unposed

Privacy policy

Last updated 19 September 2026.

Draft. This policy has not yet been reviewed by a lawyer. It is published so that its contents are visible and can be checked against what the software does.

The short version

You bring your own API key and your own social accounts. Your content is generated with your provider account, published to your accounts, and stored on our server so the service can schedule and learn from it. We do not sell anything, track you, or train on your work. If you delete your account, your files are deleted — not flagged.

Who is responsible

The controller of your personal data is Mikkel Vejen, trading as Unposed, Hasselhaven 85, Lystrup, Denmark. For anything in this policy, or to exercise any right below, contact privacy@unposed.xyz.

Unposed is operated by a sole trader. There is no separate company, and no CVR number has been registered at the time of writing; if that changes, this section changes with it.

What we hold, and why

WhatWhyLegal basis
Your email address and a hash of your passwordTo let you sign in, and to tell one account from another. The password itself is never stored — only a scrypt hash, which cannot be reversed.Performance of a contract
A session cookieTo keep you signed in. One cookie, strictly necessary, no analytics or advertising cookies of any kind.Performance of a contract
Your AI provider API keySo the software can generate content using YOUR account with that provider. Encrypted with AES-256-GCM before it is written down and decrypted only into the process that makes your images — never into a web page, including your own.Performance of a contract
Access tokens for social platforms you connect, and the account name they belong toSo the software can publish content you have approved, at the times you scheduled. The account name is stored so you can see which account is connected — a token alone gives you no way to check.Performance of a contract
The content you create: your product description, audience notes, written copy, generated images and video, captions and scheduleIt is the thing the service produces. It is yours.Performance of a contract
Performance figures you importTo learn which of your posts worked, so later ones can be weighted towards what did. Imported by you from your own platform exports; we do not read your accounts to collect them.Performance of a contract
A record of every publish attempt, including failuresSo you can see what was posted, what was refused and why. A post that silently failed and a post that has not come up yet are otherwise indistinguishable.Performance of a contract
Server and service logs, which include IP addresses, and email addresses in scheduled-run logsTo keep the service running and to investigate faults and abuse.Legitimate interests (running a secure service)

What we do not do

Your API key, and your relationship with your AI provider

Unposed does not resell generation. You connect your own key, and your provider bills you directly under your own agreement with them. That means the content you generate is sent to that provider by the software on your behalf, under your account and their terms — so their privacy policy governs what happens to it there, and you should read it.

Your key is encrypted before it is written down. We show you only a fingerprint of it — the first and last few characters — so you can tell which key is stored without it ever being sent back to a browser. You can delete it at any time, and deleting it removes it from our systems entirely.

Social accounts you connect

When you connect a social account, we store an access token, a refresh token if the platform issues one, the platform’s own identifier for the account, and a label so you can see which account it is. These are encrypted at rest with the same protection as your API key.

We use that access for one purpose: publishing content you have approved, at the times you scheduled it. We do not read your feed, your followers, your direct messages, or other people’s content.

You can disconnect an account at any time, which deletes our copy of the token. Deleting our copy does not revoke the token at the platform — to do that, remove the app’s access in that platform’s own settings, and you should do both.

Content you upload

Screenshots and images you add to describe your product are stored as files in your workspace and are sent to your AI provider as context when drafting. If those images contain personal data — other people, real names, account details — that data goes with them. Consider what is on a screen before you add it.

Where your data is

Everything is held on servers within the European Union. Your content is not copied to any other service except when it is sent to your AI provider to be generated, or to a social platform you connected in order to be published.

When a Reel is published, the video file is briefly reachable on a random, unguessable web address, because Instagram fetches videos rather than accepting uploads. That address is used once, revoked as soon as the publish finishes whether it succeeded or not, and expires regardless.

Who else processes your data

There are no others — no analytics provider, no advertising network, no customer-tracking tool.

If you are a business customer and your own customers’ personal data passes through Unposed, we will enter into a data processing agreement with you under Article 28 of the GDPR. Ask at privacy@unposed.xyz. Note that your AI provider and the social platforms you connect are your own relationships, not our sub-processors, so their terms are between you and them.

How long we keep it

Your account data and content are kept for as long as your account exists. Sessions expire on their own. Logs are kept for as long as they are useful for diagnosing faults and then rotated away.

When you delete your account, the account record is removed and your workspace directory — every file, image, video and database belonging to you — is deleted from disk. Related records are removed with it. This is immediate and cannot be undone, which is the point: “deleted” should mean deleted.

Security

Passwords are stored as scrypt hashes. API keys and platform tokens are encrypted with AES-256-GCM using a key held only on the server and never in our source code — the software refuses to start without one rather than falling back to a default. Traffic is served over HTTPS. Sessions use cookies that JavaScript cannot read, and actions that change anything are protected against cross-site request forgery.

No system is perfectly secure, and we would rather say so than imply otherwise.

Your rights

Under the GDPR you have the right to:

Write to privacy@unposed.xyz and we will respond within one month. If you are unhappy with how we handle it, you may complain to your local data protection authority. In Denmark that is Datatilsynet (datatilsynet.dk).

Children

This service is for businesses and people marketing their own products. It is not intended for anyone under 16, and we do not knowingly hold data about children.

Changes

If this policy changes in a way that affects you, the date above changes and we will tell you before the change takes effect where the law requires it. Past versions are kept in the project’s source history.

back to sign in