1.1Overview and Scope
This Privacy Policy explains how Lunark Dynamics LLC collects, uses, discloses, stores, retains, protects, and deletes personal data in connection with POSTARYX. POSTARYX is operated by Lunark Dynamics LLC.
This Policy applies to visitors to our public websites, prospective and current customers, Account holders, Workspace members, people who communicate with us, and individuals whose information is processed through enabled Service features. It also explains how POSTARYX handles data from Connected Platforms when a user authorizes an integration.
Connected Platforms have their own privacy notices, developer terms, and user controls. This Policy describes POSTARYX’s processing; it does not replace the privacy policies of Facebook, Instagram, Threads, LinkedIn, TikTok, Google, YouTube, Pinterest, Reddit, X, or other third-party services.
1.2Data Controller
For personal data that Lunark Dynamics LLC determines the purposes and means of processing — such as Account registration, billing administration, website operations, security, product analytics, direct communications, and legal compliance — Lunark Dynamics LLC generally acts as the data controller, business, or equivalent responsible entity under applicable privacy law.
Controller: Lunark Dynamics LLC
Registered address: [Registered Address]
Privacy contact: [Privacy Email]
General support: [Support Email]
1.3Controller / Processor Roles for Customer Data
For User Content and other personal data a customer or Workspace submits to POSTARYX and directs us to process on its behalf, Lunark Dynamics LLC may act as a processor, service provider, contractor, or equivalent role under applicable law, depending on the facts and jurisdiction. The customer generally determines why the data is processed and is responsible for its lawful basis, privacy notices, consents, rights handling, and instructions.
Where required, our customer data processing terms are available at [DPA URL or DPA Request Process]. If an enterprise agreement or signed DPA conflicts with this public policy regarding processor obligations, the signed agreement controls for the covered processing.
Connected Platforms may independently act as controllers or equivalent entities for data on their own services. Authorizing POSTARYX does not transfer responsibility for a platform’s independent processing to Lunark Dynamics LLC.
1.4Information We Collect
1.4.1Account and Identity Data
- Name, email address, password hash or authentication identifier, profile image, language, timezone, organization or company name, role, and Account preferences.
- Sign-up, login, password reset, verification, multi-factor authentication, session, and account-recovery information where those features are enabled.
- Information made available by a third-party sign-in provider if you choose a supported federated login method.
1.4.2Workspace and Team Data
- Workspace name, member list, invitations, team roles, administrator assignments, permissions, client/workspace relationships, approval activity, and configuration settings.
- Audit or activity records showing actions taken in a Workspace where those records are enabled.
1.4.3Connected Platform and OAuth Data
- OAuth access tokens, refresh tokens, authorization codes, scopes/permissions, token expiration or refresh information, revocation status, app/client connection identifiers, and related authorization metadata.
- Platform account, member, Page, profile, organization, business, channel, board, subreddit, workspace, server, site, or other identifiers returned by a Connected Platform.
- Usernames, display names, profile images, account types, Page/channel names, roles or administrative relationships, and other account metadata needed to present or validate a connection.
- Platform data described in the platform-specific sections below, including posts, media, publishing status, analytics, comments, replies, business/listing data, and other permitted fields if the corresponding feature is enabled.
1.4.4User Content and Media
- Drafts, captions, post text, hashtags, links, images, video, audio, thumbnails, alt text, notes, approval comments, content-calendar entries, publishing times, media metadata, files, and other content you upload or create.
- Processing derivatives needed to deliver content, such as resized images, transcoded media, thumbnails, public delivery URLs, previews, or temporary upload objects, where required by a Connected Platform.
- Published-post identifiers, status responses, error messages, retry data, and other records used to track the result of a requested action.
1.4.5Billing and Transaction Data
- Plan, subscription status, invoice history, billing email, billing address, tax information, currency, payment status, transaction or invoice identifiers, and limited payment-method metadata made available by [Actual Payment Provider or Merchant of Record].
Full payment card or bank credentials should be processed by the payment provider rather than stored by POSTARYX unless the final payment architecture expressly states otherwise. Verify the actual payment-data flow before publication.
1.4.6Usage, Device, Log, and Security Data
- IP address, browser type, operating system, device type, language, approximate location derived from IP where used, referring URL, request timestamps, and session identifiers.
- Pages and features used, API requests, publishing attempts, successes/failures, performance information, system errors, connection-health events, rate-limit events, and operational metrics.
- Authentication, password-reset, authorization, security, audit, abuse-prevention, and incident-investigation records to the extent logged in production.
1.4.7Support, Sales, and Communications
- Support requests, emails, chat messages, bug reports, feedback, survey responses, sales communications, attachments, and records of interactions with our team or service providers.
- Marketing communication preferences and engagement information where marketing messages are used and such tracking is permitted.
1.4.8Cookies and Similar Technologies
We may use cookies, local storage, pixels, SDKs, and similar technologies for authentication, security, preferences, analytics, performance, consent management, and marketing attribution, as described in the Cookie Policy.
1.4.9Optional AI Data
If POSTARYX later enables AI-assisted features, the Privacy Policy and Subprocessor Disclosure must be updated before production use to identify the provider, categories of data sent, purposes, retention posture, user controls, and any model-training or secondary-use restrictions. This V2 document does not represent that an AI provider currently receives User Content.
1.5Sources of Information
We collect information directly from you and other Workspace users, automatically through your use of the Service, from our payment/support/infrastructure providers, and from Connected Platforms when you authorize access. We may also receive business contact information from legitimate sales or support interactions, subject to applicable law.
For Connected Platform data, the categories available to POSTARYX depend on the scopes you grant, the platform’s API, your account type, your role on the relevant asset, and the enabled POSTARYX feature.
1.6How We Use Information
- Provide, authenticate, operate, and maintain Accounts and Workspaces.
- Connect authorized third-party accounts, validate permissions, refresh or check connection health, and display connected assets.
- Store drafts and media, schedule content, publish at your direction, retrieve publication status, retry permitted failures, and display results.
- Retrieve and display platform analytics, comments, replies, profile/Page/channel information, or other permitted data when those features are enabled.
- Manage roles, team collaboration, approval workflows, notifications, and account administration.
- Process subscriptions, invoices, taxes, refunds, failed payments, fraud prevention, and billing support.
- Protect the Service, users, Connected Platforms, and third parties by detecting abuse, account takeover, credential compromise, malicious traffic, rate-limit evasion, or policy violations.
- Monitor, debug, test, measure, maintain, and improve the Service and integration reliability.
- Send transactional or service communications such as receipts, security alerts, failed-post notices, reconnect notices, policy notices, and support responses.
- Send marketing communications where permitted by law and subject to opt-out or consent requirements.
- Comply with legal obligations, enforce our agreements, respond to valid legal process, protect rights and safety, and establish or defend legal claims.
- Create aggregated or de-identified information where permitted by law, provided it is not reasonably capable of identifying an individual.
1.7Legal Bases Where GDPR, UK GDPR, or Similar Laws Apply
- Contract: processing needed to create Accounts, provide requested Service features, publish at your direction, manage subscriptions, and support customers.
- Legitimate interests: operating, securing, debugging, measuring, preventing abuse, communicating about the Service, and improving reliability, balanced against applicable individual rights.
- Consent: where required for non-essential cookies, certain marketing communications, optional integrations, or other processing for which consent is the appropriate legal basis.
- Legal obligation: tax/accounting records, regulatory obligations, lawful requests, sanctions compliance, and other duties imposed by law.
- Vital interests or public-interest grounds: only where applicable in exceptional circumstances.
OAuth authorization is a technical authorization mechanism by which a platform user grants POSTARYX specified permissions. The appearance of an OAuth “consent” screen does not by itself determine the privacy-law legal basis for every processing activity.
1.8Platform-Specific Data Handling
Each subsection should remain limited to functionality actually enabled and permissions actually approved. Remove optional categories that are not implemented or approved before platform submission.
1.8.1Meta Platform Data — Facebook Pages
When you connect a Facebook Page through a Meta-authorized flow, POSTARYX may receive and process OAuth Data and permitted Page data necessary to let you identify an eligible Page, connect it to a Workspace, publish content at your direction, and display related status or analytics if those features are enabled.
Data POSTARYX may access: Meta user/account identifiers needed for authorization; Page IDs; Page names; profile or Page images; administrative or Page-selection relationships; Page metadata and content permitted by the granted scopes; User Content and media you direct us to publish; published-post IDs and status; and, only if enabled and approved, engagement, comments, replies, or insights/analytics.
Permissions: The specific permissions requested are displayed in Meta’s authorization flow and should be limited to the functions POSTARYX actually provides. Examples may include permission to list Pages you administer, read Page metadata, manage posts, and — only where the related feature is enabled — read insights or manage engagement. The exact production permission set must match the approved Meta app configuration.
Purpose: to let you select an authorized Facebook Page, render the connection in POSTARYX, publish or manage posts at your direction, confirm delivery, provide historical publishing records, and display permitted analytics or engagement features that you choose to use.
Storage and retention: active OAuth Data is retained while the connection is active and should be deleted promptly after disconnection or revocation, subject to limited backup/technical cycles. Page identifiers, publishing records, and permitted analytics may be retained while the Account/Workspace is active when needed for the requested Service, unless a shorter platform rule applies or you delete them.
Deletion: you may disconnect the Page in POSTARYX and/or revoke access from Meta. Account deletion follows Section 2.15 and the Data Deletion Instructions. Meta integrations are also subject to the Meta Data Deletion Request Callback described below.
Sharing: we disclose this data to Meta when carrying out your requested actions and to subprocessors that support hosting, database, storage, security, logging, email, or other Service operations as necessary. We do not sell Facebook Page data or provide it to ad networks or data brokers for their independent advertising or brokerage purposes.
1.8.2Meta Platform Data — Instagram
When you connect an eligible Instagram account, POSTARYX may process OAuth Data and Instagram account information made available through the authorized integration path.
Data POSTARYX may access: Instagram account or business identifiers, username/display name, profile image, account type or eligibility information, User Content and public-media delivery references, captions, publishing container/status identifiers, publication results, platform limits/status, and — only if enabled and approved — insights or other permitted analytics.
Authorization paths: POSTARYX may support an Instagram Login path and/or a Facebook Login path depending on the production implementation, Meta approval, and user account setup. The scopes shown by Meta are the authoritative permissions requested for that connection.
Purpose: to identify the Instagram Professional account you chose, prepare and deliver User Content, monitor platform processing/publishing status, display publication history, and provide permitted analytics where enabled.
Media processing: where Instagram requires media to be retrievable from a public URL, POSTARYX may temporarily or persistently host a delivery copy through [Actual Storage / CDN Provider]. The production retention and URL-access model must be verified and disclosed consistently with the Service.
Storage, retention, deletion, and sharing: OAuth tokens and connection metadata are retained while the connection is active; publishing records and content are retained as needed to provide the Service; disconnection/revocation removes active authorization data as described in Section 2.15; and data is shared only with Meta and necessary subprocessors for the requested Service, legal/security purposes, or other disclosures described in this Policy.
1.8.3Meta Platform Data — Threads
When you connect a Threads profile, POSTARYX may process OAuth Data, account/profile identifiers, basic profile information, User Content, media, publishing status, and — if approved and enabled — replies or insights.
Permissions: the production app may request basic account access and content-publishing permission, plus reply-management or insight permissions only if those features are actually offered and approved. Users see requested scopes during the platform authorization flow.
Purpose: to connect the selected Threads profile, publish content at your direction, display status and history, and provide optional reply or analytics features where enabled.
Token lifecycle: Meta token lifetimes and refresh requirements may change. POSTARYX’s production implementation should monitor authorization health, refresh tokens where permitted and required, and notify users when reconnection is necessary. Do not treat this sentence as confirmation of a deployed refresh worker until verified.
Deletion and sharing: disconnecting/revoking the integration should remove active authorization data and stop further access; data is shared with Meta and necessary subprocessors only for the purposes described in this Policy.
1.8.4Meta Data Deletion Request Callback
For production Meta integrations, POSTARYX maintains, or before enabling production Meta access will maintain, a Data Deletion Request Callback mechanism that is configured in the relevant Meta developer application and that processes valid platform-initiated deletion requests.
Placeholder callback endpoint: https://api.example.com/meta/data-deletion
The production callback must be implemented and tested to validate the request as required by Meta, initiate deletion or identify the applicable deletion workflow, and return the confirmation response required by the platform, including a confirmation URL and/or code where required. [VERIFY META CALLBACK IMPLEMENTATION BEFORE PUBLICATION / APP REVIEW].
A user-facing data-deletion page or email address does not replace the technical callback where Meta requires the callback.
1.8.5LinkedIn Data
When you connect a LinkedIn member account or LinkedIn Page/organization, POSTARYX may process OAuth Data and the minimum LinkedIn data needed for the enabled approved use case.
Member/account information: member/account identifier, name or display name, profile image, login/identity information returned through approved sign-in scopes, and personal-profile publishing data where that feature is supported.
Organization/Page information: organization/Page IDs, names, logos/images, administrative relationship information, content, publishing status, and other approved Page-management data.
Publishing and community data: User Content you direct us to publish, post identifiers/status, and — only where a declared and approved use case requires it — comments, comment content, and limited commenter/member fields displayed in POSTARYX.
Purpose: authorized content scheduling and publishing, Page/profile management, permitted comment display or engagement workflows, and related analytics or status functions that are actually enabled.
Restricted use: POSTARYX does not use LinkedIn data for prohibited scraping, lead extraction, unauthorized aggregation, resale, data enrichment, or automation-at-scale that conflicts with LinkedIn developer restrictions.
Storage and deletion: active OAuth Data is retained while connected and should be removed promptly after disconnection/revocation. Other LinkedIn-derived data is retained only as needed for approved functionality and the retention schedule in this Policy, subject to any stricter LinkedIn rule. Account deletion removes associated platform-derived data from active systems except lawful retention and backup cycles.
Sharing: data is shared with LinkedIn to carry out user-directed actions and with necessary subprocessors. We do not sell LinkedIn data or provide it to ad networks/data brokers for their independent use.
1.8.6TikTok Data
When you connect TikTok, POSTARYX may process OAuth Data and data required for the TikTok Content Posting functionality you choose to use.
Account information: TikTok account identifier, creator nickname/display information and other basic account information returned through the approved login/account scopes, plus posting eligibility or creator information used to show which account is being targeted.
Publishing data: user-supplied photos/videos, title/caption, media delivery information, publishing status, privacy selection, available interaction settings such as comments/duet/stitch, commercial-content selection, and platform responses needed to complete or display the requested publish operation.
OAuth permissions: the authorization screen shows the actual scopes requested, which may include basic account information and direct publish/upload permissions appropriate to the media type and production feature.
Purpose and user control: to identify the connected creator, let you prepare and preview your own supplied content, present platform-required privacy and disclosure choices, obtain the user action required to publish, transmit the media, and show processing status. POSTARYX should not silently preselect a privacy choice or bypass required platform disclosures.
Storage and deletion: OAuth Data and connection metadata are retained while connected; user media and publishing records are retained under the general content-retention schedule; disconnecting/revoking stops new access and removes active authorization data as described in Section 2.15.
Sharing: TikTok data is sent to TikTok for the publish flow and processed by necessary POSTARYX subprocessors. We do not sell TikTok data or provide it to ad networks/data brokers for independent advertising or brokerage.
1.8.7Google and YouTube Data
When you authorize a Google or YouTube connection, POSTARYX may process OAuth Data and data from the Google APIs or YouTube API Services needed for the approved functionality.
Channel/account information: Google account identifiers returned to the app as permitted, YouTube channel ID, channel title/name, channel image or metadata, and other fields needed to display and manage the authorized channel.
Upload/publishing data: video files supplied by you, titles, descriptions, thumbnails, privacy/publishing settings, upload status, video IDs, playlist/upload references, and API responses needed to publish and track an upload.
Analytics: where the required API permissions are approved and the feature is enabled, POSTARYX may retrieve channel or content analytics and display them in your Workspace.
OAuth permissions: YouTube publishing may require sensitive or restricted Google OAuth scopes. The Google consent screen displays the actual scopes requested. POSTARYX should request only scopes necessary for enabled features and maintain any verification or assessment required by Google.
Purpose: to let you select an authorized channel, upload/publish content, display upload status and identifiers, manage approved channel functions, and show analytics where enabled.
Storage and revocation: active OAuth Data is retained while the connection remains active; upload records and channel metadata are retained under the applicable schedule. You may disconnect through POSTARYX where available or revoke access from your Google Account permissions. Revocation stops future API access using the revoked credential.
YouTube-specific restriction: POSTARYX is intended to operate through authorized publishing and management APIs and not as an unofficial YouTube downloading or circumvention service. Video display should use official mechanisms where the applicable YouTube terms require them.
Sharing: data is shared with Google/YouTube for user-directed actions and with necessary subprocessors. We do not sell Google/YouTube API data or provide it to data brokers/ad networks for independent use.
1.8.8Google Business Profile Data
If Google Business Profile functionality is enabled and approved, POSTARYX may process OAuth Data and user-owned business/location information such as account or location IDs, business name, address, categories, listing metadata, media, post/update content, publishing status, and permitted performance information.
We use this data to display locations the authorized user may manage, perform requested listing or post actions, and present permitted performance or status information. Active OAuth credentials are retained while the connection is active and deleted/revoked as described in Section 2.15. Business Profile data is shared with Google and necessary subprocessors only for the requested functionality and other purposes described in this Policy.
1.8.9Pinterest Data
When you connect Pinterest, POSTARYX may process OAuth Data and the Pinterest account/board/Pin information necessary for approved publishing and account-selection features.
Data POSTARYX may access: Pinterest user/account identifiers, board IDs/names and minimal board metadata, Pin IDs and permitted metadata, User Content to create Pins, destination URLs, publication status, and other fields permitted by the approved scopes.
Permissions: the production scope set should remain minimal for the enabled functions, such as account read access and the board/Pin read-write permissions actually required.
Storage restriction: Pinterest may restrict caching or retention of API-derived data. POSTARYX must minimize Pinterest-derived data, avoid indefinite caching where prohibited, and use a short refresh/retention period consistent with current Pinterest rules. The production period is [Pinterest Data Retention Period] and must be confirmed before publication. User-created content and POSTARYX’s own publishing records may be treated separately where permitted.
Deletion: disconnecting/revoking removes active OAuth Data; cached platform-derived metadata should expire or be deleted according to the confirmed Pinterest retention rule and account-deletion process.
Sharing: data is shared with Pinterest for authorized actions and with necessary subprocessors. We do not sell Pinterest API data or provide it to ad networks/data brokers for independent use.
1.8.10Reddit Data
When a Reddit integration is enabled and the required platform access conditions are satisfied, POSTARYX may process OAuth Data, Reddit account identifiers/username, authorized subreddit/community information, subreddit rules or posting constraints made available through the API, User Content, flair or destination selections, post IDs/status, and comments or other data only if an enabled approved feature requires them.
We use this information to connect the authorized account, help you select a destination, surface relevant posting constraints where available, publish at your direction, and display status/history. POSTARYX may apply rate limits or anti-spam controls to protect the shared API client and comply with platform rules.
Reddit commercial API use may require express written approval or another commercial arrangement. POSTARYX may restrict the integration until that condition is met. The Service may identify itself to Reddit using a descriptive User-Agent or other platform-required client information.
Active OAuth Data is retained while connected and deleted/revoked as described in Section 2.15. Reddit data is shared with Reddit for requested actions and with necessary subprocessors; it is not sold or provided to ad networks/data brokers for independent use.
1.8.11X Data
When you connect X, POSTARYX may process OAuth Data, X account identifier/username/profile metadata, User Content and media, post IDs/status, and permitted analytics or owned-account data if those features are enabled.
Depending on the production architecture, POSTARYX may use platform credentials managed by Lunark Dynamics LLC or may permit you to supply your own developer credentials. Customer-supplied API keys, client secrets, or similar credentials are treated as sensitive authentication data and should be stored only for the requested integration, protected according to verified security controls, and deleted when the applicable integration is removed.
We use X data to connect the authorized account, publish requested content, show delivery status/history, and provide any permitted analytics. We share it with X and necessary subprocessors only for the Service and other disclosures described in this Policy.
1.8.12Other Connected Platforms
POSTARYX may support additional services such as Discord, Slack, Telegram, Bluesky, Mastodon, Nostr, Farcaster, Lemmy, Twitch, Kick, Dev.to, Hashnode, WordPress, Dribbble, Whop, Listmonk, MeWe, Skool, Moltbook, and other integrations that may be added or removed over time.
Depending on the connector, POSTARYX may receive account or workspace identifiers, profile/site/server/channel information, content and media, publishing status, analytics, OAuth tokens, API keys, application passwords, bot tokens, per-instance credentials, or other authorization material that you provide or authorize.
For credentials with unusually high sensitivity — such as application passwords or cryptographic private-key material — POSTARYX should minimize retention, avoid logging secrets, encrypt them at rest using verified controls, limit access by least privilege, and provide an obvious deletion/revocation path. These are required/intended practices and must be verified connector by connector before public claims are made.
Beta or experimental integrations may rely on evolving platform APIs. Their data practices remain subject to this Policy, but data categories and availability may change with the connector. Material new data uses will be reflected in an updated policy.
1.9Data Minimization; No Sale; No Data-Broker or Ad-Network Use
POSTARYX is intended to request and retain only the platform permissions and data reasonably necessary for enabled features. Platform review requirements may further limit which fields can be cached or retained.
Lunark Dynamics LLC does not sell OAuth tokens, Connected Platform credentials, User Content, or Platform Data. We do not provide Connected Platform data to ad networks or data brokers for their independent behavioral advertising, audience enrichment, or data-broker purposes.
If applicable privacy law defines “sale,” “sharing,” “targeted advertising,” or similar terms more broadly, our legal disclosures and opt-out mechanisms must be evaluated against the actual production advertising/analytics stack before launch. [VERIFY COOKIE/ADTECH STACK].
1.10How We Share Information
- Connected Platforms: when you authorize a connection or instruct us to publish, retrieve data, or perform another platform action.
- Subprocessors/service providers: vendors that provide hosting, databases, object storage, content delivery, payment processing, email, support, monitoring, security, analytics, or other operational services, subject to contractual and privacy requirements appropriate to the service.
- Workspace members: according to the roles, sharing settings, and permissions configured by the customer.
- Professional advisers: accountants, lawyers, auditors, insurers, banks, and similar advisers under appropriate confidentiality obligations.
- Authorities and protective disclosures: where required by law, valid legal process, regulator request, or where reasonably necessary to investigate fraud, abuse, security threats, rights violations, or risks to users/platforms.
- Corporate transactions: to a buyer, investor, lender, successor, or professional adviser in connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to applicable law.
- With your direction or consent: where you instruct us to make a disclosure or separately authorize it.
1.11Subprocessors
POSTARYX relies on service providers to operate the Service. The public list below is a placeholder and must be replaced with actual vendors before publication.
Provider
Purpose
Data processed
[Actual Cloud Hosting Provider]
Compute, networking, hosting
Account/Workspace data, application traffic, logs, Platform Data as hosted
[Actual Database Provider]
Managed database / persistence
Account data, Workspace data, integration metadata, publishing records, limited Platform Data
[Actual Storage / CDN Provider]
Media/object storage and delivery
User Content, media, thumbnails, temporary/public delivery objects
[Actual Payment Provider or Merchant of Record]
Checkout, billing, taxes, refunds, fraud
Billing contact details, transaction identifiers, payment metadata; provider processes payment credentials
[Actual Email Provider]
Transactional/service email
Email address, message content, delivery metadata
[Actual Monitoring Provider]
Error monitoring, performance, observability
Technical logs, error events, device/request data; may contain limited identifiers depending on configuration
[Actual Security Provider, if any]
Security controls, abuse prevention, edge protection
IP/device/request/security-event data, depending on provider
[Actual Support Provider, if any]
Customer support
Account/contact data, support messages, attachments
[Actual AI Provider, only if enabled]
Optional AI-assisted features
[Prompts/content/context actually sent, if enabled]
We may replace or add subprocessors as the Service evolves. Where required by contract or applicable data protection law, we will provide notice and/or an objection mechanism for material new subprocessors. A current list should be maintained at [Subprocessor Page URL or this Privacy Policy section].
1.12International Transfers
POSTARYX and its service providers may process data in countries other than the country where you live or where your organization is established. Actual hosting and processing locations are [Hosting / Processing Region(s)] and must be confirmed before publication.
Where cross-border transfer restrictions apply, Lunark Dynamics LLC will use an appropriate lawful transfer mechanism required for the relevant transfer, which may include Standard Contractual Clauses, the UK International Data Transfer Addendum or Agreement, adequacy decisions, contractual safeguards, or another legally recognized mechanism. Do not list a transfer mechanism as used unless it is actually in place with the relevant provider.
1.13Security and Data Protection
We take data protection seriously, but this public policy must not overstate controls that have not been confirmed. The following are the security practices POSTARYX is required or intended to maintain and should be converted to unconditional present-tense claims only after implementation is verified:
- encryption in transit using current TLS configurations for production web and API traffic;
- encryption at rest for production databases and object storage where supported and appropriate;
- encryption or equivalent strong protection for OAuth tokens, API credentials, application passwords, and other secrets, with key/secret separation where feasible;
- role-based and least-privilege production access using named accounts rather than shared logins;
- authentication controls appropriate to Account and administrative risk;
- secret-management procedures restricting who and what systems may read production credentials;
- security, audit, and operational logging with defined access and retention;
- monitoring and alerting for material service failures, credential/token health, abuse, and security events;
- backup and recovery practices with documented retention and periodic restoration testing;
- incident-response procedures with assigned ownership, investigation, containment, remediation, and legally required notification processes;
- personnel onboarding/offboarding and production-access review;
- vendor/subprocessor diligence proportionate to the data processed; and
- data-minimization, retention, and deletion procedures by data type and platform.
No internet service is completely secure. We cannot guarantee that unauthorized third parties will never defeat safeguards. The separate Security & Data Protection Disclosure in this Legal Pack contains the implementation-verification framework.
1.14Retention
We retain personal data only as long as reasonably necessary for the purposes described in this Policy, subject to platform rules, legal obligations, security needs, dispute preservation, and verified technical deletion cycles. The table below is the V2 baseline and must be reconciled with actual production settings.
Data category
V2 retention baseline
Implementation note
Account profile and Workspace administration data
While active; after verified deletion request, target removal from active systems within up to 90 days unless shorter processing is feasible or longer retention is legally required.
Verify production deletion job and exceptions.
Drafts, scheduled content, and media
Until deleted by the user, published and removed under product settings, or Account/Workspace deletion; temporary processing copies may expire sooner.
Verify media lifecycle and object-storage policies.
Published-post records / status / permitted analytics
While the Account/Workspace is active and the history feature is used, unless user deletes, a platform rule requires earlier deletion, or the Account/Workspace is deleted.
Avoid retaining fields that are not needed.
OAuth access/refresh tokens
While the integration is active; intended to be deleted promptly after disconnection/revocation, subject to limited backups and technical logs.
Verify connector-by-connector upstream revoke + local delete.
Customer-supplied API keys / app passwords / private credentials
Only while required for the user-requested connector; delete when the credential/integration is removed.
Never log secrets; verify encryption and access controls.
Pinterest API-derived metadata
Short TTL only, consistent with current Pinterest rules: [Pinterest Data Retention Period].
Do not cache indefinitely; verify exact fields and rule.
Billing, invoice, tax, accounting records
[Actual legal/accounting retention period].
Retain only as required for tax, accounting, audit, fraud, chargeback, or legal purposes.
Security and operational logs
[Actual Log Retention Period].
Set by risk/security needs; minimize content and access.
Support records
[Actual Support Retention Period].
May be retained for service history, disputes, quality, and legal needs.
Backups
[Actual Backup Retention Period], after which deleted data is overwritten or expires through normal backup rotation.
Deleted data should not be restored to active use except disaster recovery; re-apply deletion where appropriate.
1.15Deletion, Disconnection, and Revocation
You can request deletion of your POSTARYX Account and associated personal data through [Account Deletion UI Path] where available or by contacting [Privacy Email]. We may verify your identity and authority before processing a request.
- Account deletion: initiates deletion or de-identification of Account and Workspace data associated with the request, subject to administrator ownership issues, other users’ rights, legal retention, dispute/security preservation, and backup cycles.
- Connected Platform disconnection: stops future access using the connection and should revoke or invalidate the upstream platform authorization where the platform supports a revocation method and POSTARYX has implemented it.
- OAuth token removal: active access/refresh tokens and comparable credentials should be removed promptly from live POSTARYX systems after confirmed disconnection/revocation, subject to tightly limited backups or security logs.
- Stored content deletion: drafts, media, schedules, publication records, analytics, and platform-derived data are deleted or de-identified according to the account/content deletion workflow and retention schedule, subject to platform-specific shorter rules.
- Platform-side copies: deleting from POSTARYX does not automatically delete posts or data already stored by a Connected Platform unless POSTARYX sends a specific delete request and the platform accepts it. You may need to delete content directly on the platform.
- Backups: data deleted from active systems may persist until overwritten or expired through [Actual Backup Retention Period]. Backup data is not intended for ordinary product use.
Detailed instructions are published at /data-deletion.
1.16Your Privacy Rights and Choices
Depending on where you live and subject to exceptions, you may have rights to request access, correction, deletion, restriction, objection, portability, information about disclosures, withdrawal of consent, or review of certain automated decisions. You may also have rights to opt out of certain sale/sharing/targeted advertising activities if such activities occur under applicable law.
- Account data: update certain information in settings where available.
- Connected Platforms: disconnect through POSTARYX where available and/or revoke POSTARYX from the platform’s permissions page.
- Marketing: use the unsubscribe mechanism in marketing emails; necessary service messages may continue.
- Cookies: use the consent interface where provided and browser/device controls, subject to the Cookie Policy.
- Privacy requests: contact [Privacy Email]. We may verify identity and authority and may ask an authorized agent to provide proof of authorization where applicable.
We will respond within the time required by applicable law. If we deny or limit a request, we will explain the basis where legally required. You may have a right to appeal or complain to a data protection authority.
1.17Cookies and Similar Technologies
Our Cookie Policy describes the categories, purposes, providers, consent rules, and controls applicable to cookies and similar technologies. The final policy must match the actual production cookie scanner / tag configuration and should not name a vendor that is not in use.
1.18Children
POSTARYX is intended for business users and is not directed to children. The V2 baseline is that users must be at least 18 years old. We do not knowingly seek to collect personal data directly from children under 18. If you believe a child has provided personal data to POSTARYX, contact [Privacy Email]. [Counsel: confirm age threshold and jurisdiction-specific requirements.]
1.19Business Transfers
If Lunark Dynamics LLC is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, personal data may be disclosed to advisers and counterparties and transferred as part of the transaction, subject to applicable law and appropriate confidentiality safeguards.
1.20Legal, Safety, and Rights Disclosures
We may preserve, access, or disclose information where we reasonably believe it is necessary to comply with law or valid legal process; protect users, the public, Connected Platforms, or the Service; investigate fraud, abuse, security incidents, or rights violations; enforce agreements; or establish, exercise, or defend legal claims. We will evaluate requests according to applicable law and the data actually available to us.
1.21Changes to This Privacy Policy
We may update this Policy as our Service, integrations, vendors, laws, or platform requirements change. We will change the “Last updated” date and provide additional notice for material changes where appropriate or required. We may update a platform-specific section when approved scopes or features materially change.
1.22Contact
Privacy controller: Lunark Dynamics LLC
Product: POSTARYX
Registered address: [Registered Address]
Privacy requests: [Privacy Email]
General support: [Support Email]
Legal notices: [Legal Email]
Security reports: [Security Email or Security Contact Process]