Privacy Policy
Last updated: May 3, 2026
This Privacy Policy explains how ConFYI Post (“ConFYI Post”, “we”, “us”, or “our”) collects, uses, shares, and protects personal data in connection with the ConFYI Post social-media scheduling, publishing, analytics, and team-collaboration service (the “Service”), the website at post.con.fyi and related pages (the “Site”). It applies to visitors, account holders, workspace members, prospects, support contacts, and anyone else who interacts with us. By using the Site or Service, you acknowledge this Policy. Our contractual terms are in the Terms of Service.
1. Who we are
The Service is operated by Open Growth Group INC, a corporation incorporated in Delaware, USA. In this Policy, “ConFYI Post”, “we”, “us”, and “our” mean Open Growth Group INC.
Open Growth Group INC operates this ConFYI Post deployment and its configured integrations. The deployment uses Postiz software and may connect to third-party social platforms, but it is not operated by postiz.com or by any connected platform.
For privacy questions, requests, or complaints, contact hello@opengrowthgroup.co.
2. The Service in brief
ConFYI Post lets approved teams connect social-media and communication channels to centrally schedule, publish, analyse, and collaborate on content. Features include a calendar and scheduling engine, media library, publishing queue, analytics, team and workspace management, and integrations with third-party platforms. Features and supported channels depend on the configuration and platforms you choose to connect.
3. The data we collect
3.1 Account and identity data
We may collect your name, email address, password credential or salted password hash, profile picture, organisation name, role, language, timezone, workspace membership, invitations, and permissions. If you sign in through another provider, we receive the basic profile fields and email that provider returns.
3.2 Connected-platform data
When you connect a third-party social or messaging account, we receive and store data made available through that platform’s API, including OAuth access and refresh tokens, granted scopes, platform usernames and identifiers, profile and page metadata, channel IDs, and content or engagement data needed to provide the Service.
This can include posts you create or schedule, published-post records, comments, replies, direct messages where you explicitly enable that feature, analytics, and audience-level aggregates exposed by the platform. You can revoke access from the connected platform at any time. For YouTube, use of the integration is also subject to the YouTube Terms of Service and Google Privacy Policy.
3.3 Content you provide
We collect text, images, video, audio, captions, links, hashtags, schedules, prompts, comments, approval notes, calendar metadata, and other content you upload to or generate within the Service.
3.4 Billing data
If a paid plan is offered, we collect plan, subscription, invoice, billing-contact, billing-address, and tax information needed to administer it. Payment-card and bank-account details are collected directly by the relevant payment processor. We receive only the tokenised reference and limited payment metadata needed for reconciliation and support.
3.5 Logs, usage, and device data
We may collect IP address, user-agent, browser and operating-system details, device identifiers, referrer URL, language, approximate location derived from IP, pages visited, features used, posts created or published, API calls, error reports, performance metrics, login timestamps, session data, and security events.
3.6 Communications and support data
We collect messages sent by email or support channels, surveys, feedback, feature requests, and engagement information for marketing messages where applicable.
3.7 Cookies and similar technologies
We use cookies, local storage, pixels, and similar technologies for authentication, security, preferences, analytics, and service operation. You can manage non-essential cookies through available controls or your browser settings. Disabling strictly necessary cookies may prevent parts of the Service from working.
4. How we use data and legal bases
We process personal data to:
- provide the Service, authenticate users, manage workspaces, store and publish content, return analytics, and provide support (performance of contract);
- administer commercial plans, issue invoices, prevent payment fraud, and comply with tax obligations where applicable (performance of contract; legal obligation);
- secure the Service, detect abuse and account takeover, investigate incidents, and enforce the Terms (legitimate interests; legal obligation);
- operate, maintain, debug, monitor, and improve a reliable Service (legitimate interests);
- send service-related messages and, where permitted or opted into, marketing communications (performance of contract; consent or legitimate interests); and
- respond to lawful requests, defend claims, and comply with law (legal obligation; legitimate interests).
We do not sell personal data. We do not use the content of scheduled posts, connected-platform content, or private messages to send advertising.
5. AI-assisted features
Optional AI features may generate or rewrite captions, hashtags, image prompts, video scripts, or analytics summaries. To provide them, we may transmit prompts and the inputs you choose to include to third-party model providers acting as service providers. We ask those providers to protect your inputs and not use them to train their models except where you expressly opt in or a separate disclosed provider policy applies. AI output may be inaccurate; you remain responsible for reviewing it before publication.
6. Controller and processor roles
For account, billing, Site analytics, marketing, and security data, Open Growth Group INC acts as a data controller.
For content you publish through the Service and personal data about your audience, followers, customers, or message contacts that flows through the Service on your instructions, you may be the controller and Open Growth Group INC may act as your processor. You are responsible for having a lawful basis, providing notices, and honouring rights for that processing. Additional data-processing terms may apply where required.
7. Who we share data with
We do not sell or rent personal data. We share it only as needed to provide and protect the Service:
- Hosting and service providers. Cloud hosting, storage, database, email, monitoring, support, analytics, payment, and AI providers process data under appropriate contractual and security controls.
- Connected platforms. When you schedule or publish, we transmit the selected content to the platform you chose and receive data when you request analytics. That platform’s policy governs its subsequent use.
- Workspace members. Content, schedules, comments, and approvals may be visible to members of the workspaces you join, according to their roles and permissions.
- Professional advisers and authorities. Accountants, lawyers, insurers, regulators, courts, and law-enforcement authorities may receive data where confidential advice, legal compliance, fraud prevention, security, or protection of people requires it.
- Successor entities. Data may transfer in a merger, acquisition, financing, reorganisation, or sale of assets, subject to continued protection or notice of a changed policy.
8. International data transfers
Open Growth Group INC is incorporated in Delaware, USA, and our providers may process data in the United States, the European Union, the United Kingdom, and other jurisdictions. Your data may therefore be transferred outside your country. Where required by applicable law, we use recognised transfer safeguards such as Standard Contractual Clauses and appropriate technical and organisational measures.
9. Data retention
- Account data is kept while your account is active and ordinarily for up to 90 days after closure to allow recovery, unless longer retention is required.
- Unpublished scheduled content is kept until publication or deletion.
- Published-post records and analytics are kept while the account is active so historical reporting remains available.
- OAuth tokens are kept while a connection is active; revoked tokens are deleted promptly.
- Billing records are retained for the period required by tax and accounting law.
- Operational and security logs are ordinarily retained for up to 12 months, while encrypted backups roll off on their normal schedule.
We may retain data longer where necessary for legal, regulatory, dispute-resolution, security, or fraud-prevention reasons.
10. Security
We maintain administrative, technical, and physical safeguards designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Measures may include TLS, encryption of sensitive credentials, password hashing, role-based access controls, least-privilege access, audit logging, vendor commitments, and incident-response procedures. No system is completely secure, and we cannot guarantee absolute security.
11. Your rights
Depending on where you live, you may have the right to access your personal data, receive a portable copy, request correction or deletion, object to or restrict processing, withdraw consent, and lodge a complaint with your supervisory authority. ConFYI Post does not sell personal data or share it for cross-context behavioural advertising.
Most changes can be made in your account, profile, workspace, or integrations settings. For requests that cannot be handled in-product, email hello@opengrowthgroup.co. We may verify your identity and will respond within the time required by applicable law. We will not discriminate against you for exercising your rights.
12. California privacy rights
If you are a California resident, applicable California privacy laws may provide rights to know, delete, correct, limit certain uses of sensitive personal information, and receive equal treatment when exercising those rights. ConFYI Post does not sell personal information or share it for cross-context behavioural advertising. Contact hello@opengrowthgroup.co to exercise California rights.
13. Children
The Service is intended for business use and is not directed to children. We do not knowingly collect personal data from children under 18. If you believe a child provided personal data, contact us at hello@opengrowthgroup.co and we will investigate and delete it where required.
14. Marketing and cookie choices
You can unsubscribe from marketing emails using the unsubscribe link in the message. This does not stop transactional and account-related messages. You can manage cookie preferences through available Site controls or your browser settings.
15. Third-party sites and services
The Site and Service link to and integrate with third-party services. Their handling of data is governed by their own privacy policies, not this one. Review the privacy policy of each platform you connect to ConFYI Post, including the Google Privacy Policy for YouTube integrations.
16. Changes to this Policy
We may update this Policy from time to time. If a change is material, we will provide reasonable notice before it takes effect. The date at the top of this page shows when the Policy was last updated.
17. Contact us
For privacy questions, requests, or complaints:
Open Growth Group INC
Delaware, USA
hello@opengrowthgroup.co

