NewDepost AI 2 is live 🎉Read the update

Privacy Policy

Last updated: September 13, 2026

1. Who we are

Depost AI is operated by Remoteen ("Remoteen", "we", "us" or "our"), a company based at 4th Floor, 37 Civic Center, Block M, Model Town Extension, Lahore, Pakistan. This policy explains what personal data we collect when you use the Depost AI website, the application at app.depost.ai, the MCP connector and API, and any optional browser extension we publish (together, the "Service"), what we do with it, and the choices you have.

For the data you give us when you create an account and use the Service, Remoteen is the data controller. If you use Depost AI as an agency or a team to manage content for clients, you are the controller of your clients' data and we process it on your behalf; see section 9.

Questions about this policy go to support@depost.ai.

2. The short version

  • We collect what we need to run the Service: your account details, the LinkedIn data you connect, the content you create, and how you use the app.
  • Your content is processed by AI providers to generate drafts and analysis. They do not use it to train their models. Nobody else sees it.
  • Your data is hosted in the United States, on Amazon Web Services, with Cloudflare in front.
  • We never see or store your LinkedIn password.
  • We keep your data for as long as your account exists. When you delete your account, everything is deleted from our live systems straight away, and from backups within 30 days.
  • We do not sell your data and we do not share it with advertisers.

3. What we collect

Account data. Your name, email address, password (stored as a hash, never in plain text) and, if you sign in with Google, LinkedIn, Microsoft or X, the name, email and profile picture that provider shares with us. If you are on a team plan, the workspace name and the roles of its members.

Connected LinkedIn data. When you connect a LinkedIn account we read, with your authorisation, the profile details, posts, and performance data of that account, such as impressions, reactions, comments and follower counts, and we keep syncing them so your analytics stay current. We read only the account you connect. We never receive your LinkedIn password, and we do not store LinkedIn session cookies or tokens on our servers beyond the access token LinkedIn issues for publishing.

Your content. Everything you create or add in the Service: brand profile and voice settings, ideas, drafts, scheduled and published posts, graphics, chat conversations with the Service, documents and links you add as knowledge, and the notes and memory the Service builds up about your brand over time.

Billing data. Your plan, invoices and payment status. Card details are entered directly with Paddle, our payment provider, and never reach us. We receive the last four digits and the card type for display.

Usage data. How you use the Service: pages and features used, actions taken, the browser and device you use, your IP address and approximate location, and error reports if something goes wrong. Some of this comes from cookies; see our Cookies Policy.

Support and correspondence. What you send us by email or through the support chat, so we can help you.

4. How we use it

  • To run the Service: generate drafts and ideas, analyse your performance, publish and schedule posts, and keep your brand memory up to date.
  • To run your account: sign you in, bill you through Paddle, and send you transactional email such as receipts, security notices and scheduled-post confirmations.
  • To help you: answer support requests and investigate problems you report.
  • To improve the Service: understand which features are used, and find and fix errors.
  • To tell you about Depost AI: product updates and occasional marketing email, which you can stop at any time with the unsubscribe link in every message.
  • To keep the Service safe: detect abuse, enforce our Terms, and meet our legal obligations.

If you are in the EEA or the UK, section 13 sets out the legal basis for each of these purposes.

We do not make decisions about you by automated means that have legal or similarly significant effects.

5. AI providers

Depost AI is built on large language and image models from third-party providers. To generate a draft, an idea, an analysis or a graphic, the relevant content is sent to one of these providers and the result is sent back to you. The providers we use are Google, OpenAI, Perplexity and Anthropic. Which one handles a given request depends on the feature.

We use these providers through their business APIs, under terms that do not allow them to use your content to train their models. They process your content only to return a result to us. We do not use your content to train models either.

6. Where your data is stored

Depost AI is hosted on Amazon Web Services in the United States. Cloudflare, a US company, provides our content delivery network, security layer and file storage. Our AI providers are US companies and process requests in the US. If you use the Service from outside the United States, your data is transferred to and processed in the United States; see section 12.

7. Who we share it with

We share personal data only with the service providers below, who process it on our behalf and under our instructions, and only to the extent needed for the purpose listed. We do not sell personal data, and we do not share it with advertisers or data brokers.

ProviderPurposeCountryPrivacy
Amazon Web ServicesHosting, storage and emailUnited Statesaws.amazon.com/privacy
CloudflareContent delivery, security, file storage and the free toolsUnited Statescloudflare.com/privacypolicy
GoogleAI models, sign in with Google, website analyticsUnited Statespolicies.google.com/privacy
OpenAIAI modelsUnited Statesopenai.com/policies/privacy-policy
PerplexityAI web researchUnited Statesperplexity.ai/hub/legal/privacy-policy
AnthropicAI modelsUnited Statesanthropic.com/privacy
PaddlePayments, invoicing and sales tax, as Merchant of RecordUnited Kingdom and United Statespaddle.com/legal/privacy
SentryError and performance monitoring. Receives technical error reports, not your contentUnited Statessentry.io/privacy
CrispSupport chat, when you open itFrancecrisp.chat/en/privacy
LinkedInThe platform you connect. Receives the posts you publish and the authorisation you grantUnited Stateslinkedin.com/legal/privacy-policy

List current as of September 13, 2026. If we add a provider that will process your content, we will update this table before it starts and, for account holders, tell you by email.

We may also disclose personal data if the law requires it, to respond to a valid request from a public authority, to protect the rights, safety or property of Depost AI or its users, or as part of a merger, acquisition or sale of the business, in which case we will tell you before your data becomes subject to a different policy.

8. Connected accounts and the MCP connector

Connecting LinkedIn. You connect LinkedIn by authorising Depost AI through LinkedIn's own sign-in. LinkedIn gives us a token that lets us publish for you and read your data; it does not give us your password, and you can revoke it at any time from LinkedIn's settings or by disconnecting the account in Depost AI. The Service drafts content; it publishes only when you publish or at the time you schedule, and it sends comments or messages only when you send them.

MCP connector and API keys. If you connect an AI client such as Claude or ChatGPT to Depost AI, you create a key in your account and give it to that client. When the client asks, the connector returns the data the key's scopes allow, such as brand context, content and analytics, and it saves back what you tell the client to save, such as a draft. A brand key can only reach that brand's workspace; a workspace key can reach the brands your role allows. We do not push data to your AI client, and we do not receive your conversations with it. What the client's provider does with the data it retrieves is governed by their privacy policy. Keys are stored securely, and every use is checked against your current role. Revoking a key takes effect immediately.

9. Workspaces, brands and roles

Depost AI organises content into brands, and brands into workspaces. In a workspace:

  • Owners and admins can see and manage every brand in the workspace, including brands marked private, and can see who is a member and what they do in the workspace.
  • Members can see only the brands they have been added to, with the role they were given there.
  • Deleting a brand deletes that brand's posts, drafts, ideas, analytics, brand memory, knowledge, media, connected accounts and API keys.
  • Removing a member ends their access immediately and disables their API keys. Content they created stays with the brand, because it belongs to the brand, not the member.
  • Deleting a workspace deletes every brand in it, with everything listed above.

If you are an agency or a team managing a client's brand, you are the data controller for the client's content and for any personal data in it. We process it on your behalf, as your processor, under these terms and our Terms of Service. It is your responsibility to have the client's permission and to tell them how their data is handled. We will not access a client's brand except to provide the Service, to help you when you ask, or where the law requires it.

10. How long we keep your data

We keep your data for as long as your account exists, so that your history, analytics and brand memory keep working for you. We do not delete content from an active account on a timer; you can delete any brand, post, idea, document or conversation yourself at any time.

When you delete your account, we delete the account and everything in it: your profile, every brand and workspace you own, posts, drafts, ideas, analytics, brand memory, knowledge, media, chat history, connected accounts and API keys, and we instruct our service providers to delete the copies they hold to run the Service for you. This happens on our live systems straight away, so export anything you want to keep first. Encrypted backups that still contain your data expire within 30 days; they exist to restore the Service after a failure and are never used to bring a deleted account back.

Two exceptions: invoices and payment records are kept by Paddle for as long as tax law requires, and technical logs and error reports, which contain no content, are kept for a limited period for security and debugging and then deleted.

To delete your account, email support@depost.ai from your account email address. If you are a member of someone else's workspace, deleting your account removes you from it; the workspace and its content stay with the owner.

11. Your rights

Wherever you are, you can:

  • Access and correct your account data, from your account settings or by asking us.
  • Export your content. Ask us and we will send you a copy of your posts, analytics, ideas and brand memory in a structured, machine-readable format within 30 days.
  • Delete your account and everything in it, as described in section 10.
  • Stop marketing email with the unsubscribe link in any message, or by asking us. Transactional email about your account continues while you have one.
  • Object to or restrict processing based on our legitimate interests, and withdraw consent where we rely on it.

To use any of these rights, email support@depost.ai. We may ask you to confirm that you control the account. We answer within one month. If you are in the EEA or the UK, section 13 sets out your rights under the GDPR and the UK GDPR, including the right to lodge a complaint with a supervisory authority.

If your data is in a workspace controlled by an agency or a team, please contact them first, as they decide what happens to it. We will help them respond.

12. International transfers

We are based in Pakistan and our Service is hosted in the United States, so your data is transferred to and processed in those countries, and by the providers in section 7. Where the law that applies to you requires safeguards for such transfers, such as for data from the EEA or the UK, we rely on standard contractual clauses with our providers and on the safeguards those providers have in place, such as the EU-US Data Privacy Framework where a provider is certified under it.

13. GDPR and UK GDPR

If you are in the European Economic Area or the United Kingdom, the EU General Data Protection Regulation and the UK GDPR apply to how we handle your personal data, even though we are based outside those regions. This section brings together what those laws require us to tell you.

Controller. Remoteen, at the address in section 1, is the controller for the personal data of account holders and website visitors. We have not appointed a data protection officer. All data protection questions and requests go to support@depost.ai.

Processor. Where an agency or a team uses Depost AI to manage a client's content, that customer is the controller of the client's data and we are their processor, as described in section 9. We offer a data processing agreement covering the Article 28 terms; email us to request it.

Legal basis for each purpose.

What we doLegal basis
Create and run your account, provide the Service, bill you, send transactional emailPerformance of our contract with you (Article 6(1)(b))
Generate drafts, ideas, analysis and graphics from the data you connect and the content you createPerformance of our contract with you
Answer support requestsPerformance of our contract with you
Understand how the Service is used, improve it, find and fix errorsOur legitimate interest in running and improving a product our customers rely on (Article 6(1)(f))
Keep the Service secure, prevent abuse, enforce our TermsOur legitimate interest in protecting the Service and its users; legal obligation where the law requires it
Email existing customers about Depost AI product updates and offersOur legitimate interest in telling customers about the product they use, with an opt-out in every email; your consent where local law requires it
Analytics cookies on our website and appYour consent (Article 6(1)(a)), which you can withdraw as described in the Cookies Policy
Comply with law and respond to valid requests from authoritiesLegal obligation (Article 6(1)(c))

Data you have to provide. A name, an email address and a password, or a sign-in provider in place of the password, are needed to create an account; without them we cannot provide the Service. Everything else you add is your choice, and the Service works with less.

Your rights. You have the right to access your personal data, to have it corrected or erased, to restrict or object to its processing, to receive it in a portable format, to object to direct marketing at any time, and to withdraw consent without affecting processing that happened before you withdrew it. How to use these rights is in section 11. We respond within one month; for complex requests we may take up to two further months, and we will tell you if we need the extra time. We do not charge for requests unless they are manifestly unfounded or excessive.

Complaints. You have the right to lodge a complaint with a supervisory authority, in particular in the EEA or UK country where you live or work. We would welcome the chance to resolve any concern first, so please contact us before you do.

Transfers. We are in Pakistan and our service providers are in the United States and the United Kingdom. Neither Pakistan nor the United States has a general adequacy decision, so we rely on the safeguards in section 12: standard contractual clauses with our providers, the EU-US and UK-US Data Privacy Framework where a provider is certified under it, and the security measures in section 14.

Automated decisions. We do not make decisions about you by automated means that have legal or similarly significant effects.

14. Security

All traffic to the Service is encrypted in transit, and stored data is encrypted at rest. Passwords and API keys are never stored in plain text. Access to production systems is limited to the people who need it to run the Service. Our AI providers and other processors are bound by contract to protect your data. No system is perfectly secure, so if you believe your account has been accessed without permission, tell us at once at support@depost.ai. If we discover a breach affecting your personal data, we will tell you without undue delay.

15. Cookies

We use a small number of cookies to keep you signed in, remember your settings, run the support chat, and understand how the website is used. Details, including how to opt out of analytics, are in our Cookies Policy.

16. Children

The Service is for people aged 18 and over. We do not knowingly collect personal data from anyone younger. If you believe a child has given us personal data, contact us and we will delete it.

17. Changes to this policy

We will update this policy when the Service or the law changes. The date at the top shows the current version. If a change materially affects how we use your data, we will email account holders before it takes effect.

18. Contact

  • Email: support@depost.ai
  • Post: Remoteen, 4th Floor, 37 Civic Center, Block M, Model Town Extension, Lahore, Pakistan