Last updated 15 September 2026
Privacy
PostDori holds your business's social media accounts and writes posts for them. That means we hold access tokens and post content, and it means you should know exactly what we keep. This page says what is stored, why, and how to delete it.
Who we are
PostDori is operated from Dhaka, Bangladesh. If you want to reach a person about anything on this page, write to privacy@postdori.app. We answer in Bangla or English, whichever you write in.
What we store
- Your account
- Your name, email address, and a hash of your password. We never store the password itself — it is hashed with Argon2id, which cannot be reversed. If you sign in with Google we store the Google account id, not a password.
- Your business
- Everything you tell us in Brand setup: what you sell, who buys it, your tone of voice, the words you want us to avoid, your delivery areas and price range. This is the material the AI writes from.
- Connected social accounts
- The Facebook Page or Instagram account id and name, and an access token. The token is encrypted before it is written to the database and is never sent to your browser. We do not store your personal Facebook login, and we do not keep a user-level token after the connection is set up.
- Posts and pictures
- Drafts, captions, hashtags, schedules, and any images or videos you upload. Uploaded files are stored in object storage; the link to them is stored with the post.
- Results
- Reach, likes, comments, shares and saves for posts PostDori published, fetched from the platform after publishing. These are numbers about posts, not about the people who saw them.
- Assistant conversations
- What you type to the assistant and what it replies, so the conversation makes sense when you come back to it, plus a record of every action it took on your behalf.
- An audit log
- Who did what and when, including which actions the AI took rather than a person. This exists so that "what happened to my account" always has an answer.
- Technical logs
- Ordinary server logs: request paths, timings, error traces, and IP addresses. Access tokens, passwords and post content are deliberately kept out of them.
Why we store it
All of it exists to do the one job you hired the product for: write posts that sound like your business and put them out on time. We do not sell any of it, we do not share it with advertisers, and we do not build profiles of your customers.
In GDPR language, our lawful basis is performance of the contract with you for everything above, except technical logs and audit entries, which we keep on the basis of a legitimate interest in running the service securely.
What the AI sees
When PostDori writes a post, it sends your brand profile, the brief you gave, and recent post performance to Anthropic's API to generate the text. It does not send your email address, your password, your access tokens, or your customers' details.
Your content is not used to train any model. The assistant can read and write your posts and your calendar; it cannot change your brand settings, connect or disconnect accounts, invite people, or touch billing, and it has no way to run arbitrary queries against the database. Deleting or cancelling anything always asks you first.
How long we keep it
Sessions and refresh tokens expire on their own. Password reset and email verification links expire within hours. Everything else — your brand, your posts, your results — stays until you delete it, because a calendar that quietly loses last year's posts is worse than useless.
When you delete your workspace we remove your brand profile, posts, media, schedules, conversations and connected accounts within 30 days. Audit entries and invoices are kept longer where we are required to keep them, with the personal details stripped out.
Deleting your data
You can disconnect a Facebook Page or Instagram account at any time from Connections. Doing so deletes the stored token immediately. You can also remove the app from Facebook Settings → Business Integrations, which has the same effect.
To delete everything, write to privacy@postdori.app from the email address on the account, or use the delete option in Settings. We confirm in writing when it is done. There is no retention hold and no reactivation window — once it is gone, it is gone.
Your rights
You can ask for a copy of everything we hold about you, ask us to correct it, or ask us to delete it. We do not charge for this and we do not ask why. Email privacy@postdori.app and we will respond within 30 days.
Security
Passwords are hashed with Argon2id. Social access tokens are encrypted with AES-256-GCM before storage and are only decrypted inside the worker at the moment a post goes out. Session cookies are httpOnly and cannot be read by JavaScript. Every request is checked against the workspace it claims to belong to, so one business can never read another's data.
No system is perfect. If we ever discover a breach affecting your data, we will tell you what happened and what it means for you, without waiting to have a good answer ready.
Changes
If this page changes in a way that affects you, we will email you before it takes effect. See also our terms of service.
This document was drafted by the people who built PostDori, so that it describes what the software genuinely does rather than what a template assumes. It has not yet been reviewed by a lawyer. Before PostDori takes payment or serves users outside a private beta, it needs that review.