Legal
Privacy policy
What Postfolio stores, who processes it, and how to get it back or have it deleted. The short version: we keep the notes we write for you, we never sell them, and we never use them to train anything.
Last updated September 29, 2026 · Friday Labs · [email protected]
This is an English translation, provided for convenience. Friday Labs is a Brazilian company and the Portuguese version is the governing one — where the two diverge, the Portuguese text prevails.
1. Who we are
Postfolio is built and operated by Friday Labs (“we”, “us”), a company incorporated in Brazil. For the purposes of the Brazilian General Data Protection Law (LGPD, Lei nº 13.709/2018) and the EU/UK General Data Protection Regulation (GDPR), Friday Labs is the controller of the personal data described in this policy.
Everything in this document applies to the Postfolio mobile app and to this website. Questions, requests and complaints all go to [email protected].
2. What we collect
| What | Why |
|---|---|
| Account details — your email address, your name if you give us one, the identifier returned by Apple or Google when you sign in that way, your chosen language, and your app settings. | To give you an account, sync it across your devices and write to you about it. |
| What you save — the link you shared, the text we derive from it (title, description, ingredients, steps, places, tips), one small cached copy of the post’s thumbnail image, the tags and folder it lands in, and any notes or corrections you add. | This is the product. Without it there is nothing to read back. |
| Device and technical data — app version, operating system, device model, push notification token, and a device identifier used alongside your account to apply the free allowance. | To run the app, deliver notifications, diagnose faults and stop the free tier being farmed. |
| Usage analytics — optional. Which screens are opened and which features are used, plus crash reports. Never the content of your library. | To see what’s broken and what’s unused. Off unless you turn on “Help improve Postfolio” in Settings; in the EU and UK it stays off until you opt in. |
| Subscription data — your plan, its status and renewal date, and the store transaction identifiers, passed to us by Apple or Google. | To unlock Pro. We never see or store your card details — payment happens entirely inside the App Store or Google Play. |
| Messages you send us — your name, your email address, and whatever you write in the contact form or in an email. | To answer you. |
We do not store the media itself. Postfolio never downloads or re-hosts the video or the images from a post. We store the text we derive from it and one small cached thumbnail, and we always link back to the original. If a provider declines to process a link, we don’t cache the thumbnail either — all that remains is a link you already had.
3. How we use it
- To create your account and keep your library in sync across your devices.
- To read a link you shared: resolve it, extract what it contains, write the summary, file it into a folder and make it searchable.
- To send the notifications you’ve enabled — mainly “your save is ready”.
- To answer your messages and provide support.
- To take payment for Pro and apply the right plan to your account.
- To keep the service secure and working: detect abuse, stop runaway costs, fix crashes.
- To meet legal, tax and accounting obligations.
We do not use your data for advertising, we do not build profiles for third parties, and we do not sell it. Ever.
4. Legal bases
Under the GDPR and the LGPD we rely on:
| Basis | For |
|---|---|
| Performance of a contract (LGPD art. 7, V) | Running your account, processing the links you share, syncing, and billing for Pro. |
| Consent (LGPD art. 7, I) | Optional analytics, push notifications, and any marketing email. You can withdraw it at any time in Settings, with no effect on the rest of the service. |
| Legitimate interests (LGPD art. 7, IX) | Security, fraud and abuse prevention, and keeping the service reliable — balanced against your rights, and never extended to reading your library. |
| Legal obligation (LGPD art. 7, II) | Tax, accounting and lawful requests from authorities. |
5. Service providers
We rely on third-party service providers to run Postfolio: hosting and storage, turning a link into readable text, sending notifications and email, managing subscriptions through the app stores, and, only if you opted in, product analytics. Each of them acts as our processor, receives only what its task requires, may only act on our instructions, and is contractually barred from using your content for any purpose of its own. Card data never reaches us or them: payments are handled entirely by Apple and Google.
A current, named list of these providers is available on request at [email protected].
6. We don’t train on your library
Nothing in your library is used to train a model, ours or anyone else’s, and we don’t read your saves to improve the product. When we work on the quality of our summaries we do it against our own test set of public posts, not against anybody’s account.
We also don’t sell your data, share it with advertisers or data brokers, or use it to profile you.
7. International transfers
Some of our providers operate outside Brazil, the EEA and the UK — mainly in the United States and the European Union. Where personal data is transferred internationally we rely on the mechanisms allowed under the LGPD (arts. 33–36) and the GDPR (chapter V), including Standard Contractual Clauses and equivalent contractual guarantees.
8. How long we keep it
- Your library — for as long as your account exists. We don’t expire saves, and downgrading from Pro never deletes anything.
- Deleted saves — kept in Trash for 30 days so you can restore them, then permanently removed.
- A deleted account — your saves, cached thumbnails, search indexes and subscription record are deleted within 30 days of the request, and purged from encrypted backups within a further 30 days.
- Support messages — 24 months, so we have the history if you write again.
- Analytics, if you turned it on — 12 months.
- Billing and tax records — for the period Brazilian law requires, regardless of account deletion.
9. Your rights
Under the LGPD (art. 18) and the GDPR you can ask us to:
- confirm that we process your data, and give you access to it;
- correct anything incomplete, inaccurate or out of date;
- anonymise, block or delete data that is unnecessary, excessive or processed unlawfully;
- give you a copy in a machine-readable format, or transfer it to another provider (portability);
- tell you who we’ve shared your data with;
- withdraw a consent you gave — analytics, notifications, marketing — and explain what happens if you do;
- object to processing based on our legitimate interests.
How to ask: email [email protected] from the address on your account, or use the contact form, and say what you want. We reply within 30 days. A portability request comes back as a JSON file containing your saves, folders, tags and notes.
Deleting your account doesn’t need an email: it’s in the app, under You → Delete my account. It’s a two-step confirmation, and it deletes your saves — including anything still in Trash — permanently.
If you think we’ve got this wrong, you can complain to the Brazilian data protection authority (ANPD) or, in the EU/UK, to your local supervisory authority. We’d rather you told us first.
10. Children
Postfolio isn’t intended for children under 13, and we don’t knowingly collect their data. Where local law sets a higher age for consent to online services — 16 in parts of the EU — that age applies instead. If you believe a child has given us personal data, write to us and we’ll delete it.
11. Security
Data is encrypted in transit and at rest. Your authentication token is held in the device keychain or keystore, not in ordinary app storage. You can put a device lock — Face ID, fingerprint or passcode — in front of the app in Settings. Internal access is limited to the people who need it to run the service.
No service is perfectly secure. If you find a vulnerability, please tell us at [email protected] before disclosing it publicly — we’ll work with you.
12. This website
This site sets no advertising or tracking cookies and doesn’t profile visitors. Our hosting provider keeps short-lived technical logs for security and reliability. If you use the contact form, what you write is used to answer you and for nothing else.
The web reader at web.app-postfolio.com, where you can read your library on a computer, keeps a copy of that library in your browser so it opens quickly, and two sign-in cookies that keep you signed in. Signing out deletes all three. It sets no other cookies.
13. Abuse and takedowns
Every Postfolio library is private to the person who made it — nothing is published, and there is no public feed. If you believe content processed through Postfolio infringes your rights or breaks the law, write to [email protected] with the link and an explanation, and we’ll act on valid notices. We report and cooperate where the law requires it.
14. Changes
When this policy changes we publish the new version here with a new date at the top. If a change materially affects how we handle your data, we’ll tell you in the app or by email before it takes effect.
15. Contact
Friday Labs
[email protected]
Or use the contact form — a person answers.