Privacy Policy
Last updated: August 24, 2026
This policy explains what MajesticPenguin LLC ("Postcone", "we", "us") does with personal information.
Read this part first
Postcone handles personal information in two different roles, and almost everything below depends on which one applies.
As a controller, for information about our customers — the people who sign up, log in, invite colleagues, and pay us. We decide how that is used, and this policy governs it.
As a processor, for the event data our customers send us about their users. We hold that on our customers' instructions and do not decide what it is for. If you are an end user of a company that uses Postcone and you want to know why your data is there, ask that company — their privacy policy governs, not ours. We will refer requests we receive about their data back to them.
Sections 2 to 6 are about the controller role. Section 7 is about the processor role.
1. Contact
Questions, or to exercise a right: privacy@postcone.com, or write to MajesticPenguin LLC, 1522 Western Ave STE 80544, Seattle, WA 98101.
2. What we collect about our customers
You give us:
- Account information — name, email address, password (stored hashed and salted, never in plain text).
- Google sign-in information, if you use it — your name, email address, and Google account identifier. We do not receive your Google password.
- Workspace information — workspace names, membership, roles, invitations.
- Billing information — billing contact and address. Card details go directly to Stripe; we never see or store full card numbers.
- Support correspondence — what you write to us and our replies.
We collect automatically:
- Service logs — IP address, timestamps, endpoints called, API key identifiers, request outcomes, user agent. We use these to run the Service, investigate faults, enforce rate limits, and detect abuse.
- Product usage — which features are used and how often, so we know what to build.
We do not run third-party advertising or analytics trackers in the application, and we do not sell personal information or share it for cross-context behavioural advertising.
3. Why we use it, and our legal bases
| Purpose | Legal basis (UK/EU GDPR) |
|---|---|
| Creating and running your account | Performance of a contract |
| Providing the Service and support | Performance of a contract |
| Billing, invoicing, collections | Performance of a contract; legal obligation |
| Security, abuse prevention, rate limiting | Legitimate interests — keeping the Service safe |
| Improving and debugging the Service | Legitimate interests — a service that works |
| Service announcements you cannot opt out of | Performance of a contract |
| Marketing email about our products | Consent, or legitimate interests where permitted; unsubscribe at any time |
| Responding to legal requests | Legal obligation |
4. Automated features and our model provider
Some features use a third-party large language model to suggest what your columns mean and which data views are worth building.
What is sent: the column name, summary statistics for that column, and a small number of example values taken from the table. Samples, not whole tables or rows. If a column contains personal information, example values from it are what gets sent.
What the provider may do with it: the provider does not train on our requests, fine-tune on them, or use them to improve its models. It does not retain request content beyond short-lived operational caching of up to 24 hours, after which the content is purged. The provider is named in our Sub-processor list.
Turning it off: a workspace owner can have LLM-assisted features disabled for a workspace, and then nothing from that workspace is sent to the model provider. Ask at support@postcone.com. A switch you can operate yourself is being built; until it ships, the request is the mechanism.
We do not use personal information to make decisions with legal or similarly significant effects about anyone.
We do not use Customer Data to train, fine-tune, or otherwise improve any machine-learning model — not our own, and not the model provider's. This is a term of our Terms of Service (§4.2), not a preference you have to find and switch off.
We do build models from two things that are not Customer Data, and we would rather say so than let you find out. The first is how the Service is used — which features and endpoints get called, how long queries take, what fails. The second is aggregate statistics computed across many customers, of the kind that describe a pattern rather than a person: how often a column named a certain way turns out to hold a certain kind of value. Neither identifies you, your users, or anyone else, and neither includes the contents of your tables or your queries. §4.3 of the Terms defines both and draws the line.
What the Service works out about your data — a column's type, its statistics, a suggested data view — is treated as your data, not ours. That matters here because analysing data first would otherwise be a way around the paragraph above.
5. Who we share it with
- Sub-processors — the service providers listed on our Sub-processor page, each under contract to process only on our instructions.
- Professional advisers — lawyers and accountants, under duties of confidence.
- Authorities — where we are legally required. We will tell you unless legally prohibited.
- A buyer — if we are acquired or merge, information may transfer. We will give notice before it becomes subject to a different policy.
We do not sell personal information.
6. Retention, security, transfers and rights
Retention
- Account information — while your account is open, then deleted or anonymised within 30 days of closure.
- Customer Data — see §7.
- Billing records — as long as tax and accounting law requires, typically seven years.
- Service logs — 90 days.
- Backups — data persists in backups until they age out on our normal cycle, after which it is unrecoverable.
Security
Encryption in transit and at rest; scoped API keys you can revoke; access limited to staff who need it; passwords hashed and salted. No system is perfectly secure, and we do not claim otherwise. Report a vulnerability to security@postcone.com.
If something goes wrong
If we discover a security incident affecting your personal information, we will tell you without undue delay. We will say what we know, what we do not know yet, which data was involved, what we have done about it, and what — if anything — you should do. If the law requires us to notify a regulator, we will, within the deadline it sets.
We would rather tell you early and be wrong about the scope than wait until we have a tidy account. Notice goes to the email on your account, so keep it current.
Where the affected data is Customer Data, we are the processor and you are the controller: we notify you, and you decide what your own users are told. Our Data Processing Agreement governs the timing and content of that notice.
International transfers
We are based in the United States and our sub-processors are largely in the United States. Where we transfer personal information out of the UK or EEA we rely on the European Commission's Standard Contractual Clauses, with the UK Addendum or IDTA as applicable. Ask at privacy@postcone.com for a copy of the safeguards.
Your rights
Depending on where you live you may have the right to access, correct, delete, port, restrict, or object to our processing, and to withdraw consent. To exercise any of these, email privacy@postcone.com. We will verify who you are and respond within the time the law allows — one month under UK/EU GDPR, 45 days under California law, each extendable where permitted.
We will not treat you differently for exercising a privacy right.
If you are in the UK or EEA you may complain to your data protection authority; in the UK that is the Information Commissioner's Office.
If you are in California, the CCPA as amended by the CPRA gives you rights to know, delete, correct, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined, so there is nothing to opt out of. Over the past twelve months we have collected the categories described in §2 — identifiers, customer records, commercial information, and internet activity — for the purposes in §3, and disclosed them for business purposes only to the sub-processors in §5. We do not knowingly collect personal information from anyone under 16.
If you are in another US state with a privacy law — Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and a growing list of others — you have broadly the same rights to know, correct, delete, and obtain a copy of your personal information, and to appeal if we refuse a request. Rather than track which right your state grants this year, we extend all of them to everyone: email privacy@postcone.com and we will honour the request. If we decline, we will tell you why and how to appeal, and you may also complain to your state attorney general.
We do not sell personal information or use it for targeted advertising under any of these laws, and we do not process it for profiling that produces legal or similarly significant effects. Several of these laws also require us to honour an opt-out preference signal such as Global Privacy Control. There is nothing for such a signal to switch off here, because we do not sell or share personal information in the first place.
7. Customer Data — where we are a processor
When our customers send us event data about their users, they are the controller and we are the processor. They decide what to send and why; we act on their instructions.
- We process it only to provide the Service to them, as set out in our Terms of Service and our Data Processing Agreement.
- We do not sell it, share it with other customers, or use it for our own purposes beyond running and securing the Service.
- Retention is controlled by the customer. After account termination it is available for export for 30 days and then deleted.
- Sub-processors that touch it are marked as such on the Sub-processor page, including our model provider (§4).
If you are an end user of a company that uses Postcone: we have no direct relationship with you and generally cannot identify you within a customer's data. Please direct access or deletion requests to that company. If you contact us, we will pass the request on and support them in answering it.
Business customers who need a Data Processing Agreement can read ours at postcone.com/dpa — it is the Bonterms standard form, incorporated unmodified. Write to privacy@postcone.com to have it signed.
8. Cookies
We use cookies and equivalent local storage that are strictly necessary: keeping you signed in, remembering your theme, and security. We do not use advertising or cross-site tracking cookies, so there is no consent banner. Blocking these will break sign-in.
9. Children
Postcone is a business service, not directed to children, and we do not knowingly collect information from anyone under 18. If you believe a child has given us information, write to privacy@postcone.com and we will delete it.
10. Changes
We will post revisions here and update the date above. For material changes we will give notice by email or in the application before they take effect.