Privacy Policy
Last updated: 13 July 2026
This Privacy Policy explains how Toksta Solutions LTD (“we”, “us”, or “our”) collects, uses, and shares personal data when you use Flypost, including https://www.flypost.io and https://app.flypost.io (the “Service”).
We are the data controller for personal data processed through the Service. If you have questions or want to exercise your privacy rights, contact us at [email protected].
1. Who we are
- Service: Flypost
- Controller: Toksta Solutions LTD
- Address: 124 City Road, London, England, EC1V 2NX
- Company number: 13018428
- Contact: [email protected]
2. Data we collect
Depending on how you use the Service, we may collect:
Account and profile data
- Name, email address, and password (or authentication data if you sign in with Google).
- Optional referral source (for example, how you heard about us).
- Workspace, team, and billing details, including subscription plan and Stripe customer identifiers.
Content and usage data
- Brand information, voice settings, target audience, and other profile data you provide during onboarding.
- Source materials you upload or connect (URLs, documents, blog posts, videos, notebooks, and similar assets).
- Drafts, posts, carousels, infographics, images, and other content you create in the Service.
- Scheduling settings, publishing history, and post analytics where enabled.
- Prompts, edits, and interactions with AI features.
LinkedIn and third-party integration data
- If you connect LinkedIn, we may receive profile information, posts, analytics, and tokens needed to schedule or sync content, subject to the permissions you grant.
- Data from other services you choose to connect, as permitted by those services.
Technical and analytics data
- Device and browser information, IP address, log data, and approximate location derived from IP.
- Product analytics events (for example, page views and feature usage) via PostHog.
- Security signals, including data processed by Cloudflare Turnstile to protect sign-up and other forms.
- Cookies and similar technologies on our website and app.
Payment data
Payments are processed by Stripe. We receive billing status, subscription details, and limited payment metadata, but we do not store full card numbers on our servers.
Communications
If you contact us, we keep the content of your messages and related contact details so we can respond and maintain support records.
3. How we use data
We use personal data to:
- Provide, operate, and maintain the Service.
- Create and personalise AI-assisted drafts and assets based on your brand and source materials.
- Schedule and publish content to LinkedIn when you request it.
- Process subscriptions, trials, invoices, and account management.
- Monitor usage, diagnose issues, improve features, and protect against fraud and abuse.
- Send service-related messages (for example, account, billing, and security notices).
- Comply with legal obligations and enforce our Terms of Service.
With your consent or where permitted by law, we may also send product updates or marketing communications. You can opt out of marketing emails at any time.
4. Legal bases
We are a UK company. If you are in the UK, EEA, or another region with similar requirements, we rely on:
- Contract — to provide the Service you signed up for.
- Legitimate interests — to secure, improve, and analyse the Service, and prevent abuse, balanced against your rights.
- Consent — where required, for example certain optional marketing.
- Legal obligation — where we must retain or disclose data to comply with law.
If you are in the United States, we process personal information as described in this policy and as permitted under applicable US state privacy laws. Where those laws grant you specific rights, you may contact us to exercise them.
5. AI processing
To generate drafts and assets, we send relevant prompts and context (which may include your brand information and source content) to AI model providers via our infrastructure. We use this data only to deliver the feature you requested. We do not use your private workspace content to train public foundation models.
AI outputs may be stored in your account so you can review, edit, and publish them.
6. How we share data
We share personal data with service providers that help us run the Service, including:
- Supabase — authentication, database, and file storage.
- Stripe — payments and subscription management.
- PostHog — product analytics (EU-hosted where configured).
- Cloudflare — hosting, CDN, and bot protection (Turnstile).
- Trigger.dev — background processing for content generation and sync jobs.
- AI and enrichment providers — including OpenRouter and related model providers, plus LinkedIn data enrichment services where used.
- Google — if you choose Google sign-in.
- LinkedIn — when you connect your account for scheduling, sync, or analytics.
These providers process data on our instructions and under appropriate contractual safeguards where required.
We may also disclose data:
- To workspace members you invite, according to your project permissions.
- If required by law, court order, or to protect rights, safety, and security.
- In connection with a merger, acquisition, or sale of assets, subject to standard confidentiality obligations.
We do not sell your personal data.
7. International transfers
We are based in the United Kingdom. We and our providers may process data in countries other than where you live, including the United States and the European Economic Area. Where required, we use appropriate safeguards such as the UK International Data Transfer Agreement, Standard Contractual Clauses, or equivalent mechanisms.
8. Retention
We keep personal data for as long as your account is active and as needed to provide the Service. When you delete your account or specific content, we delete or anonymise associated personal data within approximately 30 days, except where we must retain it longer for:
- Legal, tax, or accounting obligations (for example, billing records may be kept for up to seven years).
- Security, fraud prevention, and dispute resolution (for example, certain logs may be kept for up to 12 months).
- Backups, which are purged on a rolling schedule.
9. Security
We use administrative, technical, and organisational measures designed to protect personal data, including encryption in transit, access controls, and monitoring. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Your rights
Depending on where you live, you may have the right to:
- Access, correct, or delete your personal data.
- Object to or restrict certain processing.
- Data portability.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with your local data protection authority (in the UK, the Information Commissioner's Office).
To make a request, email [email protected]. We may need to verify your identity before responding.
11. Cookies and analytics
We use cookies and similar technologies to keep you signed in, remember preferences, measure product usage, and protect the Service. You can control non-essential cookies through your browser settings. Blocking essential cookies may affect functionality.
12. Children
The Service is not directed to children under 18, and we do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and update the “Last updated” date. Material changes may also be notified through the Service or by email.
14. Contact
Privacy questions or requests: [email protected].
General support: [email protected].