Privacy Policy
Last updated: 28 September 2026
Postjam is run by Computer go beep AB ("we", "us"), a company registered in Sweden. This policy explains what we collect when you use Postjam at postjam.app, why we collect it, and what you can ask us to do with it.
Postjam produces short-form posts, vertical videos and photo slideshows, from the footage, images, text and music you supply or pick from our library, and posts them to social accounts you connect. Most of what we hold is therefore your own content and your own account credentials, held so we can publish on your behalf.
What we collect
Account details. Your name, email address, and the credentials you use to sign in.
Connected social accounts. When you connect YouTube, Instagram, TikTok, a Facebook Page, or Threads, we store the access and refresh tokens that platform issues us, along with the account handle and channel or page ID. We ask each platform for the narrowest permissions that let us publish a post and read back the statistics for that same account. We do not request permission to read your private messages, your follower lists, or anything belonging to other people.
Content and media. The clips, screen recordings and images you upload to your gallery, the text lines and captions you write, the posts you import by link, the library pictures and songs you pick, and the finished videos and slideshows we render for you.
Your business. The company name, website, product description and category you give us when you set up a workspace, which the text on your posts is written around.
Performance data from your accounts. After we publish, we pull back aggregate figures for your own posts and accounts: views, likes, comment counts, follower and following counts. These are totals. We do not collect the identities of the people who watch, like, or comment on your posts, and we do not store comment text.
Billing data. If you are on a paid plan, Stripe processes your payment and gives us your billing name, country, the last four digits of your card, and the status of each charge. We never receive your full card number.
Technical data. Your IP address, browser and device type, and how you move through the app. This reaches us through our hosting provider and through Vercel Speed Insights, which measures page performance. Once you are signed in, Mixpanel also records which parts of the app you use and the answers you give while setting up your workspace, so we can see which features matter and where new users get stuck.
Why we use it
Under the GDPR we rely on these legal bases:
- To perform our contract with you — running your account, taking payment for it, rendering your videos and slideshows, publishing to the platforms you connected, and showing you how those posts performed.
- Our legitimate interests — keeping the service secure, diagnosing faults, and understanding which parts of the product are slow or broken.
- Your consent — for anything outside the above, which we will ask for separately and which you can withdraw at any time.
- Legal obligation — where we have to keep records or respond to a lawful request.
Who we share it with
We do not sell your personal information, and we do not share it for advertising. We pass data to the following providers only so they can perform a job for us:
- Stripe — payment processing for paid plans.
- Vercel — hosting, and Speed Insights for page performance measurement.
- Mixpanel — product analytics for signed-in users.
- Cloudflare — rendering videos and slideshows (Workers) and storing media (R2).
- OpenAI — reading the posts you import, rewriting text lines where an automation asks for it, and reading the website you paste at sign-up. See the section on models below.
- Google, Meta, and TikTok — the APIs behind YouTube, Instagram, Facebook Pages, Threads, and TikTok, which receive the videos, slideshows and captions you publish.
Most of these act as processors bound by contract. Two do not. The social platforms are independent controllers for content once it is posted to your account there, and their own privacy policies govern what happens after publication. Stripe is an independent controller for payment and fraud prevention, under its own privacy policy.
We will also disclose data if the law requires it, or to protect our rights or someone's safety.
YouTube API Services
Postjam uses YouTube API Services to connect your YouTube channel, upload the videos you choose to publish, and read back the aggregate statistics for those uploads. By connecting a channel you also agree to the YouTube Terms of Service, and Google's own handling of your data is described in the Google Privacy Policy.
What we store from Google is what the sections above describe: the OAuth tokens Google issues us, your channel name and ID, and the view, like, and comment totals for the videos we published. Postjam's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
You can disconnect your channel inside Postjam at any time, which deletes the stored tokens straight away, or revoke Postjam's access from Google's side on the Google security settings page.
Where a model reads your content
Postjam does not generate footage or images. A language model reads your content in four places, and in each we send OpenAI only what that job needs:
- Importing a post. When you paste a public post link, we download that post's slides or video through our own servers and send each slide, or a frame of each scene, to the model to read the text on it and describe the background. The post's caption goes with it so the hashtags can be sorted.
- Naming an automation. The cover image of a pasted post is read once so the automation can be titled after its first line.
- Rewriting text. Where you set an automation to rewrite its text lines, the line and your product description are sent so the model can write variations of it.
- Setting up a workspace. When you paste your website at sign-up, the text of that page is sent so the form can be filled in for you to correct.
Nothing sent this way is used to train a model: OpenAI's API terms, which we use it under, exclude training on it. Media you upload to your gallery is never sent to a model unless you pick one of these actions on it.
Do not upload media showing someone who has not agreed to appear in it. If you upload a person's face or voice, you are confirming you have their permission.
Cookies
We use cookies that are strictly necessary to keep you signed in and to keep the service secure. We do not use advertising cookies or cross-site tracking pixels. Speed Insights measures performance without setting cookies. Once you are signed in, Mixpanel keeps an identifier in your browser's local storage so that your actions in the app count as one person; nothing is stored while you browse the public site.
Where your data is stored
We operate in the EU, but several of our providers are based in the United States. Where data leaves the European Economic Area, the transfer is covered by the European Commission's Standard Contractual Clauses or an equivalent safeguard.
How long we keep it
We keep your account data for as long as your account is open, and delete it within 30 days of you closing it or asking us to erase it. Tokens for a social account are deleted as soon as you disconnect that account. Media you upload, import or render stays until you delete it.
You can delete your account yourself under Settings → Account → Delete account, which removes every workspace you own, its media, its connections and its tokens at once. The steps are on our delete your account page.
Billing records are the exception. Swedish bookkeeping law requires us to keep invoices and payment records for seven years, so those survive an erasure request.
How we protect it
Traffic is encrypted in transit with TLS. Stored media is encrypted at rest and held in access-controlled storage. Social tokens are kept apart from the rest of your account data and scoped to the minimum permissions the job needs. No system is perfectly secure, and we cannot promise absolute safety.
Your rights
If you are in the EEA or the UK, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or send it to another provider in a portable form. Where we rely on consent, you can withdraw it at any time.
Write to g@computergobeep.org and we will respond within one month. If you are unhappy with our answer, you can complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten) or to the regulator where you live.
If you are in California
You have the right to know what personal information we collect and why, to request a copy, to ask us to delete or correct it, and not to be discriminated against for exercising any of these rights.
We have not sold or shared personal information in the past twelve months, as the CCPA defines those terms, and we do not use your information for cross-context behavioural advertising. Because there is nothing to opt out of, we do not offer a "Do Not Sell or Share My Personal Information" link. To make any other request, email g@computergobeep.org.
Children
Postjam is for businesses and professional creators. It is not aimed at children, and we do not knowingly collect data from anyone under 16. If you believe a child has given us data, contact us and we will delete it.
Changes
If we change this policy we will update the date at the top of this page. If a change materially affects your rights, we will tell you directly.
Contact
Computer go beep AB g@computergobeep.org
This policy is governed by Swedish law.