At PostStreak, your privacy is not an afterthought — it's a design principle. This policy explains what data we collect, why we collect it, and how it's protected. We keep things plain and readable, not buried in legalese.
01 · About
Who We Are
PostStreak is a product of Polykoe, a technology company focused on tools for modern content creators and businesses. PostStreak helps individuals and brands maintain consistent social media presence across LinkedIn, X (Twitter), TikTok, Instagram, and Threads — powered by AI and streak-based accountability.
For any privacy-related matters, contact us at: [email protected]
02 · Data
Information We Collect
We collect only what is necessary to operate the service. Here is exactly what that includes:
- Account information
Your name and email address, obtained when you sign in via Google OAuth.
- OAuth access tokens
When you connect a social platform (LinkedIn, X, TikTok, Instagram, Threads), we store the access token issued by that platform so we can publish posts on your behalf. We do not store your social media passwords.
- Post content
The text content of posts you schedule or publish through PostStreak, stored so we can display your history and power our Queue feature.
- Streak data
Your posting streak count, longest streak, total posts, and last post date — used to power the streak feature that is core to the product.
- Usage data
General usage signals (e.g. which features you use) to help us improve the product. We do not use third-party analytics trackers.
03 · Purpose
How We Use Your Data
Your data is used exclusively to deliver the PostStreak service. Specifically:
- Publishing posts to your connected social accounts when you click "Post now" or when a scheduled post fires
- Generating AI content using Groq's language models — your topic/prompt is sent to Groq and not stored beyond the response
- Tracking your posting streak and surfacing your streak history on the dashboard
- Authenticating your session so you can securely access your account
- Sending account-related transactional emails (e.g. password resets) — we do not send marketing emails without explicit opt-in
We never sell your data. We do not share your personal information with advertisers, data brokers, or any third party for commercial purposes.
04 · Integrations
Third-Party Services
PostStreak connects to the following external services. Each has its own privacy policy and data practices:
- LinkedInSocial publishing
We post content on your behalf using the LinkedIn REST API. Your LinkedIn access token is stored encrypted in our database. LinkedIn's data practices are governed by LinkedIn's Privacy Policy.
- X (Twitter)Social publishing
We post tweets and threads via the X API v2. Your X OAuth token is stored securely. X's data practices are governed by X's Privacy Policy.
- TikTokSocial publishing
We post TikTok content via the TikTok API. TikTok's data practices are governed by TikTok's Privacy Policy.
- Instagram & Threads (Meta)Social publishing
We publish to Instagram and Threads via the Meta Graph API. Meta's data practices are governed by Meta's Privacy Policy.
- SupabaseDatabase & authentication
All user data, tokens, posts, and streak data are stored in Supabase. Data is encrypted at rest and in transit. Supabase is SOC 2 Type II compliant.
- GroqAI inference
Your content topic or prompt is sent to Groq to generate AI posts and hooks. Groq does not store prompts beyond the inference request.
- VercelHosting & edge network
PostStreak is hosted on Vercel. Request logs may be retained by Vercel for a short period for debugging purposes.
05 · Security
Data Storage & Security
We take the security of your data seriously. Here is how we protect it:
- All data is stored in Supabase, which encrypts data at rest using AES-256 and in transit using TLS 1.2+.
- OAuth access tokens are stored in a dedicated, access-controlled table. They are never logged or exposed in API responses to the client.
- When a social account is disconnected or a token expires, the token is marked as expired in our database and no longer used for publishing.
- Our API routes run on Vercel's edge infrastructure with no persistent server access.
- We use Row Level Security (RLS) in Supabase to ensure users can only access their own data.
06 · GDPR
Your Rights
If you are located in the European Economic Area (EEA), United Kingdom, or another jurisdiction with data protection laws, you have the following rights:
- Right to Access
Request a copy of all personal data we hold about you.
- Right to Correction
Request correction of inaccurate or incomplete data.
- Right to Deletion
Request deletion of your account and all associated data ("right to be forgotten").
- Right to Portability
Request your data in a portable, machine-readable format.
- Right to Object
Object to specific processing of your data, including any profiling.
- Withdraw Consent
Withdraw consent for data processing at any time by deleting your account.
To exercise any of these rights, email [email protected]. We will respond within 30 days.
07 · Retention
Data Retention
We retain your data for as long as your account is active. Specifically:
- Post content is retained indefinitely while your account is active so you can access your history.
- OAuth tokens are retained until you disconnect a platform, the token expires, or you delete your account.
- Streak data is retained for the lifetime of your account.
- Upon account deletion, all personal data is permanently deleted within 30 days, except where we are required by law to retain certain records.
08 · Termination
Account Termination
You may delete your PostStreak account at any time from your Settings page. Upon deletion:
- Your profile, post history, streak data, and OAuth tokens are permanently deleted from our systems.
- Posts that were already published to social platforms are not deleted from those platforms — you must remove them directly from LinkedIn, X, TikTok, Instagram, or Threads.
- Scheduled posts that have not yet been published will be cancelled and will not fire.
We also reserve the right to terminate or suspend accounts that violate our Terms of Service.
10 · Age
Children's Privacy
PostStreak is not directed to individuals under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe a minor has provided us with personal data, please contact us at [email protected] and we will promptly delete it.
11 · Updates
Policy Changes
We may update this Privacy Policy as our product evolves or as required by law. When we make material changes, we will:
- Update the "Last updated" date at the top of this page.
- Send an email notification to all registered users.
Continued use of PostStreak after a policy update constitutes acceptance of the revised policy.
12 · Contact
Contact Us
For privacy inquiries, data requests, or to report a concern:
- [email protected]
- Company
- Polykoe
- Product
- PostStreak (poststreak.app)