PostRoom.

PostRoom · Beta

Privacy, in plain language.

How the PostRoom beta handles workspace and reviewer information. Operated by Kartheek Akella in India. Updated 4 October 2026.

Information used to run your workspace

Clerk handles account sign-in and the identity information you provide during registration. PostRoom associates your Clerk account ID with rooms, client names, draft titles and text, chosen channels, planning dates, review feedback, activity records and API key labels. API key secrets and review-link tokens are stored as hashes rather than readable secrets.

What a reviewer shares

A reviewer can provide a name, an approval or request for changes, and feedback. These are stored with the draft’s workflow history and shown to the workspace owner. Reviewer names are self-reported. Reviewing does not require a PostRoom account.

Who can see submitted content

The owner can view workspace content. Anyone with an active room review link can see submitted drafts, including content already approved or sent back for changes. Private drafts are excluded from that review view. A link lasts seven days unless revoked or replaced sooner. People may retain copies of content they have already viewed; revoking a link does not recall those copies.

Service providers

PostRoom uses Clerk for authentication, and Sites hosting with Cloudflare infrastructure and D1 storage to operate the application. These providers may process account information, request metadata and service data needed to deliver their services. Read Clerk’s privacy policy and Cloudflare’s privacy policy for their practices.

Dodo Payments is being considered for future paid checkout; payment onboarding is incomplete and PostRoom does not currently offer live purchases. If enabled, the checkout will identify the payment provider and explain its handling of billing information. Do not send card or bank details through drafts or feedback.

Cookies, storage and AI

Sign-in relies on Clerk’s session technology, including authentication cookies or browser storage. PostRoom uses server-side request counters to limit abuse. The current product does not run AI generation on your drafts. If you connect your own agent, you decide which external tool receives workspace data through the API.

Optional Google Analytics

If you choose “Allow analytics”, PostRoom loads Google Analytics to measure visits, campaign sources and successful product actions, such as creating a room, requesting review and opening checkout. Google receives technical browser and network information and uses first-party analytics cookies. Advertising personalization and Google signals are disabled. We do not send your email address, account ID, client names, draft content, feedback or private review-link tokens to Analytics. Page addresses are reduced to public page categories and optional campaign labels; full referrer addresses are excluded.

You can decline without affecting the service, or change your choice through “Analytics preferences” at the bottom of each page. Withdrawing consent stops future collection and removes this site’s analytics cookies; it does not automatically erase information already received by Google. Read Google’s privacy policy for its data practices.

Retention and deletion

Workspace data remains stored until it is deleted or removed as part of operating the service. Deleting a draft removes it from the board, but activity records may remain, including the deleted draft’s title, reviewer names and feedback. Deleting a Clerk sign-in account does not currently trigger automatic deletion of PostRoom workspace data. There is no published fixed retention schedule for this beta.

Use the contact page to request access, correction or removal of your information. A reviewer can also ask the workspace owner to help identify the room and content involved. We may need to verify a request before acting on it.