PostMine
Legal
Plain-language summaries of how PostMine works. Questions go to support@postmine.tech.
Privacy
What we store
- Your X authentication identity: provider user ID and provider name, plus email when X supplies one.
- When you select an optional GitHub repository, we store its repository and installation identifiers, name, URL, visibility and default branch; selection, consent and project-sharing disclosure timestamps; refresh history; and derived project Facts with source records, evidence hashes and truncation or redaction flags. We do not retain raw private code in Facts, History, logs, artifacts or shared caches. Derived Facts from a private repository may be visible to members of the PostMine project you selected.
- When you connect the optional GitHub App as a repository source, not as a PostMine sign in method, we also store your GitHub provider identity: provider name and provider user ID, plus a derived compatibility email. We do not use email to merge GitHub identities. The GitHub authorization handoff token is encrypted for at most 10 minutes while installation completes, destroyed when used, and expired handoffs are deleted. Installation tokens are short lived and are never stored as source credentials.
- Your connected X account credentials, encrypted at rest with AES-256-GCM.
- With your explicit consent, PostMine reads up to the latest 100 bookmarks from your connected X account per sync and stores the source post, author, link and import metadata until you request account or personal-data deletion. Removing a bookmark on X does not remove our stored copy, and we do not synchronize X-side deletions.
- Your connected X account's handle, display name and profile image URL, used to show your account across the dashboard and to render your avatar in the reply composer.
- The content and status of your Main Chat results and X publishing targets, including one image per result.
- Project facts about your product and experience: product facts, founder experience, client stories and metric results. For each fact we store the topic it belongs to, its value, how quickly it may change, when it was observed, its source and a verbatim evidence quote, confidence, whether it contains another person's personal data, its active, superseded or retracted status, who created the version, and when the version was created or updated. Updating a fact keeps the earlier version as superseded; retracting it marks it retracted instead of immediately deleting the row. Fact versions remain with the project until your account is deleted.
- Your composer chat turns, including the message text, role, conversation and project, and attachment references or snapshots. When a referenced public donor post or reply opportunity is removed from live discovery, we retain the minimum public source-card content and reply context needed to keep that conversation intelligible. This may include public post text, author name, handle and avatar, link, publication time and public counts, donor direction, and the opportunity reply draft and target. We retain these turns and snapshots with the project until your account is deleted.
- Your tone profile: style traits automatically derived from your recent public X posts.
- Your analytics-consent choice, stored server-side as a single row: your user id, whether you accepted, and when. We keep it only so your choice is honoured even for events that have no browser session, such as a subscription renewal, and never to track you.
- The opportunities we surface for you: the public post we found, its source, the Find clients keyword that matched it, and a short reason why it was kept. We do not generate a reply draft for it. For an X thread we store the author display name, handle and avatar, the post text, the link, and public counts such as likes, reposts, replies and views. For a Reddit thread we store the subreddit, the author's username, the thread text, the link, and public counts such as upvotes and comments. For a Hacker News thread we store the title, the thread text, the author's username, the link, and public counts such as points and comments. For a Threads post we store the author's username, the post text, the link, and public counts such as likes and replies.
- Your Find clients keywords: up to 20 search phrases you save for your project. We keep them until you change them or your account is deleted.
- A small curated pool of public X posts we use as writing examples. For each we keep the post text, the author's display name, handle and avatar, the link, the post date and public counts.
- Client-story candidates we find for your project: verbatim testimonial or case-result quotes from your public website, with the source-page URL, and up to 1,000 characters of text and the link from public X or Reddit posts that mention your product. These quotes may contain other people's personal data, such as a reviewer's name, role or employer, because we keep them verbatim as published on the source page. We keep candidates to help you find usable case studies, and a candidate you confirm is retained as a project fact. Candidates are deduplicated so we do not store the same quote twice and persist until your account is deleted.
- When you run a public account audit, we store a snapshot of that run: the public profile of the handle you entered, and for each collected public post its text, link, media references, any quoted post, publication time and public counts, together with the audit outcome for that post, the probabilities the AI model assigned to its answer options, and the provider-call accounting for the evaluation (a call identifier, attempt and token counts). The overall score is computed in your browser from the per-post outcomes and is not part of the stored snapshot. Today we keep these run snapshots until we remove them; there is no automatic deletion period yet. Cancelling or re-running an audit stops further work but does not erase an already stored snapshot. They are kept to check and calibrate the quality of the audit verdicts, to account for provider usage and cost, and to answer repeat audits: if anyone audits the same handle within 24 hours of a completed audit, we show them a copy of that stored result (the public profile, the public posts and their per-post outcomes) instead of reading X and running the AI evaluation again. The copy never includes who ran the original audit, and after 24 hours a new audit reads X again.
Processors we use
- Supabase for the database and authentication.
- Vercel for hosting and the scheduler cron.
- Upstash Redis for short lived caches, counters and locks: GitHub installation repository listings, including repository visibility, and release, pull request and commit snapshots from the repository you select are cached for up to 24 hours. It never stores raw private repository code, your imported bookmarks or your drafts.
- Polar for billing and subscription management.
- Resend for transactional email (failure and token-expiry alerts) and the daily digest and re-engagement reminder emails.
- PostHog (EU region) for product analytics and session replay, so we can see how the product is used and where it breaks. Enabled only after you accept analytics cookies. Session replays record your session, including the content you type and view, such as draft posts and captions; passwords are excluded.
- AI model providers to adapt your text per platform, to write your project documents, to suggest Find clients search keywords and to filter Find clients results: the OpenAI API, and the Google Gemini API as a fallback when an OpenAI request fails, times out or returns unusable output. The inputs described in this item and in the GitHub Fact extraction item below are sent to them only to provide the features described in those two items; neither OpenAI nor Google uses this text or data to train their models. When Find clients searches, the text of each public post found and the saved keyword that found it are sent to these model providers to decide which posts to show. When you ask for Find clients keyword suggestions, the short description you type, your saved keywords, your project name and, if different, your saved product profile name are sent to these model providers to suggest search keywords. Text you submit through the Facts workflow and every user message in Main Chat may be sent to these model providers to extract explicit project facts, including verbatim evidence quotes and whether they contain another person's personal data. Each extraction request also includes your project's stored active facts: their subject, type, value and date, including any fact flagged as containing another person's personal data, so the model updates the right fact instead of duplicating it. Main Chat may send your stored facts to the model providers when it creates or adapts a draft; facts flagged as containing another person's personal data are excluded from that drafting context. When you sign in with X or connect your X account, PostMine automatically retrieves up to 100 of your recent public X posts and sends them to these model providers to infer your writing style and build your tone profile. These model providers also receive the public posts found as client-story candidates, which can contain other people's names or other personal data, together with your product name and website, to judge whether a post is a genuine story about your product. For chat replies we also send OpenAI a pseudonymous project code: a one-way hash of your project that contains no name, email or project ID. OpenAI uses it only to route repeated requests from the same project to its prompt cache so answers arrive faster; it cannot be turned back into your identity or project.
- For GitHub Fact extraction, we send these model providers (OpenAI, or Google Gemini as a fallback) metadata plus release, merged pull request and main branch commit content from the repository you select. Only when the workspace owner explicitly consents for that version of the repository selection may we also send bounded, redacted diff excerpts from public or private repositories; changing or reconnecting the selection requires renewed consent.
- Web research providers (Tavily, Jina, Firecrawl, Exa and Serper) to read the public web page you ask us to analyze and to find and read competitors’ public pages for the Competitor Analysis document. We send them the public URLs being analyzed, not your account data.
- X (api.x.com) recent search to gather public posts for the Customer Research document, find public mentions for client-story candidates, and build your author voice. For research, we send queries built from your project’s product name, category and pain terms. For client-story search, we send your product name or website domain. For author-voice analysis, we send a from:<your X handle> query and retrieve up to 100 of your recent public posts. We do not send private content, and only public posts are returned. We store client-story candidates as described above. Find clients does not use this X API search.
- ScrapeCreators (a public-data search provider for Reddit) to find public Reddit threads for Find clients (the Reddit opportunity finder), and ScrapeCreators and Serper (a Google Search API) to find public mentions for client-story candidates. For Find clients, we send your saved Find clients keywords. For client-story search, we send your product name or website domain. We never send your account data or private content, and only public threads are returned. We store surfaced opportunity threads for your dashboard; for a client-story candidate we keep up to 1,000 characters of the post text and its link. We do not use the official Reddit API, and we never post to Reddit for you.
- Algolia (the Hacker News Search API at hn.algolia.com) to find public Hacker News threads for Find clients (the Hacker News opportunity finder). We send your saved Find clients keywords; we never send your account data or private content, and only public threads are returned. We store the surfaced thread (the title, the thread text, the author’s username, the link, and public counts such as points and comments) so it can be shown in your dashboard. There is no Hacker News account connection, and we never post to Hacker News for you.
- A third-party public-data search provider to find public Threads posts for Find clients (the Threads opportunity finder). We send a short search query built from your saved Find clients keywords; we never send your account data or private content, and only public posts are returned. We store the surfaced post (the author's username, the post text, the link, and public counts such as likes and replies) so it can be shown in your dashboard. This opportunity search does not use the official Threads API, and we never post opportunity replies to Threads for you.
- Google PageSpeed Insights (Google APIs) to audit the public site you ask us to analyze, for the Analytics column (PageSpeed, SEO and GEO signals). We send only that public URL, never your account data.
- X (api.x.com) is the only connected publishing API. We use the encrypted X credentials for the account you connect to publish content only after your explicit Post now action or schedule. Threads results use a pre-filled composer in your own browser and no Threads token.
- TwitterAPI.io (a third-party public-data provider for X) to search public X posts for Find clients, and to read the public profile and the public timeline of a handle for the public account audit. For Find clients, we send your saved Find clients keywords and store the surfaced public posts for your dashboard. We send it only the handle being audited and, to read its timeline, that account's public X user ID; it returns only public data: the profile and up to four pages of the timeline (up to 20 posts per page), from which PostMine keeps at most 40 eligible public posts per run. These reads do not use the official X API and never touch a connected PostMine account.
- TypeSafe (an AI evaluation model) to evaluate the public account audit: we send it the text of each public post collected for the run, and each per-post decision comes with the probabilities the model assigned to its answer options; PostMine stores those probabilities, together with the provider-call metadata (call identifier, attempts and token counts), alongside the outcome. Those probabilities and call records exist only to check and calibrate the quality of the verdicts and to account for provider usage and cost - the verdict itself never reads them. PostMine computes the overall score from those decisions in your browser.
- X Circle: the handle you enter is sent from your browser to FxTwitter, a free public service, to read public posts; if it is unavailable, our server reads the same public posts through TwitterAPI.io. Profile photos load from X's image servers. When a circle is drawn, we save it for its share link: the public handles, display names and profile photo links of the people in the circle, saved for 90 days and deleted automatically within a day after that.
Reminder emails
- We send a daily digest email, at most once a day, letting both free and paid users know when fresh posts or reply opportunities are waiting in PostMine. We email only when something new is ready; for accounts that stay away we ease off the come-back reminders and eventually stop them.
- Every email also carries a one-click unsubscribe link (no login needed). Once you opt out we honour it and stop sending reminders. Important account emails, such as a failed post or an expiring connection, are transactional and always come through.
What we never do
- We never post on your behalf without an explicit action: Post now or a schedule you set.
- We never post replies to other people's posts for you: opportunity reply drafts are yours to copy and post manually.
- We never use your content to train any model.
- We never sell your data.
Deletion
- Retracting a project fact is a soft deletion: the fact is marked retracted and stops being an active fact, while its stored version remains until account deletion. Superseded fact versions and composer chat turns are also retained with the project until account deletion.
- How to request deletion: email support@postmine.tech from your sign-in identity. We complete deletion requests within 30 days and confirm completion by reply. The request deletes your connections, rounds, drafts and project data. Posts already published stay on their platforms, because they are no longer ours to remove.
Cookies
- Essential cookies for sign-in and your session, plus a cookie that records your analytics-consent choice.
- Analytics cookies (PostHog) are set only after you click Accept in the consent banner, and never for advertising. If you Reject, no analytics cookies are set. You can change your choice any time by clearing cookies in your browser.
- The public account audit sets pm_pa_guest, a strictly necessary cookie that marks your browser as the owner of the audit runs you start, so only your browser can view their results. It carries no tracking data and is stored for one year.
Terms
Billing
- PostMine has one paid plan: Pro at $29/mo. Billing runs through Polar.
- Monthly is billed every month. Yearly is billed once, upfront, for 12 months at $278: an effective $23/mo, about 20% off.
- Prices may change with at least 30 days notice, but never in the middle of a period you have already paid for: any change takes effect only at your next renewal.
- If your subscription lapses, scheduled rounds hold with a blocked status and publish automatically once payment resumes.
Free plan
- PostMine has a free plan, not a trial. Start free with no card and stay on the free plan as long as you like.
- A card is asked for only when you upgrade to Pro, and the first charge happens at the moment of the upgrade. Cancel anytime in one click in Billing.
AI credits
- AI actions can cost different numbers of credits. PostMine may reserve an estimated amount while an action runs, but charges only actual usage up to that reservation after the result is durably saved; PostMine absorbs usage above the reservation.
- A failure before the result is durably saved does not consume credits. A saved result remains charged and available after reload.
- Free includes 200 AI credits once. Pro includes 3,000 AI credits per subscription month with no rollover.
- Credits have no cash value and cannot be transferred between accounts or workspaces.
- We may change future credit allowances. A decrease applies only to a future period and never reduces credits already granted for your current period.
- Free and Pro each include one active project. Additional projects, credit top-ups and add-ons are not currently offered.
Refunds
- Full refund within 14 days of any first charge, no questions asked. After that, refunds are pro-rated at our discretion.
- Refund requests go to support@postmine.tech.
Cancellation
- Cancel in one click in Billing. You keep full access until the end of the period you have paid for.
- After the period ends your workspace drops back to the free plan and Pro features turn off. We never delete your content: resubscribe to restore full access.
Your responsibilities
- You are responsible for the content you publish and for following each platform’s own rules and terms.
- Project documents and client-story candidates may surface third-party public content gathered for your analysis, including testimonials from public website pages and public X or Reddit posts with their source links. That content belongs to those third parties and is subject to their own terms. You are responsible for having a lawful basis to reuse a named person's words or other personal data. Documents and candidates are research aids, not legal or financial advice, so verify any fact, price or quote before you rely on it or confirm it as a project fact.
- Reply opportunities on X, Reddit, Hacker News and Threads are drafts for you to review and post yourself, from your own account: we never post them for you. A Main Chat result for Threads opens a pre-filled composer in your own Threads session; PostMine does not connect a Threads publishing account or post it for you. You are responsible for what you post and for following each community's rules, including the individual subreddit rules on Reddit, the Hacker News guidelines and Threads' community guidelines.
Public account audit
- The public account audit reads only public X accounts: the public profile and recent public posts of a handle you enter. Use it only for lawful purposes; do not use it to harass, target or profile individuals.
- An audit verdict, such as PASS or SLOP, is an automated opinion produced by an AI model. It is not a fact, not proof that any content was AI-generated, and not a statement about any person. Verify independently before you rely on it or repeat it.
Service
- PostMine is provided as-is. We aim for best-effort delivery with one automatic retry on transient failures, then a clear error and a manual Retry.
Accounts and sign-in
- You sign in to PostMine with X.
- GitHub is an optional repository source. The GitHub App grants PostMine only read access to Contents, Metadata and Pull requests for the repositories you select; it grants no repository write access.
Publishing and accounts
- PostMine publishes only on your explicit action: Post now or a schedule you set. There is no unattended auto-posting.
- You are responsible for the content you approve and publish, including its compliance with each platform’s rules on AI-assisted and automated content.
- PostMine is not liable for reach changes, restrictions or enforcement actions taken by platforms against your accounts.
License
- The PostMine source code is proprietary. © 2026 Yerkebulan Rakhimov. All rights reserved. Your use of the service is governed by these Terms.