Security & Trust
Last updated: July 27, 2026
This page is maintained by Postential to answer common security and privacy questions about Postential. It describes the controls that are actually enabled in the product today, in plain language. It is a description of our practices, not a certification or an independent audit.
Who can see your data
- Every account is protected by an email and password, plus a one-time sign-in code sent to your email that expires after 15 minutes.
- Passwords are checked against a database of known-breached passwords at signup and reset, and are never stored in readable form.
- Your posts, media, brand settings, analytics, and connected accounts are scoped to your account at the database level. Access rules are enforced by the database itself, not only by the app screen you are looking at — so one customer cannot read another customer's rows even if a bug or a crafted request tries.
- Team workspaces are opt-in. Teammates only see the workspace they were invited to, and each role (owner, admin, editor, reviewer) can do only what that role allows.
- Administrative screens are gated by a separate roles table, so admin rights can never be granted by editing your own profile.
How your data is protected
- All traffic to and from Postential is encrypted in transit over HTTPS/TLS.
- Uploaded images and videos live in a private storage bucket. Files are served through short-lived links tied to your session, not public URLs.
- Social platform access tokens are encrypted before being written to the database, and are only decrypted server-side at the moment a request to that platform is made. They are never sent to your browser.
- Secrets and API keys used by the product are stored in a managed secret store and are only readable by server-side code. They are never exposed to the browser.
- Analytics records (post metrics, usage counters) are append-only — they cannot be edited or deleted from the client, so your reporting history cannot be quietly rewritten.
AI content safety
Postential generates captions, content ideas, platform variations, images, and logos. Every prompt passes through a safety layer before it reaches a model:
- Requests for sexual content, anything sexualizing minors, hateful or harassing content, graphic violence, illegal or dangerous instructions, medical misinformation, impersonation, or scam material are blocked. Requests involving minors are blocked outright and never model-adjudicated.
- The safety layer is tuned for the beauty industry, so legitimate professional topics — waxing, injectables, body contouring, boudoir or swimwear promotions for adult clients, before-and-after transformations — are not blocked.
- Blocked attempts are logged. Repeated violations within 24 hours automatically suspend the account pending review.
- You remain responsible for reviewing and approving anything you publish. See our Acceptable Use Policy.
Abuse prevention and rate limits
AI generation, social account connections, and usage-consuming actions are rate limited per account using short rolling windows, with an additional hourly ceiling across all AI features. Limits are enforced server-side in the database, so they cannot be bypassed from the browser. If you hit a limit, you will see a friendly message and can retry shortly — normal day-to-day use is well within these thresholds.
Third-party integrations
We keep the list of services that can touch your data short and purposeful:
- Lovable Cloud — application hosting, database, authentication, and file storage.
- Lovable AI — the gateway used for caption, idea, image, and logo generation. Prompts are sent for processing to produce your result.
- Stripe — subscription billing. Card details are entered directly with Stripe; Postential never sees or stores your full card number.
- Meta (Instagram/Facebook) and X — connected only when you explicitly authorize them through the platform's own OAuth screen. You choose the permissions, and you can disconnect any account at any time from Settings → Accounts, which deletes the stored tokens.
- Email delivery — transactional emails (sign-in codes, password resets, onboarding) are sent from our own verified sending domain.
- Analytics — privacy-conscious product analytics to understand feature usage. See our Cookie Policy.
Shared responsibility
Our hosting provider secures the underlying infrastructure. Postential is responsible for the application's access rules, data handling, and the safeguards described above. You are responsible for keeping your sign-in credentials private, managing who you invite into your workspace, choosing which social accounts to connect, and reviewing content before you publish it.
Your rights and data control
- You can export or delete the content you create at any time from within the app.
- You can request access to, correction of, or deletion of your personal information — see the Privacy Policy for how to submit a request.
- Deleting your account removes your profile, posts, media, and connected-account tokens.
Reporting a security issue
If you believe you have found a vulnerability, please email support@postential.com with steps to reproduce. Please give us a reasonable window to investigate and fix the issue before disclosing it publicly. We do not pursue legal action against good-faith researchers who follow this process.
For anything else, contact support@postential.com or visit Support.