Your data
Privacy Policy
This notice explains what Postilae processes, why, for how long, and the choices and GDPR rights available to you.
Last updated
1. Controller and contact
Postilae is operated by Simona-Alexandra Ursache in Romania. Simona-Alexandra Ursache is the controller of the personal data described in this notice. Privacy questions and requests can be sent to hello@postilae.com; this inbox is active and monitored for privacy matters.
2. Data we process
The data involved depends on whether you use a temporary session, create an account, submit feedback, or choose an online provider feature.
- Account and profile data: your name, email address, authentication account and identifiers, and your current optional email-news preference and opt-in timestamp.
- Encrypted workspace data: supported book metadata, reading positions and progress, highlights, annotations, notes, reading sessions, projects, links, preferences, and related workspace content. This data is encrypted on your device before it is cached or synchronized. Postilae does not store your workspace passphrase and cannot decrypt the retained workspace for you.
- Device-only data: the PDF, EPUB, and DOCX file bytes you attach, the account-scoped encrypted browser cache, and app-managed local copies. Original source-file bytes are not included in the cloud snapshot.
- Temporary signup handoff data: a same-tab copy of the temporary workspace placed in browser session storage only after you actively start account creation.
- Feedback data: a rating, an optional comment, submission time, and any personal information you choose to include in the comment.
- Abuse-prevention data: a short-lived pseudonymous HMAC key derived server-side from a network address or account identifier when feedback is submitted. The raw network address is not stored in the feedback rate-limit table.
- Technical and usage information made available through Lovable's built-in analytics, to the extent that service collects it, and security or diagnostic information needed to operate and protect the service. Encrypted workspace content and source-file bytes are not analytics content.
- Messages and request data: information you include when contacting us about support, privacy, or legal rights.
The Postilae profile does not request a home address, Romanian personal numerical code (CNP), phone number, or date of birth. Please do not include sensitive personal data in free-text notes or feedback unless it is genuinely necessary for your own use.
3. Purposes and legal bases
We process personal data only for the purposes below. The references are to Article 6(1) GDPR.
- Contract (Article 6(1)(b)): to create and authenticate an account; maintain the profile; retain, cache, synchronize, restore, and export the workspace you request; and provide user-requested discovery or hosted-reading actions.
- Legitimate interests (Article 6(1)(f)): to keep Postilae secure and reliable, prevent misuse, diagnose failures, understand basic service use through Lovable's built-in analytics, improve the product using private feedback, answer non-contractual enquiries, and establish or defend legal claims. These interests are limited by data minimisation, encryption, user controls, and your right to object.
- Consent (Article 6(1)(a)): for optional email news if that capability is launched, and for any optional analytics storage or access where consent is required. Consent can be withdrawn at any time without affecting processing that was lawful before withdrawal.
- Legal obligation (Article 6(1)(c)): where processing is necessary to comply with a binding legal duty.
4. What is required and what is optional
A name, controlled email address, and authentication credentials are required only if you choose to create an account and retain a workspace. Without them, you may use the full reading workspace in a temporary page session, but it normally disappears when the page is closed or reloaded. Email-news consent and feedback are optional; refusing or withdrawing either does not affect the account or encrypted sync.
5. Temporary sessions, encryption, files, and deletion
Before account creation starts, the workspace exists only in the active page session and is not saved to browser storage or uploaded. If you actively start signup, a same-tab handoff is stored in browser session storage for no more than 24 hours so the authentication redirect can return your work. It is removed earlier after a successful transfer, a rejected signup, or expiry.
After sign-in and passphrase unlock, supported workspace data is encrypted on the device before it is written to the account-scoped browser cache or synchronized as an encrypted Lovable Cloud snapshot. Postilae does not store the passphrase and cannot recover, reset, or use it to decrypt the workspace. PDF, EPUB, and DOCX source-file bytes remain on the device where they were attached and must be reattached on another device.
Deleting your account through the account panel removes the authentication account, profile, encrypted cloud snapshot, account-scoped browser cache, unlock key, and app-managed attached-file copies. Postilae does not currently offer a durable separate cloud-snapshot deletion or cloud-sync-off control: an active sync could recreate a snapshot, so account deletion is the current way to permanently remove the app-managed cloud copy. Files and backups you exported outside Postilae remain under your control.
6. Recipients and providers
Personal data is available only where needed to operate a feature or meet a legal duty. Postilae does not sell or rent personal data.
- Simona-Alexandra Ursache, as operator and controller, for administration, support, privacy requests, and private product feedback.
- Lovable Cloud and Supabase for hosting, authentication, profiles, encrypted snapshots, feedback storage, service infrastructure, and Lovable built-in analytics.
- Google only if you choose Google sign-in. Google processes that sign-in under its own privacy information.
- Internet Archive or another catalogue, search, or hosted-reading provider only when you actively request that provider-backed feature. The selected provider applies its own privacy information to its service.
- Competent authorities or professional advisers only where disclosure is legally required or necessary to establish, exercise, or defend legal claims.
7. Analytics, email news, and feedback publication
Postilae currently uses Lovable's built-in analytics. Google Analytics is not active. Google Analytics or a similar optional analytics service will not be introduced without first updating this notice and applying consent controls where required.
No Postilae newsletter is currently being sent, and no newsletter provider has been selected. The account profile only prepares an optional opt-in choice. Before email news is launched, this notice will be updated to identify the provider and relevant processing. The choice is off by default and is not required for an account.
Feedback is reviewed privately for product improvement. It is not published as a testimonial and will not be used as one without separate, explicit consent.
8. Hosting locations and international transfers
Postilae is operated from Romania. The current hosting and processing region used by Lovable Cloud and Supabase has not been confirmed, so this notice does not claim a particular region. If a provider processes personal data outside the European Economic Area, the transfer must use an applicable GDPR mechanism, such as an adequacy decision or appropriate safeguards under Article 46, including standard contractual clauses where relevant. Contact hello@postilae.com for current transfer information or a way to obtain the relevant safeguards.
9. Retention
We use the following periods or criteria:
- Account, profile, authentication data, and the encrypted synchronized workspace are kept while the account exists and are removed through account deletion, except where a limited record must be retained to comply with law or resolve a legal claim.
- The temporary signup handoff is kept for no more than 24 hours and is removed earlier after successful transfer, rejection, or expiry.
- The current email-news preference and opt-in timestamp are kept with the profile while the current consent is active. Withdrawing consent turns the preference off and clears the active-consent timestamp.
- Identifiable feedback is kept for no more than 24 months and is deleted sooner on a valid request or when the related account is deleted. Only anonymous, aggregated product insights that no longer identify you may remain.
- Pseudonymous feedback rate-limit keys are removed after no more than 2 days.
- Lovable's built-in analytics and necessary technical or security records are kept only as long as needed for service measurement, troubleshooting, and security, under the available provider controls. Postilae does not claim an unconfirmed fixed provider period.
- Exports are created only when you request them. Postilae does not retain a separate server copy solely because you exported; downloaded copies remain under your control.
10. Age
Postilae is for people aged 16 or older. If you are 16 or 17, or otherwise below the age of majority where you live, you must have a parent or legal guardian's permission as described in the Terms. Postilae does not collect a date of birth to verify age. A parent or guardian who believes a younger person's data has been provided can contact hello@postilae.com.
11. Your GDPR rights
Depending on the circumstances, you may ask for access, correction, deletion, restriction, or portability of your personal data; object to processing based on legitimate interests; and withdraw consent at any time. Withdrawal does not affect prior lawful processing. You can delete the account directly in the account panel and can export workspace data using Postilae's export tools. To exercise another right, email hello@postilae.com. We may request only the information reasonably needed to verify your identity.
12. Complaints
Please contact hello@postilae.com first if you would like us to address a concern. You also have the right to lodge a complaint with a data-protection authority. In Romania, this is the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP). Its official complaints information is at https://www.dataprotection.ro/?page=Plangeri_meniu. You may also complain to the supervisory authority for your habitual residence, workplace, or the place of the alleged infringement.
13. Automated decisions
Postilae does not use personal data for solely automated decisions that produce legal effects or similarly significant effects, and it does not profile users for advertising.
14. Changes to this notice
The date at the top will change when this notice is updated. Material new processing, including a newsletter provider or Google Analytics, will be described before it begins and consent will be requested where applicable.