What this covers
This page explains what PostRoast collects when you use www.postroast.app, why we keep it, and who else sees it. We do not sell drafts. Public roast cards are published only when you click share.
Operator: Audiencon. Contact: @audiencon on X.
What we collect
- Account: email, name if you give one, hashed password or OAuth identity, plan, and Stripe customer id if you pay.
- Drafts and output: the text you paste, the roast, scores, rewrites, Studio threads, and Ideas you generate.
- Usage: roast, critique, and rewrite counts so daily caps work. We store a posted timestamp if you mark a thread as posted. That mark stays in PostRoast. It is not a post to X.
- Product analytics: page views and feature use through PostHog, with a device or person id.
- Technical: IP address, user agent, and cookies needed to keep you signed in.
Why we keep it
We use this data to run the roast, enforce plan caps, save history, take payment, debug failures, and see which parts of the product people actually use. We do not use your drafts to train a public model of our own. The model provider that generates a roast receives the draft for that request under their terms.
Who processes it
- Better Auth — sign-in and sessions.
- Stripe — checkout, subscriptions, and Founder payments.
- PostHog — product analytics.
- OpenAI — roast, rewrite, critique, and Ideas generation.
- Neon (Postgres) — application database.
- Vercel — hosting and request logs.
X sign-in, when enabled, is for identity only. We do not request posting permission, we do not read your timeline, and we do not schedule on your behalf.
Cookies
We use a session cookie so you stay signed in, and PostHog cookies or local storage for analytics. There is no advertising pixel from us. If we ever add one, this page will say so.
How long we keep it
Account data and drafts stay while the account is open. Usage events stay as long as we need them to enforce caps and understand the product. Public roast cards stay until you unpublish them or we take them down. Server logs rotate on the host's schedule. Stripe keeps payment records as the law requires.
Your choices
You can stop pasting drafts. You can close the account. You can ask us to delete the account and stored drafts by writing @audiencon on X from the handle or email we have on file. We will keep what the law or a payment dispute requires.
If you are in a place with access, correction, or deletion rights (including the EEA, UK, or California), use the same contact. We will not charge you to ask.
Children
PostRoast is not for children under 16. If we learn an account belongs to someone younger, we will delete it.
Changes
If the way we handle data changes in a material way, we will update this page and the date at the top. The Terms of use cover the product rules. The FAQ covers how the tool works.