Privacy Policy
Last updated: July 18, 2026
1. Who we are
Postbotic is an AI-assisted social media management platform operated by Ayotiq Digital Technologies, based in Saskatchewan, Canada (“Postbotic”, “we”, “us”). We handle personal information in accordance with Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA).
Questions, access requests, or complaints can be sent to privacy@ayotiq.com.
2. Information we collect
We collect only what the product needs to work:
- Account information. Your name, email address, and password when you sign up. Passwords are stored only as salted bcrypt hashes — we never store or see your plaintext password. Sessions use a signed cookie.
- Workspace content. Business and brand information you enter (or approve from our website-analysis bootstrap), content drafts, campaign plans, and media files you upload.
- Connected social account data. When you connect a Meta (Facebook) account, we store the list of Pages you manage, the Page you select, and the access tokens needed to publish on your behalf. See section 4 for details.
- Audit and security data. A server-side audit log of significant actions (for example approving a post or connecting an account), including the acting user, timestamp, and IP address. This exists for security and accountability, not marketing.
- AI generation records. Records of AI generation requests (prompts, model used, estimated cost) so we can enforce usage limits and spending caps.
3. How we use information
- To provide the service: drafting, reviewing, and publishing social media content that you explicitly approve.
- To generate content with AI. Your brand information and drafts are sent to Google Vertex AI (Gemini models) to produce suggestions. They are used to answer your request, not to train models under our control.
- To secure the platform: authentication, tenant isolation, rate limiting, and audit logging.
- To communicate with you about your account or the service.
We do not sell personal information, we do not share it with advertisers or data brokers, and we do not use third-party advertising or analytics trackers on this site. The only cookie we set is the session cookie that keeps you logged in.
4. Meta (Facebook) platform data
When you choose to connect a Facebook account, Postbotic requests three permissions and nothing more:
pages_show_list— to show you the Pages you manage so you can pick one to connect.pages_read_engagement— to read engagement data for content published through Postbotic, so we can report how your posts performed.pages_manage_posts— to publish content to your selected Page, and only content you have approved.
What we do with this data:
- Page access tokens are encrypted at rest with AES-256-GCM and are decrypted only server-side at the moment of an API call.
- We store only your Page list, the connected Page’s ID and name, and the encrypted tokens — not your personal Facebook profile, friends, or messages. We access no profile information beyond the basics required for OAuth login.
- Publishing is human-gated: nothing is posted to your Page without an explicit approval in the product.
What we never do with Meta platform data:
- Sell it, license it, or share it with third parties for advertising, data brokering, or any purpose other than operating the service you signed up for.
- Use it to build profiles of people who interact with your Page.
- Retain tokens after disconnection — disconnecting a Page in the product immediately deletes the stored access tokens.
5. Service providers
We use a small number of infrastructure providers to run Postbotic, each acting on our instructions:
- Google Cloud (United States, us-central1): application hosting (Cloud Run), database (Cloud SQL), media file storage (Cloud Storage), and AI content generation (Vertex AI / Gemini).
- Meta Platforms: only when you connect a Facebook Page, to list Pages, read engagement, and publish approved content.
Because our infrastructure runs on Google Cloud in the United States, your information is stored and processed there and may be subject to lawful access requests under U.S. law.
6. Retention and deletion
- Account and workspace data is retained while your account is active.
- Social access tokens are deleted immediately when you disconnect the account in the product.
- You can request deletion of your account and associated personal information at any time by emailing privacy@ayotiq.com. We will complete deletion within 30 days, except for records we are required to keep for legal, security, or audit purposes, which are retained only as long as necessary for those purposes.
7. Security
- All traffic is encrypted in transit (TLS).
- Social access tokens are encrypted at rest (AES-256-GCM).
- Passwords are hashed with bcrypt.
- Access is controlled by role-based permissions with strict tenant isolation between organizations and workspaces, backed by server-side audit logging.
8. Your rights
Under PIPEDA you may request access to the personal information we hold about you, ask us to correct it, withdraw consent (which may limit the service we can provide), or request deletion. Contact us at privacy@ayotiq.com and we will respond within 30 days. If you are unsatisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada.
9. Children
Postbotic is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under the age of majority in their province or territory of residence.
10. Changes to this policy
If we make material changes to this policy, we will update the “last updated” date above and, where changes significantly affect how your information is handled, notify account holders by email or in-product notice.