Back to PersonnaPress

Privacy Policy

Effective date: July 2026

PersonnaPress ("we", "us", or "our") is committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights.

1. What We Collect

We collect the following information when you use PersonnaPress:

  • Your email address and hashed password, or your Google profile information (name, email, Google account ID) if you sign in with Google OAuth
  • Website URLs and content you provide for brand voice analysis
  • Brain Dump text you enter when creating campaigns
  • Files you upload (images and documents for content generation)
  • Billing information processed by Stripe (we do not store card numbers)

Social Platform Connections

When you connect a social platform or publishing destination, PersonnaPress stores the OAuth credentials required to publish on your behalf. Specifically:

  • Facebook Pages and Instagram: encrypted Page Access Tokens, long-lived user tokens, Facebook Page IDs, Instagram Business Account user IDs, and account display names
  • Threads: encrypted long-lived user access tokens and Threads user IDs
  • X (Twitter): encrypted OAuth 2.0 access and refresh tokens
  • LinkedIn: encrypted OAuth 2.0 access tokens and LinkedIn member URNs
  • WordPress.com: encrypted OAuth access tokens and site identifiers
  • WordPress (self-hosted): credentials you provide (stored encrypted)
  • GitHub Pages: GitHub App installation IDs and repository identifiers
  • Webflow: encrypted API tokens and site identifiers

All OAuth tokens are encrypted at rest. We do not collect or store your social posts, followers, messages, or any other content from connected platforms beyond what is necessary to authenticate and publish.

2. How We Use Your Data

We use your data solely to provide the PersonnaPress service:

  • Blog posts and social content are generated using an AI language model. Depending on your account configuration, content may be processed by the Google Gemini API or the Anthropic Claude API. Your content is sent to the active AI provider for processing.
  • Featured images are generated using the Replicate API (FLUX 1.1 Pro model), developed by Black Forest Labs. Images you request may be processed by their infrastructure.
  • Authentication and session management
  • Billing and subscription management via Stripe
  • Publishing content to platforms you have connected (Facebook Pages, Instagram, Threads, X, LinkedIn, WordPress, GitHub Pages, Webflow) using the OAuth credentials you authorized

3. Third-Party Services

PersonnaPress relies on the following third-party services to operate. Each has its own privacy policy:

  • Google Gemini API: content generation (optional AI provider)
  • Anthropic (Claude API): content generation (default AI provider)
  • Replicate / Black Forest Labs (FLUX 1.1 Pro): image generation
  • Meta (Facebook, Instagram, Threads): publishing integration via the Meta Graph API and Threads API
  • X Corp (Twitter): publishing integration via the X API v2
  • LinkedIn: publishing integration via the LinkedIn API
  • WordPress.com / Automattic: publishing integration
  • GitHub: publishing integration via the GitHub App API
  • Webflow: publishing integration via the Webflow API
  • Stripe: billing and payment processing
  • Supabase: data storage and file hosting
  • Vercel: frontend hosting and edge delivery
  • Resend: transactional email (account verification, notifications)
  • Sentry: error monitoring (anonymized stack traces; no personal content is sent)

We encourage you to review the privacy policies of these services, as they govern how your data is handled on their platforms.

4. Data Retention

Your data is retained for the lifetime of your account. OAuth tokens for connected platforms are deleted immediately when you disconnect a platform or when your account is deleted.

After your free trial expires and you do not upgrade:

  • After 30 days your account is flagged for deletion
  • A 7-day warning email is sent
  • After 37 days total, your account and all associated data (clients, campaigns, platform connections, uploaded files, and OAuth tokens) are permanently deleted

5. Meta Platform Data and Data Deletion

PersonnaPress is a registered Meta app that uses the Meta Graph API to publish to Facebook Pages, Instagram Business Accounts, and Threads. In accordance with Meta's Platform Terms:

  • We only request the permissions necessary to publish content on your behalf: instagram_content_publish, pages_manage_posts, threads_content_publish and the read permissions required to discover your connected accounts.
  • We do not access or store your personal Facebook profile, friend lists, private messages, or any data beyond platform tokens and account identifiers.
  • Meta may notify us when you remove PersonnaPress from your Facebook app settings. To fully remove all associated data, delete your PersonnaPress account from Account Settings.

To delete all data PersonnaPress holds from your Meta platform connections, delete your PersonnaPress account from Account Settings.

6. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: request a copy of the personal data we hold about you
  • Deletion: request that we delete your personal data. You can do this immediately by deleting your account from the Settings page, or by contacting us.
  • Correction: request correction of inaccurate data
  • Portability: request a machine-readable export of your data
  • Objection: object to certain processing of your data

To exercise any of these rights, email us at support@personnapress.com with the subject line “Privacy Request”. We will respond within 30 days.

You can also delete your account at any time directly from the Settings page. Deleting your account permanently removes all your data. This action cannot be undone.

7. Cookies

We use the following cookies only:

  • Session cookie (httpOnly, 7-day expiry): used for authentication only
  • OAuth state cookies (httpOnly, 10-minute expiry): short-lived cookies set during platform OAuth flows to prevent cross-site request forgery. Deleted immediately after the OAuth flow completes.

We do not use tracking cookies, advertising cookies, or any third-party analytics cookies.

8. Contact

If you have questions about this policy, contact us at support@personnapress.com.