Privacy Policy
Last updated: August 1, 2026
Applies to the AI Marketing Team service at crewpost.ai.
AI Marketing Team ("we", "us", "our"), also known as Crewpost at crewpost.ai, provides software that helps businesses generate, review, schedule, publish, and improve social posts with AI agents (an AI marketing team — not crew or workforce scheduling), and prepare social profile templates. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have.
By creating an account or using the service, you agree to this policy. If you do not agree, please do not use the service.
1. Who is responsible
The service is operated as AI Marketing Team at crewpost.ai. For privacy questions or deletion requests, use our contact form. We do not publish a support email address on this site.
2. Information we collect
2.1 Account & workspace
- Business / organization name, your name, and email address at signup
- Authentication credentials managed by our auth provider (see Third parties)
- Workspace settings you choose (e.g. timezone, website and booking URLs, agent display names, plan/trial usage metadata)
2.2 Content you create
- Projects/campaigns, briefs, drafts, captions, images, schedules, and approvals
- Profile kit brand answers and generated templates (taglines, bios, checklists, logos)
- Comment-reply drafts and related moderation choices in the product
- Messages you send through the contact form (name, email, topic, message body)
2.3 Connected social accounts (e.g. LinkedIn)
If you choose to connect LinkedIn (or another channel we support later), we collect only what is needed to provide the features you enable, within the permissions you grant during OAuth:
- Account / Page identifiers and display names for the profiles or Company Pages you select
- Access tokens (and related expiry metadata) stored securely so we can publish, read engagement, and sync comments on your behalf
- Content and metrics related to posts we publish or analyze for you (e.g. captions, media references, engagement stats, public comments on those posts)
We do not request access beyond the scopes shown on the LinkedIn (or other provider) consent screen. Disconnecting a channel deletes the stored token for that connection; it does not remove posts already published on that network.
2.4 Technical & usage data
- Session cookies and similar technologies required to keep you signed in and protect the service
- First-party aggregate analytics: page path, UTC day counts, and coarse traffic dimensions (country code from the edge, referrer host, UTM parameters when present, device class, hour of day). No cookies, no IP storage, no advertising identifiers — used to understand site and product traffic
- Server-side product events (e.g. content generated, LinkedIn connected) tied to your workspace where relevant, used only for operating and improving the service
- Basic operational logs (e.g. automation/cron run status, errors) used to operate and debug the product
- Approximate device/browser information that may appear in standard HTTP logs on our hosting provider
We do not use third-party advertising pixels or sell personal data for ads.
3. How we use information
We use the information above to:
- Provide, maintain, and improve the AI Marketing Team product
- Generate text and images via AI providers you trigger through the product (briefs, posts, profile kits, comment replies, insights)
- Publish and schedule content to social accounts you have connected and authorized
- Sync comments, draft replies, and surface performance insights you request
- Enforce plan limits, trials, and workspace isolation
- Measure aggregate site traffic and feature usage so we can improve the product
- Respond to support, sales, and privacy requests
- Secure the service, prevent abuse, and meet legal obligations
4. AI processing
When you ask the product to generate or rewrite content, relevant inputs (e.g. your brief, brand notes, page copy, or comment text) are sent to our AI providers solely to produce the requested output. We do not use your workspace content to train public foundation models for unrelated third parties. Provider terms govern how those vendors process API traffic; see Third parties below.
5. How we share information
We share data only as needed to run the service, not for sale or unrelated advertising:
- Service providers — hosting, database, auth, AI, email delivery, and similar infrastructure (listed below)
- Social platforms you connect — LinkedIn, X, Facebook, Instagram, TikTok (and others as we add them), when you authorize publishing or reading data through their APIs
- Legal / safety — if required by law, or to protect users, the public, or our rights
- Business transfers — if we reorganize or transfer the service, data may move with it under continued privacy protections
Each customer workspace is isolated. Row Level Security and related controls are designed so one organization cannot read or write another organization's data.
6. Third-party services
We currently rely on providers including:
- Supabase — database, authentication, file storage
- Cloudflare — application hosting (Workers) and image generation (Workers AI)
- Anthropic — text generation for agents
- Resend — delivery of contact-form messages
- LinkedIn — OAuth and APIs when you connect a profile or Company Page
- X (Twitter) — OAuth and APIs when you connect a profile
- Meta — Facebook Page and Instagram Business OAuth and Graph APIs when you connect them
- TikTok — Login Kit and Content Posting API when you connect a profile
Each provider processes data under its own terms and privacy policy, and only receives what is needed for its function. Additional channels (e.g. YouTube) will follow the same pattern: only after you connect them and grant permissions.
7. Cookies & similar technologies
We use essential cookies and local session storage to authenticate you, protect against CSRF-style abuse on OAuth flows, and keep the dashboard working. We also collect privacy-friendly first-party page-view aggregates (path + day only) without setting analytics cookies. We do not run third-party ad trackers on the marketing site or app for behavioral advertising. See our Cookie Policy.
8. Retention & deletion
We retain account and workspace data while your account is active and as needed to provide the service. Automation logs and similar operational records may be kept for a limited period for reliability and security.
You may disconnect social accounts anytime in the dashboard (Channels), which removes stored tokens for that connection. To request deletion of your account and associated personal data, submit a request via the contact form. We will respond within a reasonable period. Some information may remain in backups or logs for a limited time, or where we must keep it for legal reasons. Content already posted to LinkedIn or other networks remains under that platform's control until you remove it there.
9. Your choices & rights
Depending on where you live, you may have rights to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your account or certain data
- Object to or restrict certain processing
- Export a copy of data you provided (where applicable)
- Withdraw consent for optional connections (e.g. disconnect LinkedIn)
To exercise these rights, use the contact form. You can also update much of your workspace data directly in the product.
10. Security
We use industry-standard measures appropriate to a multi-tenant SaaS product, including encrypted transport (HTTPS), access-controlled databases, isolation between workspaces, and restricted handling of social access tokens (service-role paths where required). No method of transmission or storage is 100% secure; please use a strong unique password and keep your login private.
11. International transfers
We and our providers may process data in the United States and other countries where those providers operate. If you access the service from another region, your information may be transferred across borders. Where required, we rely on appropriate safeguards offered by our vendors (such as standard contractual clauses).
12. Children
The service is intended for business use by adults. We do not knowingly collect personal information from children under 16 (or the minimum age required in your jurisdiction). If you believe a child has provided us data, contact us and we will take appropriate steps to delete it.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will change the "Last updated" date above and, for material changes, provide a more prominent notice in the product or by email when appropriate. Continued use after an update means you accept the revised policy.
14. Contact
Privacy questions, access requests, or deletion requests: Contact us.
Related: Terms of Use · Cookie Policy
We may update this Privacy Policy from time to time. The date at the top shows the latest version.