privacy policy
What we store. What we never see.
Effective 2026-07-07 · Treezy Technologies Inc ("PostWeavers", "we") · applies to the PostWeavers extension, PostWeaver Cloud, and postweavers.com
The short version: your feed lives in your browser, your API key never leaves your device, we collect no analytics in the extension, we don't sell or share data for advertising, and nothing is ever posted on your behalf. The long version follows, organized by where data lives.
1. Data that stays on your device (never sent to us)
- Posts you scroll past on X are parsed locally so the extension can show engagement badges, filter your feed, learn your voice, and give drafting context. They're stored in your browser's local storage (IndexedDB / extension storage) and go nowhere else. We have no server-side copy and no ability to read them.
- Your API key (bring-your-own-key mode) is stored in the extension's local storage and sent only to the provider you chose (Anthropic or OpenAI) directly from your browser, over TLS. It is never synced, never sent to our servers, never seen by us.
- Extension preferences (theme, feature toggles, thresholds) live in extension storage on your device.
2. Data synced to your account (only if you sign in)
Signing in with Google creates a Firebase account keyed to a user ID. We then sync your drafting settings (persona, learned voice profile, custom instructions, strategy preferences, model preferences) to Google Cloud Firestore so your other devices and the future mobile apps can share them. We also store your account email. Access is restricted by security rules so only your authenticated account can read your data. Your captured feed and your API key are explicitly excluded from sync.
3. Data processed when you draft with PostWeaver Cloud
- In Cloud mode, each draft request (the post you're replying to, the context you toggled on, your persona/voice settings, and your rough thought) passes through our backend (a Google Cloud Function) to Anthropic to generate the draft, then streams back to you.
- We keep per-day usage counters (number of drafts, token counts) tied to your user ID to enforce plan limits. We do not build an archive of your prompts or drafts on our servers.
- Anthropic processes these inputs as a service provider under its commercial API terms, which by default do not permit training on API data. In bring-your-own-key mode, none of this touches our servers. Your browser talks to your provider directly.
4. Billing data
Payments are handled entirely by Stripe. Your card number goes to Stripe, not to us. We store the subscription status, plan, period dates, Stripe customer/subscription identifiers, and the email you used at checkout, keyed to your account, so the Service knows your plan. Invoices and receipts are Stripe's records, available in the billing portal.
5. The website
postweavers.com is a static site hosted on Firebase Hosting behind Cloudflare. We run no analytics scripts, no ad pixels, and set no tracking cookies. Our infrastructure providers (Google, Cloudflare) generate standard server logs (IP address, user agent, requested URL) to operate and secure the service; we don't use them to profile you. Fonts load from Google Fonts, which receives the standard request metadata involved in serving a file.
6. Who we share data with (and who we don't)
We share personal data only with the processors needed to run the Service:
- Google (Firebase / Google Cloud): authentication, database, hosting, functions.
- Anthropic: Cloud-mode draft generation.
- Stripe: payments and subscription management.
- Cloudflare: DNS and network security for the website.
We do not sell personal data, share it for cross-context behavioral advertising, or give data brokers anything. We may disclose data if legally compelled (we'll challenge overbroad requests) or as part of a merger/acquisition, in which case this policy continues to apply and we'll notify you.
7. Retention
- Local data: yours; deleted when you clear it or uninstall the extension.
- Synced settings: kept while your account is active; deleted on request (see §9).
- Usage counters: operational records, kept up to 24 months for abuse prevention and accounting, then deleted or aggregated.
- Billing records: kept as long as tax and accounting law requires.
8. Security
All transport is TLS. Server-side data lives in Google Cloud with per-user security rules; our model API key lives in Google Secret Manager, never in client code; webhooks are signature-verified. No internet service can promise perfect security, but the architecture is deliberately minimal: the most sensitive things (your feed, your key) never leave your machine at all.
9. Your rights and controls
- Access / export / delete: email hello@postweavers.com from your account email and we'll provide or delete your synced data within 30 days. Local data you can wipe yourself by removing the extension.
- Cancel billing: self-serve in the billing portal; refunds per the Terms.
- EEA/UK (GDPR): you have rights of access, rectification, erasure, restriction, portability, and objection, and to lodge a complaint with your supervisory authority. Our lawful bases are contract performance (running the Service), legitimate interests (security, abuse prevention), and consent where required.
- California (CCPA/CPRA): you have rights to know, delete, correct, and opt out of sale/sharing. We don't sell or share personal information as those terms are defined, and we don't use sensitive personal information beyond providing the Service. We honor these rights regardless of where you live.
10. Children
The Service is not directed to children under 13, and we don't knowingly collect their data. If you believe a child under 13 has an account, email us and we'll delete it.
11. International transfers
Our infrastructure runs in the United States (Google Cloud, us-central1). If you use the Service from elsewhere, your data is processed in the US under our processors' standard safeguards (including Standard Contractual Clauses where applicable).
12. Changes to this policy
We'll post updates here with a new effective date. For material changes we'll give notice on the site (and by email or in-product notice for signed-in users) before they take effect.
13. Contact
Treezy Technologies Inc · hello@postweavers.com
Terms of Service · Usage Policy · ← Back to install