Contents
- 1. Controller and Data Protection Officer (DPO)
- 2. Data we collect
- 3. How we use data and legal bases
- 4. Artificial Intelligence
- 5. Sharing and processors (sub-processors)
- 6. International data transfers
- 7. Your rights as a data subject
- 8. Cookies
- 9. Processor on behalf of customers
- 10. Retention and deletion
- 11. Security
- 12. Children and adolescents
- 13. Changes to this Policy
- 14. Contact
Privacy Policy
Last updated: June 24, 2026 · Effective date: June 24, 2026
This Privacy Policy explains how Gawry & Co Servicos LTDA, a Brazilian limited liability company (sociedade empresária limitada) registered under CNPJ No. 10.548.738/0001-41, with registered office at Rua Leopoldo, 446, Andaraí, Rio de Janeiro - RJ, CEP 20541-170 (“PostFrames”, “we”, or “us”), collects, uses, shares, and protects personal data when you use PostFrames, our social-media post creation platform, available at postframes.co, postframes.io, and related applications (the “Service”).
We process personal data in accordance with Brazil’s General Data Protection Law (Lei nº 13.709/2018, “LGPD”), the Brazilian Internet Civil Framework (Lei nº 12.965/2014), and the Consumer Defense Code (Lei nº 8.078/1990), where applicable.
By using the Service, you acknowledge that you have read and understood this Policy. Capitalized terms not defined here have the meaning given in our Terms of Use.
1. Controller and Data Protection Officer (DPO)
Data controller: Gawry & Co Servicos LTDA, CNPJ 10.548.738/0001-41, Rua Leopoldo, 446, Andaraí, Rio de Janeiro - RJ, CEP 20541-170.
For most data we collect, we act as controller. When you use the Service to process third-party personal data within your own content (for example, by uploading client images), you are the controller of that data and PostFrames acts as processor, as described in Section 9 and, where applicable, a Data Processing Addendum.
Data Protection Officer (DPO / “Encarregado”): Gustavo Gawryszewski DPO contact: dpo@postframes.co.
2. Data we collect
2.1. Data you provide
- Sign-up and account: name, email address, and password (stored hashed). Optionally, a profile photo/avatar.
- Social login: if you sign in with Google, we receive your name, email, and account identifier from Google, per the permissions you grant.
- Workspace (organization): organization name, invited members, roles (owner, admin, member), and collaboration data.
- User Content: prompts, brand specifications (colors, fonts, logos, your brand “DESIGN.md”), images and media you upload, and the posts, carousels, stories, and captions you generate.
- Payment: when you subscribe to a paid plan, card data is collected and processed directly by Stripe (we do not store full card numbers). We receive billing data from Stripe such as name, billing email, country, last 4 digits, transaction status, and subscription identifiers.
- Communications: messages you send to support, survey responses, and emails.
2.2. Data collected automatically
- Usage and log data: IP address, access date/time, pages and features used, actions in the Service, session identifiers. Access-log retention complies with the Internet Civil Framework.
- Device and browser data: browser type, operating system, language, display settings.
- Cookies and similar technologies: see Section 8 and our Cookie Policy.
2.3. Third-party data
We may receive data from identity providers (Google), the payment processor (Stripe), and analytics tools, always limited to what is needed to operate the Service.
We do not intentionally collect sensitive personal data (LGPD art. 11). Please do not include sensitive data in prompts or content unless strictly necessary and at your own responsibility.
3. How we use data and legal bases
We process personal data for the purposes below, each grounded in an LGPD legal basis (arts. 7 and 11):
| Purpose | Legal basis (LGPD) |
|---|---|
| Create and maintain your account; operate and provide the Service; generate your posts | Performance of a contract (art. 7, V) |
| Process payments, subscriptions, and billing fraud prevention | Performance of a contract (art. 7, V); legal obligation (art. 7, II) |
| Send operational communications (security, billing, Service changes) | Performance of a contract (art. 7, V); legitimate interest (art. 7, IX) |
| Ensure security, prevent fraud and abuse, and keep access logs | Legitimate interest (art. 7, IX); legal obligation (art. 7, II, Internet Civil Framework) |
| Improve and develop the Service (aggregate analytics and metrics) | Legitimate interest (art. 7, IX) |
| Send marketing communications about PostFrames | Consent (art. 7, I) or legitimate interest, with opt-out |
| Comply with legal/regulatory obligations and authority orders | Legal obligation (art. 7, II); exercise of rights (art. 7, VI) |
| Non-essential cookies (analytics, preferences) | Consent (art. 7, I) |
You may object to legitimate-interest processing and withdraw consent at any time (Section 7).
4. Artificial Intelligence
PostFrames uses third-party AI models to generate and refine posts, images, and captions. To do so, we send those providers the content needed (your prompts, brand specifications, uploaded media, and generation parameters) solely to produce the result you requested.
- We do not use your User Content to train AI models, and the AI providers we use do not use your content to train their models.
- Provider retention: for open models routed via OpenRouter, we enable Zero Data Retention (content is not retained). OpenAI, Anthropic, and Google may retain logs temporarily (e.g., for safety and abuse prevention), without using them for training.
- AI generation may produce inaccurate, generic, or unexpected results; you are responsible for reviewing content before publishing it (see Terms of Use).
- AI providers act as processors/sub-processors and are listed in Section 5.
5. Sharing and processors (sub-processors)
We do not sell your personal data. We share data only with providers that help us operate the Service, as needed and under contractual security and confidentiality obligations. Categories and main processors:
| Processor | Purpose | Location |
|---|---|---|
| Stripe | Payment and subscription processing | US / global |
| OpenAI | Image (gpt-image-1) and text generation | US |
| Anthropic | Text generation/authoring (Claude) | US |
| Text/image generation (Gemini/Vertex); social login | US / global | |
| OpenRouter | Routing to open models (Zero Data Retention), including providers such as Cerebras and Groq | US / global |
| Cloudflare | CDN, security, attack mitigation | Global |
| IONOS | Server hosting and storage | US (US data center) |
| Resend | Transactional email (verification, magic link) | Brazil (São Paulo) |
| PostHog | Product (Studio) usage analytics | EU (Germany) |
| Google Analytics | Website (marketing) usage analytics | US / global |
We may also share data: (i) with authorities under a lawful order; (ii) to exercise or defend rights; (iii) in a corporate reorganization, merger, or acquisition, maintaining data protection; and (iv) with your consent.
Organization-managed accounts: if you sign up with an organization email or are invited to a workspace, the organization’s owner/admin may access account data and content associated with that workspace.
6. International data transfers
Several processors are located outside Brazil (for example, in the United States). Your data may therefore be transferred and processed abroad, subject to Chapter V of the LGPD (art. 33). We adopt safeguards such as standard contractual clauses, assessment of country adequacy/ANPD decisions, or other legally provided guarantees, and, where applicable, your specific consent, to ensure a level of protection consistent with the LGPD. In particular, the application is hosted in a US data center (IONOS), and providers such as Stripe, OpenAI, Anthropic, and Google may also process data in the US, and PostHog in the European Union.
7. Your rights as a data subject
Under LGPD art. 18, you may, at any time and free of charge:
- Confirm that we process your data;
- Access your data;
- Correct incomplete, inaccurate, or outdated data;
- Request anonymization, blocking, or deletion of unnecessary, excessive, or non-compliant data;
- Request data portability to another provider;
- Request deletion of data processed based on consent;
- Obtain information about entities with which we share data;
- Be informed about the possibility of not consenting and the consequences;
- Withdraw consent.
To exercise your rights, write to dpo@postframes.co. We may request information to verify your identity. We will respond within statutory deadlines. Some requests may be limited by legal obligations (e.g., log retention) or third-party rights.
You may also file a complaint with the Brazilian Data Protection Authority (ANPD), www.gov.br/anpd.
8. Cookies
We use essential cookies (for authentication and Service operation) and non-essential cookies (preferences and analytics), the latter subject to your consent. For details and how to manage them, see our Cookie Policy.
9. Processor on behalf of customers
When you use the Service to process third-party personal data (e.g., client images in your posts), you are the controller and PostFrames acts as processor, handling that data only per your instructions and to provide the Service. For business customers, this may be governed by a Data Processing Addendum (DPA); contact dpo@postframes.co.
10. Retention and deletion
We retain personal data for as long as needed for the purposes in this Policy and to comply with legal obligations:
- Account and content data: while your account is active. After closure, we delete or anonymize it within a commercially reasonable period, unless legally required to retain it.
- Application/connection access logs: for the periods required by the Internet Civil Framework.
- Tax and payment data: for the periods required by tax and civil law.
- Backups: may retain copies for a limited period before being overwritten.
11. Security
We adopt technical and administrative measures to protect data (LGPD art. 46), including encryption in transit, password hashing, access control, per-organization (tenant) isolation, and monitoring. No system is fully immune to incidents; in the event of a relevant security incident, we will notify data subjects and the ANPD as required by law.
12. Children and adolescents
The Service is intended for users 18 or older and for professional/business use. We do not knowingly collect data from children or adolescents. If we become aware of such collection without a proper legal basis, we will delete the data.
13. Changes to this Policy
We may update this Policy to reflect legal or Service changes. Material changes will be communicated by email and/or notice in the Service, and the “Last updated” date will be revised. Continued use after the changes take effect constitutes agreement.
14. Contact
Privacy questions, requests, or complaints: Email: dpo@postframes.co DPO: Gustavo Gawryszewski