Privacy policy

Last updated: August 12, 2026

lazy-dist is a distribution autopilot for solo founders: it drafts, schedules, and publishes content on your behalf, and measures what it returns. This policy covers what we collect, why, and the control you have over it.

What we collect

  • -Account data: your name and email address, via our authentication provider (Clerk).
  • -Product data: the one-line descriptions, URLs, strategies, voice samples, guardrails, and content drafts you enter or that the system generates for your projects.
  • -Credentials: OAuth tokens and API keys for the social platforms (X, LinkedIn, Reddit, Instagram, and others) and community platforms (Discord, Discourse, Circle) you choose to connect. These are stored encrypted with AES-256-GCM and are used only to act on your behalf on those platforms.
  • -Usage and performance data: post performance metrics (reach, clicks, signups), system run logs, and product analytics events.
  • -Cookies: authentication cookies from Clerk, and a signed first-party attribution cookie (ld_attr) that records which tracked link brought a visitor, for up to 30 days.

How we use it

  • -To operate the distribution autopilot: generating strategies and drafts, scoring content against your voice, scheduling and publishing posts to platforms you connected, measuring results, and improving future content.
  • -To send you the exceptions you asked to be notified about (held drafts, expired logins, community flags).
  • -We do not sell your data. We do not use your content or credentials to train models for other customers.

Third-party processors

  • -Clerk (authentication), Neon (database), Vercel (hosting), Google (Gemini models that generate and score content), Railway (the self-hosted Postiz publishing service), and the platforms you connect (their respective APIs, under their own privacy policies).
  • -Content you approve or that passes your quality bar is published to third-party platforms under your own accounts; once published, that content is governed by the platform's policies.

Retention and deletion

  • -Project data is kept while your account is active. Delete a project and its strategies, posts, drafts, and metrics are removed. Disconnect a platform and its stored credential is deleted.
  • -To delete your account and all associated data, email privacy@lazy-dist.com. We confirm deletion within 30 days.

Your rights

  • -You may access, correct, export, or delete your data at any time. Email privacy@lazy-dist.com for any privacy request.
  • -If you are in the EEA/UK, you have the right to lodge a complaint with your supervisory authority.

First 50 (Discovery)

  • -First 50 is an opt-in research tool: given your product brief, it searches public posts on X for people who may need your product, shows you those posts and plain-English reasoning, and lets you record who you contacted. It is research only - it does not draft or send messages.
  • -It uses the X API with your own app-only bearer token under your account and X's terms; you pay X directly for API reads.
  • -Ephemeral processing: matched post excerpts and the reasoning that produced them are kept for at most 24 hours and then permanently deleted. They are never used to build a profile or to contact anyone automatically.
  • -Permanent retention is limited to a stable platform user ID, your chosen status for that person (new/contacted/replied/signed up/declined/do not contact), and dates - the minimum needed to never silently re-surface someone you already contacted. No post content or reasoning is kept permanently.
  • -Where a candidate's X bio links to a company site, we fetch that single page to understand the sector they work in; we do not enrich profiles or look up accounts a person did not themselves disclose.

Changes

  • -We will post changes on this page and update the date below. Material changes will be called out in the product.

Questions: privacy@lazy-dist.com