1. Controller and data protection officer
The data controller is WHFDEV Tech Consulting, operator of Postarra. To exercise rights, ask questions or reach the data protection officer, use: talkto@postarra.com.
2. Data we collect
We collect only what is needed to run the service:
- Account: name, email and profile picture provided by Google login (OAuth).
- Billing: subscription and customer identifiers from Stripe. We do not store card numbers; payment is processed by Stripe.
- Usage content: projects, slides, brand kits, prompts, uploaded reference images and generated assets.
- Usage and diagnostics: product events (via PostHog, only with consent) and error reports (via Sentry).
- Technical data: access logs, device/browser type and cookies (see Cookie Policy).
3. Legal bases and purposes
We process data based on the grounds of the LGPD (Articles 7 and 11) and the GDPR (Article 6), according to purpose:
- Performance of a contract (LGPD art. 7, V / GDPR art. 6(1)(b)): create and maintain your account, generate and store assets, process subscriptions and quota.
- Consent (LGPD art. 7, I / GDPR art. 6(1)(a)): non-essential cookies and product analytics, managed by the consent banner.
- Legitimate interest (LGPD art. 7, IX / GDPR art. 6(1)(f)): security, fraud prevention and service improvement, always balanced against your rights.
- Legal obligation (LGPD art. 7, II / GDPR art. 6(1)(c)): record keeping and responding to authorities.
4. Use with AI providers
To generate images and text, your prompts and any reference images are transmitted to third-party AI providers acting as processors: Google (Gemini), Replicate and Anthropic. These providers process the content to return a result under their own terms and policies. Do not include unnecessary sensitive personal data in prompts. See the AI Notice for more detail.
5. Who we share with
We share data only with processors/sub-processors needed to operate the service, under a contractual duty of protection:
- Google (authentication / OAuth);
- Stripe (payments and billing);
- Supabase (database and storage);
- Replicate, Google and Anthropic (AI image and text generation);
- Resend (transactional email);
- PostHog (product analytics, subject to consent);
- Sentry (error monitoring);
- application hosting provider.
We may also disclose data when required by law, court order, or to protect the rights, safety and integrity of the service.
6. International transfers
Some processors handle data outside Brazil and the European Union (for example, in the United States). In those cases we adopt appropriate safeguards required by the LGPD (art. 33) and the GDPR (Chapter V), such as standard contractual clauses or adequacy decisions where applicable.
7. Retention
We keep data for as long as necessary for the purposes in this policy and legal obligations. When you close your account, we delete or anonymize data within a reasonable period, except where mandatory retention applies (for example, tax and billing records).
8. Your rights
At any time and free of charge, you may exercise the rights set out in the LGPD (art. 18) and the GDPR (Articles 15 to 22):
- confirm the existence of processing and access your data;
- correct incomplete, inaccurate or outdated data;
- request anonymization, blocking or deletion of unnecessary data;
- portability to another provider;
- deletion of data processed under consent;
- information about sharing;
- withdraw consent and object to processing based on legitimate interest.
To exercise any right, write to talkto@postarra.com. You may also lodge a complaint with the Brazilian National Data Protection Authority (ANPD) or the competent supervisory authority in the European Union.
9. Security
We adopt technical and organizational measures to protect data, such as encryption in transit, access control and monitoring. No system is fully immune; in the event of a material security incident, we act under the LGPD and the GDPR, including notifying authorities and data subjects where required.
10. Children
The service is not directed to children. We do not knowingly collect data from minors below the legal minimum age. If we identify improper collection, we will delete the data.
12. Changes to this policy
We may update this policy. Material changes will be communicated by reasonable means. The last updated date appears at the top of this page.
This document is informational and does not replace legal advice. To exercise rights or ask questions, contact talkto@postarra.com.