PrimusPost (“we,” “us,” or “our”) provides an AI content repurposing studio that turns your ideas into voice-matched social media posts and carousels. Because your writing style and ideas represent your personal identity and intellectual capital, protecting your privacy is fundamental to our architecture.
This Privacy Policy explains what personal data we collect, how we process and store it, our third-party sub-processors, and your legal rights under global data protection regulations including the General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA).
1. Information We Collect
We collect only the minimum necessary data required to deliver our services:
- Account & Identity Data: Your name and email address, collected and verified securely via our authentication provider, Clerk.
- User Content & Writing Samples: The raw text drafts, transcripts, bullet points, and historical writing samples you paste into the Studio to extract your Voice DNA.
- Extracted Voice DNA Profiles: The mathematical vocabulary vectors, cadence parameters, and stylistic traits calibrated from your writing samples.
- Generated Output History: The posts, captions, threads, and carousel decks generated by the platform and stored in your private Content Library.
- Waitlist Information: If you join our waitlist before registering, your email address and optional writing samples are retained strictly for beta onboarding or until you request deletion.
2. No AI Model Training on Your Content
We operate strictly on enterprise paid AI API endpoints (Google Cloud Vertex AI). Under these commercial terms:
- Your data is NEVER used to train, fine-tune, or improve foundation AI models (neither Google's models nor any public LLMs).
- Your writing samples and raw inputs are processed in-memory during inference to apply dynamic voice prompts, and are never retained for model training.
- Your unpublished thoughts, draft posts, and voice profiles remain 100% private to your account.
3. How We Use Information (Purpose Limitation)
We process your data strictly for legitimate operational purposes:
- To extract your personalized Voice DNA and generate multi-platform content upon your explicit request.
- To maintain your private Content Library and enable draft editing, regeneration, and PDF carousel export.
- To authenticate your identity, manage account sessions, and prevent unauthorized access.
- To process subscription billing and credit quotas through our Merchant of Record.
- To detect and prevent platform abuse, fraud, and security threats.
We do not sell, rent, or monetize your personal data or writing samples to third parties or data brokers.
Where the GDPR or UK GDPR applies, each purpose above rests on one of the following legal bases (Article 6):
| Purpose | Legal basis |
|---|---|
| Voice DNA extraction, content generation, library storage and export | Performance of a contract — Art. 6(1)(b) |
| Authentication, session management and account security | Performance of a contract — Art. 6(1)(b) |
| Subscription billing, credit accounting and tax records | Performance of a contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) |
| Abuse, fraud and security-threat detection | Legitimate interests — Art. 6(1)(f), in keeping the service available and secure |
| Optional product analytics | Consent — Art. 6(1)(a), withdrawable at any time via the cookie notice |
4. Third-Party Sub-Processors
To provide our cloud services we rely on the following sub-processors. Each is engaged under a data processing agreement, and this list is the complete set that may handle personal data on our behalf:
| Sub-Processor | Role & Purpose | Location |
|---|---|---|
| Google Cloud Vertex AI | AI inference & text generation (zero model training) | United States / Global |
| Clerk | Authentication, user identity & session security | United States |
| Dodo Payments | Merchant of Record (MoR), payment processing & tax compliance | United States / Global |
| Supabase / PostgreSQL | Encrypted relational database storage for drafts and voice profiles | United States |
| Vercel | Edge compute, serverless hosting & cookieless web analytics | United States / Global |
| PostHog | Optional product analytics and browser error reporting. Only engaged if you accept optional analytics in our cookie notice; session replay and autocapture are disabled, so no recording of your screen and no text of your drafts is ever sent. | United States |
5. Security & Encryption
We implement comprehensive technical and organizational measures to safeguard your information:
- Encryption in Transit: All data transmitted between your browser and our servers is encrypted using modern TLS 1.3 protocols.
- Encryption at Rest: Database records, stored drafts, and voice profiles are encrypted at rest using industry-standard AES-256 encryption.
- Row-Level Data Isolation: Every database query enforces strict tenant isolation, ensuring only your authenticated session can access your drafts and voice profiles.
6. Data Retention & Account Deletion
We retain your personal data only for as long as your account remains active. You maintain full control over your data lifecycle:
- Self-Serve Deletion: You can delete any individual post or voice profile at any time directly within the Studio or Content Library.
- Complete Account Deletion: Deleting your account permanently purges your user profile and triggers a cascading deletion of all associated voice profiles, post history, and draft carousels from our databases within 30 days.
7. Your Rights (GDPR & CCPA/CPRA)
Depending on your location, you have statutory privacy rights under applicable data protection laws:
- Right of Access & Portability: You have the right to request a copy of the personal data we hold about you in a structured, machine-readable format.
- Right to Rectification: You can correct or update inaccurate account information via your Settings.
- Right to Erasure (“Right to be Forgotten”): You can request the complete erasure of your personal data by deleting your account or emailing our privacy team.
- Right to Restrict Processing: You can request that we restrict the processing of your data under certain circumstances.
- Right to Object: You can object at any time to processing we carry out on the basis of our legitimate interests, and we will stop unless we can demonstrate compelling legitimate grounds that override your interests.
- Right to Withdraw Consent: Where we rely on consent — optional product analytics is the only such processing — you can withdraw it at any time through the cookie notice. Withdrawal does not affect the lawfulness of processing carried out before you withdrew.
- No Sale or Sharing: We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not process it for cross-context behavioural advertising. There is therefore nothing for you to opt out of.
- Non-Discrimination: Under the CCPA, we will not discriminate against you (e.g., deny service or alter pricing) for exercising your statutory privacy rights.
- Right to Complain to a Supervisory Authority: If you are in the EEA or the UK, you may lodge a complaint with your local data protection supervisory authority — in the UK, the Information Commissioner’s Office (ico.org.uk) — without contacting us first. We would appreciate the chance to address your concern directly, but you are not required to give us one.
To exercise any of these rights, contact us at privacy@primuspost.com. We respond to all verified requests within thirty (30) days.
8. Cookies & Local Storage
Cookies required for authentication and security are always set. Optional product analytics is off until you accept it in our cookie notice, and rejecting it keeps it off. We do not use advertising cookies, retargeting pixels, or cross-site behavioural tracking. For the full cookie table and how to change your choice, see our Cookie Policy.
9. International Data Transfers
PrimusPost processes data on secure cloud infrastructure located in the United States. When personal data is transferred outside the European Economic Area (EEA) or the UK, we ensure adequate protections are in place by utilizing Standard Contractual Clauses (SCCs) approved by the European Commission, alongside technical encryption safeguards. For transfers to the United States we rely on the European Commission’s Standard Contractual Clauses together with the UK International Data Transfer Addendum where the UK GDPR applies.
Where we are required to designate a representative in the European Union or the United Kingdom under Article 27 of the GDPR or UK GDPR, that representative’s name and contact details will be published in this section. Until then, all data protection enquiries from any jurisdiction should be sent to privacy@primuspost.com, which is monitored for this purpose.
10. Contact & Privacy Officer
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please reach out to our privacy team:
Data controller: PrimusPost
Data protection enquiries: privacy@primuspost.com
Contractual notices and support: support@primuspost.com
We respond to verified data protection requests within thirty (30) days. If a request is complex or you have made several, we may extend that period by up to two further months and will tell you why within the first thirty days.