Privacy policy
Version 8 October 2026, under legal review
Who is responsible
The controller of your personal data is EndorphinIT a.s., Švábova 772/18, 152 00 Praha 5, Czech Republic, company ID 21906998 (see the imprint). For anything about your data, write to hello@postcache.dev.
What we collect and why
- Waitlist. When you join the waitlist we store your email address, the platforms you ticked, what you wrote about your use case, and the time you signed up. We use this only to contact you about early access, including the invitation email. The legal basis is your consent (Art. 6(1)(a) GDPR).
- Account and sign-in. For an account we store your email address, your plan, your API keys (as hashes) and your usage. Signing in uses a link we email you (valid 15 minutes) and a session cookie (30 days). The legal basis is the contract with you (Art. 6(1)(b) GDPR).
- Payments. Paid plans are billed by Stripe Payments Europe, Ltd. (Ireland). Stripe receives your email address and your payment details; postcache never sees card numbers. Stripe's own privacy policy applies to the payment data it processes. For pay-per-use and credit packs paid in USDC we store the payment reference (transaction hash) and the paying wallet address, and use them to prevent reuse of a payment and to limit abuse; for these records the retention for payment records below applies. The legal basis is the contract with you (Art. 6(1)(b) GDPR).
- Uploaded files. We store the files your software uploads, with their size, target platform, check results and how often their URL was fetched, until they expire or are deleted. We also store a SHA-256 fingerprint of each file. A fingerprint is a short code computed from the file; the file can't be rebuilt from it. We use it to keep removed and illegal files from being uploaded again. If your files contain personal data of other people, we process it for you under our data processing terms.
- Reports and moderation. If you report content, we store the report, the email address you give us (optional) and your IP address, to handle the report and prevent abuse of the form. We keep a log of moderation actions (reports, removals, suspensions, refused uploads). The legal basis is our legal obligations as a hosting service under the Digital Services Act (Art. 6(1)(c) GDPR) and our legitimate interest in a safe service (Art. 6(1)(f) GDPR).
- Emails you send us. If you write to one of our addresses, we keep the message and your address to answer you. The legal basis is our legitimate interest in replying (Art. 6(1)(f) GDPR).
- Analytics. To see how the website and the service are used, we use PostHog (PostHog, Inc., USA) as our processor. On our public pages it counts page views and clicks without cookies and without storing anything in your browser; the data goes through our own server to PostHog. PostHog tells visitors apart by a code computed from the IP address and browser, which changes every day, and does not keep the IP address. From our server we also send PostHog a few events about accounts (sign-up, sign-in, uploads with their target platform, plan changes), linked to your account number, never to your email address or your files. The dashboard sends no page analytics. The legal basis is our legitimate interest in understanding and improving the service (Art. 6(1)(f) GDPR); you can object by writing to hello@postcache.dev.
- Technical data. Like most websites, the proxy in front of our servers writes access logs with the IP address, time and requested address of each request; we use them only to run and secure the service. To protect our forms from abuse, the server also counts requests per IP address in memory for one hour. The legal basis is our legitimate interest in running a secure service (Art. 6(1)(f) GDPR).
The website sets no cookies except the sign-in session cookie and stores nothing else in your browser. It loads no third-party resources: analytics go through our own server. Fonts are served from our own server. We monitor the service's availability with our own tools; this monitoring collects no visitor data.
How long we keep it
- Waitlist data: until you ask us to delete it or withdraw your consent, and at most 24 months after you signed up.
- Uploaded files: until they expire (at most 7 days) or you delete them. Removed files are deleted at once.
- File fingerprints: as long as the file is hosted; fingerprints of removed or illegal files are kept on our block list without a time limit.
- Account data: while you have an account. Invoices and payment records are kept as long as Czech accounting and tax law requires (up to 10 years).
- Reports and the moderation log: 2 years, or longer while a case with an authority or court is open.
- Sign-in links: 1 day after they expire or are used. Sessions: until they expire.
- Emails: as long as needed to deal with your request.
- Analytics events: at most 2 years.
Where it is stored and who sees it
All data is stored on servers we operate in the Czech Republic, except analytics events, which PostHog stores in the USA. Only our team sees the data, apart from the payment data Stripe processes for paid plans and the analytics events PostHog processes for us. The transfer of analytics events to the USA is covered by the EU standard contractual clauses in PostHog's data processing agreement (Art. 46 GDPR). We pass data to authorities only where the law requires it, such as reports of illegal content. We do not sell your data or share it with anyone else.
Your rights
You can ask for access to your data, its correction or deletion, restriction of processing, or a copy in a portable format, and you can object to processing based on legitimate interest. You can withdraw your consent at any time by writing to hello@postcache.dev; this does not affect processing that happened before. You also have the right to complain to the Czech data protection authority, Úřad pro ochranu osobních údajů (uoou.gov.cz).