Get2Post Privacy Policy
Version: 1.0
Effective date: August 16, 2026
Get2Post, also referred to as G2P, is a service operated by 3CodeMonkeys, LLC.
This Privacy Policy explains how 3CodeMonkeys, LLC (3CodeMonkeys, we,
us, or our) collects, uses, discloses, retains, and protects personal
information in connection with Get2Post.
1. Operator and privacy contact
3CodeMonkeys, LLC
1382 Thistle Lane
Shakopee, MN 55379, USA
Privacy questions and requests may be sent to support@get2post.com. The same monitored address handles support, account, billing, security, abuse, and outage requests using separate request categories.
2. Scope and United States-only launch
This Policy applies to the Get2Post website, application, APIs, support process, billing integration, advertising integration, AI features, MCP surfaces, bots, automations, diagnostics, and related services.
Get2Post is initially offered and supported only in the United States. This Policy and the launch consent and rights process are prepared for United States users. We do not claim worldwide availability. International availability and additional jurisdiction-specific privacy notices require separate implementation and validation before activation.
This Policy does not replace the privacy notices of third-party endpoints, identity providers, AI providers, payment services, advertising services, MCP clients, or integrations that Customer chooses to use.
3. Roles and Customer direction
An organization controls its Get2Post membership, workspaces, service identities, permissions, Customer Content, and instructions. When we process Customer Content at an organization's direction, the organization is responsible for having an appropriate basis and authority for that content and instruction. Individuals should direct a Customer Content request to their organization when the organization controls the relevant data. We will assist as appropriate and will separately handle information that 3CodeMonkeys controls for account, security, billing, advertising, or legal purposes.
4. Information we collect
The information collected depends on how Get2Post is used and which features are enabled.
4.1 Account, identity, and organization information
We may collect:
- name, email address, account identifiers, authentication method, linked identity-provider identifiers, and account status;
- organization and workspace names and identifiers;
- membership, role, permission, invitation, owner, administrator, and service identity records;
- authentication, authorization, approval, recovery, and delegated-access events; and
- preferences, settings, consent state, and support references.
We do not ask users to send passwords, recovery codes, secret keys, tokens, or session cookies to support.
4.2 Customer Content
Customer Content may include:
- API endpoint URLs, methods, query parameters, headers, request bodies, response data, cookies, scripts, assertions, schemas, and examples;
- collections, folders, lifecycle versions, environments, variables, secret values, files, imports, and exports;
- workflow definitions, schedules, Bot Runs, automation instructions, prompts, AI input and output, MCP instructions, and integration configuration;
- test results, execution receipts, logs, audit evidence, error details, and history; and
- other information Customer chooses to store, transmit, or generate.
Customer decides what it places in these fields and should minimize personal and sensitive information. Designated secret handling and redaction boundaries should be used for credentials. Customer must not place secrets in names, ordinary support messages, or other non-secret fields.
3CodeMonkeys processes Customer Content only as reasonably necessary to provide, operate, support, troubleshoot, secure, and maintain Customer's Get2Post service; investigate customer-reported problems; comply with Customer's instructions; enforce the Terms; and satisfy legal obligations. We do not use Customer Content for unrestricted product improvement.
4.3 Usage, device, operational, and diagnostic information
We may collect service, operational, and security information such as:
- sign-in, session, route, feature, request, workflow, Bot Run, automation, AI, MCP, and integration activity;
- timestamps, organization and workspace context, actor type, approval state, result status, duration, error category, and trace or correlation identifiers;
- browser, device, network, IP address, navigation events, feature interactions, performance measurements, and service-log information generated by hosting, identity, security, monitoring, or diagnostic systems;
- plan, entitlement, seat, allowance, budget, metered quantity, and billing ledger information; and
- advertising eligibility, consent state, provider-load status, and limited advertising telemetry when advertising is enabled.
We refer to aggregated or deidentified information and metadata about how the service is used and performs as Usage Data. Get2Post may use aggregated or deidentified operational information and Usage Data to improve reliability, security, accessibility, usability, and the service generally, provided that the information cannot reasonably identify Customer or its users or reveal or reconstruct Customer Content.
General logs, audit views, support views, MCP reads, diagnostic evidence, and evidence packages are designed not to expose secret values, raw payment-card data, or unnecessary payload content. Credentials, authorization headers, environment secrets, payment information, and other sensitive fields are excluded or redacted by default where reasonably practicable. No redaction mechanism eliminates all risk, so Customer must still minimize sensitive inputs.
4.4 Billing information
For paid plans, we may collect billing contact details, plan, interval, seat quantity, subscription and commercial state, included and metered usage, invoice references, totals, currency, adjustments, credits, payment status, provider event identifiers, and reconciliation results.
Stripe is the initial payment and invoice provider where billing is enabled. Payment-method and card entry occurs on Stripe-hosted surfaces. Get2Post does not need to store raw payment-card numbers or security codes. Stripe provides limited customer, subscription, invoice, and payment-state information needed to operate and reconcile billing.
4.5 Support communications
We collect information a requester sends to support@get2post.com, including the selected category, message, timestamps, reply history, and any non-secret account, organization, workspace, invoice, transaction, or trace reference needed to resolve the request. Categories include general help, bugs, account access, billing, privacy, security, abuse, and outages.
Do not send credentials, sensitive headers, private keys, secret-bearing payloads, or unreviewed screenshots or attachments. We verify identity and authority before protected disclosure or action. There is no fixed launch response-time promise.
5. Sources of information
We collect information:
- directly from users and organization administrators;
- from Customer-authorized users, service identities, MCP clients, bots, automations, imports, endpoints, and integrations;
- from identity providers used to sign in or link an account;
- from Stripe for billing and payment state;
- from Google when Google advertising is enabled;
- automatically from Get2Post, its hosting platform, security controls, logs, monitoring, and diagnostic systems; and
- from support communications or lawful security, abuse, and incident reports.
6. How we use information
We use information to:
- create and authenticate accounts and enforce organization, workspace, role, and service-identity boundaries;
- provide, execute, store, synchronize, export, and support the features Customer selects;
- process API requests, workflows, AI features, MCP operations, bots, automations, and integrations at Customer's direction;
- apply approvals, entitlements, limits, budgets, rate controls, and safety checks;
- maintain execution, audit, security, billing, diagnostic, and reliability evidence;
- provide support, verify requesters, investigate problems, and communicate about the service;
- operate subscriptions, seats, metered usage, invoices, payment state, and provider reconciliation;
- present Google advertising to eligible Free with ads users only when the applicable configuration and consent/privacy controls permit it;
- detect, prevent, investigate, and respond to fraud, abuse, unlawful conduct, unauthorized access, security harm, outages, and evidence-destruction risk;
- identify software defects and investigate reliability, performance, security, accessibility, user-interface, and usability problems;
- improve reliability, security, accessibility, usability, and the service generally using aggregated or deidentified operational information and Usage Data that cannot reasonably identify Customer or its users or reveal or reconstruct Customer Content; and
- comply with law, preserve evidence, enforce agreements, and protect rights and safety.
7. AI processing and model training
When an authorized user selects an AI feature, Get2Post may send the user's instruction and the minimum workspace or request context needed for that operation to the enabled AI provider. The exact data depends on the selected task. Users should review inputs, remove unnecessary personal or secret data, and review output before use.
Customer Content may also be processed by an AI provider when limited processing is reasonably necessary to provide support or investigate a specific customer problem. In either case, the processing remains subject to applicable provider terms, security controls, and data-protection requirements.
3CodeMonkeys does not use Customer Content to train or fine-tune general-purpose or shared AI models unless Customer separately and affirmatively opts in. AI-assisted diagnostic analysis is not permission to use Customer Content for model training. Any future program that would use Customer Content for training or fine-tuning a shared or general-purpose AI model must require a separate affirmative opt-in and may not be introduced through a silent Terms or Privacy Policy update.
AI output and related metadata may be stored in the workspace, execution history, audit evidence, or provider usage records when required for the feature, security, support, billing, or evidence. Customer-selected AI providers may process data under their own terms and privacy notices.
8. MCP, service identities, bots, and automation
MCP clients, service identities, bots, agents, and scheduled automations can access or change Customer Content or call external systems within the scope authorized by Customer. We process identity, authorization, workspace, capability, approval, schedule, credential-reference, execution, and audit information to validate and record those actions.
Non-human activity may occur without a person actively viewing Get2Post. Get2Post may deny an action when identity, tenant, authorization, approval, entitlement, commercial state, budget, or security context is missing or inconsistent. Secret values are not intended to be returned through general MCP read surfaces, mutation responses, audit views, or support displays.
9. Automated diagnostics and AI-assisted analysis
Get2Post may use automated diagnostics, including AI-assisted analysis, together with limited review by authorized personnel to identify errors, investigate reported problems, and improve reliability, security, accessibility, and usability. These capabilities may be enabled or disabled depending on operational, testing, support, security, and investigation needs; this Policy does not state or imply that every customer session is continuously monitored.
Diagnostic information may include feature interactions, navigation events, browser and device information, performance measurements, error logs, and appropriately protected diagnostic evidence. Sensitive fields are excluded or redacted where reasonably practicable. Credentials, authorization headers, environment secrets, payment information, and other sensitive fields must be excluded or redacted by default.
If limited Customer Content is reasonably necessary to investigate a specific customer issue, access must be restricted to authorized personnel and approved systems; limited to the minimum information reasonably necessary; used only for support, debugging, security, or investigation; recorded in appropriate audit evidence; and retained only for the applicable support or investigation period, subject to the 90-day deletion requirement below unless a documented legal or security exception applies.
Automated diagnostic capabilities must not use Customer Content or identifiable production-session information to train general-purpose or shared AI models. They also must not make final account-suspension, termination, billing, or other materially significant customer decisions without appropriate human review.
10. Cookies, local storage, and similar technologies
Get2Post may use cookies, browser storage, and similar technologies for authentication and session protection, security, preferences such as theme, consent state, and other functions needed to operate the service.
Separately, Customer may configure API request cookies or a request cookie jar as Customer Content for calls to Customer-selected endpoints. Those API request cookies are governed by Customer's instructions and the destination service; they are not the same as Get2Post website cookies.
Browser settings may limit cookies or storage, but blocking necessary technologies may prevent sign-in or other features from working.
11. Google advertising and consent
The Free with ads plan may present Google advertising opportunities after eligible successful direct API request runs. Paid plans bypass the Free with ads advertising gate. The initial provider is Google AdSense, the Google advertising service used by Get2Post.
When Google advertising is enabled, Google may use cookies, local storage, device or online identifiers, IP address, browser or device information, and activity information to deliver, measure, secure, limit, or personalize advertising under Google's terms and privacy notices. Get2Post does not control Google's independent processing.
Provider advertising must remain disabled if required provider configuration, allowed-domain validation, or applicable advertising consent is unavailable or denied. For the United States launch, Get2Post must honor implemented state-law choices concerning targeted advertising and recognized universal opt-out signals where required. Until the required consent, targeted-advertising opt-out, and universal opt-out handling are implemented and validated for the launch context, Production advertising must not be activated.
Users may change an available advertising choice through the implemented consent or privacy control or may contact support@get2post.com. An opt-out may prevent provider advertising from being presented; it does not remove necessary service storage or Customer-configured API request cookies.
12. When we disclose information
We may disclose information only as described below and subject to applicable authorization, contracts, and law.
12.1 Within Customer's organization
Information may be visible to organization owners, administrators, members, workspace collaborators, support delegates, service identities, or integrated clients according to their roles, workspace scope, approvals, and permissions.
12.2 Customer-selected destinations and integrations
We transmit Customer Content to the endpoints, websites, AI providers, MCP clients, webhooks, or integrations Customer instructs Get2Post to use. Customer is responsible for the destination and its authority to receive the data.
12.3 Service providers
We use service-provider categories needed to operate Get2Post, including:
- Microsoft Azure and related Microsoft identity, hosting, database, storage, monitoring, and security services;
- Stripe for payment, subscription, billing portal, invoice, payment-state, and reconciliation services;
- Google for sign-in when selected and for Google AdSense advertising when lawfully enabled;
- email and support-routing services;
- AI providers enabled for selected AI features; and
- monitoring, diagnostics, security, and delivery providers used to operate the service.
Providers receive only the information reasonably needed for the configured service and process it under their applicable agreements and notices. A feature or provider is not used merely because it appears in this list; it must also be configured and enabled.
12.4 Legal, safety, and enforcement
We may preserve or disclose information when required or permitted by law; to respond to lawful process; to cooperate with law enforcement; to protect customers, providers, 3CodeMonkeys, or the public; or to investigate fraud, abuse, unlawful conduct, security harm, or evidence-destruction risk.
13. Retention
We retain information only as long as reasonably needed for operational, legal, billing, tax, security, audit, fraud-prevention, support, investigation, recovery, dispute, enforcement, and backup purposes. Different categories of information have different operational lifecycles, and the internal retention schedule must document the retention and deletion rules for each category of information.
Customer Content ordinarily remains while the applicable account, organization, workspace, or feature is active, unless an authorized user deletes it sooner. After account termination or an authenticated deletion request, Get2Post must delete Customer Content from active systems and complete deletion from ordinary backup systems no later than 90 days afterward.
Narrow exceptions may apply where particular information must be retained for legal compliance, billing and tax records, fraud prevention, security investigations, dispute resolution, enforcement, or preservation of audit evidence. Any information retained under an exception must be limited to what is necessary, protected from unrelated use, and deleted or deidentified when the applicable need ends.
Support and investigation records, including limited Customer Content accessed to investigate a specific customer problem, are retained only for the applicable support or investigation period and remain subject to the 90-day deletion ceiling unless a documented legal or security exception applies. Backup and recovery copies are not a user-accessible archive; Customer Content subject to deletion must age out of ordinary backups within the same 90-day period.
Where a plan or feature requires an approved evidence-retention duration and no duration is configured, Get2Post may fail closed rather than promise or expose unconfigured history.
14. Export, correction, deletion, and account closure
Get2Post provides organization and workspace export functions to authorized users. Workspace exports may contain folders, request definitions, and available lifecycle versions. Organization exports may contain organization settings, members, linked-provider metadata, service identities, invitations, workspaces, requests, environments, and variable definitions and values within the authorized organization boundary. Exports may contain sensitive data and must be protected after download.
Authorized users may update supported account, organization, workspace, and Customer Content fields. Authorized users may delete supported content or a workspace. Personal account deletion removes the account and its live memberships, linked sign-in providers, preferences, and matching invitations, but a last remaining organization owner must transfer ownership or use organization closure. Historical actor, audit, billing, security, and other lawfully retained evidence may remain without preserving a live user account to the extent permitted by Section 13.
Organization closure stops active use. Following account termination or an authenticated deletion request, Customer Content must be deleted from active systems and ordinary backup systems within the 90-day period described in Section 13, subject only to the narrow documented exceptions described there. For a protected export, correction, access, or deletion request, contact support@get2post.com. We verify identity, authority, and organization or workspace ownership before disclosure or mutation and may deny or narrow a request where required or permitted by law.
15. United States privacy rights
Depending on the state where a United States resident lives and subject to applicable exceptions, the resident may have rights to:
- confirm whether personal information is processed and access it;
- correct inaccurate personal information;
- obtain a portable copy of certain information;
- delete certain personal information;
- opt out of targeted advertising or other processing for which applicable law provides an opt-out;
- have a recognized universal opt-out signal honored where required; and
- appeal a denied request where applicable law provides an appeal right.
Submit a request or appeal to
support@get2post.com with the [Privacy]
category if available. Describe the request without sending credentials or
unnecessary Customer Content. We may ask for information needed to verify
identity, authority, residence, and the organization or workspace involved.
An authorized agent must provide evidence of authority as required by
applicable law.
We will not discriminate against a person for exercising an applicable privacy right. A request may affect functionality when the information is necessary to provide the service. We may retain information or deny a request where an exception applies, including for security, fraud prevention, legal compliance, billing, audit evidence, dispute, or the rights of others.
16. Security and incident response
We use administrative, technical, and organizational measures intended to protect information, including authenticated access, role and tenant controls, designated secret handling, redaction, audit evidence, provider signature validation where applicable, and restricted service identities. No system is completely secure.
Customers are responsible for choosing lawful data, minimizing sensitive content, protecting accounts and exports, assigning least privilege, reviewing AI and automated actions, rotating credentials, and monitoring authorized use.
Report suspected account compromise, credential exposure, cross-tenant access,
privacy incident, or vulnerability to
support@get2post.com using the [Security]
category if available. We may take immediate protective action, preserve
evidence, and provide notices required by applicable law.
17. Children
Get2Post is not offered to anyone under 18. We do not knowingly permit a person under 18 to create or use an account. Contact support@get2post.com if you believe a person under 18 provided personal information through Get2Post.
18. Changes and versioned notice
We may update this Policy as Get2Post, providers, law, or supported geography changes. Each release will have a stable version and effective date. Material changes require notice and renewed acceptance through the implemented acceptance flow where required. Historical versions and acceptance evidence must not be silently overwritten.
A future program that would use Customer Content to train or fine-tune a shared or general-purpose AI model requires a separate affirmative opt-in and may not be introduced through a silent update to this Policy or the Terms.
The version and effective date at the top identify this Policy. A future international launch, new advertising provider, or materially different data use requires separate notice, implementation, and validation before activation.
19. Contact us
Privacy questions, rights requests, appeals, and complaints may be sent to:
3CodeMonkeys, LLC
1382 Thistle Lane
Shakopee, MN 55379, USA
support@get2post.com
Please do not include passwords, secret keys, tokens, session cookies, payment card data, or unnecessary Customer Content in a privacy request.