only if you enable AI image generation) | To generate featured images for your posts | Contract |
| Tavily API key (optional — only if you enable web research during quality checks) | To search the web for current information used to fact-check and refresh your posts | Contract |
All credentials are encrypted at rest (AES-256-GCM) with the encryption key held separately. Credentials are decrypted only when a pipeline run needs them. Credential values are never included in data exports, logs, or API responses.
4d. Pipeline run history
| What | Why | Legal basis |
|---|---|---|
| Run status, timestamps, error messages | Dashboard history, service monitoring, anonymised aggregate statistics | Legitimate interests — statistics are aggregated and anonymised so no individual can be identified |
Our balancing assessment: We have considered whether our use of pipeline run history for aggregate marketing statistics could be overridden by your interests. We believe it cannot, because: (a) the statistics we publish cannot identify any individual user; (b) the data used is operational in nature (counts and timestamps, not content); and (c) you would reasonably expect a software product to track whether its own pipelines succeed or fail. Run records are linked to your account for 30 days only; after that they are detached and anonymised into aggregate counts that cannot identify you (see section 9).
4e. Privacy consent record
| What | Why | Legal basis |
|---|---|---|
| Timestamp of policy acceptance at sign-up | Audit trail demonstrating informed consent | Legal obligation |
4f. Support chat conversations
| What | Why | Legal basis |
|---|---|---|
| The content of messages you send in the in-app support chat | To generate a relevant response to your question using AI | Legitimate interests — providing effective support for PostChute users |
| Conversation turn count and timestamps, not message content | To enforce fair-use rate limits and manage service costs | Legitimate interests — protecting service integrity |
The support chat is available to signed-in users. It works only from our help documentation and what you type — it has no access to your account data, your credentials, or your content. Your messages are processed in memory to generate a reply and are never written to our database or linked to your account. The chat history you see exists only in your browser and disappears when you close the chat.
Support chat messages are sent to Anthropic via PostChute's own Claude API account to generate a response — Anthropic processes them on our behalf (see section 7). PostChute does not store support chat message content after your browser session ends. Please don't include personal data in your messages that isn't needed to answer your question — for anything account-specific, email data@postchute.com instead.
5. Data we do not collect
- The content of your Notion pages beyond what is needed to process and publish them
- Any data from your WordPress site beyond a successful publish confirmation (status code and post URL)
- Location data
- Any data from your device beyond standard web server access logs
Support chat messages are transiently processed while you use the chat, but are not stored by PostChute after the session ends.
Content belonging to other people. The Notion pages you process may include personal data about people other than you (for example, a name mentioned in a draft post). During a pipeline run we handle that content only transiently, on your instructions, for the sole purpose of drafting, refining, and publishing your post. We do not store it beyond what the run needs, and we do not use it for any other purpose. You remain the data controller for the content you choose to process and publish.
6. Server logs, cookies, and browser storage
Our servers automatically generate access logs (IP address, browser type, pages visited, timestamps). We use these logs to monitor for errors and security issues.
We retain server logs for 30 days, after which they are automatically deleted. We consider this period proportionate for security monitoring and error diagnosis.
Cookies and browser storage. When you sign in to PostChute, a session token is stored in your browser so that you stay signed in as you move around the app. This is strictly necessary for the service to function — without it, you would have to sign in again on every page. Because it is strictly necessary, it does not require your consent under PECR, but we tell you about it here for transparency. We do not use advertising cookies, analytics cookies, or any other tracking technologies.
7. Who we share your data with, and where it goes
We do not sell your personal data. We use the following data processors under Data Processing Agreements:
| Processor | What data | Why | Location |
|---|---|---|---|
| Supabase Inc. | All data in section 4 | Database and authentication | EU (DPA accepted) |
| Google Cloud Platform | Server logs; application runtime | Cloud hosting | EU — europe-west2 (DPA accepted) |
| Anthropic, PBC | Support chat message content for the duration of a support session only (not stored by us) | AI inference for support chat responses | United States (we use Anthropic's commercial terms, which include data processing and international transfer safeguards) |
| Mailgun (Sinch) | Your email address and the content of transactional emails (e.g. account invitations and privacy-policy update notices) | To send you service emails about your account | EU (we have accepted Mailgun's DPA) |
When you connect to Notion, WordPress, your chosen AI provider, or the optional image-generation and web-research services described below, your credentials are transmitted directly to those services to authenticate requests made on your behalf. Those services are independent data controllers for the data you hold with them, and are subject to their own privacy policies. We encourage you to read them:
- Notion: https://www.notion.com/trust/privacy-policy
- Anthropic (if you use Anthropic as your AI provider): https://www.anthropic.com/legal/privacy
- OpenAI (if you use OpenAI as your AI provider): https://openai.com/security-and-privacy/
- Google (if you enable AI image generation): the image-generation prompt for your post is sent to Google's Gemini API using the API key you supply. See https://policies.google.com/privacy.
- Tavily (if you enable web research during quality checks): search queries built from your post's title, keywords, and category are sent to Tavily using the API key you supply. See https://www.tavily.com/.
- WordPress: Privacy practices for your WordPress site depend on how it is hosted. If you self-host WordPress (the most common case), you are the data controller for your own site and there is no central privacy policy. If you use WordPress.com, see Automattic's privacy policy at https://automattic.com/privacy/.
International transfers
Data we hold about you. The data described in section 4 is stored with our processors in the EU (see the table above). UK law recognises the EU/EEA as providing adequate protection for personal data, so no additional transfer safeguards are required. For waitlist data, the transfers involved (including to Google in the United States) and the safeguards covering them are set out in section 3e.
Support chat conversations. Messages you send to the support chat are processed by Anthropic in the United States, as our processor, under the commercial terms referred to in the table above.
Content sent to services you connect. Anthropic, OpenAI, Google, and Tavily are United States companies. When a pipeline run uses your chosen AI provider, the content of the post being prepared is transmitted to that provider, using the API key you supplied, and is handled under that provider's own terms and privacy policy (linked above). This can include Research Pack notes, linked Notion-page content, supported attachments, and public-page extracts that you choose to add to a post. PostChute handles this material only for the active run and does not store extracted research in its run history. If you enable the optional features, an image-generation prompt for your post is sent to Google's Gemini API, and public URLs in a Research Pack are sent to Tavily for extraction — each using the API key you supplied. These optional features are off unless you provide the relevant key, and you can stop using any of these services at any time by removing its key. Similarly, where your published posts go depends on where your WordPress site is hosted, which is under your control.
8. Your rights
Under UK GDPR, you have the following rights. You can exercise any of these by contacting us at data@postchute.com.
Right of access. You can request a copy of the personal data we hold about you. We provide a self-service data export in your account settings (Account → Download my data). The export contains all personal data we hold, excluding credential values (see section 4c).
Right to erasure. You can delete your account at any time from your account settings (Account → Delete account). Deletion is permanent and removes all data associated with your account from our active systems. This cannot be undone. Two things to be aware of:
- Server logs may retain your IP address for up to 30 days after deletion (see section 6).
- We retain a minimal, non-identifying record of the deletion itself (timestamp and an internal reference) so that we can demonstrate, if asked, that we honoured your request. This record contains no email address, name, or other personal data that could identify you. See section 9 for the retention period.
Right to rectification. You can update your display name and email address at any time from your account settings.
Right to data portability. Your data export (described under Right of access above) is provided in JSON format, which is machine-readable and can be imported into other systems.
Right to object. You have the right to object to any processing we base on legitimate interests. At present, that means our use of pipeline run history (see section 4d), including its use in anonymised aggregate marketing statistics, and the support chat (see section 4f) — though the simplest way to object to the support chat is just not to use it. To exercise this right, contact us at data@postchute.com. As with all rights requests, we will respond within one calendar month (see below).
Right to restrict processing. In certain circumstances, you can ask us to restrict the processing of your data while a dispute is resolved.
Automated decision-making. We do not make any solely automated decisions about you that have legal or similarly significant effects. PostChute's AI features generate and refine blog content under your direction — they do not make decisions about you as a person.
Right to complain to us. You have the right to complain directly to us if you believe we have not handled your personal data properly. You can complain by emailing data@postchute.com, or by any other means that reaches us. We will acknowledge your complaint within 30 days, look into it without undue delay, keep you informed of our progress, and tell you the outcome. Complaining to us first is often the quickest way to resolve a problem, but it never removes or delays your right to go to the ICO (below).
Right to lodge a complaint with the ICO. If you believe we have handled your data unlawfully, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
We aim to respond to all rights requests within one calendar month of receipt, as required by UK GDPR. In rare cases involving particularly complex requests, we may extend this period by up to two further months — if we need to do so, we will tell you within the first month and explain why.
9. How long we keep your data
| Data | Retention period |
|---|---|
| Account credentials, display name, third-party credentials | For the lifetime of your account; deleted immediately on account deletion |
| Pipeline run history | 30 days in identifiable form. After 30 days, run records are detached from your account and anonymised, leaving only an aggregate count that cannot be linked back to you. Anonymised aggregates are not personal data and may be kept indefinitely |
| Privacy consent timestamp | 6 years after consent or account closure (Limitation Act 1980) |
| Account deletion record | 6 years after deletion (non-identifying: timestamp and internal reference only) |
| Support chat messages | Not stored by us — processed in memory only and discarded once the reply is sent. Chat history exists only in your browser until you close the chat |
| Server logs | 30 days, then automatically deleted |
10. Security
- All data transmitted over HTTPS (TLS)
- Third-party credentials encrypted at rest; encryption key held separately
- Row-level security enforced in the database — each user can only access their own data
- Account deletion requires password confirmation
If you discover a security vulnerability, contact us immediately at security@postchute.com.
11. Children
PostChute is not intended for anyone under 18. This is because the third-party AI services used by PostChute (Anthropic and OpenAI) have their own age requirements, and our service depends on them. If you believe we have collected data from a minor, contact data@postchute.com and we will delete it immediately.
12. How you accept this policy
You accept this Privacy Policy when you create an account. The consent checkbox on the sign-up page is empty by default — you must actively tick it. The exact timestamp is recorded in your account record.
13. Changes to this policy
When we make a material change affecting your rights, we will notify you by email and ask for your acceptance before you continue. For minor changes (typos, clarifications), we update the document and date without requiring re-acceptance.
14. Contact
Rebecca Brown, trading as PostChute
Level One, Basecamp Liverpool, 49 Jamaica Street, Liverpool, L1 0AH
Email: data@postchute.com
ICO registration: ZC166256