← Postwake

Privacy Policy

Last updated: July 1, 2026

Postwake (“Postwake”, “we”, “us”) is a cross-posting service: you connect your social accounts, and when you post on a connected origin account (such as Bluesky), we copy that post to your other connected accounts (such as Mastodon and Threads). This policy explains exactly what data we handle and why. We do not sell your data, and we do not use it to train any AI models.

Information we collect

  • Account & sign-in. Your email address, used only to create your account and send you a passwordless magic-link to sign in. Authentication is handled by Supabase Auth.
  • Connected social accounts. When you connect an account (Bluesky, Mastodon, Threads), we store the access and refresh tokens that account’s provider issues to us, along with your handle/username, account ID, and the instance or service it belongs to. These tokens are what let us read your origin posts and publish to your targets on your behalf.
  • Your posts and media. To cross-post, we read the content of posts you publish on your connected origin account — text, images, and video — and temporarily store that content so we can reliably deliver it to your target accounts. Media files are held in object storage (Cloudflare R2) for the duration needed to complete delivery.
  • Delivery & usage records. We keep a log of what was synced where, when, and whether it succeeded or was skipped (for example, because a daily limit was reached), plus daily usage counters used to enforce plan limits.
  • Billing. If you upgrade to a paid plan, payments are processed by our payment provider (Dodo Payments). We store a customer/subscription identifier and your current plan and status. We do not store your card or payment details ourselves.

How we use your information

  • To authenticate you and operate your account.
  • To read posts from your origin account and publish them to the target accounts you have connected — the core function of the service.
  • To enforce your plan’s limits and prevent abuse or duplicate posting.
  • To show you the status and history of your syncs.
  • To process payments and manage subscriptions, if you have a paid plan.

We only publish to a platform when you have connected it as a target and you post on your origin account. We do not post anything you did not originate.

How your data is protected

Access and refresh tokens for your connected accounts are encrypted at rest using authenticated encryption (AES-256-GCM) before being stored, with each record’s key bound to your account. Access to our systems is restricted, and data is isolated per user at the database level.

Third-party services

We rely on the following processors to run Postwake:

  • Supabase — database and authentication.
  • Cloudflare R2 — temporary storage of post media.
  • Upstash (Redis) — rate limits and daily usage counters.
  • Inngest — background job queue that performs the syncs.
  • Dodo Payments — payment processing (paid plans only).
  • The platforms you connect — Bluesky, Mastodon, and Threads (Meta), which receive the posts you choose to cross-post. Your use of those platforms is also governed by their own privacy policies.

Data retention

Post content and media are retained only as long as needed to complete and record delivery to your target accounts, and are then removed on a rolling basis. Connected-account tokens are retained until you disconnect the account or delete your account. Delivery logs are kept to give you sync history and for troubleshooting.

Your choices and rights

  • Disconnect an account at any time from your dashboard; this removes the stored tokens for that account and stops all syncing to/from it.
  • Delete your account and data. Email us at nayan.surya.official@gmail.com and we will delete your account, connected-account tokens, stored content, and associated records.
  • Access or correct the information we hold about you by contacting us.

When you revoke Postwake’s access from a platform’s own settings, that platform will notify us and we will remove the corresponding tokens.

Children

Postwake is not directed to children and is intended for users aged 13 and older.

Changes to this policy

We may update this policy from time to time. When we do, we will revise the “Last updated” date above. Material changes will be communicated where appropriate.

Contact

Questions or requests about this policy or your data: nayan.surya.official@gmail.com.