Privacy policy
How AnyPoster, operated by the operator of this service, handles personal data.
Last updated 9 October 2026
Who is responsible
the operator of this service, calle montano 4, 29012, Malaga, Spain, operates AnyPoster. Contact for anything in this policy: info@builtwithskills.com. We have not appointed a data protection officer because the law does not require one for our size and activity; write to the same address for any data protection matter.
Two roles. For your account (you, or the people on your team), we decide how the data is used, so we are the controller. For your customers' messages, when a business uses AnyPoster to answer people who message or comment on its Facebook Page or Instagram account, that business decides how the conversations are used and we process them on its behalf, as its processor, under our data processing agreement.
What we collect
- Account data: your name, email address, the workspaces you belong to and your role, and the sign-in method you use (Google, or an emailed link). We never ask you to choose a password.
- Billing data: held by Stripe. We receive your billing name, email, country and tax number if you give one, plan, invoices and payment status. We never see your full card number.
- Connected-account data: when you connect a platform (for example Google, Facebook, Instagram, LinkedIn or X), we store the access it grants, encrypted, plus the account's public name, picture and identifiers. We also read the posts we published and their statistics, and for Facebook and Instagram the messages and comments sent to the account.
- Content: what you write, upload and schedule, your brand settings, link-in-bio pages, notes and AI knowledge base.
- Messaging data (about people who contact a business that uses us): the message or comment, their page- or Instagram-scoped ID, public name, username and profile picture from Meta, tags and notes the business adds, and which automation replied.
- Usage and technical data: counts of posts, AI use and storage for plan limits; your IP address, browser type and the pages requested, recorded in server logs for security and fault-finding.
We do not knowingly collect special categories of data (health, beliefs and similar). People can type anything in a message; the business using AnyPoster is responsible for what it asks people to send, and we treat message content as confidential.
Why we use it, and our legal basis
| Purpose | Legal basis | Data |
|---|---|---|
| Creating and running your account and workspace; sign-in; support | Performing our contract with you (GDPR art. 6(1)(b)) | Account data |
| Billing, invoices, tax records | Legal obligation (art. 6(1)(c)) | Billing data |
| Publishing, statistics and replying on the accounts you connect | Performing our contract with you (art. 6(1)(b)) | Connected-account data, content |
| Keeping the service secure, preventing abuse, fixing faults, enforcing limits | Our legitimate interest in a secure, working service (art. 6(1)(f)) | Usage and technical data |
| Service emails: sign-in links, invitations, receipts, report emails, notices about these policies | Performing our contract (art. 6(1)(b)) | Email address |
| Answering the people who message a business that uses us | The business's own basis (usually its legitimate interest or the person's request); we act as its processor | Messaging data |
| Answering your questions and legal requests | Legitimate interest and legal obligation (art. 6(1)(f), (c)) | What you send us |
We do not sell your data, use it for advertising, or build profiles of you. We send no marketing email without your consent. Where we rely on legitimate interests we have weighed them against your rights and you can object (see “Your rights”).
Google, Meta and the other platforms
We use the access you grant only to do what you ask: publish your posts, read their statistics and, for Facebook and Instagram, receive and answer messages and comments. We do not use it for advertising, to train general AI models, or to build anything other than the features you see. You can disconnect an account at any time, here or in the platform's own settings, and we stop using the access at once.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We follow the Meta Platform Terms for data we receive from Facebook and Instagram, including honouring deletion requests (see below).
If you message a business that uses us
We receive the message or comment, your page- or Instagram-scoped ID, and your public name, username and profile picture from Meta, so the business can read and answer you. Automated and AI replies can be labelled as automated. The business that you messaged is responsible for how it uses the conversation; ask it, or us, to delete it. We keep it only as long as the business chooses (default one year).
AI
When a business uses AI writing help or AI replies, the text needed for the task (the draft, the conversation, the business's own notes) is sent to Anthropic to produce the answer. Under Anthropic's commercial terms it is not used to train their models. AI output can be wrong; a person decides what is published, except where a business switches on automatic AI replies. AI is never used to make decisions that have legal or similarly significant effects on anyone.
Who we share it with
Only with the companies that help us run the service (see the subprocessors list), the platforms you connect (to carry out your instructions), the workspace's other members according to their roles, professional advisers and authorities when the law requires, and a buyer if the business is sold (we would tell you and this policy would continue to apply). Staff and contractors can see your data only to give support you asked for, to fix an error that stopped an automated process, to protect the service, or when the law requires it.
Transfers outside your country
Some of our providers are in the United States. Where data leaves the European Economic Area or the United Kingdom, the transfer relies on an adequacy decision, the EU–US Data Privacy Framework where the provider is certified, or the European Commission's Standard Contractual Clauses, together with other safeguards. You can ask us for a copy of the safeguards.
How long we keep it
- Account data (name, email, role)
- While the account exists, then until the workspace is erased
- Workspace content (posts, media, settings)
- While the workspace exists; erased 14 days after the owner deletes it
- Inbox messages and contacts
- One year by default, or the period the workspace owner chooses in Settings → Data
- Billing records
- As long as tax and accounting law requires (in Spain, normally 6 years)
- Audit log of administrative actions
- While the workspace exists
- Server and security logs
- Short periods, set by our hosting provider
- Backups
- Roll over within 30 days after the data was deleted from live systems
- Sign-in links and sessions
- Links: 15 minutes, once. Sessions: 30 days, or until you sign out
Your rights
Under the GDPR and similar laws you can ask to see your data, correct it, delete it, restrict how we use it, export it in a common format, and object to processing based on our legitimate interests. Where processing relies on consent you can withdraw it at any time. You will not be treated worse for using these rights.
Owners can export a whole workspace and delete it in Settings → Data, and anyone can delete their own account there. For anything else, email info@builtwithskills.com. We answer within 30 days, and may need to confirm who you are first. If you are not satisfied you may complain to your data protection authority; in Spain that is the Agencia Española de Protección de Datos.
To remove what a business holds about you because you messaged it: remove our app in your Facebook settings (Settings & privacy, then Apps and websites), which sends us a deletion request automatically, or email info@builtwithskills.com. You can look up the status of a request with the confirmation code you were given, on this page (?deletion=your-code).
Cookies
Only the ones the service needs: your sign-in, the workspace and brand you picked, and your theme. No advertising or tracking cookies, so there is no cookie banner. Details are on the cookie policy.
Children
AnyPoster is a business tool and is not meant for anyone under 18. We do not knowingly collect data from children; if you think we have, tell us and we will delete it.
Security
Connected logins are encrypted at rest, traffic uses HTTPS, access is limited by workspace and role, and administrative actions are logged. See security for what is in place and what we do not claim. If a breach affects your data we will tell you and the authorities as the law requires.
California residents
We do not sell or share personal information for cross-context behavioural advertising, and we do not use sensitive personal information to infer characteristics. For the data of people who contact a business through AnyPoster, we are that business's service provider. California residents can ask to know, correct or delete their information by emailing info@builtwithskills.com.
Changes to this policy
When we make a change that matters, we will email workspace owners at least 30 days before it applies and update the date at the top. Earlier versions are available on request.
Contact
the operator of this service, calle montano 4, 29012, Malaga, Spain. Email info@builtwithskills.com. See also the legal notice.