Privacy Policy
Last updated: 21 September 2026
iStudio (“we”, “us”) is a social publishing tool that lets you connect your social accounts and schedule or publish posts to them. This policy explains what we collect, why, how we protect it, and how you can delete it.
Who we are
iStudio is operated as part of the NavaTOP product family. You sign in with your GenAI ID account, then optionally connect the social accounts you manage — on Facebook, Instagram, Threads, TikTok, YouTube, or Pinterest — so that iStudio can publish content on your behalf. We only ever act on the accounts and content you explicitly connect and submit.
What we collect
- Account profile — when you sign in through GenAI ID single sign-on, we store your account identifier, email address, display name, and avatar.
- Connected accounts — when you connect an account (a Facebook or Instagram account, a Threads, TikTok, YouTube, or Pinterest account) through that platform’s login, we store the account’s ID, name, and picture, and an access token that lets us publish to it. Tokens are encrypted at rest and are used only to publish the content you schedule.
- Content you create — the captions, links, media (images/videos) you upload, and the schedule times of the posts you build in iStudio.
- Publishing records — the status of each scheduled post and the ID of the resulting post on the platform, so we can show you what published and retry failures.
- Session data — a login cookie holding an opaque session identifier.
We do not collect payment information, and we do not run third-party advertising or analytics trackers.
How we use it
- To authenticate you and keep you signed in.
- To publish or schedule the posts you create to the accounts you connected.
- To show you the status and history of your posts and connected accounts.
We do not use your content or account data for any purpose other than delivering the publishing features you asked for.
How we share it
We share data only where it is necessary to run the service:
- The platform you publish to — when you publish or schedule a post, we send that post’s content, and use the access token for that account, to the platform’s API: Meta (Facebook, Instagram, Threads), TikTok, Google (YouTube), or Pinterest. Each platform’s handling of that data is governed by its own policies. We only ever send data to a platform you connected yourself, and only the content you chose to publish there.
- Cloudflare — our application, database, and media storage run on Cloudflare’s infrastructure.
Because a platform must be able to fetch your images and videos in order to publish them, media you upload is served from a public content-delivery URL while it is in use.
We do not sell your data or share it with any other third parties for advertising or marketing.
Where it is stored and how it is protected
Data is stored in Cloudflare D1 (database) and Cloudflare KV (sessions and uploaded media). Account access tokens are encrypted before being stored. All traffic is served over HTTPS.
Data retention
We keep your account, connected accounts, content, and publishing records for as long as your account is active. When you disconnect an account, its stored access token is deleted. When you delete your data or account (see below), we remove your records from our systems.
Deleting your data
You are in control of your data at any time:
- Disconnect an account — removing a connected account in iStudio deletes the stored access token for it immediately.
- Delete everything — to delete your iStudio account and all associated data (profile, connected accounts, content, and publishing history), email us at the address below with the subject “Delete my data”, using the email on your account. We will process the deletion and confirm when it is complete.
- Revoke access from the platform — you can also remove iStudio at any time from the platform’s own app settings (for example, on Facebook under Settings & Privacy → Settings → Apps and Websites), which revokes our access to that account.
Children’s privacy
iStudio is not directed to children under 13, and we do not knowingly collect data from them.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the “Last updated” date at the top of this page.
Contact
Questions about this policy or requests to delete your data: contact@navatop.com.