Privacy
Postdate is operated by Armanac LLC. Armanac LLC is responsible for the personal data processing described in this policy.
How your content is protected
Your browser encrypts your text and files before upload, using a method called AES-256-GCM. Your device creates the key. You can write an optional public teaser. Prediction and reveal templates add a one-word public label. Matching wording typed or pasted into your draft can add the same label; review shows it before posting. We store your teaser and any label you keep without encryption. They can appear before your Postdate opens. The page explains this where you write the teaser. You see both during review and can remove the label.
For Standard messages, we hold the key and release it at your chosen opening time. We promise not to read your content before then. We can decrypt it early, but our policy forbids it.
Timelock encrypts the key using drand, a public network that releases random numbers. When we say "we can't see it early", we mean encryption prevents early access. This protects access through the link, assuming drand and the encryption remain secure. It cannot erase originals or keys retained by the sender.
What we store
For each message link, we store the encrypted data, opening time, expiry time, and key. For Timelock, that key is itself encrypted for a future drand release. We store your public teaser without encryption until expiry cleanup. It stops appearing on the Postdate page at expiry. We store any prediction or reveal label you keep the same way. The label lets the page suggest the matching template. Anyone with the link can see your teaser and label, including in link previews. We serve teaser preview images while the message exists, unless it is blocked for review. Servers near visitors keep temporary preview copies, sometimes until the message expires. We cannot control previews saved by other services.
An unfinished checkout retains its encrypted upload, key, settings, teaser, and label for up to four days. It also records whether you started from someone else's message page and, when available, a broad landing-page category, first landing language, and traffic-source category (search, X, Product Hunt, other referral, or unknown). Pending records expire after four days; scheduled cleanup removes abandoned large uploads. When the message is created, we count those categories in daily totals. We never store them on the finished message link or send them to Stripe.
Filenames are inside the encrypted data. We do not store filenames separately or inspect them.
We use hashing to turn IP addresses into codes. We use these codes to limit requests and handle abuse reports. Report records also hold a hashed network identifier and remain for 60 days. Hashes of encrypted uploads used to detect repeated uploads remain for 30 days. Our application stores these hashes rather than raw IP addresses. Cloudflare processes your IP address to serve requests and run the bot check.
When a message expires, we stop access. Scheduled cleanup removes expired keys and public fields; delays or outages can postpone cleanup. You can no longer open it through Postdate. Copies people already opened or saved remain. We keep a small record of the expired link for about 30 more days. This lets the page say "this expired" instead of "never existed". That record has no key.
We keep a small moderation record for links reported or removed for abuse. The record includes the link identifier, report counts, reasons, times, content type, and an approximate size range. Removed links also leave a persistent record so they stay marked as removed. It never includes the content, key, or raw IP address. We keep it as long as needed to handle abuse and legal requests.
Payments
Stripe processes payments for paid messages. Your full card number and security code go directly to Stripe. Our application does not receive them. Stripe sends checkout and payment information to our server, which can include an email address and billing details supplied at checkout. Our application uses payment status, amount, currency, and random references to confirm the purchase. It does not save a customer profile.
Our checkout requests do not send Stripe your Postdate link, content, or key. We send Stripe random references and match them to your link ourselves. One reference returns you to Postdate after payment. Scheduled cleanup deletes it after about five days. We keep the payment confirmation reference for about 45 days. This lets us match late confirmations to the right message and fix payment issues. Neither reference contains your content or key.
Cookies and analytics
To restore an unfinished draft, this browser saves your text, teaser, and settings locally without encryption. Attached files are not saved with the regular draft. When you choose another language while composing, your browser temporarily saves the complete draft, including attached files, on your device without encryption so the next page can restore it. We remove that temporary copy when it is read. An interrupted handoff is valid for five minutes; expired copies are removed the next time a language handoff is saved, or when you clear this site’s browser data. After a successful post, we clear the draft text. This tab also stores your sharing receipt and, for Standard, your private delete link. Clear this site’s browser data to remove locally saved information.
We use no third-party tracking analytics and set no tracking cookies. We keep daily totals for page entries, composer starts, checkouts, created links, paid creations, and grants, grouped by a small set of landing-page, first landing-language, and traffic-source categories. These totals contain no visitor identifiers, message links, content, filenames, full referring URLs, or search terms. Your tab keeps only these categories, an expiry time, and a start flag in session storage for a 30-minute measurement window; they are not used to identify you across tabs or visits. Browser measurement respects Do Not Track and Global Privacy Control. Server totals still count successful creations and checkouts, with missing attribution recorded as unknown. The create page uses Cloudflare Turnstile to block bots. Turnstile may set its own functional cookie during the check. See Cloudflare's privacy policy for details. Postdate runs on Cloudflare. Cloudflare processes requests to serve the site.
We recognize X and Product Hunt from the referring site or a recognized utm_source value in a shared link. Your browser reduces this information to a source category before measurement. Other query parameters are ignored by this measurement. Landing language describes the page, not your nationality or location.
Contact
Email privacy@postdate.io with privacy questions. Report abuse to abuse@postdate.io.