posto

Privacy Policy

This policy explains how Posto handles information for its advertising platform, websites, advertiser services, Developer tools, SDKs, and APIs.

Effective August 25, 2026 · Version 2026-08-25

1. Scope and roles

This policy applies when you visit Posto, create or administer an account, use our advertiser or Developer services, integrate a Posto SDK or API, receive an ad through a participating app, or interact with an ad served by Posto.

Posto acts as a controller or business for account administration, service security, fraud prevention, billing, legal compliance, and its own product operations. For contextual ad requests, attribution, and conversion data submitted by a customer, Posto may act as a processor or service provider on that customer's documented instructions. The applicable agreement and Data Processing Addendum describe those roles in more detail.

2. Information we collect

  • Account and business information, such as name, work email, company, role, website, business-verification details, account status, and legal consents.
  • Advertising and catalog information, including campaigns, budgets, products, creatives, targeting constraints, bids, delivery settings, and performance.
  • Developer and app information, including app and placement configuration, SDK version, authentication credentials, integrity-verification results, and integration diagnostics.
  • Context submitted for an ad request: up to six alternating user/assistant messages representing the most recent three conversation turns, after deterministic PII filtering, plus optional age range, gender, and coarse country, region, or city supplied by the integrating app.
  • Delivery and interaction information, including request, auction, candidate, impression, click, redirect, conversion, event time, and coarse technical metadata. Posto uses signed tracking tokens and does not require a browser advertising pixel.
  • Conversion API information, including event type, event ID, Posto click ID, event time, and purchase value in USD cents when relevant.
  • Security and fraud information, such as IP and user-agent hashes, request velocity, HMAC verification, Apple App Attest or Google Play Integrity results, risk reasons, and investigation records. Posto does not ask SDK integrators to transmit a hardware device identifier.
  • Payment and payout status supplied by our payment processor. Posto does not store full card or bank-account numbers.
  • Communications, support messages, survey responses, and website logs.

3. Sources

We receive information from account users; advertisers; Developers and their apps; end-user devices when a properly authenticated SDK request is made; payment, cloud, integrity, and analytics providers; and from events generated through use of the service.

4. How we use information

  • Provide, authenticate, secure, operate, and improve Posto.
  • Match contextual requests to eligible advertisements and enforce hard category, language, location, price, and safety constraints.
  • Run auctions, pace budgets, measure delivery, attribute conversions, prevent duplicate counting, and produce reports.
  • Detect abuse, invalid traffic, replay, compromised apps, and fraudulent conversions or payouts.
  • Administer accounts, send transactional email, process payments and payouts, comply with law, and enforce agreements.
  • Create aggregate or de-identified statistics that are not reasonably linkable to an individual.

5. Contextual matching and automated processing

User messages are the authoritative source for semantic matching and hard constraints. Assistant messages are processed separately and may provide a small, bounded reference adjustment only among candidates already eligible from the user's text. Optional demographic fields are used only for an advertiser's explicit audience gate and are not placed in query embeddings.

Posto uses automated systems to select and price ads, detect invalid traffic, and help Campaign Agents optimize delivery. These systems do not make decisions that produce legal or similarly significant effects for an end user. Developers must not submit sensitive-context conversations, and Posto suppresses advertising in configured sensitive contexts.

6. How we disclose information

We disclose information to vendors that host, secure, authenticate, process payments, deliver transactional email, or provide models needed for the service; to advertisers and Developers through aggregated or attributed reporting; to professional advisers; in a corporate transaction; and when required to protect rights, safety, or comply with law.

We do not disclose unfiltered conversation text to advertisers. We do not sell conversation text. Posto does not use optional demographic information for unrelated profiling.

7. Retention

  • Redacted request transcripts: 30 days, then only derived intent, hashes, risk outcomes, and aggregates remain.
  • Raw traffic-risk events: 30 days; aggregated risk and velocity data: 180 days.
  • Non-billable SDK test requests and tokens: 7 days.
  • Account action tokens: until used or expired, then removed by maintenance.
  • Account information: while active and during a 30-day closure grace period, then anonymized unless retention is required.
  • Financial, settlement, tax, legal-consent, and confirmed fraud-audit records: up to 7 years or longer when law or an active dispute requires.
  • Other operational data: only for the period reasonably necessary for the purposes above or as stated in an applicable agreement.

8. Security

Posto uses transport encryption, access controls, secret isolation, signed requests, mobile app-integrity verification, idempotency controls, audit logs, backup and recovery procedures, and risk-based settlement holds. No system is perfectly secure; report suspected security issues to security@postoconnect.com.

9. International transfers

Posto and its service providers may process information outside the country where it was collected. Where required, Posto uses an approved transfer mechanism and supplementary safeguards. Customers may request the current transfer mechanism and subprocessor list.

10. Your choices and rights

Depending on location, you may request access, correction, deletion, portability, restriction, objection, or withdrawal of consent. California residents may also request to know, correct, or delete covered personal information and may exercise applicable opt-out or limitation rights without discrimination. Posto does not presently sell personal information or share it for cross-context behavioral advertising as those terms are defined by California law.

Account users can download an account export or schedule account closure from Privacy & account. End users of a Developer's app should normally contact that Developer first; Posto will assist the Developer when it acts as processor. Requests may be sent to privacy@postoconnect.com. We may verify identity and preserve records that law requires us to retain.

11. Children

Posto is not directed to children under 13 and account holders must be at least 18. Developers may not use Posto in a child-directed service or knowingly submit children's personal information without Posto's prior written approval and all legally required consent.

12. Changes and contact

We will post material changes and update the effective date. When required, we will provide additional notice or obtain consent. The operator is PostoX, Inc, at 131 Continental Drive Suite 305, Newark, DE 19702. Privacy questions: privacy@postoconnect.com.