Privacy Policy — Post a Magic

Privacy Policy

Last updated: March 24, 2026

1. Introduction#

Welcome to Post a Magic ("we", "us", or "our"). Post a Magic is an AI-powered platform that helps creators grow their Threads audience, schedule posts, and track analytics. This Privacy Policy explains what information we collect, how we use it, and the choices you have.

By accessing or using our service at postamagic.com or app.postamagic.com, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect#

2.1 Account Information

When you create an account we collect your email address and (optionally) your name. Authentication is handled via Google OAuth or email/password through Firebase Authentication.

2.2 Threads Account Data

When you connect your Threads account, we request access to the Threads API on your behalf. We may collect and store:

  • Your Threads user ID, username, and profile information
  • Posts (threads) you have published, including text, media, and metadata
  • Replies and engagement data associated with your posts
  • Audience and follower analytics provided by the Threads API
  • OAuth access tokens required to act on your behalf

We access only the Threads data that is necessary to provide the features you use. We do not read private messages.

2.3 Usage Data

We automatically collect information about how you interact with our service, such as pages visited, features used, and actions taken. This helps us improve the product.

2.4 Waitlist Information

If you join our waitlist we collect your email address for the sole purpose of notifying you when access is available.

3. How We Use Your Information#

We use the information we collect to:

  • Provide, operate, and maintain the Post a Magic service
  • Connect to the Threads API and perform actions you request (posting, scheduling, analytics)
  • Generate AI-powered content suggestions and analytics insights based on your Threads data
  • Schedule and publish posts to Threads on your behalf at times you choose
  • Send transactional emails (account confirmations, scheduled post notifications)
  • Improve our algorithms and develop new features
  • Prevent fraud and ensure the security of our service
  • Comply with legal obligations

We do not sell your personal data or Threads content to third parties. We do not use your data to train general-purpose AI models that are made available to other users.

4. Sharing Your Information#

We may share information with:

  • Meta Platforms / Threads: When you use our service, data is exchanged with the Threads API (operated by Meta Platforms, Inc.) as required to fulfill your requests.
  • Infrastructure providers: We use Cloudflare (hosting and edge computing), Neon (managed PostgreSQL database), and Firebase (authentication). These providers process data only as necessary to deliver our service.
  • AI service providers: We use Cloudflare AI to power our AI-generated suggestions. Cloudflare explicitly states that it does not use Customer Content to train machine learning models or Large Language Models (LLMs) — see Cloudflare's Responsible AI policy. Your content is never used to train AI models.
  • Legal requirements: We may disclose your information if required by law or to protect the rights, property, or safety of Post a Magic, our users, or the public.

5. Data Retention#

We retain your account information and Threads data for as long as your account is active or as needed to provide the service. OAuth tokens for Threads are refreshed automatically and revoked immediately upon account disconnection or deletion.

You may request deletion of your account and associated data at any time by contacting us (see Section 9). Upon deletion we will remove your personal data within 30 days, except where retention is required by law.

6. Cookies and Tracking#

We use essential cookies to maintain your authenticated session (via a secure, httpOnly JWT cookie). We do not use third-party advertising or tracking cookies.

7. Security#

We implement industry-standard security measures including HTTPS encryption for all data in transit, httpOnly secure cookies for session tokens, and access controls on our databases. No method of transmission over the internet is 100% secure, however, and we cannot guarantee absolute security.

8. Your Rights#

Depending on your location you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Request deletion of your data ("right to be forgotten")
  • Withdraw consent for processing at any time
  • Port your data to another service
  • Lodge a complaint with your local data protection authority

You can also disconnect your Threads account at any time from the Settings page within the app, which will immediately revoke our access to your Threads data.

9. Data Deletion Instructions#

If you have connected your account via Facebook / Meta login and wish to delete the data Post a Magic has collected, follow these steps:

  1. From within the app: Go to Settings → Account → Delete Account. This will permanently delete your account and all associated data, including your Threads tokens and any stored posts or analytics.
  2. Via Facebook Settings: Visit Facebook → Settings → Apps and Websites, find Post a Magic, and click Remove. This revokes our access token. Then email us (see Section 10) to request full data deletion.
  3. By email: Send a request to privacy@postamagic.com. To protect your security, we may require you to verify your identity or confirm the request via the email address associated with the account before proceeding with deletion.

We will confirm receipt within 5 business days and complete deletion within 30 days. You will receive an email confirmation once your data has been removed.

⚠️ Once an account is deleted, data cannot be recovered.

10. Contact Us#

If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us at:

Post a Magic

Email: privacy@postamagic.com

Website: postamagic.com

11. Changes to This Policy#

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page and, where appropriate, notify you by email. Continued use of the service after changes take effect constitutes acceptance of the revised policy.