Privacy Policy
In effect from 5 September 2026.
What Pollenstack stores, who else sees it, and how to get it deleted. There are no analytics scripts, no advertising pixels and no third-party trackers on this site, so most of the usual contents of a privacy policy do not apply and are not here.
Who is responsible
Ludovico Bessi, a sole proprietor established in Switzerland, is the controller of the personal data described here. Contact: support@pollenstack.com.
What we store
- Your email address, because sign-in is an emailed link and there is no password.
- Your timezone, so a post scheduled for 09:00 goes out at 09:00 where you are.
- Your posts — the text, any images you upload, when they are scheduled, and whether each platform accepted them.
- Your connected accounts — the platform, the display name, and the identifier our scheduling provider uses. Not your LinkedIn or X credentials; see below.
- Your voice examples — posts you have already published, retrieved from your connected accounts or pasted in by you, which is what the drafting imitates.
- Sources you hand the agent — a URL you paste, the readable text of the page it points at, or notes you type.
- A record of each drafting run — model, token counts and cost. Metadata for billing and debugging, not a copy of the draft.
- Delivery notifications from our scheduling provider, kept so the same notification arriving twice cannot be applied twice.
What we do not store
- No password. There is not one to leak.
- No LinkedIn or X access tokens. Connecting an account authorises PostPeer, and the tokens live there, not in our database.
- No card details. They go directly to our payment processor and never reach our servers.
- No tracking. One cookie, described below, and nothing else.
Cookies and local storage
One cookie: a signed session cookie that says you are signed in. It is strictly necessary for the service to work, so there is no consent banner to click through. Your light-or-dark preference is kept in your browser's local storage and never reaches us.
Who else sees your data
These are the only processors involved, and each one gets only what its job needs:
- Supabase — the database and the sign-in links. Holds everything listed above.
- PostPeer — schedules and publishes your posts, hosts the images attached to them, and holds the authorisation to your LinkedIn and X accounts. Receives post text, images and scheduling times.
- Google — the Gemini API, which writes the drafts. Receives your voice examples and the source material for the draft being written, for the length of that request. Google states that data sent to the paid Gemini API is not used to train its models. We do not train anything on your content, ever.
- Render — runs the application. Sees traffic in transit and keeps its own access logs.
- Our payment processor — your name, email, card details and billing history. We receive only the subscription status.
We do not sell personal data, and we do not share it with anyone not on this list except where the law requires it.
Where it is held
Data is stored on infrastructure operated by the providers listed above. Where it leaves Switzerland or the EEA, those transfers rely on those providers' standard contractual clauses. Email support@pollenstack.com for the current hosting regions and you will be told which ones they are.
Logs
Our application logs record a request identifier, the method and path, and the outcome of a request — not the contents of your posts, and never any API key. Our host keeps its own access logs, which include IP addresses, under its retention policy.
How long we keep it
For as long as you have an account. Ask us to delete it and everything belonging to you is removed within 30 days — posts, images, voice examples, sources, run records, and the account itself. Cancelled and published posts are kept while the account exists, because they are your record of what you published, not clutter for us to tidy away.
Deleting a Pollenstack account does not withdraw the authorisation you gave to LinkedIn or X. Revoke that in each platform's own settings.
Your rights
Under Swiss data protection law and, where it applies to you, the GDPR, you can ask for a copy of your data, ask for it to be corrected or deleted, ask for it in a portable form, object to a particular use, or withdraw consent. Email support@pollenstack.com and you will get an answer within 30 days. There is no charge and no form to fill in.
If you think we have handled your data badly, you can complain to the Swiss Federal Data Protection and Information Commissioner, or to the supervisory authority where you live. We would rather you told us first.
Changes
If this policy changes in a way that affects how your data is used, we will email you before the change takes effect. The date at the top always says which version you are reading.