Privacy Policy
Last updated: 11 August 2026
This policy explains what PostReef (postreef.com) collects, why, and what you can do about it. The controller is Francisco Macedo, sole trader, Rua Acácio de Paiva 10, 2.º Dto., 1700-005 Lisboa, Portugal — [email protected].
What we collect
Account data. Your email address, and your name and profile picture if you sign in with Google. Passwords are stored hashed; we never see them in the clear. Legal basis: performance of our contract with you.
Usage data. The URLs you submit, the options you pick, the results we return, timings, credit ledger entries, and API request logs. This is the Service — we cannot run an extraction without it. Legal basis: contract.
Billing data. Amounts, dates, and Stripe's identifiers for your customer record, payments, and saved card (brand and last four digits only). We never receive or store your full card number — Stripe collects it directly. Legal basis: contract and our legal obligation to keep accounting records.
Operational logs. Errors and diagnostics, retained short-term to keep the Service working. Legal basis: our legitimate interest in a secure, functioning service.
We do not use third-party analytics, advertising, or tracking cookies. The only cookies we set are the ones that keep you signed in.
What we do with extracted content
When you submit a URL we fetch what is publicly available there through a rotating proxy network, store it on our server, and — if your request includes an AI extraction — send the relevant parts to Google's Gemini API to produce your structured result.
- Extraction artifacts (video, audio, transcripts, comment dumps, page text) are deleted automatically about five weeks after the run.
- Your structured results, run metadata, and ledger entries are kept for your history and our accounting.
- We do not use your content or results to train AI models, and our AI provider processes them under its API terms without using them for training.
Who we share it with
We use these processors, and nothing more:
| Processor | Purpose | Where |
|---|---|---|
| Stripe | payments, saved cards, invoicing | EU/US |
| Google (Gemini API) | AI extraction | US |
| Hetzner | server hosting and database | Germany |
| Cloudflare | network, TLS, backup storage | EU/US |
| Resend | transactional email (login links, notifications) | US |
| Webshare | proxy network used to fetch source pages | US/EU |
Transfers outside the EEA rely on the European Commission's Standard Contractual Clauses or an adequacy decision. We do not sell your personal data, and we do not share it for advertising.
We may disclose data where legally required, or to establish or defend legal claims.
How long we keep it
- Extraction artifacts: about five weeks.
- Run records, results, and account data: until you delete your account.
- Billing and ledger records: as long as tax and accounting law requires (up to 10 years in Portugal), even after account deletion.
Your rights
If you are in the EEA or UK you can ask us to give you a copy of your data, correct it, delete it, restrict or object to processing, or export it in a portable format. Write to [email protected] and we will respond within 30 days. You may also complain to your national data protection authority — in Portugal, the CNPD.
Deleting your account removes your account data, runs, and results. Billing records that we are legally required to keep are retained.
Security
Traffic is encrypted in transit. The database sits on a private network with encrypted daily backups. API keys are stored hashed and shown once at creation. Access to production is limited to the operator.
No system is perfectly secure. If we discover a breach affecting your personal data we will notify you and the supervisory authority as the GDPR requires.
Children
The Service is not for anyone under 18, and we do not knowingly collect data from children.
Changes
We will post material changes to this policy here and, where they matter, email you before they take effect.