PostCard Privacy Policy
Effective: September 3, 2026
Summary: PostCard does not sell user data, use it for advertising, or operate an analytics service. Designs and settings are stored locally in Chrome. Data leaves the browser only when a user requests a feature that requires a third-party service, such as AI generation, image search, or inserting a finished post into a social network.
Who operates PostCard
PostCard is an open-source Chrome extension published by EVOKNOW, Inc. This policy describes how the PostCard extension collects, uses, stores, and discloses information.
Information PostCard handles
- User-created content: card text, captions, tables, uploaded or pasted images, slide content, recorded video, and related design settings.
- Extension settings: selected fonts, editor state, schedules, automation history, and optional AI configuration.
- Selected webpage text: only when the user chooses “Create PostCard from selection” from Chrome's context menu.
- Website interaction: the active supported social-network tab, its hostname, and the post composer needed to insert content at the user's request.
- Camera and microphone data: only after the user grants permission and starts a recording feature.
- Optional AI data: the user's AI-provider API key, prompt, selected provider, model, schedule, and generated post history.
How information is used
PostCard uses this information only to create and restore designs, render and download media, insert user-approved content into supported social-network composers, record requested camera or microphone media, search for optional media, and run user-configured AI or scheduled-posting features.
Local storage and retention
Designs, captions, settings, API keys, schedules, and automation history are stored in chrome.storage.local on the user's device. Selected webpage text is temporarily stored locally and removed after it is loaded into the editor. Camera and microphone media is processed locally unless the user chooses to insert it into a third-party social network. Local data remains until the user clears it, starts a new session where applicable, clears history where available, or uninstalls the extension.
When information is transmitted
- Social networks: when the user selects Insert, Post, or a configured scheduled-post action, PostCard sends the user-approved caption and media to the selected social network through that network's webpage.
- AI providers: when optional AI automation is enabled or tested, the user's prompt and instructions are sent directly over HTTPS to the chosen provider, currently OpenAI or Anthropic. The user's API key is used directly with that provider and is not sent to EVOKNOW.
- Media and fonts: search terms may be sent to GIPHY when the user performs a GIF search. Images and fonts may be requested from GIPHY, Google Fonts, and the MyPoint.Cards featured-image service. Those services receive ordinary network information such as the user's IP address and request headers.
Use of third-party services is governed by their own privacy policies and account settings.
Sharing, selling, and advertising
EVOKNOW does not sell or rent extension user data, does not use it for personalized advertising, and does not transfer it for creditworthiness, lending, or unrelated profiling. PostCard discloses data only when necessary to perform a feature the user requests, to comply with applicable law, or to protect security and legal rights.
Chrome Web Store Limited Use
PostCard's use and transfer of information received from Google APIs complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. Data obtained through extension permissions is used only to provide or improve PostCard's user-facing features. It is not used for personalized advertising and is not made available for human review except with the user's affirmative consent for support, when required for security, when required by law, or after aggregation and anonymization for internal operations.
Security
PostCard uses HTTPS for supported external services. Sensitive settings remain in Chrome's local extension storage. No method of storage or transmission is completely secure, so users should protect their browser profile and AI-provider credentials.
User choices
Users may leave AI automation disabled, decline camera or microphone access, avoid optional searches, clear saved designs or automation history, remove stored settings through Chrome, and uninstall PostCard. Users can also revoke permissions through Chrome's extension settings.
Changes to this policy
This policy may be updated when PostCard's features or data practices change. The effective date above will be revised, and material changes will be reflected on this page.
Contact
For privacy questions or data requests, email EVOKNOW at kabir@evoknow.com. Please do not post sensitive personal information in a public GitHub issue.