Who is responsible
The company below decides how and why your personal data is used for WhichPost (the "controller" under the GDPR). "We" on this page means this company.
- Company name
- Simplified AI Solutions Kft.
- Registered office
- 1119 Budapest, Etele út 31. 1. em. 4. ajtó
Węgry
Registration and tax details are in the legal notice.
What we keep and why
We keep only what WhichPost needs to work, to stay secure and to improve. For each kind of data, here is what it is, why we use it, the legal basis and how long we keep it.
Your account
- What
- Your email address, your language, when you joined and last signed in, and the version of our terms you accepted. Your sign-in sessions are stored only as scrambled codes (hashes), never in readable form.
- Why
- To sign you in with an emailed link, keep your workspaces private, and send you the emails you ask for.
- Legal basis
- To provide the service you asked for (contract, GDPR Art. 6(1)(b))
- How long
- Until you delete your account. A sign-in link works once, for 15 minutes. A session ends after 14 days without a visit, and after 60 days in any case.
Your workspace data
- What
- What you upload or connect: post lists and CSV files (links, posting times, views, payouts), installs, sign-ups, purchases and revenue, and the reports and share links made from them.
- Why
- To measure which posts brought sign-ups, installs and paying users, and to show you the results.
- Legal basis
- To provide the service you asked for (contract, GDPR Art. 6(1)(b))
- How long
- Until you delete the workspace or your account.
This data can include information about your own customers, such as purchase records. For that data you decide what is uploaded or connected, and we use it only to provide WhichPost to you.
Keys to services you connect
- What
- The keys you give us for Stripe (restricted, read-only), RevenueCat or Superwall, and the data we read with them, such as purchases, subscriptions and revenue.
- Why
- To import your data and keep your results up to date. Read-only keys can't change anything in your accounts. Full Stripe secret keys are refused.
- Legal basis
- To provide the service you asked for (contract, GDPR Art. 6(1)(b))
- How long
- Until you disconnect the service or delete the workspace. Keys are stored encrypted and are never shown again after you save them.
Free tools without an account
- What
- The files you upload to the free post analyzer or the install-source check, and the report made from them. For the bought views check: the post link you paste and the public counts we read from it (views, likes, comments), kept for up to 7 days and then deleted.
- Why
- To give you the result you asked for, and to let the same browser open its report again.
- Legal basis
- To provide the service you asked for (contract, GDPR Art. 6(1)(b))
- How long
- Reports made without an account are deleted automatically 7 days after they were made, together with their files and any share links; copies in our backups are gone within 12 weeks after that. The cookie that lets your browser reopen its reports lasts 30 days, but the reports themselves are gone after 7. Ask us and we'll delete yours sooner. If you sign in within those 7 days, the reports this browser made become part of your account: they're kept until you delete your account, and deleted with it.
Feedback and the idea board
- What
- Your message and answers, the page you sent it from, your language, the version of WhichPost that served the page, the kind of device (phone, tablet or desktop) and, if you ask for a reply, your email. Votes on the idea board are linked to your account. To prevent abuse we keep a scrambled code made from your IP address (a hash), never the address itself.
- Why
- To improve WhichPost, to answer you, and to keep spam and abuse out.
- Legal basis
- Our legitimate interests (GDPR Art. 6(1)(f))
- How long
- Messages: 24 months. Reply emails: 12 months after our last exchange, or until you ask. The IP code: 30 days. Spam: 30 days. Your IP address itself is held only in memory, for up to 24 hours, to limit abuse. When you delete your account, your votes are removed and your messages are no longer linked to you.
How we measure the site
- What
- For each request: the page, the time, whether it worked, the site that linked to it, campaign tags in the link (utm), your country (from our network provider, Cloudflare), and your browser type and device class. On public pages, a small script of our own notes which parts of the page were on screen and for how long, how far you scrolled, and which of our buttons and links you used; it never records what you type. We don't store your IP address: we turn it, with your browser type, into a code with a random key that changes every day and is then deleted, so we can count a visitor once a day but can't recognise you on another day. If your browser sends Do Not Track or Global Privacy Control, we only count the page view, without the code or the script.
- Why
- To see which pages and sections people read, where visitors come from, how much traffic is automated, and to keep the site running and secure.
- Legal basis
- Our legitimate interests (GDPR Art. 6(1)(f))
- How long
- Request log: 90 days. Reading data: 180 days. After that only daily totals without any code are kept. You can object at any time by turning on Global Privacy Control or Do Not Track, or by writing to us.
Quotes and testimonials
- What
- If you agree to be quoted, the text, name and details you confirm, and a record of your agreement.
- Why
- To show what customers say about WhichPost, only with your permission.
- Legal basis
- Your consent (GDPR Art. 6(1)(a)), which you can withdraw at any time
- How long
- While the quote is published, for up to 24 months. You can withdraw at any time with one click; withdrawn or expired quotes are erased within 30 days.
The waitlist
- What
- Your email and, if you share them, your product's name, your monthly creator spend and a note.
- Why
- To tell you when WhichPost opens for you.
- Legal basis
- Your consent (GDPR Art. 6(1)(a)), which you can withdraw at any time
- How long
- Until you ask us to remove it.
Emails we send to businesses
- What
- We sometimes email people at agencies and app companies that publicly run creator or clipping campaigns, to offer WhichPost. We hold your name, the business email address you or your company published for contact, your role, your company or app, the public facts about your campaign that we mentioned, the dates we wrote and anything you replied.
- Why
- To offer a business service relevant to your role. Where your country's law requires consent before a business email, we don't email you without it.
- Legal basis
- Our legitimate interests (GDPR Art. 6(1)(f))
- How long
- 6 months after our last email if you don't reply. If you ask us to stop, we keep only your email address on a do-not-contact list, so that we never email you again.
Where it came from: your company's or app's own website, its App Store or Google Play developer page, or a public campaign page. We note the source page with your record.
You can object at any time, free of charge: reply "no" or write to support@whichpost.app, and we'll stop immediately. You also have the rights listed below.
Billing records
- What
- When paid plans open: the plan you buy, invoices and the billing details the law requires on them. We never see or store full card numbers.
- Why
- To bill you and to meet accounting and tax rules.
- Legal basis
- A legal obligation (GDPR Art. 6(1)(c)), and our contract with you (GDPR Art. 6(1)(b))
- How long
- For as long as accounting and tax law requires.
Where data is stored
While WhichPost is being built, it runs on our own computers. Before launch we'll name where your data is stored and, if any of it leaves the European Economic Area, the safeguards that protect it.
How we protect it
Keys to connected services are encrypted at rest. Sign-in links and sessions are stored only as hashes. Reports are private to your workspace; share links expire and can be revoked. Pages with private data are never stored by caches. Only the people who run WhichPost can reach the data, and only to provide and protect the service.
Your rights
Under the GDPR you have these rights over your personal data:
- See it: ask for a copy of what we hold about you.
- Correct it: fix anything that's wrong.
- Delete it: delete your account on your account page. This removes your account, sessions and memberships, the workspaces you alone own with their keys, reports and share links, and the reports you made with the free tools. Your feedback messages are no longer linked to you.
- Take it with you: get the data you gave us in a common, machine-readable format.
- Object: object to uses based on our legitimate interests.
- Restrict: ask us to pause using it while a question is settled.
- Withdraw consent: where we rely on your consent, withdraw it at any time. This doesn't affect what happened before.
To use any of these rights, write to support@whichpost.app. We answer within one month.
You can also complain to a data protection authority. Ours is the Hungarian National Authority for Data Protection and Freedom of Information (NAIH), naih.hu. You can also contact the authority where you live or work.
Automated decisions
We don't make decisions about people that have legal or similarly significant effects on them. Our models measure campaigns and posts, not individuals.
Children
WhichPost is a service for businesses. It isn't meant for anyone under 18, and we don't knowingly keep data about children.
Changes to this policy
When we change this policy we update the version and date at the top of this page. If a change affects how we use your data, we'll tell you by email or in WhichPost before it takes effect.
Contact
Questions about privacy: support@whichpost.app.