Back to campaigns
PRIVACY & SECURITY

A small amount of storage, for a working website.

Sign-in cookies

Supabase sets first-party cookies named sb-…-auth-token (sometimes split into numbered parts) to keep your account session working. Sign-in and recovery flows can also use a temporary code-verifier cookie.

Session cookies can remain for up to 400 days from the last refresh; the login tokens have their own expiry. Signing out clears the active sign-in cookies. A temporary verifier is cleared when its flow finishes.

Your language choice

When you choose a language, postly.language.choice is saved in local storage on this device until you select Automatic or clear the site data. Earlier versions also stored postly.language and a sidebar_state cookie lasting seven days; this version no longer writes either.

Automatic language uses the country estimated from your IP address by our hosting provider, with your browser language as a fallback. It does not request GPS location. You can change the language at any time.

AI support and saved conversations

Opening support creates a random support cookie for 30 days. Guest chats are linked to that cookie; signed-in chats are linked to your account. Your questions and replies are stored so you can reopen them. Use Clear chat to delete your saved conversation.

Messages are sent through Vercel AI Gateway to Google Gemini. When signed in, support receives your current wallet amounts, recent withdrawal statuses, your recent tasks and the current task instructions to answer your question. It does not receive bank account numbers, PayPal emails, passwords or other users’ records. Do not paste sensitive payment details into chat.

Support can also see which page and campaign you are viewing and whether your email, picture and saved accounts are set up. It receives setup flags, not your PayPal email or bank details.

AI submission checks

Submitted videos, public post text and proof screenshots may be processed through Vercel AI Gateway and Google Gemini to compare them with the campaign instructions. Reports identify accessible evidence, mismatches and details that could not be checked. They are stored with your task and visible only to you and the administrator. AI results do not approve tasks or transfer money.

Wallet and payment details

We send account emails when a new task reward is credited and when a withdrawal is requested, marked paid or rejected. Emails use your account address and include the amount and a wallet link, without bank account numbers or PayPal receiving details. Delivery attempts and provider message IDs are stored to prevent duplicates and retry failures.

Withdrawal details are stored encrypted and shown only to you and the administrator handling your request. Financial transactions are kept as an append-only history with unique IDs. Local currency estimates do not change the earned amount. Your selected display currency is remembered in postly.currency.choice on this device.

Saved profile and payout accounts

Your profile picture is stored privately and resized with embedded metadata removed. You can replace or remove it in your profile. Saved social profile links are unverified shortcuts for new campaign applications. Saved PayPal payout details are encrypted and available only through your own account; when you request a withdrawal, its destination is also available to the administrator handling it. Saving or removing defaults does not change existing tasks or withdrawal requests.

Public profile search

When you search a social username, the server requests that public profile from the selected platform. Public names, biographies, profile pictures and visible counts are cached for up to seven days; searches can reuse a recent result for six hours. Pictures are resized and stored as previews. This does not sign you in to a social network or verify ownership. Missing or blocked details stay unavailable.

External websites

Google Drive videos, social platforms, and tutorial sources open only when you follow their links. Those websites have their own cookie and privacy settings. Postly does not load a Google Drive video player automatically.

First-visit security notices

On your first visit, we may email the connection IP address, estimated country/city and visit time to bussines@wawyshorts.win for website security. Vercel estimates the location from the IP; VPNs, mobile networks and proxies can make it inaccurate. We do not collect GPS coordinates or an exact address.

A signed, secure cookie named __Host-postly.visit prevents repeat alerts for 30 days. The server keeps keyed hashes for duplicate suppression and rate limits, and removes records older than 31 days when processing a new visit. Raw IP addresses are not stored in this application database for this feature. The email is processed by Resend and remains in the administrator’s mailbox until deleted; deleting site cookies does not delete those emails.

Alerts are limited to one per browser in 30 days and one per IP in 24 hours, up to 5 per hour and 20 per day for the website. This is a limited security signal, not a complete visitor history or proof of a person’s identity. Contact bussines@wawyshorts.win about these records.

Offers and reservation activity

We offer a limited selection of tasks using saved platforms, completed tasks and rotation. Regional prices use public World Bank country groups and the country estimated from your connection. The exact price is shown before acceptance and stays fixed for that task. If the region is wrong, contact the owner.

For new reservations, we record the first and last page view, download click, copied text or guide action. Opening a download is not proof that the file finished downloading. These events manage the displayed start deadline and one reminder. Started work is not automatically released for inactivity.

Connection countries and keyed IP fingerprints are kept for up to 31 days to help review repeated accounts and admin watch rules. Shared networks or travel are not proof of abuse. Recent connection records are removed after 31 days; administrator watch rules and review records remain until removed. Flags require human review; a hold affects new reservations only. Owner messages are private between you and the owner; AI replies are separately labeled.

Your controls

You can delete this site’s cookies and stored data in your browser. Clearing or blocking login cookies signs you out or prevents sign-in. Blocking language storage means your choice will not be remembered.

Referral invitations and reward checks

If you choose Continue with this invitation, a signed first-party postly_invite cookie remembers the invitation for up to 30 days. You can continue without it. It is removed after the invitation is attached to your new account. Existing accounts cannot switch inviters.

We store the inviter, invited account, eligibility, review reasons and the unique $1 reward transaction for each person. To detect repeated receiving accounts, we store keyed fingerprints of payout destinations, not additional plain-text bank details. Existing recent network fingerprints and email verification help review abuse. Shared Wi-Fi is not proof of abuse. Referral records and financial records remain for support and dispute handling; contact bussines@wawyshorts.win about access or removal.

The inviter and invited friend each receive $1 once only after both emails are verified, the new friend earns at least $5 from approved tasks, and their first qualifying withdrawal is marked paid. No self-referrals, duplicate identities, fake tasks, bought referrals or spam. Monthly program and inviter limits apply; eligible rewards wait if the budget is full. The owner reviews flagged referrals and supplies a reason for rejection.

AI campaign drafts

The administrator can send video links, accessible videos, reference pictures and a writing brief through Vercel AI Gateway to Google Gemini. Drafts, the source type, token counts and estimated generation cost are stored privately for the administrator. Generated text is reviewed before publication. Distinct comment assignments are saved with each task.

Owner YouTube connections

The website owner can authorize YouTube channels through Google. Postly stores the channel ID, name and picture, an encrypted access credential, and the video, text and delivery result for each requested comment. This information is private to the owner and the server. YouTube account passwords are never collected by Postly.

A secure temporary cookie named __Host-postly-youtube-… protects each connection attempt for up to ten minutes. Disconnect removes the saved access credential and cancels queued comments; channel details and comment history remain. Google access can also be revoked in your Google Account permissions. Contact bussines@wawyshorts.win to request removal of retained connection records.

Google Privacy Policy · Google Account permissions

Questions about cookies?

Updated 25 September 2026