Asteria Engine Logo

Privacy Policy

Last updated: January 10, 2025

At Asteria Engine (trading as Asteria Engine), we respect your privacy and are committed to protecting your personal data. This policy explains how we collect, use, store, and secure information in compliance with UK GDPR and Data Protection Act 2018.

1. Information We Collect

Account Information

  • Name, email address, company name, and job title
  • Billing information (processed securely via Stripe—we never store full payment details)
  • Account preferences, timezone, and notification settings

Content & Campaign Data

  • Social media posts, captions, media files, and campaign content you create
  • Brand guidelines, voice profiles, and AI training data you upload
  • Connected social media account metadata (usernames, follower counts, engagement metrics)
  • Scheduling information and publishing history

Usage Analytics

  • Device information, IP address, browser type, and operating system
  • Pages visited, features used, and time spent in the platform
  • Error logs and performance metrics to improve stability
  • AI model interactions and content generation requests

Social Media Connections

When you connect social media accounts (LinkedIn, Facebook, Instagram, TikTok, YouTube, Twitter/X), we collect:

  • OAuth access tokens (stored encrypted) to publish on your behalf
  • Profile information, page details, and publishing permissions
  • Post performance metrics (impressions, engagement, reach) for analytics

2. How We Use Your Data

We process your personal data under the following lawful bases:

Service Delivery (Contractual Necessity)

  • Providing access to Asteria Engine platform and features
  • AI content generation, scheduling, and publishing automation
  • Brand Intelligence Engine training and optimization
  • Customer support and technical assistance

Product Improvement (Legitimate Interest)

  • Analyzing usage patterns to enhance AI model performance
  • Developing new features based on user behavior
  • Monitoring system health and preventing abuse
  • Conducting research to improve content generation quality

Legal Compliance (Legal Obligation)

  • Maintaining audit logs for security and fraud prevention
  • Responding to legal requests and regulatory requirements
  • Enforcing our Terms of Service and acceptable use policies

Marketing Communications (Consent)

With your explicit consent, we may send:

  • Product updates, feature announcements, and best practice guides
  • Educational content and webinar invitations
  • Promotional offers (you can opt out anytime)

AI Training: Your uploaded content is used to train your workspace's Brand Intelligence Engine. This data remains isolated to your workspace and is never shared with other customers or used for general model training.

3. Data Storage & Security

Infrastructure & Location

  • Data is hosted on secure cloud infrastructure in the UK and EU (AWS eu-west-2 London region)
  • All data transfers are encrypted in transit using TLS 1.3
  • Data at rest is encrypted using AES-256 encryption
  • Database backups are performed daily with 30-day retention

Security Measures

  • Multi-Factor Authentication (MFA): Required for all workspaces
  • Role-Based Access Control: Granular permissions and workspace isolation
  • Audit Logging: Immutable logs of all account activities
  • Penetration Testing: Regular third-party security assessments
  • Incident Response: 24/7 monitoring and automated threat detection

Data Retention

  • Active account data is retained for the duration of your subscription
  • After account deletion, data is permanently removed within 30 days
  • Billing records are retained for 7 years per UK tax law
  • Audit logs are retained for 12 months for security purposes

4. Your Data Rights (UK GDPR)

Under UK data protection law, you have the following rights:

Right to Access

Request a copy of all personal data we hold about you

Right to Rectification

Correct inaccurate or incomplete personal data

Right to Erasure

Request deletion of your personal data (right to be forgotten)

Right to Restriction

Limit how we process your data in certain circumstances

Right to Data Portability

Receive your data in a structured, machine-readable format

Right to Object

Object to processing based on legitimate interests

How to Exercise Your Rights

To make a data subject request, email privacy@postpilot.ai with your account details. We will respond within 30 days as required by UK GDPR.

5. Third-Party Services

We use carefully vetted third-party services to deliver Asteria Engine. These processors are GDPR-compliant and bound by data processing agreements:

Stripe

Payment processingEU/UK

Privacy Policy →

AWS (Amazon Web Services)

Cloud infrastructure & database hostingUK (London)

Privacy Policy →

OpenAI

AI content generation (GPT-4, DALL-E 3)US (Standard Contractual Clauses)

Privacy Policy →

Anthropic

AI assistant capabilities (Claude)US (Standard Contractual Clauses)

Privacy Policy →

PostHog

Product analyticsEU

Privacy Policy →

Resend

Transactional emailsEU

Privacy Policy →

Social Media Platforms: When you connect accounts (LinkedIn, Facebook, Instagram, etc.), their respective privacy policies govern how they handle data. We only access data necessary for publishing and analytics.

6. Children's Privacy

Asteria Engine is not intended for users under 16. We do not knowingly collect data from children. If you believe we have inadvertently collected such data, please contact us immediately.

7. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated via email and a notice in the platform. Continued use after changes constitutes acceptance.

8. Contact & Data Protection Officer

For privacy inquiries, data subject requests, or security concerns:

Email: privacy@postpilot.ai

Data Protection Officer: dpo@postpilot.ai

Company: Asteria Engine Ltd (trading as Asteria Engine)

Jurisdiction: United Kingdom

If you are not satisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk

This Privacy Policy was last updated on January 10, 2025.

For contractual terms and service agreements, please review our Terms of Service.