Privacy Policy
Effective October 5, 2026
The short version
Postern is local-first by design. Your code, your agent sessions, and the pairing between your phone and computer never pass through our servers — your phone talks to your machine directly. We only hold the minimum needed to sell and renew licenses.
What we collect
- Purchase details — collected and held by Paddle, our merchant of record: email, name, billing address, payment method. We never see your card number.
- License records — on our license server (Cloudflare Workers + KV): Paddle transaction and customer IDs, the plan bought, your machine codes, and license expiry. Used to issue, renew, and recover keys.
- Email — used only to send your license key and recovery keys, delivered via Resend.
What we don't collect
- No telemetry, analytics, or tracking in the extension or web app.
- No cookies on this site. Your language choice is stored in your browser's localStorage and never leaves it.
- No code, prompts, transcripts, or session content — those never leave your machine.
Third parties
- Paddle — payment processing and tax handling (Paddle Privacy).
- Cloudflare — hosts the license worker and its key-value store.
- Resend — sends transactional license and recovery emails.
Retention
License records are kept while your subscription is active plus a grace period, and are removed when the record expires. Recovery rate-limit entries expire in minutes.
Your rights
Email support@postern.download to request a copy or deletion of the license records we hold for your email. Payment records are subject to Paddle's retention obligations as merchant of record.
Security
License keys are Ed25519-signed and verify offline. The local API on your machine requires a host token. The license webhook verifies Paddle's HMAC signature on every delivery.
Changes
Updates are posted on this page with a new effective date.