PRIVACY
Data exists to route work, prove effects and let the owner control the workspace.
PostSteward stores the minimum product state needed to authenticate the owner, delegate agent authority, route reviewed social publishing and preserve evidence of what happened.
Information PostSteward handles
- Owner identity: verified identity-provider subject and completion proof used to establish the workspace and owner session.
- Workspace content: projects, approved campaign text, schedules, automation profiles, source observations, receipts and related evidence.
- Social provider authority: account identity and encrypted provider access/refresh material when an owner connects a provider.
- Agent authority: hashed grant records, scopes, expiry and revocation state. Newly issued secret tokens are shown once.
- Billing state: PostSteward stores the identifiers and evidence needed to reconcile Stripe entitlement/payment state. Card/payment credentials remain with the payment provider.
- Optional GitHub source authority: selected-repository installation state and encrypted refreshable authority when private GitHub source access is connected.
- Operational evidence: bounded security, request, recovery and external-effect records needed to fail closed and investigate an operation.
Credentials and browser storage
Provider credential material is encrypted server-side. PostSteward does not intentionally put provider access tokens, refresh tokens or agent bearer tokens into browser local storage. Owner sessions use secure HTTP-only cookies and CSRF protection for browser mutations.
Do not place provider tokens, agent tokens, payment credentials or private source credentials in a campaign, prompt, repository document or support issue.
Export, retention and erasure
The owner Data surface supports workspace export before deletion, bounded retention archive/pruning and explicit workspace erasure. Exports exclude provider credentials and payment tokens. Some safety records, such as tombstones or duplicate/external-effect fences, may be deliberately retained where removing them could reactivate stale state or permit a duplicate external effect.
Provider-side authorisations can outlive PostSteward's local credential material until the owner or provider revokes them. Workspace deletion removes locally usable authority but cannot promise deletion of records independently retained by social, payment or source providers under their own policies.
Third-party services
PostSteward can interact with identity providers, social platforms, Stripe, GitHub and Cloudflare infrastructure. Those services process data under their own terms and policies. Provider API charges, access rules and retention are separate from PostSteward.
Questions or deletion requests
Use the in-product Data controls for export and workspace erasure. For product questions, use the support guidance. Include a bounded PostSteward reference ID when available, but never include secrets.