Legal

Privacy Policy

Last updated 2026-05-05

1. What we collect

When you sign up we collect your email and any data you choose to add: 12 onboarding answers, voice baseline text, channel URLs, scripts you generate, posts you create, and YouTube performance numbers you record manually. We collect operational metadata (timestamps, IDs, AI cost) needed to run the service.

2. How we use it

To run the studio: store your projects, generate content in your voice, enforce billing caps, surface analytics. We do not sell your data. We do not train external models on your content.

3. Sub-processors

We rely on specialized vendors. Each only sees what they need.

VendorPurposeRegion
SupabaseDatabase, auth, file storageUS (managed Postgres)
VercelHosting + serverless runtimeGlobal CDN, US origin
StripePayments + billingUS
OpenAIText embeddings (RAG)US
xAIText generation (scripts, posts)US
ResendTransactional email (magic link)US
Upstash RedisCache + cost-cap countersGlobal geo-replicated
Trigger.devBackground jobs (when wired)US

4. Data retention

Active project data lives as long as your account does. Account deletion soft-deletes for 30 days (recovery window) then hard-deletes via cascade. AI generation audit rows retain for 1 year (cost reconciliation + abuse signals). Idempotency keys auto-expire 24 hours.

5. Your rights (GDPR + CCPA)

You can export all your data, correct it, or delete the account. Email nabilakhanblogs@gmail.com.

6. AI disclosure

Generated content is marked with C2PA Content Credentials when image generation is used. You always see what the AI produced. No auto-publish without your click.

7. Cookies + sessions

One httpOnly session cookie. No third-party tracking pixels. Analytics (PostHog) when enabled is privacy-respecting and IP-truncated.

8. Contact

Email nabilakhanblogs@gmail.com for any privacy question, data request, or sub-processor concern.