Postcraft is operated by Farkhanda Jabeen For Lifestyle Coaching ("we," "us," "our"), a Sole Establishment licensed in Dubai, UAE (DET License No. 1638196). This policy explains what information Postcraft collects from its users, why, and how it's handled.
1. Who this applies to
This policy covers everyone who creates a Postcraft account, including Farkhanda Jabeen and every additional user (e.g. classmate health coaches) invited to use it.
2. What we collect
Account information: your name, email address, and a securely hashed password — we never store your password in plain, readable form.
Your content: the topics, captions, and graphics you create or upload for your posts, carousels, and videos, plus your posting schedule and publishing history.
Your brand voice settings: the role, scope of practice, tone, and content rules you write yourself to guide how AI-generated drafts sound — this is text you write, not data we collect about you.
Connected social accounts: when you connect Instagram, Facebook, LinkedIn, or a WordPress blog, we store the access tokens, page/account IDs, and (for WordPress) site URL needed to publish content or read your blog on your behalf. You generate these credentials directly through Meta's, LinkedIn's, or WordPress's own tools — we never receive or store your Instagram, Facebook, or LinkedIn login password.
Your own AI provider connection: if you connect an AI provider (such as OpenAI, Anthropic, Cerebras, or Groq) to generate captions and content ideas, we store that provider's API key so you don't have to re-enter it each time. When you click "Generate with AI," your topic and brand-voice text are sent straight to that provider using your own key — they are the one generating the content from it, matched to your own brand voice, not us. This is always your own account, never a shared Postcraft key.
Stock-photo API keys: if you connect Pexels and/or Unsplash to search for stock photos, we store your own free API key for each.
Your setup preferences: your chosen region, content niche, and voice from the Setup screen — used only to show you trending topics and content angles relevant to where you are and who you serve. This exists for your own use; we don't review, monitor, or otherwise use these settings ourselves.
Basic usage data: things like login times and error logs, used only to keep the app running and troubleshoot problems.
3. How your data is stored and protected
Your account and content data is stored in a private database, hosted on Railway. Passwords are hashed, never stored as plain text. Social-media and AI-provider credentials are encrypted at rest (AES-256-GCM), also never stored as plain text. Each user's data is isolated from every other user's — one user's content, schedule, and connected accounts are never visible to another user of Postcraft.
Day-to-day, the only information about you that Farkhanda Jabeen looks at is your name and email — for example, to identify your account or help you log back in. Everything else described above (your content, your connected-account credentials, your AI provider key, and so on) is stored so the app itself can run those features, and it is never reviewed or used by Farkhanda Jabeen unless you specifically ask for help — for example, to troubleshoot a bug or fix a publishing error.
4. Who else your data goes to (third parties)
To do its job, Postcraft shares limited data with:
Meta (Instagram/Facebook) and LinkedIn — to publish your content to the accounts you've connected, using the credentials described above.
Railway — our hosting provider, which stores the underlying database and runs the application.
Your own connected AI provider (e.g. OpenAI, Anthropic, Cerebras, Groq, or a self-hosted server) — when you click "Generate with AI," your topic and brand-voice settings are sent directly to your own AI provider, which is the one that collects and processes them to generate captions and content matched to your voice. This always uses your own account and API key, never a shared Postcraft one, and only happens when you explicitly ask for it. Postcraft itself does not store, train on, or otherwise use that exchange — once it reaches your chosen AI provider, how they handle it is covered by their own privacy policy, not ours.
Google News' public RSS feed — used to source real, current headlines for suggesting trending topics for your region. This is public news content, not personal data. The resulting topic suggestions are cached and shared across all Postcraft users for the same region, never tied to any one user.
Pexels / Unsplash — if you search for a stock photo, your search query is sent to retrieve matching images, using your own connected API key.
Your own WordPress site, if connected — Postcraft reads its public blog posts via WordPress's own public feed, to let you build content from articles you've already written. Nothing is posted to, or logged into, your WordPress site.
We do not sell your data, and we never share your content or connected-account information with other Postcraft users.
5. How long we keep your data
If you delete a single piece of content, it's held in a recycle bin for 30 days so you can restore it if you change your mind, then it's permanently deleted.
If you close your Postcraft account, we delete your account, your content, and your connected-account credentials immediately — we don't keep a backup copy. Meta, LinkedIn, and any other platform you've connected may retain their own separate records under their own policies, which are outside our control.
6. Your rights
You can request a copy of your data, ask us to correct inaccurate data, or ask us to delete your account and associated data, by emailing info@fitnhealthylifestylecoach.com. You can also disconnect any social media account from Postcraft at any time from within the app, which revokes our access to that account going forward.
7. Changes to this policy
If Postcraft's features change in a way that affects what data we collect or share, we'll update this policy and note the date at the top.