Privacy Policy
Effective October 6, 2026
We collect what the studio needs to run your account and make your creations: your name, email, the files you upload, your prompts and the media generated from them. Generations are processed by the AI providers listed below. If you connect Facebook, Instagram, YouTube, TikTok or LinkedIn, we store the account details and access those platforms give us, encrypted, and use them only for what you ask. We don't sell your data, show ads or use analytics or tracking cookies, and you can download or permanently delete your data from Settings at any time.
1. Who we are
Creative Studio (studio.buildbazaar.io) is operated by Creative Studio (“we”, “us”). We are responsible for the personal data described in this policy. You can reach us at creativestudio@gmail.com.
2. What we collect
Account information
- Your name and email address.
- Your password, stored only as a salted scrypt hash. We never store or see your password itself.
- An optional profile photo, your creation defaults and your brand kit.
Your content
- Images, videos and audio you upload, such as product shots, reference images, music and voice-overs.
- Prompts, scripts and creative settings you enter, including ones an AI agent sends on your behalf.
- Images, videos, voice-overs, captions and final renders generated for you, plus your projects and their revision history.
Technical and security information
- Your active sign-in sessions and the browser (user agent) each one was created from, so you can review and sign out devices in Settings.
- Your IP address, used only to limit repeated sign-in and sign-up attempts.
- Records of generation jobs (what was requested, its status and the result) and a security log of agent access, token changes, paid-generation approvals and account deletion. The security log never contains your email address, prompts, passwords or other secrets.
Connections you set up
- If you link social accounts through our publishing partner, the access key for that link, stored encrypted.
- If you connect a platform directly (Facebook and Instagram, YouTube, TikTok or LinkedIn), the account details and access tokens described in Connected social accounts.
- If you create agent (MCP) access tokens, their names, permissions and expiry. The tokens themselves are stored only as one-way hashes.
3. How we use it
- To provide the service: creating your account, signing you in, storing your projects and generating the media you ask for.
- To publish for you: sending a finished video and its caption to the social platforms you choose, only when you ask.
- To keep the studio secure: limiting abuse, investigating suspicious activity and enforcing our Acceptable Use Policy.
- To support you: answering your questions when you email us.
We process your data to perform our agreement with you (our Terms of Service), for our legitimate interest in keeping the service secure, and to meet legal obligations. We do not use your content to train AI models.
5. Connected social accounts
In Settings → Connections you can connect a social platform directly. You sign in on the platform's own page and choose what to allow; we never see your platform password. For each connection we receive and store:
| Platform | Access you approve | What we store |
|---|---|---|
| Facebook and Instagram (Meta) | See the Facebook Pages you manage and their Instagram professional accounts, and publish to them | Your app-specific Facebook user ID, name, the permissions you granted and a long-lived access token |
| YouTube (Google) | See your YouTube channel and upload videos to it | Your YouTube channel ID and title, the permissions you granted, and access and refresh tokens |
| TikTok | Read your basic profile and post videos to your account | Your TikTok open ID, display name, the permissions you granted, and access and refresh tokens |
| Read your basic profile and post on your behalf | Your LinkedIn member ID, name, the permissions you granted and an access token |
- How we use it: to show which account is connected and, when you ask us to, to publish the content you approve to that account. We never post without your instruction, and we don't use platform data for advertising, sell it, share it with other customers or use it to train AI models.
- How we protect it: access and refresh tokens are encrypted with AES-256-GCM and bound to your account. They are never shown in the studio, included in your data download or written to our logs.
- How long we keep it: until you disconnect the account or delete your studio account. Tokens also expire on the platform's schedule; LinkedIn and Meta tokens last about 60 days.
- How to remove it: select Disconnect in Settings → Connections. We revoke our access at the platform where it offers a way to do that and delete the stored data immediately. You can also remove our access on the platform: Facebook Business integrations, Google security settings, TikTok's Apps and services permissions in the app, or LinkedIn Permitted services.
YouTube and Google
Creative Studio uses YouTube API Services. By connecting YouTube you also agree to the YouTube Terms of Service, and Google's handling of your information is described in the Google Privacy Policy. You can revoke Creative Studio's access to your Google account at any time on the Google security settings page.
Creative Studio's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. International processing
Our providers may process data in countries other than yours, including the United States. Where the law requires it, we rely on appropriate safeguards such as standard contractual clauses.
7. How long we keep it
- Account data and content are kept until you delete them or delete your account.
- Sign-in sessions expire after 7 days, or sooner if you sign out or revoke them.
- Agent tokens expire after the period you choose (30, 90 or 365 days) unless you choose no expiry or revoke them earlier.
- Media links sent for social publishing expire after 24 hours.
- Connected social accounts are kept until you disconnect them or delete your account (see Connected social accounts).
When you delete your account, we remove your profile, sessions, tokens, projects, uploads, generations, profile photo, voice previews and social connections (revoking our access at the platforms that support it), and cancel running generations. If a step fails we retry it automatically. Afterwards we keep only a deletion record and security log entries tied to a random account ID. Neither contains your name, email or credentials. Residual copies may remain in backups for a limited period until they are overwritten.
8. Your rights and choices
Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to or restrict how we use it. In the studio you can:
- Download your data: Settings → Data & privacy → Download my data.
- Correct your details: update your name and photo under Settings → Profile, and your email and password under Account & security.
- Delete everything: Settings → Data & privacy → Delete account.
- Disconnect access: revoke sessions, agent tokens and social connections in Settings at any time.
For anything else, email creativestudio@gmail.com. We will respond within the time the law requires and won't treat you differently for exercising your rights. You can also complain to your local data protection authority.
9. Deleting your data
- Everything: Settings → Data & privacy → Delete account removes your account and all the data listed in How long we keep it.
- One platform: Settings → Connections → Disconnect, or remove our access on the platform as described in Connected social accounts.
- From Facebook: removing Creative Studio in your Facebook settings sends us an automatic deletion request. We delete the data we received from Facebook and Instagram and give Facebook a confirmation code; you can check its status on our data deletion page.
- By email: write to creativestudio@gmail.com and we'll complete the deletion within 7 days.
10. Security
Passwords are hashed with scrypt, the session cookie can't be read by page scripts, social connection keys and platform access tokens are encrypted, agent tokens are stored only as hashes and every agent action is limited to its owner's account. No system is perfectly secure, so use a unique password and tell us if you suspect unauthorized access.
11. Children
The studio is for adults (see our Terms of Service) and is not directed at children. We don't knowingly collect data from anyone under 18. If you believe a child has given us personal data, contact us and we will delete it.
13. Changes to this policy
If we change how we handle your data, we'll update this page and its effective date. For significant changes we'll also tell you in the studio before they take effect.
Questions?
Email creativestudio@gmail.com and we'll get back to you.