Legal

Privacy Policy.

Effective date: May 24, 2026 · Last updated: May 24, 2026

Social Media Studio (“Studio,” “we,” “us,” or “our”) operates the Social Media Studio platform at socialmediastudio.io. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our service. By using Studio, you agree to the practices described here.

01

Information We Collect

Information you provide directly:

  • Account information — your name, email address, and password when you register.
  • Billing information — payment card details processed and stored by our payment processor (Stripe). We never store full card numbers on our servers.
  • Content — posts, captions, prompts, brand kit assets, images, and other content you create or upload within Studio.
  • Communications — messages you send to our support team or via in-app feedback.

Information collected automatically:

  • Usage data — pages visited, features used, actions taken, timestamps, and session duration.
  • Device data — browser type, operating system, IP address, and referring URLs.
  • Cookies and similar technologies — see Section 7 for details.

Information from third parties:

  • Connected social accounts — when you authorize Studio to connect to Instagram, LinkedIn, TikTok, or other platforms, we receive access tokens and the profile data those platforms permit under their OAuth scopes. See Section 4 for more.
02

How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Studio platform and its features.
  • Publish and schedule content to your connected social accounts on your behalf.
  • Generate AI-powered captions, visuals, and strategy insights using the context you provide.
  • Process payments and manage your subscription.
  • Send transactional emails — receipts, password resets, approval notifications, and scheduling confirmations.
  • Send product updates or marketing emails if you have opted in (you can unsubscribe at any time).
  • Detect and prevent fraud, abuse, and security incidents.
  • Comply with legal obligations.
  • Improve and develop new features based on aggregate, anonymized usage patterns.

We do not sell your personal data to third parties, and we do not allow advertisers to target you based on your Studio data.

03

Information Sharing

We share your information only in the following circumstances:

  • Service providers — we work with vetted third-party vendors (payment processors, cloud hosting, email delivery) who process data only on our behalf and under strict data processing agreements.
  • Team members and collaborators — if you are on a Team or Agency plan, other members of your workspace can see the content, posts, and activity within that workspace as permitted by your role settings.
  • Client portals — on the Agency plan, content shared via a client approval portal is accessible to the client link recipient.
  • Legal requirements — we may disclose data when required by law, court order, or to protect the rights, safety, or property of Studio, our users, or the public.
  • Business transfers — in the event of a merger, acquisition, or sale of assets, your data may be transferred. We will notify you before your data becomes subject to a materially different privacy policy.
04

Connected Social Accounts

Studio integrates with third-party social media platforms (such as Instagram, LinkedIn, TikTok, X, Facebook, and others) via their official APIs. When you connect an account:

  • We store OAuth tokens to act on your behalf (publishing posts, reading analytics).
  • We access only the scopes you explicitly authorize during the OAuth flow.
  • We do not read your personal messages, contacts, or private data beyond what is required for scheduling and analytics features.

You can revoke access at any time from within Studio's settings or directly from the third-party platform's settings.

Your use of connected platforms is also governed by each platform's own privacy policy and terms of service.

05

Data Retention

We retain your account data for as long as your account is active. If you cancel your subscription or delete your account:

  • Your content and personal data will be deleted from our active systems within 30 days of account deletion.
  • Backups containing your data may persist for up to 90 days before being purged from our backup systems.
  • We retain billing records and transaction history for up to 7 years as required by applicable financial regulations.
  • Audit trail logs on Team and Agency plans are retained for the duration of the subscription and deleted 30 days after account closure.
06

Security

We implement industry-standard technical and organizational measures to protect your data, including:

  • Encryption in transit (TLS 1.2+) for all data exchanged with our platform.
  • Encryption at rest for sensitive data stored in our databases.
  • Access controls limiting employee access to customer data on a need-to-know basis.
  • Regular security reviews and dependency audits.

No system is completely secure. If you discover a vulnerability, please disclose it responsibly by contacting [email protected].

07

Cookies & Tracking

We use the following types of cookies and similar technologies:

  • Essential cookies — required for authentication, session management, and core functionality. These cannot be disabled.
  • Preference cookies — remember your settings (such as dark/light mode) across sessions.

We do not use advertising or third-party tracking cookies for ad targeting.

08

Your Rights

Depending on your location, you may have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Correction — request that we correct inaccurate or incomplete data.
  • Deletion — request that we delete your personal data (“right to be forgotten”).
  • Portability — request an export of your data in a machine-readable format.
  • Objection — object to certain processing activities, such as marketing emails.
  • Restriction — request that we limit how we process your data in certain circumstances.

To exercise any of these rights, email us at [email protected]. We will respond within 30 days. We may need to verify your identity before processing the request.

If you are located in the European Economic Area, UK, or California, additional rights and obligations may apply under GDPR or CCPA respectively.

09

Children's Privacy

Studio is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with their data, please contact us at [email protected] and we will delete it promptly.

10

Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and by displaying a prominent notice within the app at least 14 days before the changes take effect. The updated policy will be posted at socialmediastudio.io/privacy with a new effective date.

Continued use of Studio after the effective date constitutes acceptance of the revised policy.

11

Contact

For questions about this Privacy Policy or to exercise your rights, contact us at:

PT. Anak Kucing Terbang

Operating as Social Media Studio

Email: [email protected]

Website: socialmediastudio.io