— Legal
Privacy Policy
Last updated September 25, 2026
This policy explains what data Post Inbound collects, what it's used for, who it's shared with, how long it's kept and how you control and delete all of it. It covers the website and the LinkedIn integration.
Who is responsible
Post Inbound is operated by Carlos Henrique de Oliveira, an individual, who is the controller of your personal data under Brazil's General Data Protection Law (Law 13,709/2018, “LGPD”). Contact for any privacy matter: postinbound@chenoli.com.br.
What data we collect
- Account: name, e-mail, chosen language and theme.
- Content you create: post requests, generated texts and images, uploaded attachments, tweak history, design systems and style references.
- AI provider API keys: stored encrypted and used only to call the provider you chose.
- Technical and security data: IP address and browser used in sessions and in the security log (sign-ins, wrong-code attempts, connections and disconnections).
- Problem reports: the message, screen and images you send are e-mailed to support and are not kept in the app.
LinkedIn data
We only access LinkedIn when you click “Continue with LinkedIn” or “Connect LinkedIn” and approve it on LinkedIn's own screen. We never see or store your LinkedIn password.
- What we receive and store: your LinkedIn member identifier, name, e-mail, profile picture (we keep only a reduced 96×96-pixel copy) and the access tokens, stored encrypted. We don't access your connections, feed, messages, companies or any other data.
- When we collect it: at the moment you approve. Name and picture are refreshed only when you sign in with LinkedIn again or reconnect; we never fetch your data in the background or on an automated schedule.
- What we use it for: signing you in; showing which profile is connected and your picture in the menu; and posting to your profile only when you click “Publish now”. Nothing is ever posted automatically.
- Who we share it with: no one. LinkedIn data is not sent to the AI provider, not sold and not used for advertising.
- How to withdraw consent: in Settings › LinkedIn, “Disconnect” deletes the tokens, name and picture and revokes access on LinkedIn; “Unlink sign-in” removes LinkedIn sign-in and deletes the identifier. You can also remove Post Inbound at linkedin.com › Settings › Data privacy › Permitted services.
- How to request deletion: through the options above, by deleting your account, or by writing to the contact in this policy.
What we use data for
We don't sell personal data and don't use it for advertising.
- Providing the service: generating, storing, tweaking and publishing your posts (legal basis: performance of a contract, LGPD art. 7, V).
- LinkedIn integration: with your consent (art. 7, I), which you can withdraw at any time.
- Security and abuse prevention: sessions, attempt limits and the security log (legitimate interest, art. 7, IX).
- Support: answering problem reports and privacy requests.
Who we share data with
- The AI provider you connected (for example OpenAI, Anthropic or Google), using your own key: it receives the request, texts, images and attachments needed to generate the post. Its processing follows that provider's own terms and policy.
- LinkedIn: receives the post's text, hashtags and image when you publish.
- Infrastructure: hosting, database, file storage and e-mail delivery services, which process data only on our behalf.
- Authorities: when required by law.
How long we keep data
- Posts (text, image and versions): 14 days after creation, published ones included; then they're deleted automatically. What you already published stays on your LinkedIn.
- Uploaded but unused attachments: 24 hours.
- Codes sent by e-mail: valid for 10 minutes and deleted within 2 days. An unfinished LinkedIn sign-in: valid for 10 minutes and deleted in the next daily cleanup.
- Sessions: up to 30 days without use; expired sessions are deleted in the daily cleanup.
- Account, design systems, style references, AI keys, LinkedIn connection and security log: while the account exists, or until you delete each item.
Security
All traffic uses HTTPS. AI keys and LinkedIn tokens are stored encrypted, session credentials never sit in browser storage and files are served through temporary links. If an incident affects your data, we'll notify you and the authorities within the legal deadlines.
Your rights
At any time you can confirm whether we process your data, access it, correct it, request portability, learn who we share it with, withdraw consent and request deletion (LGPD art. 18).
To delete everything at once, use the user menu › Delete account: deletion is immediate and covers posts, files, keys, the LinkedIn connection (with access revoked) and the security log. For any other request, write to postinbound@chenoli.com.br; we reply within 15 days.
Changes to this policy
If we change anything relevant, especially about how LinkedIn data is used, we'll tell you by e-mail or in the app before the change takes effect and, where the law requires, ask for your consent again.