Privacy policy
What PosterMu stores about you, why, who else sees it, and how to get it back or get rid of it.
← Back to PosterMuThe short version
You can browse and design without an account. If you make one, we store your email, a username and the posters you choose to save — and that's close to all of it.
There are no analytics, no advertising trackers and no third-party scripts beyond Google's sign-in and Stripe's checkout. We don't sell data, and there is nobody to sell it to. You can export everything or delete the account outright from Account settings, without asking us.
Who is responsible
Noah Arons is responsible for the personal information handled by postermu.com (the “data controller”, if you're reading this with GDPR in hand). Contact details are on the contact page.
What we collect, and why
If you never sign in: nothing that identifies you is stored in our database. Your design work happens in your browser, and the API keys you enter in Settings stay in your browser's local storage — they are never sent to us for safekeeping and we could not produce them if asked.
If you make an account (handled by Google Firebase Authentication, so we never see or store a password):
- Your email address, whether it's verified, a username and a display name — to identify the account and let you sign in.
- Posters you explicitly save: the title, media type, style, a thumbnail image and the settings needed to reopen them. Posters you don't save are never uploaded.
- A profile picture, if you upload one.
- Favourites and any design reviews you leave.
- If you buy something: what you bought, when, the amount, and identifiers linking the purchase to Stripe. Card details never touch this app — they go straight to Stripe and we receive only the outcome.
- Technical records: ordinary web-server logs, and an IP address recorded against moderation and administrative actions so abuse can be traced. Rate limiting also counts requests per account or IP address in memory.
- Usage of the media APIs is metered against a one-way hash of the API key that made the call — a fingerprint, never the key itself, and it can't be reversed into one.
What we deliberately don't do
- No analytics, product telemetry, heatmaps or session recording. None are installed.
- No advertising, no ad networks, no pixels, no cross-site tracking, no data brokers.
- No selling, renting or sharing your information for anyone else's marketing.
- No storing your third-party API keys on our servers.
- No marketing email. The only messages we send are the ones you ask for: verification, password reset, and receipts.
Who else processes it
We use a small number of providers to run the service. They act on our instructions and are not free to use your information for their own purposes.
- Google (Firebase Authentication) — sign-in, email verification and password resets. Google receives your email address and sign-in activity.
- Stripe — payment processing. Stripe receives your payment details and email, and is the controller of that data in its own right.
- netcup GmbH — hosting. The servers are in Germany, so if you're outside the EU your information is stored there; if you're inside it, it stays there.
- The media APIs you choose to query (Spotify, TMDB, IGDB and the rest) receive whatever you search for, and under your own API key where you've supplied one. Those requests are governed by your agreement with each provider — see Terms & data sources.
How long we keep it
- Account data: until you delete the account.
- Saved posters and uploads: until you delete them, or the account.
- Purchase records: kept after deletion where tax and accounting rules require it, reduced to the transaction itself.
- Administrative and moderation logs: kept as a record of what staff did, which is the point of them.
- Backups: rolling, deleted after 14 days. A deletion reaches the live service immediately and ages out of backups within that window.
Your rights, and the buttons that exercise them
Depending on where you live you may have rights under Canada's PIPEDA, the UK/EU GDPR, or your own local law. Rather than make you write to us, two of them are wired into the app:
- Get a copy — Account settings → Download my data, which exports your account, posters, favourites and purchases as JSON.
- Delete everything — Account settings → Permanently delete my account. It removes the account, saved posters, uploads, favourites and reviews. It cannot be undone.
- Correct something — edit it in your profile, or ask us.
- Object, restrict, or withdraw consent — ask us.
- Complain — to the Office of the Privacy Commissioner of Canada, or to your local supervisory authority if you're in the UK or EU. We'd rather you told us first.
We answer requests within 30 days and don't charge for them.
Cookies
One cookie, and it is strictly necessary: a signed session cookie that keeps you logged in. It's HttpOnly (scripts can't read it) and Secure (it won't travel over plain HTTP). There are no advertising or analytics cookies, which is why you aren't being asked to accept any.
Your browser also keeps your API keys and editor preferences in local storage. That never leaves your device except when a key is used to make the fetch you asked for.
Children
PosterMu isn't aimed at children under 13, and we don't knowingly hold their information. If you believe a child has made an account, tell us and we'll remove it.
Security, honestly stated
Traffic is encrypted with HTTPS, passwords are handled by Google and never reach us, card data is handled by Stripe and never reaches us, sessions can be revoked from your account page, and the database is backed up daily. No service can promise it will never be breached; if one affects you, we'll tell you and the relevant regulator without undue delay.
Changes
If this policy changes materially we'll update the version date below and say so on the site. Continuing to use PosterMu after that means the new version applies.
Version 2026-07-31. Part of the Terms of Service.