Where your data is stored
Postfjord runs on Google Cloud in Belgium. Emails you send with Postfjord go out through Amazon's email service in Stockholm. Your posts, contacts, messages and settings are stored there, and they are encrypted on disk.
A few services we use can handle data in the USA, like the AI that writes drafts and Stripe for payments. Our privacy policy lists each one and the legal safeguard it uses.
Every connection is encrypted
The app and the site only answer over HTTPS, with TLS 1.2 or newer. Your browser is told to never use an unencrypted connection to Postfjord, and the app cannot be shown inside another website, so nobody can dress it up to trick you into clicking.
The app also keeps a list of the places it may load code from: Postfjord itself, Google for sign-in, and Facebook for connecting your pages. Your browser refuses code from anywhere else. So if someone slipped a script into a post or a name, it would not run.
We never see your password or your card
- Passwords are handled by Firebase Authentication from Google. We never see or store your password. You can also sign in with Google.
- Payments go through Stripe. Your card number never reaches Postfjord.
Signing in
- New passwords need at least 10 characters. We refuse the ones attackers try first, and any password that showed up in a known data leak. That check sends only the first 5 characters of a scrambled copy, so it never sees your password.
- Sensitive changes ask you to confirm it is you when your last sign-in was more than 10 minutes ago: making an API key, connecting Claude or Stripe, inviting someone, and deleting a workspace or your account.
- Changing or resetting your password signs out your other devices.
- Two-step verification with an authenticator app is there for every account, with recovery codes for a lost phone. Passkeys with Face ID or Touch ID count as both steps. Our own team uses them to reach admin tools.
The keys you give us
- Your social media accounts connect with each platform's own sign-in. Postfjord gets a key that can post for you, and it is stored encrypted. You can disconnect at any time, and the key is deleted.
- Stripe, AI and booking keys you paste in are stored encrypted, and only our servers can read them. For Stripe we ask for a restricted key with a single permission, and we refuse a full secret key.
- Your Postfjord API keys are shown once, when you make them. We store only a fingerprint of each key that cannot be turned back into the key, so even we cannot read it.
Who can do what
Each workspace has owners, editors and viewers, and our database rules check every read and write against your role. The rules have their own tests, which run before a change goes live.
Your data is yours
You can delete a workspace or your whole account yourself, and the data goes with it. How we handle personal data is in our privacy policy, and businesses can sign our data processing agreement.
Found a problem?
Write to hello [at] postfjord.com and tell us what you found. We read every report, answer, and fix real problems fast. Please give us a chance to fix it before you tell anyone else. The same address is in our security.txt.
FAQ
Where is my data stored?
In the EU: on Google Cloud in Belgium, and emails go out from Amazon in Stockholm. Some services we use, like AI drafts and payments, can handle data in the USA; the privacy policy lists them.
Can Postfjord read my password?
No. Passwords are handled by Firebase Authentication from Google, and we never see them.
What happens to my social media accounts if I leave?
When you disconnect a channel or delete your account, the key that lets Postfjord post for you is deleted.