Privacy Policy
Last updated: June 19, 2026
This Privacy Policy explains what data VoicePost collects, how we use it, and the choices you have. It applies to voicepo.st and the VoicePost application. We try to collect only what we need to run the product.
1. Data we collect
- Account data — your email address and name, created when you sign up (authentication is handled by Supabase Auth).
- Content you create — the project details, memory-bank notes, prompts, drafts, and posts you generate or save in VoicePost.
- X (Twitter) connection — if you connect X, we store OAuth access/refresh tokens, encrypted at rest (AES-256-GCM), and basic profile data needed to publish on your behalf. Tokens are never sold, never logged, and never shown in error messages.
- Reddit identity — your public Reddit username and the karma / account-age you self-report. We do not use Reddit OAuth and never access or post to your Reddit account; we only read public Reddit RSS feeds.
- Billing data — handled by Dodopayments, our payment processor and merchant of record. We receive subscription status and receipts; we do not receive or store your full card details.
- Usage & device data — product analytics events, log data, and error reports, used to operate, secure, and improve the Service.
2. Google user data
VoicePost uses Google OAuth solely for account authentication — we request only the openid, email, and profile scopes. We do not access Gmail, Google Drive, Google Calendar, or any other Google product. This section documents our compliance with the Google API Services User Data Policy.
- Data accessed — When you sign in with Google, we receive your Google account email address, display name, profile picture URL, and a unique Google account identifier (sub/UID). No other Google data is accessed — we do not access Gmail, Google Drive, Google Calendar, or any other Google product.
- Data usage — Your email and name are used solely to create and identify your VoicePost account. Your profile picture may be displayed inside the app as your avatar. Your Google account ID is used only to link your Google identity to your VoicePost account. This data is not used for advertising, profiling, or any purpose beyond authentication.
- Data sharing — Your email address is stored in our database (Supabase, EU region) and shared with Resend solely to send you transactional account emails (e.g. password reset, billing receipts). We do not sell, rent, or share your Google user data with advertisers, data brokers, or any third party except the subprocessors listed in Section 5 where strictly necessary to operate the Service.
- Data storage & protection — Your account data is stored in Supabase (London, EU). Data is encrypted in transit (TLS) and at rest. Database row-level security ensures your data is only accessible to you. Google OAuth tokens are managed by Supabase Auth and are never stored in application logs or exposed in API responses.
- Data retention & deletion — Your Google-sourced account data (email, name, profile picture) is retained for as long as your VoicePost account is active. When you delete your account from within the app, all associated personal data is permanently deleted. You may also request deletion by emailing [email protected].
VoicePost’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
3. How we use your data
- to provide the Service — generate drafts, plan Reddit activity, publish approved X posts;
- to personalise output to your voice and project;
- to process payments, provide support, and send service emails;
- to monitor, secure, debug, and improve the Service;
- to comply with legal obligations.
We do not sell your personal data, and we do not show you third-party ads.
4. AI processing
To generate content, your inputs (such as prompts, memory-bank notes, and the source material you provide) are sent to our AI providers — primarily Anthropic (Claude) for generation and Voyage AI for embeddings used in trend matching. We send these providers only what is needed to produce your result. Under their API terms, your inputs are not used to train their public models. Article screenshots used as “receipts” are captured by ScreenshotOne and stored in Cloudflare R2.
5. Subprocessors
We rely on the following providers to run VoicePost:
- Supabase — database, authentication, and storage (EU region — London, eu-west-2)
- Anthropic — AI generation (Claude)
- Voyage AI — text embeddings
- ScreenshotOne — article screenshots
- Cloudflare R2 — file/asset storage
- Upstash — caching and rate limiting
- Resend — transactional and lifecycle email
- Dodopayments — payments (merchant of record)
- PostHog — product analytics (US cloud)
- Sentry — error monitoring
- Inngest — background job processing
6. Cookies and analytics
We use essential cookies to keep you signed in and to operate the app. We use PostHog to understand how the product is used so we can improve it. We do not use advertising cookies.
7. Data retention
We keep your data for as long as your account is active or as needed to provide the Service. When you delete your account, we delete or anonymise your personal data, subject to limited records we must retain for legal, accounting, or security reasons.
8. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data. You can delete your account from within the app, which cascades and removes your associated data. To exercise other rights, email [email protected].
9. Security
We protect data with encryption in transit, encryption of OAuth tokens at rest (AES-256-GCM), and database row-level security that isolates each user’s data. No system is perfectly secure, but we work to safeguard your information.
10. International transfers
Your account data is stored in the European Union (our Supabase database is hosted in the EU — London, eu-west-2). Some of our subprocessors operate in the United States — for example, AI generation (Anthropic, Voyage) and product analytics (PostHog). As a result, when we generate content or measure usage, some data may be transferred to and processed in the US and other countries where those providers operate. We rely on those providers’ safeguards for such transfers.
11. Children
VoicePost is not directed to children. You must be at least 18 to use it, and we do not knowingly collect data from children.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will update the “Last updated” date and, for material changes, take reasonable steps to notify you.
13. Contact
Questions about privacy? Email [email protected].