Privacy Policy
Last updated: January 10, 2025
At Asteria Engine (trading as Asteria Engine), we respect your privacy and are committed to protecting your personal data. This policy explains how we collect, use, store, and secure information in compliance with UK GDPR and Data Protection Act 2018.
1. Information We Collect
Account Information
- Name, email address, company name, and job title
- Billing information (processed securely via Stripe—we never store full payment details)
- Account preferences, timezone, and notification settings
Content & Campaign Data
- Social media posts, captions, media files, and campaign content you create
- Brand guidelines, voice profiles, and AI training data you upload
- Connected social media account metadata (usernames, follower counts, engagement metrics)
- Scheduling information and publishing history
Usage Analytics
- Device information, IP address, browser type, and operating system
- Pages visited, features used, and time spent in the platform
- Error logs and performance metrics to improve stability
- AI model interactions and content generation requests
Social Media Connections
When you connect social media accounts (LinkedIn, Facebook, Instagram, TikTok, YouTube, Twitter/X), we collect:
- OAuth access tokens (stored encrypted) to publish on your behalf
- Profile information, page details, and publishing permissions
- Post performance metrics (impressions, engagement, reach) for analytics
2. How We Use Your Data
We process your personal data under the following lawful bases:
Service Delivery (Contractual Necessity)
- Providing access to Asteria Engine platform and features
- AI content generation, scheduling, and publishing automation
- Brand Intelligence Engine training and optimization
- Customer support and technical assistance
Product Improvement (Legitimate Interest)
- Analyzing usage patterns to enhance AI model performance
- Developing new features based on user behavior
- Monitoring system health and preventing abuse
- Conducting research to improve content generation quality
Legal Compliance (Legal Obligation)
- Maintaining audit logs for security and fraud prevention
- Responding to legal requests and regulatory requirements
- Enforcing our Terms of Service and acceptable use policies
Marketing Communications (Consent)
With your explicit consent, we may send:
- Product updates, feature announcements, and best practice guides
- Educational content and webinar invitations
- Promotional offers (you can opt out anytime)
AI Training: Your uploaded content is used to train your workspace's Brand Intelligence Engine. This data remains isolated to your workspace and is never shared with other customers or used for general model training.
3. Data Storage & Security
Infrastructure & Location
- Data is hosted on secure cloud infrastructure in the UK and EU (AWS eu-west-2 London region)
- All data transfers are encrypted in transit using TLS 1.3
- Data at rest is encrypted using AES-256 encryption
- Database backups are performed daily with 30-day retention
Security Measures
- Multi-Factor Authentication (MFA): Required for all workspaces
- Role-Based Access Control: Granular permissions and workspace isolation
- Audit Logging: Immutable logs of all account activities
- Penetration Testing: Regular third-party security assessments
- Incident Response: 24/7 monitoring and automated threat detection
Data Retention
- Active account data is retained for the duration of your subscription
- After account deletion, data is permanently removed within 30 days
- Billing records are retained for 7 years per UK tax law
- Audit logs are retained for 12 months for security purposes
4. Your Data Rights (UK GDPR)
Under UK data protection law, you have the following rights:
Right to Access
Request a copy of all personal data we hold about you
Right to Rectification
Correct inaccurate or incomplete personal data
Right to Erasure
Request deletion of your personal data (right to be forgotten)
Right to Restriction
Limit how we process your data in certain circumstances
Right to Data Portability
Receive your data in a structured, machine-readable format
Right to Object
Object to processing based on legitimate interests
How to Exercise Your Rights
To make a data subject request, email privacy@postpilot.ai with your account details. We will respond within 30 days as required by UK GDPR.
5. Third-Party Services
We use carefully vetted third-party services to deliver Asteria Engine. These processors are GDPR-compliant and bound by data processing agreements:
Stripe
Payment processing • EU/UK
AWS (Amazon Web Services)
Cloud infrastructure & database hosting • UK (London)
OpenAI
AI content generation (GPT-4, DALL-E 3) • US (Standard Contractual Clauses)
Anthropic
AI assistant capabilities (Claude) • US (Standard Contractual Clauses)
PostHog
Product analytics • EU
Resend
Transactional emails • EU
Social Media Platforms: When you connect accounts (LinkedIn, Facebook, Instagram, etc.), their respective privacy policies govern how they handle data. We only access data necessary for publishing and analytics.
6. Children's Privacy
Asteria Engine is not intended for users under 16. We do not knowingly collect data from children. If you believe we have inadvertently collected such data, please contact us immediately.
7. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email and a notice in the platform. Continued use after changes constitutes acceptance.
8. Contact & Data Protection Officer
For privacy inquiries, data subject requests, or security concerns:
Email: privacy@postpilot.ai
Data Protection Officer: dpo@postpilot.ai
Company: Asteria Engine Ltd (trading as Asteria Engine)
Jurisdiction: United Kingdom
If you are not satisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk
This Privacy Policy was last updated on January 10, 2025.
For contractual terms and service agreements, please review our Terms of Service.