This policy explains what personal data Imposted collects, why we collect it, who we share it with, and the choices and rights you have. We keep it in plain language on purpose.
Imposted is a tool for scheduling and cross-posting content to social networks and messaging platforms. The service is operated by Imposted, based in Denmark (“Imposted”, “we”, “us”).
For the personal data of people who sign up for and use Imposted (your account details, billing, analytics), we act as a data controller. For the content and connected-account data you put into the product so that we can publish on your behalf, we act as a data processor on your instructions — those terms are set out in our Data Processing Agreement.
When you register, we collect your name, email address, password (stored only as a salted hash), your workspace name, and preferences such as your timezone and clock format.
The posts, captions, media you upload, schedules, and drafts you create in the composer. We store these so we can preview and publish them at the times you choose.
When you connect a network (for example Slack), we store the access tokens and the identifiers needed to publish — workspace/account IDs, channel or page references, and the display names of those destinations. Access tokens are encrypted at rest. We only request the permissions needed to post on your behalf, and we never read your private messages or follower data beyond what is required to operate the connection.
We use PostHog for product analytics in a cookieless configuration: no advertising cookies, no cross-site tracking. It records pages viewed and in-product events (such as “signed up”) to help us understand how the product is used. Standard server logs (IP address, browser type, timestamps) are kept for security and debugging.
If you email us or contact support, we keep that correspondence so we can help you and keep a record.
Where the GDPR applies, we rely on: performance of a contract (to give you the service you signed up for); legitimate interests (to secure, maintain and improve the product, balanced against your rights); consent where we ask for it; and legal obligation where the law requires us to retain or disclose data.
We aim to run cookie-light. We use a strictly necessary cookie to keep you signed in. Our analytics (PostHog) is configured to be cookieless and does not build advertising profiles. We do not sell your data or share it with advertising networks.
Imposted acts on your behalf to publish to third-party platforms (such as Slack, and others as they become available). Those platforms are independent controllers of the data they hold about you and your audience, governed by their own privacy policies. When you ask us to publish, the content you scheduled is sent to the relevant platform’s API. You can disconnect any account at any time from the Connections page, which revokes our stored token.
We do not sell personal data. We share it only with service providers (“sub-processors”) that help us run Imposted, under contracts that require them to protect it and use it only on our instructions:
| Sub-processor | Purpose | Location |
|---|---|---|
| Laravel Cloud (Laravel LLC), on Amazon Web Services | Application hosting and managed database | European Union |
| Amazon Web Services EMEA | File and media storage (S3) | European Union |
| PostHog (Hiberly Inc.) | Cookieless product analytics | European Union (Frankfurt) |
We may also disclose data where required by law, to protect our rights or the safety of others, or as part of a merger or acquisition (in which case we will notify you).
We host Imposted and its data within the European Union. Where any provider processes data outside the EU/EEA, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
We keep account and content data for as long as your account is active. When you delete your workspace, we permanently remove its connections, posts, schedules and media — and if it was your only workspace, your user account is removed too. Backups and server logs are kept for a limited period and then rotated out. We may retain limited records where the law requires (for example, invoices).
We protect data with encryption in transit (TLS) and encryption of sensitive credentials at rest, access controls, and hosting on infrastructure with strong physical and operational security. No system is perfectly secure, but we work to keep your data safe and to respond quickly if something goes wrong.
Subject to applicable law, you can ask us to: access the personal data we hold about you; correct it; delete it; restrict or object to certain processing; and receive it in a portable format. You can also withdraw consent where we relied on it. Much of this you can do yourself in the app (editing your profile, deleting your workspace). To make a request, email [email protected]. If you’re in the EU/EEA and think we’ve mishandled your data, you may complain to your local supervisory authority.
Imposted is not directed to children and is not intended for anyone under 16. We do not knowingly collect data from children.
We may update this policy as the product evolves. When we make material changes we’ll update the “Last updated” date above and, where appropriate, let you know in the app or by email.
Questions about this policy or your data? Email us at [email protected].