post

Privacy Policy

Last updated: 8 October 2026

Post is designed to process your images and return results without keeping more than the service needs. This policy explains what data we use, how it’s processed, and how it’s handled.

1. What we collect

We collect only the data required to operate the app:

We do not collect:

Separately from the app, if you ask on our website to be told when post is on Android (or asked earlier to join the Android test), we store the email address you give us. See section 6.

2. How your data is used

Your data is used to provide the core functionality of the app:

Colour only works differently. The photo is graded entirely on your device, by the model built into it (Apple Intelligence on iPhone and iPad, Gemini Nano on Android). It is not uploaded to us or to anyone else, and no shot is used.

We also keep first-party records, tied to your account, of key events in your use of the app: account created, shots processed, download tapped, purchase screen viewed, purchases made, proofs developed, and, for colour only, that a grade was made, which look and strength it used and how long it took. They also include technical measurements of how a finished shot compares with the photo it came from. These are numbers, never the picture itself. These records are used only by us, to operate and improve the service. They are never sold and never shared.

3. How images are handled

We do not keep your images any longer than the service needs.

Free trial shots work differently. Free shots are proofs: full quality, watermarked. We store one image per proof with your account: the finished shot, and nothing else. The watermark is not part of what we store. It is added as the image is sent to your device, and developing your proofs stops it being added. This is what lets buying your first roll develop every proof you’ve made, on any device you sign in from. Proofs are kept until you delete your account, and deleting your account deletes them.

If you report an output, we keep that one image for up to 30 days so a person can review it, then delete it automatically. Deleting your account deletes it straight away.

On our servers, we do not build a library of your photos. Proofs and reported outputs are the only exceptions.

Your library, on your device. The app keeps every shot you make in a library on your device, so you can reopen it later. For each shot it keeps the finished picture, the copy of your photo it was made from, and the analysis that came with it. This stays on your device, and we never receive it.

On iPhone and iPad, if you are signed in to iCloud, the library is also stored in your own private iCloud, through Apple’s CloudKit, so a new device or a reinstall gets it back. Full-size originals are not included: they stay in your Photos library. This copy lives in your iCloud account, under Apple’s terms, and we cannot read it. You can turn it off for post in your device’s iCloud settings. The library is also part of your device’s own backups, again without the full-size originals.

On Android, the library is not part of Google’s automatic app backup, but it moves with your other app data when you transfer directly to a new phone. You can choose to back it up to your own Google Drive, in a private folder that only post can use and that does not appear among your files. Full-size originals are not included. Turning this on asks for that permission separately from signing in, and we cannot read this copy either.

“clear library” in the app’s settings removes the library from your device and from its iCloud or Google Drive copy. Deleting your account in the app does the same.

4. Third-party processing

We use third-party AI services to process images. Depending on the photo, your image and optional text may be processed by:

Your image and optional text are securely transmitted to these services for processing, and to no one else.

Colour only uses none of these services. Its grade is made on your device (section 2).

We access these services through their commercial APIs, whose terms do not permit your images or text to be used to train their models. Where a provider offers retention controls, we set them to the strictest available: our primary image generation route is configured for zero data retention, and your image travels inside the request itself. It is never uploaded to hosting or a CDN. Beyond these controls, providers process data in accordance with their own privacy policies, which we do not control.

These providers process data in the United States. Where UK or EU data-protection law applies to you, transfers rely on the safeguards it recognises, such as standard contractual clauses or the providers’ certifications under the UK and EU data-transfer frameworks.

5. Install attribution

We measure whether our own ads lead to installs, without identifying anyone:

Referral links in the iOS app are powered by Branch, a link-matching service. When you open the app, Branch receives the technical data needed to recognise whether a post referral link brought you there: IP address, device model and OS version, and a device-scoped identifier that is not an advertising identifier. Branch processes this on our behalf to credit referrals; it does not receive your images or account details, and does not use this data to profile you across other apps.

None of this involves tracking: no advertising identifiers, no cross-app profiles, and no App Tracking Transparency prompt. There is nothing to ask permission for.

6. Android: launch notices and test signups

Post for Android is not on Google Play yet. If you ask to be told when it is, at usepost.co/android, we store the address you give us, the date, and (if you arrived from one of our ads) which ad it was. That address is used once, to email you when the Android app is released, and is then deleted. It is not added to a mailing list, is not used for any other marketing, and is not passed to anyone else.

Before October 2026 the same page offered a place in the Android closed test. Addresses given then were used to invite those people to the test and to keep track of who was testing (Google requires each tester to be entered in Google Play Console by email address), and nothing else; they stay on those terms.

Every address on either list is deleted when the Android app is released publicly, or sooner if you ask: email app@usepost.co and we will remove you. This is separate from a post account. Asking does not create one.

7. Support messages

If you use the form at usepost.co/support, we receive what you typed: your message, your email address, and the “when” if you filled it in. If you reached the form from inside the app, it also carries a short diagnostic line the app built: your account id, the app version, your iOS version and your device model. The form shows you that line before you send it.

Reporting a finished shot with the report button sends two things more: the image you are reporting, and a reference to the shot it came from. Without them there is nothing for a person to look at. That image is kept for up to 30 days and then deleted automatically, and deleting your account deletes it straight away (section 3).

This is used to answer you and to fix what you reported, and for nothing else. Your address is not added to any list. Submissions arrive as email and stay in that mailbox; a copy is held on the server so that a message cannot be lost if delivery fails, and so we can see that nothing has gone unanswered.

Your IP address is not stored. It is held only in memory, briefly, by the counter that stops the form being flooded.

8. Data storage

We store minimal account-related data required to operate the app:

We do not store:

9. Account deletion

You can delete your account at any time from the app’s settings. If you no longer have the app installed, you can also request deletion from your browser at usepost.co/delete-account.

When you delete your account:

Deleting from your browser cannot reach your devices. A library stays on a device, and in your own iCloud or Google Drive, until you clear it in the app or remove it there yourself: in iCloud’s storage settings on an Apple device, or under “manage apps” in Google Drive’s settings.

To prevent abuse of free trials, one record survives deletion: a note that your sign-in identity has already claimed its free credits. This is the app-specific identifier your sign-in provider gives us, kept for this single purpose and linked to nothing else.

10. Data retention

11. Security

We use secure connections (HTTPS) for all data transmission. Sensitive operations, including authentication and purchases, are handled using Apple’s and Google’s secure systems.

12. Your rights

You have the right to:

To request a copy of your data, or to have your account deleted without using the app, email app@usepost.co or see usepost.co/delete-account.

13. Children

Post is not directed at children under 13, and we do not knowingly collect personal data from anyone under 13. If you believe a child under 13 has created an account, contact us and we will delete the account and its data.

14. Changes

We may update this policy from time to time. The current version is always available at usepost.co/privacy. Continued use of the app means you accept the updated policy.

15. Contact

If you have questions or wish to report a concern, contact: app@usepost.co