Postfjord
Product
postsocialPlan, write and publish to Instagram, Facebook, LinkedIn, Threads, TikTok and YouTube from one calendar, with Claude drafting in your brand voice and analytics that show what actually works. postchatOne inbox for Instagram and Facebook messages and comments, with automations that turn a comment into a conversation and always respect a STOP. postmailEmail campaigns to the contacts you already collect in Postfjord, with double opt-in, a block editor and sending from the EU, plus landing pages and a link in bio page on postfjord.page. All featuresScheduling, AI composer, inbox, DM automation, analytics, landing pages and an MCP server for ChatGPT, Claude, Gemini and other AI apps. Everything in every plan.
Solutions
For creators For small businesses For agencies For salons and beauty For gyms and studios For restaurants and cafés
Pricing Academy Blog
Sign in Get early access

Privacy Policy

Last updated: 28 September 2026

Postfjord is a marketing service for small businesses: plan and publish social media posts (postsocial), answer and automate Instagram and Facebook messages (postchat), and send email (postmail). It is operated by Yogakollektivet Sverige AB, org. nr 556858-0699, Rallarvägen 10, 755 76 Vänge, Sweden ("Postfjord", "we", "us"). This policy explains what personal data we process at postfjord.com and app.postfjord.com, why, with whom we share it, how long we keep it and what rights you have under the EU General Data Protection Regulation (GDPR).

1. Two roles: controller and processor

We are the controller for data about our customers and their team members (accounts, billing, support), for visitors to our website, and for the small amount of data we use to protect the service for everyone, such as the shared email suppression list described in section 4.

We are a processor for data that a business (a "workspace") handles about its own contacts through Postfjord: people who send a direct message to or comment on a connected Instagram or Facebook account, contacts the business adds, and people who receive its emails. For that data the business is the controller. It decides why the data is processed, and we process it only on its instructions under our Data Processing Agreement. If you are one of those contacts, see section 9.

2. Data about our customers and their team members

Account

Name, email address, a password that Firebase Authentication stores only in scrambled (hashed) form. When you choose a new password through a reset link, it passes through our servers once on its way to Firebase and is never stored or logged by us. Or, if you sign in with Google, the name, email address and profile picture Google shares. We also store your language, email preferences, dashboard layout, the workspaces you belong to and your role in each.

Access requests and invitations

When you join the waitlist on postfjord.com we store your email address, which page you signed up on and your browser's language. When you request early access we store your name, email address, company, website and the reason you give, and who approved the request. When someone invites you to a workspace we store your email address, the role and who invited you. We also keep records of email verification and password reset requests (email address, time and a hashed token).

When you sign in to the Academy on postfjord.com we create or use your Postfjord account with your email address, and store which lessons you marked done, your answers to the quick questions, the result of the final exam (whether you passed, your score when you did, the number of attempts and when), and which lessons the app ticked off because it saw you do them. For sign-in we email you a 6-digit code and keep only a keyed hash of it (never the code itself) with the number of tries. The code works for 10 minutes; its hash is deleted when you use it, or automatically within about a day after it stops working. We also keep a hash of your address with the time and number of codes sent that day, and a hash of your IP address with the number of codes asked for and typed from it that day. A diploma or certificate you ask for stores the name you type, the course, the date and an ID. Its page on postfjord.com is public to anyone with the link, so you can share it; it shows no email address.

Billing

Payments are handled by Stripe. When you choose a paid plan, Stripe collects your card details, name, billing address and, if you give one, your VAT number. Card details never reach us. We store your plan, subscription status, billing interval, renewal date and the Stripe customer and subscription identifiers.

Connected social accounts

When you connect a social account we store its identifiers, name, username and profile picture link, and the access tokens the platform issues. Tokens are encrypted (AES-256-GCM) and used only for the features you use: publishing, reading your own posts and insights, the inbox and automations, and keeping the connection alive. What else we store depends on the platform:

  • Facebook Page or Instagram professional account connected through Facebook: also the Facebook user id of the person who connected it. Connected through Instagram only: the Instagram account alone.
  • Threads profile: nothing more than the above.
  • LinkedIn profile: your LinkedIn member id, name and profile picture from LinkedIn's sign-in. LinkedIn also shares your email address when you connect, and we do not store it. LinkedIn's access expires after 60 days, and we show the date you need to connect again.
  • YouTube channel: see YouTube below.
  • X account: your X user id, username, name and profile picture link. We ask X to read your profile, to read and write posts, to upload media and to keep the connection (offline access); we do not read your timeline, followers, likes or direct messages. For each post we store its X id and link, and we count how many posts each workspace makes to X each month, because posting to X is sold with a monthly number of posts. The access tokens are stored encrypted. Disconnecting the account deletes its tokens and its details at once. Your use of X through Postfjord is also subject to X's Terms of Service and Privacy Policy.
  • Pinterest account: your Pinterest account id, username and profile picture link, and the names, ids and privacy setting (public or protected) of your boards, so you can choose where each pin goes. We ask Pinterest only to read your account and boards, to create a public board when you press New board, to read the pins Postfjord creates and to create pins; we do not read secret boards, analytics or ads, and we never change or delete a board. For each pin we store its Pinterest id and link. Disconnecting the account deletes its tokens, its board list and its details at once; if the account moves to another workspace, the old workspace loses the tokens and the board list.
  • Google Business Profile: for each business place you add, its Google location id and account id, name, street and town, Google Maps link, place id, language and whether Google lets it take posts. We ask Google for one permission, to manage your Business Profile, and use it only to list the places you manage and to create the posts you schedule; we never change your business details, hours, photos or reviews, and we do not read your reviews or insights. For each post we store its Google id and link. Disconnecting a place deletes its tokens and its details at once; if the place moves to another workspace, the old workspace loses the tokens. Our use of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements.
  • TikTok account: your TikTok user id for Postfjord (open id), display name, username and profile picture link. We ask TikTok only for your basic profile, to post videos and to send videos to your TikTok inbox; we do not read your other videos, followers, messages or statistics. Each time you open a post for TikTok we ask TikTok which privacy and interaction settings your account allows and show them, without storing them. With each post we store the settings you chose, TikTok's id for the post and, once TikTok gives one, its link. Disconnecting the account asks TikTok to end Postfjord's access and deletes its tokens and details at once. TikTok handles your data under the TikTok Privacy Policy and the TikTok Terms of Service.

YouTube

Postfjord uses YouTube API Services to upload videos to a YouTube channel you connect. By connecting a channel you also agree to the YouTube Terms of Service, and Google handles your data under the Google Privacy Policy.

What we access and store. When you connect, Google asks you to sign in and to let Postfjord upload videos to your channel. From the sign in we store your Google account id and the name on your Google account, which we show as the channel's name until your first video is uploaded. We do not ask for your email address and we do not keep your profile picture. We also store the access tokens Google issues (encrypted, as above), from the first upload on the channel id and title, and for each video you publish through Postfjord its YouTube id, link and status. We use this only to publish the videos you schedule and to show you where they went. We do not read your other videos, comments, subscribers or watch history. We do not sell this data, use it for advertising or use it to train AI models, and we share it only with the providers in section 5 that host Postfjord.

How to remove access. Disconnect the channel under Channels in Postfjord, which at once deletes its tokens, its name, the channel id and title, and the YouTube id, link and status of every video. Your Google account id is part of the internal key Postfjord files the channel's posts and their publishing log under, so it stays there until you delete those posts or the workspace. You can also remove Postfjord's access in your Google Account at security.google.com/settings/security/permissions. Postfjord can then no longer upload, and within 7 days we delete the channel's tokens, name, channel id and title and the YouTube data we stored. The channel stays in your list as revoked with only your Google account id, so that Reconnect finds it again. Disconnect it to remove it from the list.

Postfjord's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. This also covers the name, email address and picture Google shares when you sign in with Google.

Content and settings

Posts, drafts, ideas, templates, schedules, uploaded images (the app removes location, time and camera data from a photo before it is uploaded, except from a file the browser cannot open), videos and fonts (including any metadata stored inside those files), your brand profile, automations, saved segments, and daily analytics for your connected accounts (follower counts, engagement totals and your top posts). If you import your brand voice from a website, we fetch the text of that website.

API keys and integrations

For API keys we store a hash of the key, its name, prefix and when it was last used. Keys for integrations you connect (Mailchimp, or your own AI provider) are stored encrypted.

Usage, support and security

The number of AI tokens each feature uses and their cost, so we can enforce your plan's budget (we do not store the prompts). Messages you send us. Technical logs of the service (time, errors and the ids of the workspace and user involved). IP addresses are used briefly to limit the number of requests and are not stored by our code, with one exception: when someone uses a signup form, we keep a hash of the IP address, mixed with a secret that changes every day, for up to 48 hours to count signups from one device. The address itself cannot be read back from it.

Emails we send you

Service emails such as email verification, password resets, invitations, access decisions and notifications about new or assigned conversations and collected email addresses. You can turn notifications off under Account. If we send product news, you can turn it off under Account and in every such email.

3. Data a workspace processes about its contacts (we are processor)

A workspace decides which of these features it uses. Only members of that workspace can see this data in the app. Postfjord staff can access a workspace when needed for support, security, abuse handling or a legal obligation.

Messages and comments

When someone sends a direct message to or comments on a connected account, Meta passes it to Postfjord and we store it so the business can read and answer it: the person's platform id, the name and username Meta shares for them, the text, buttons they tap, links to attachments, story replies and mentions, the link or ad that opened the conversation, and for comments the author's name or username. Replies the business or its automations send are stored the same way. If the person unsends a message on Instagram, we delete its text, attachments and links from Postfjord as well. When an automation needs to know whether the person follows the account, we ask Meta and use the answer without storing it.

A WhatsApp number connected while it stays in the WhatsApp Business app also brings, once and only if the business allows it on the phone, its one to one chats from the last six months and the names and numbers in its WhatsApp contacts. The chats are stored like other messages. The contact names are kept only so threads show the name the business uses; a contact removed in the app, a deleted contact and a disconnected number take them with them.

Contact details

Details the business adds or an automation collects: email address and where it came from, first and last name, birthday, phone number, other custom fields, tags, assignment and status, whether the person has opted out of automated messages, and which tracked links the person clicked and when.

Automations and AI replies

Automations send messages based on rules the business sets. If the business uses AI replies, the last messages of the conversation and the person's display name are sent to the AI provider the workspace uses (see section 5) to draft an answer.

Email (postmail)

For workspaces that use email: contact email addresses, signups through the workspace's signup forms (the address, the first name if the form asks for it, and which form was used), the consent status for each address (when confirmation was requested and given, how, and which team member confirmed a consent given in person), for addresses imported from another email service the proof that service kept (when and from which IP address the person signed up and confirmed, and how they were added), unsubscribe records (including whether the person used the button in their mail app or the link in the email), and delivery events from Amazon SES (delivered, bounced, complained, including the recipient address). Every email carries the sender's company name, postal address and an unsubscribe link. As email features are added, workspaces may also use list import and checks of email addresses before sending. We describe those here, and add any new provider to section 5, before they are used.

Clicks and opens in campaign emails are counted per email, not per person. Links in a campaign email pass through Postfjord, which counts a click on that link and sends the reader on to the page. For each click we store which link it was and the hour, nothing about who clicked. Where Postfjord has switched on counting opens for a workspace, the email also carries a small invisible image that is the same in every copy, so loading it says that the email was opened, not by whom. For each open we store the hour and whether it looked automatic (Apple Mail loads images by itself when an email arrives). So that one person opening a link or the email many times in the same clock hour counts once, our servers make a keyed hash from the network address (for IPv6 its first half), the campaign, the link and that hour. The hash is kept as a marker that expires two hours after it is made and is deleted after that, usually within a day. Nobody in the workspace can see it. Opens that come through a mail service's image proxy, such as Gmail's or Apple's, are not deduplicated this way, since many readers share one proxy address, and may count each time, up to 20 opens for each person the email reached. We keep running totals of opens, clicks and proxy loads per email to enforce these limits; they hold numbers only. The workspace sees only totals, and none until an email has reached 10 people. Click and open records are deleted after 13 months. Postfjord does not record who opened an email or who clicked a link, and does not do so until the law on that has been checked and the person has agreed. A reader who does not want an email opening to be counted can turn off images in their mail app.

Bookings and sales

A workspace can connect its own booking system (for example Calendly or Acuity) or its own Stripe account, so Postfjord can count the bookings and sales that its posts, messages, emails and pages lead to. The booking system or Stripe sends each booking or payment to Postfjord. We keep the class or service, the time and the status of a booking, and the amount, currency and any refund of a sale, together with the contact and the automation, email or page it belongs to. The contact gets a count of bookings and purchases, the total they spent, and a Booked or Customer tag. The person's email address and name in the booking or payment are used only to find the matching contact and are not stored. The incoming event is deleted as soon as it has been matched.

Exports and integrations

A workspace can export its contacts as a file, which is created in the browser and not stored by us. If a workspace connects Mailchimp, contact email addresses, names, birthdays, phone numbers and tags are sent to its Mailchimp account, and when the workspace deletes a contact, the address is deleted from that Mailchimp audience as well.

4. Why we process data and our legal basis

Purpose (as controller)Legal basis
Create and run your account and workspaces, publish and deliver what you ask for, provide supportContract (GDPR art. 6.1 b)
Handle waitlist signups, early access requests and invitationsSteps before a contract, and legitimate interest in admitting customers carefully (6.1 b and f)
Payments, invoices and bookkeepingContract and legal obligation under the Swedish Bookkeeping Act (6.1 b and c)
Service emails and notificationsContract (6.1 b)
Product news to customersLegitimate interest, with an easy opt-out (6.1 f)
Security, rate limits, abuse prevention and reviews of risky sendingLegitimate interest in a safe and reliable service (6.1 f)
Shared email suppression list: addresses that hard bounced or complained are stored only as a SHA-256 hash so that no workspace emails them againLegitimate interest in protecting recipients and the deliverability of every customer (6.1 f)
Limits on confirmation emails: how many were sent to an address in the last 30 days and when, stored only against a SHA-256 hash of the address, so nobody can use Postfjord to flood an inboxLegitimate interest in protecting recipients and preventing abuse (6.1 f)
When a workspace is deleted, a record of who had unsubscribed from its emails, stored only as SHA-256 hashes and kept for the workspace owner, so an import into a new workspace cannot email them againLegitimate interest in respecting people's opt-outs (6.1 f)
Aggregated statistics about visits to postfjord.comLegitimate interest (6.1 f)
Google Analytics on postfjord.com, only after you accept cookiesConsent (6.1 a), which you can withdraw at any time under Cookie settings
Meta data deletion requests and other legal requestsLegal obligation and our agreements with platforms (6.1 c and b)

For contact data where we are processor, the workspace decides the purpose and needs its own legal basis, for example consent to email marketing or the rules for its existing customers under the Swedish Marketing Practices Act.

5. Who we share data with

We never sell personal data. We share it only with the providers below, under data processing terms, and with the platforms and services you choose to connect.

ProviderWhat forWhere
Google Cloud and FirebaseHosting, database, file storage, functions and sign-inDatabase, files and functions in the EU (Belgium, europe-west1). Sign-in and the website delivery network are global Google services.
Anthropic (Claude)Writing assistant, brand profile, weekly plan, help assistant, and AI replies unless the workspace uses its own AI providerUSA
OpenAITurning a dictated brief into text, unless the workspace uses its own ChatGPT key. The recording is not stored by usUSA
Amazon Web Services (Amazon SES)Sending email for workspaces that use postmail, and delivery, bounce and complaint eventsEU (Stockholm, Sweden)
StripePayments and subscriptionsEU and USA
OderlandSending our service and notification emailsSweden
CloudflareDelivering landing pages and link in bio pages on postfjord.page; visitors' requests to those pages, with their IP address, pass through itGlobal (EU-US Data Privacy Framework and standard contractual clauses)
AhrefsCookieless, aggregated visitor statistics on postfjord.comSingapore
Google (Google Analytics)Visitor statistics on postfjord.com, only after consent to cookiesEU and USA (EU-US Data Privacy Framework and standard contractual clauses)
Google FontsFonts in the app at app.postfjord.com; your browser contacts Google, which receives your IP address; postfjord.com serves its own fontsGlobal

Anthropic and OpenAI do not use data sent through their APIs to train their models, and no access tokens are ever sent to an AI provider.

Platforms and services you connect. Meta, LinkedIn, Google (YouTube), Pinterest, X and TikTok receive the posts, videos, replies and messages you send through Postfjord and send us the data described in sections 2 and 3. Each is an independent controller for its platforms. If a workspace connects Mailchimp, or chooses its own AI provider (Anthropic, OpenAI, Google Gemini, Mistral or DeepSeek), the data those features use is sent to that provider under the workspace's own agreement with it. DeepSeek processes data in China, which the EU has not found to offer adequate protection; a workspace that chooses it is responsible for that transfer.

When a provider processes data outside the EU and EEA, the transfer relies on an EU adequacy decision (such as the EU-US Data Privacy Framework for certified companies) or on the EU standard contractual clauses in that provider's data processing terms.

We may also disclose data when the law requires it, for example to a court or authority.

6. How long we keep data

DataKept
Account and profileUntil you delete your account
Workspace content, contacts, messages, comments, consent records and analyticsUntil the workspace deletes the contact or the whole workspace, or asks us to delete specific data
Automation send logs and comment triggers30 days
Finished scheduled automation steps30 days
Email delivery events from Amazon SES30 days, then deleted automatically
Shared email suppression list (hashes only)As long as needed to stop emails to addresses that bounced or complained. An address our email provider holds back for its own reasons is paused for 14 or 90 days, then tried again.
Confirmation email counts per address (a hash and dates only)31 days, then deleted automatically
A confirmation email waiting because a daily limit was reached (the address and the workspace)Up to 3 days, until it is sent or dropped
Unsubscribes from a deleted workspace (hashes only)24 months, then deleted automatically
Opt-out marker after a contact is deleted (a hash of the channel and the person's id, and when they opted out)As long as the workspace exists, so a person who asked to stop automated messages is never messaged again
Billing records and invoices7 years, as the Swedish Bookkeeping Act requires
Technical logsAbout 30 days
Database backups and restore points7 days
Our queue of notification emails, sent or not7 days, then deleted automatically
Access requests, verification and password reset records, and the record of which address you confirmedUntil you delete your account
Academy progress, diplomas and certificatesUntil you delete your account
Academy sign-in code (a keyed hash of the code, never the code, and the number of tries)Deleted when it is used; an unused one stops working after 10 minutes and is deleted automatically within about a day
Academy sign-in code counts (a hash of the address or of the IP address, the time and the number of codes sent or typed that day)2 days, then deleted automatically
Waitlist signupsUntil you ask us to remove it (email hello [at] postfjord.com) or delete an account with the same address
Invitations to a workspaceUntil the workspace or the invited person's account is deleted

Deleting a workspace (Settings → General, owner only) removes its posts, media, brand profile, members, contacts, conversations, consent records, automations, connected accounts including tokens, API keys, integration keys and queued notification emails. Deleting your account (Account → Delete my account, or Delete my account on postfjord.com/academy/me for an account that only uses the Academy) removes your profile and memberships, your access request, email verification and password reset records, the record of your confirmed address, your Academy progress, diplomas and certificate, notification emails to you, a waitlist signup and invitations to your address; workspaces you own must be deleted or transferred first. Access tokens you connected for a workspace stay with that workspace, which remains their controller. Disconnecting a channel deletes its tokens at once. We keep daily backups of the database for 7 days and can restore it to any moment in the last 7 days, so deleted data disappears from those backups within 7 days. Meta deletion requests are handled as described at postfjord.com/data-deletion. For YouTube, see YouTube in section 2.

7. Security

Data is encrypted in transit and at rest. Access tokens and integration keys are also encrypted by us before they are stored, and API keys are stored only as hashes. Access within a workspace follows the roles its owner sets. Only a small number of Postfjord staff have administrative access, and they use it only for support, security, abuse handling and legal obligations. If a personal data breach occurs we notify the Swedish Authority for Privacy Protection (IMY), and affected customers and people when the law requires it.

8. Your rights

You have the right to access your personal data, to have it corrected or deleted, to restrict or object to processing, to data portability, and to withdraw consent at any time where processing is based on consent. Much of this you can do yourself in the app. For anything else, email hello [at] postfjord.com and we answer within one month. You can also complain to the Swedish Authority for Privacy Protection, IMY.

9. If you messaged or received email from a business that uses Postfjord

The business you contacted is responsible for your data and decides how it is used. To access, correct or delete it, contact that business. You can also write to us and we pass the request on. To stop automated direct messages, reply STOP (or stopp, avsluta, unsubscribe). To stop emails, use the unsubscribe link in any email; the business cannot sign you up again, only you can.

10. Automated decisions

Postfjord does not make decisions about people that have legal or similarly significant effects. Automations follow rules the business sets, AI features produce drafts and replies, and our email safety checks may pause a business's sending for review; none of these decide anything about the people who receive messages.

11. Cookies and local storage

postfjord.com sets cookies only if you accept them in the cookie box: then Google Analytics sets its cookies (named _ga and _ga_ followed by an id, kept up to 13 months) so we can see which pages are read and how people find them. Google Signals and ad personalisation are off, and nothing is used for advertising. You can change your choice at any time with Cookie settings at the bottom of every page; declining removes the cookies. Your choice itself is kept in your browser's local storage. Without a yes, no Google script loads at all. The Academy pages (postfjord.com/academy), where you may be signed in, load neither Google Analytics nor Ahrefs, whatever you chose.

Besides that, postfjord.com sets no cookies. Its visitor statistics come from Ahrefs Web Analytics, which does not use cookies and, according to Ahrefs, uses the IP address only to estimate the country and does not store it. If you sign in to the Academy, postfjord.com keeps your sign-in session in your browser (local storage and IndexedDB, no cookies), and the address you asked a sign-in code for until you sign in, sign out or 10 minutes pass, whichever comes first. The app stores only what it needs to work in your browser: your sign-in session, preferences such as language, and an offline copy of the workspace data you have opened, so it loads quickly. The offline copy is deleted when you sign out. The pages we show when you confirm or unsubscribe from an email set no cookies and run no scripts. The signup form page sets no cookies either. It runs one small script in your browser that does a short calculation before the button can be pressed, which keeps automated signups out. The script sends nothing anywhere.

12. Children

Postfjord is a business tool and is not directed at children under 16.

13. Changes

We post changes here and update the date above. For material changes we notify customers by email or in the app before they take effect. Before we launch new platforms (such as WhatsApp), signup forms, native apps or new providers, we update this policy.

Contact

Yogakollektivet Sverige AB, org. nr 556858-0699, Rallarvägen 10, 755 76 Vänge, Sweden. hello [at] postfjord.com

Postfjord

Social media scheduling, AI writing, inbox, DM automation, email and landing pages in one product. Built in Sweden.

Product

postsocial postchat postmail Dictation Landing pages and link in bio All features Pricing Product updates Download the app

Solutions

For creators For small businesses For agencies For salons and beauty For gyms and studios For restaurants and cafés ChatGPT, Claude, Gemini and MCP

Resources

Academy Help center Getting started Blog Plans and billing MCP setup Meta Muse and other agents

Compare

Linktree alternative Later alternative Buffer alternative ManyChat alternative

Company

About Contact Press Security Status Privacy Terms Data processing Data deletion
Deutsch Français Español Português (Brasil)
© 2026 Postfjord. Yogakollektivet Sverige AB, org. nr 556858-0699, Sweden. hello [at] postfjord.com · Cookie settings

May we use Google Analytics cookies to see which pages help people? Nothing is shared for advertising. Read more