Legal
Privacy Policy
This policy explains what PostShelf collects, why, and what happens to the social posts that appear in the library.
Effective 26 August 2026. Previous versions are superseded in full.
1. The short version
- We only ever index publicly visible posts from public accounts. We do not access private accounts, direct messages, or any content behind a login.
- Posts are displayed using each platform’s official embed. That means X, Instagram, TikTok and Reddit receive requests from your browser and may set their own cookies, independently of us.
- There are no accounts yet, so we hold no names, no email addresses and no payment details. What you save is kept in your own browser and never reaches us.
- We do measure how the library is used — which posts were shown, opened, upvoted or saved, and what was typed into the search box — against a random id stored in your browser, not against you.
- Anything collected in response to a request is published to the public library. A request is not a private research tool.
- You can ask us to remove content at any time by writing to hello@postshelf.net.
2. Who we are
PostShelf (“PostShelf”, “we”, “us”) operates the website at postshelf.net, a public gallery of marketing posts published by software products on X, Instagram, TikTok and Reddit. We are the controller of the personal data described in this policy. For any privacy question, contact hello@postshelf.net.
3. What we collect about you
3.1 Accounts — there are none yet
PostShelf has no account system at the moment. The log-in and sign-up screens are placeholders: they store nothing, send nothing, and sign nobody in. We therefore hold no email addresses, no passwords, no authentication identifiers from Google or GitHub, and no profiles. If that changes, this section will be rewritten before it does.
3.2 Payments — we take none
Everything on the site is free while the library is being built. No payment is taken anywhere on postshelf.net, no card details are entered here, and we have no billing records of any kind.
3.3 Saved posts and collections
The save button and the Library write to your browser’s own local storage on the device you are using. Nothing you save is sent to us, and we cannot read it. It does not follow you to another browser or another device, and clearing your site data deletes it.
3.4 Usage measurement
We record how the library is used so we can tell which parts of it are worth building on. A random identifier is generated once and kept in your browser’s local storage; it identifies a browser, not a person, and it is not linked to any name, email or account, because there are none. Against that id we store, in our database:
- which post windows were displayed and which ones you opened;
- upvotes and saves, and their undos;
- what was typed into the product search box, and which product it matched;
- the page path and the filters that were active when the above happened.
We do not record your IP address, your location or your device model in that store, we do not build advertising profiles, and we do not sell personal data. Our hosting and database providers necessarily see the IP address of each request in order to serve it, and keep it in short-lived operational logs. If you would rather not be counted at all, blocking local storage for this site turns the measurement off entirely — the rest of the site keeps working, minus the save feature.
3.5 Requests and email
The product request form currently runs entirely in your browser: submitting it shows you a confirmation and sends nothing to us, because there is no endpoint behind it yet. If you email us instead, we keep what you sent — the product URL, handles, and your email address — so we can act on it and reply.
4. Third-party embeds and the data they collect
Every post on PostShelf is rendered with the official embed supplied by the platform it was posted on. We do not re-host media and we do not re-draw posts. As a direct consequence, when an embed loads:
- your browser makes requests to that platform’s servers — X (x.com / twitter.com), Meta (instagram.com), TikTok (tiktok.com) or Reddit (reddit.com and redditmedia.com);
- those platforms receive your IP address, user agent, and the address of the PostShelf page you are viewing;
- those platforms may read or set their own cookies and local storage, including cookies that identify you if you are logged in to them;
- that processing happens under their privacy policies and is outside our control. We do not receive the data they collect this way.
Be aware that this is not limited to the posts you actually look at. Embeds are queued rather than deferred until you reach them: opening a page starts loading every post window on it, a few at a time, from the top down — so by the time you scroll, the platforms have already been contacted for that page. The exception is a window scrolled out of sight sideways inside a horizontal row, which waits until you scroll it into view. If you want to avoid this entirely, use a browser or extension that blocks third-party embeds — the rest of the site continues to work.
The relevant policies are published by each platform: X, Instagram, TikTok and Reddit.
5. Posts, handles and public figures
The library consists of posts that were published publicly by companies and by the individuals who run them, together with the account handle, display name and profile URL needed to attribute each post correctly. Where a founder’s personal account is included, it is included because that account is used publicly to market the product.
We index only what is publicly retrievable. We do not attempt to access protected accounts, deleted posts, private communities, or content that requires a login to view. If a post is deleted or made private at the source, its embed stops rendering and we remove the record on our next pass — or immediately, if you tell us.
6. What happens to data collected for a request
Anyone can nominate a product, by URL, whose public accounts we then collect; when paid plans start, doing so will also be part of the Pro plan. Everything collected in response to a request is added to the public library and is visible to everyone. A request buys coverage and priority, not exclusivity or secrecy.
We do not publish who asked for a product, and we do not show one person’s requests to anyone else.
7. Cookies and local storage
We set no cookies of our own. There is no session to keep, no advertising and no cross-site tracking on our side. What we do use is your browser’s local storage, for two things: the random measurement id described in section 3.4, and the posts and collections you save (section 3.3). Both stay on your device.
Third-party cookies may still be set by the platform embeds described in section 4, and those are outside our control.
8. Legal bases (EEA and UK)
- Legitimate interests — keeping a public catalogue of marketing material published by companies, securing the service, and measuring usage against an id that is not tied to a person.
- Consent — where you write to us, or opt in to anything we may offer later. You can withdraw it at any time.
Contract and legal-obligation bases would cover accounts and payments; neither exists here yet, so neither is claimed.
9. Retention
We hold no account records and no billing records to retain. Measurement events are kept while they are still useful for deciding what to build, and carry no name or address to attach them to. Email you send us is kept for as long as we need it to deal with what you wrote about. Library entries are kept until the source post disappears or a removal request is received.
10. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict processing, and to complain to a supervisory authority. Write to hello@postshelf.net and we will respond within 30 days. We do not sell personal information and we do not share it for cross-context behavioural advertising.
11. International transfers
Our hosting, database and analytics providers may process data in the United States and the European Union. Where personal data leaves the EEA or the UK, transfers rely on Standard Contractual Clauses or an adequacy decision.
12. Security
Data is encrypted in transit and access to production systems is restricted to the people who need it. The best protection we currently have is how little there is to lose: no passwords, no payment details and no contact details are stored anywhere in the product. No service can promise perfect security, but we will notify affected people and the relevant authority if a breach requires it.
13. Children
PostShelf is a business tool and is not directed at children under 16. We do not knowingly collect their data; if we learn that we have, we will delete it.
14. Changes
We will post any change on this page and update the effective date. There are no account holders to email, so this page is the notice; the practices that arrive with accounts, payments or anything else new will be written here before they start, not after.
15. Contact
Privacy questions, data requests, and removal requests all go to hello@postshelf.net. See also our Terms of Service.