Privacy Policy
This Privacy Policy explains how Zaskaleta Media (including Zaskaleta Flow) processes information when users create media, use optional account and cloud features, and connect supported publishing platforms.
1. Information we process
- Account information you provide or authorize, such as email address, account identifier, profile information, and authentication session data.
- Project information you choose to save to Cloud Projects, including project metadata, prompts, captions, status, and related settings.
- Video, image, audio, captions, titles, publishing settings, and other media you choose to process or publish.
- Connected-platform account information that TikTok, Meta, Google/YouTube, or another supported provider returns after you approve access.
- Authorization tokens or similar credentials required to perform actions you request on connected platforms.
- Basic technical, security, diagnostic, and event information needed to operate, protect, troubleshoot, and improve the service.
2. Local and cloud processing
Some editing, recovery, project, and publish-queue data may be stored locally in your browser or app using browser storage such as localStorage or IndexedDB. If you choose account and Cloud Projects features, selected project information may also be stored in our Supabase-backed cloud workspace.
3. How information is used
Information is used to provide media creation, project recovery, optional cloud synchronization, account connection, direct publishing, publishing history, security, troubleshooting, and compliance functions requested by the user. We do not sell personal information.
4. Third-party platforms
Supported integrations may include TikTok, Instagram/Facebook through Meta, and YouTube through Google. Authorization is performed through the relevant provider's systems. Each provider determines the permissions available, the data returned, and the platform rules that apply.
5. Tokens and credentials
We do not ask users to provide their TikTok, Meta, Google, Instagram, Facebook, or YouTube passwords or multi-factor authentication codes. OAuth or similar access credentials used for publishing integrations are intended only for permissions explicitly granted by the user. Where server-side platform sessions are used, they are protected using secure HTTP-only session mechanisms and are not intentionally exposed to client-side JavaScript.
6. Media used for publishing
For some publishing workflows, media may be uploaded temporarily to a private storage location so that a connected platform can retrieve it using a time-limited signed URL. Temporary publishing media is intended to be deleted after completion and stale temporary media is subject to automated cleanup. Current service limits may restrict the maximum file size accepted by particular storage or platform workflows.
7. Sharing
Information may be transmitted to service providers and connected platforms only as necessary to perform the function requested by the user, such as authentication, cloud synchronization, diagnostics, or media publishing. We do not sell or rent personal information to advertisers.
8. Retention
Local project and queue data remains on the user's device until it is removed by the user, browser/app storage is cleared, or the application removes obsolete recovery data. Cloud project and profile information remains until deleted or no longer needed for the service. Temporary publishing media is intended for short-lived processing and cleanup. Authorization data is removed or invalidated when a supported connection is disconnected, expires, or is otherwise no longer required.
9. Your choices and data requests
You may disconnect supported third-party accounts, delete supported cloud projects, clear local application data, and request access, correction, or deletion of information associated with your use of Zaskaleta Media. You may also revoke authorization directly through the connected platform where available.
For deletion instructions, see Data Deletion.
10. Security
We use technical controls including encrypted or protected session storage, row-level access controls for cloud data, private storage for temporary publish media, secure transport, and request-origin protections. No online system can guarantee absolute security.
11. Children
Zaskaleta Media is not directed to children. Users must meet applicable legal requirements and the eligibility requirements of any third-party platform they connect.
12. International services
Connected platforms and infrastructure providers may process information in countries other than the user's country. Their own privacy terms and transfer mechanisms apply to data they process.
13. Policy updates
This policy may be updated to reflect changes in the service, integrations, infrastructure, legal requirements, or platform requirements. The effective date above will be updated when material changes are made.
14. Contact
Privacy questions and data requests may be sent to zaskaleta86@gmail.com.