Privacy Policy
Last updated: August 8, 2026
1. Who we are and what this covers
This policy explains how Cabana Studio (“Cabana,” “we”) handles personal information for: visitors to cabanastudio.io, people who request the demo, creators with accounts, visitors to creator Link Pages we host, and brand contacts whose details creators store in their CRM. Contact us anytime at privacy@cabanastudio.io.
2. Information we collect
- Account & profile: name, email, social handles, niche, photo, brand colors, portfolio content (work samples, rates, testimonials, bio).
- Demo access request: name, email, Instagram/TikTok/YouTube handles, audience size, and the tool you currently use - so we can follow up about Cabana and tailor the demo.
- Payments & billing: subscription plan and status, and Stripe identifiers. Card numbers and bank details go directly to Stripe - we never see or store them.
- Connected accounts: when you connect social analytics (via Phyllo) we receive engagement metrics - reach, impressions, saves, followers, per-post stats. When you connect your inbox or DMs (via Unipile) we receive inbound messages so they can become tracked deals: sender name, email/handle, subject, and message content.
- Instagram, connected directly (no Facebook): Instagram offers two ways to connect and this bullet covers one of them - the direct route, where Instagram sends the data to us with no Facebook account and no analytics vendor in between. On this route we read your Instagram username, account type, and follower and post counts, plus the two id numbers Instagram issues for the connection - one identifying your Instagram account, the other identifying you to our app specifically - which is how we recognise your account later and how Instagram tells us if you remove us. We also store an access token, encrypted, so the connection keeps working. That token is what lets us read your account’s insights for your weekly brief, and those reads are now switched on: at account level, how many people you reached over the past 28 days and how that reach splits between followers and non-followers; and for your posts, the post itself (its type, caption, link and time), how many people it reached, how many saved, shared, viewed, liked or commented on it, and for Reels the average time people watched. We read your posting history rather than only recent posts, because a rate or a trend computed from a short window is not a rate or a trend. In practice that means all of it, up to a ceiling of a few thousand posts. We do not read anyone else’s posts, and we do not read who liked or commented, only how many did. This connection is for analytics: we do not store the text of your Instagram direct messages or comments through it. (Connecting your Instagram inbox is a separate, optional feature - see “Connected accounts” above.)
- Instagram, connected through Facebook: the other route. It reads different things, so it gets its own description: your Facebook user id, and - because finding your Instagram account means asking Facebook which Pages you manage - so we briefly receive the id, name, and an access token for each of those Pages, then look up which one your Instagram account is attached to. What we keep from that is the Page we end up using and its access token, your Facebook user id, and the id of the Instagram account attached to that Page - the Facebook id being what lets us revoke our access when you remove us. We discard the other Pages’ details, and we never read any Page’s posts, followers, or messages. This route does not read the profile fields listed above.
- Disconnecting Instagram: the quickest way is Dashboard → Connections, which deletes the token and the connection immediately. You can also remove Cabana Studio wherever you granted it, which depends on which of the two routes above you used. Connected Instagram directly: Instagram → Settings → Apps and websites. Connected through Facebook: Facebook → Settings → Business integrations, because that is where the permission was granted and removing it in Instagram will not revoke it. Either way the provider notifies us and we delete the token and the connection immediately, without you having to come back here. Deleting your Cabana account destroys the token and the connection record - though not server log lines already written, which age out on their own schedule as described below. Be aware of one more asymmetry, because it decides whether disconnecting here is the whole story: for a Facebook-route connection we additionally tell Facebook to revoke our access, while for a direct Instagram one we cannot, because Instagram offers apps no way to do it. So disconnecting a direct connection here means we hold nothing and can reach nothing, yet Cabana Studio stays listed in your Instagram settings until you remove it there - which is why the app tells you so at the moment you disconnect rather than leaving you to find it later. The same is true if you delete your account without removing us in Instagram first. Anything we already used to build your past weekly briefs stays part of those briefs until you delete your account.
- YouTube, connected directly: like the direct Instagram route above, YouTube sends the data straight to us, with no analytics vendor in between. When you connect we read your channel’s name, handle, id, and subscriber and video counts from Google, and we store two access credentials, both encrypted - a short-lived one and the longer-lived one Google issues so the connection keeps working. Google’s consent screen shows you exactly the two read-only permissions we ask for (your channel details and its analytics), and you can see or withdraw the grant at any time at myaccount.google.com → Security → Third-party apps. The connection exists to read your channel’s analytics for your weekly brief - your videos and their view, like, comment, share and watch-time numbers, and how your audience splits between subscribers and non-subscribers. We never read anyone else’s channel, your comments, or who watched - only how many did.
- Disconnecting YouTube: Dashboard → Connections deletes the connection and, unlike most services, we can and do tell Google to revoke our access at the same moment - so there is normally nothing left to clean up on Google’s side (the disconnect message tells you if that revoke didn’t confirm, and where to check). Disconnecting also deletes the YouTube analytics we had stored from your channel, because YouTube’s API terms require exactly that - so unlike an Instagram disconnect, your past YouTube numbers do not stay in your dashboard after you disconnect.
- Instagram notifications, either way you connected: Both routes above share one notification endpoint, so this applies to either. Separately from your account data, if Instagram notifies us that a message, comment, or mention arrived, we log that it happened. What that line holds is the id of YOUR connected Instagram account in readable form, Instagram’s own reference numbers for the objects involved (the message, the comment, the post it was on), timing and length information, the names of the fields the notification contained, and a scrambled tag standing in for the other person. What it never holds is content - not the message, not the comment, not a name or handle. What passes through but is not kept: the notification itself contains the message or comment text and the sender’s username, and our server reads it - long enough to measure the length and file the event - then discards it. So the rule is the boundary rather than a fixed list: we receive whatever Instagram sends, and what survives is identifiers and shape, never what was said. The tag lets us see that two events came from the same person without recording who they are, and these logs age out on our hosting provider’s normal schedule.
- CRM data you store: brand contacts’ names, business emails, companies, deal terms, and notes. You control this data; we process it on your behalf (see Section 7).
- Contracts you upload: the deal contracts (PDFs) you or a brand attach to a deal, for storage and AI-assisted review (see Section 5).
- Goals you set (optional): if you use the Goals feature, any income target, follower/growth milestones, and free-text notes you enter about your own business goals.
- Usage analytics: first-party pageview and click events on our public pages - a random visitor ID (cookie
cab_vid), session ID, pages viewed, referrer, and UTM parameters. This part is first-party only. See the Cookie Policy. - Plausible (if we have it switched on): a privacy-focused analytics service that counts visits to our public pages. It does not load on your dashboard or any other signed-in workspace, and it never records one. It is third-party - the script comes from plausible.io - but it is cookieless: it sets nothing on your device, records nothing personal about you, and cannot follow you to other sites. What it does record is which page was viewed, plus any campaign tags in the link you followed (
utm_*, and the click ids ad networks append to their own links) so a visit can be credited to the ad that brought it. On a creator’s public page that address contains their handle - the public name of a public page, not something we look up about the visitor. Pages whose address is itself private, such as a contract link, are never reported at all. For that reason it is not behind the cookie notice and runs on every visit while it is enabled. We mention it because “third-party scripts only run if you accept” would otherwise be an overstatement. - Meta’s pixel (only if you accept cookies): if you accept the cookie notice and we have advertising switched on, we load Meta’s pixel script in your browser. From then on it tells Meta which pages of our site you visit, and that you signed up if you do, and it sets Meta’s own
_fbp/_fbccookies for 90 days. It is Meta’s script, so Meta receives that directly - decline the notice and it never loads. Details in the Cookie Policy. - A creator’s own pixels, on the pages we host for them: creators can add their own Meta, TikTok, or Google Analytics measurement ids to their public page and media kit. If you accept the cookie notice while visiting one, we load that creator’s chosen scripts and they report your visit to Meta, TikTok, or Google directly - so those companies receive it, not us, and what they do with it is governed by their policies and that creator’s. The creator chooses whether to use this and which services; we host the page it runs on. Declining the notice stops these scripts - though a creator can also set up measurement that runs on our server instead, which the notice does not govern; see Section 4.
- Product usage (signed in): when you use your dashboard we record which pages you visit and which features you click, tied to your account, so we can see what’s working, improve the product, and help with support. First-party only - never shared with or sold to anyone.
- Signup attempts: if a signup form submission fails (for example the email already has an account) we keep the attempted email/handle and the failure reason for up to 90 days, to prevent abuse and help you if you get stuck.
- Logs & events: an audit trail of actions in your account (e.g. deal approved, invoice sent) for security and support.
3. How we use information
- Provide and operate the Service: portfolios, CRM, media kits, payments, and integrations.
- Generate analytics-based recommendations, including with AI (see Section 5).
- Process subscriptions, transaction fees, and payouts through Stripe.
- Communicate with you: service messages (always) and marketing about Cabana (with opt-out - every marketing email includes an unsubscribe link, honored within 10 business days; or email us to opt out).
- Measure and improve our site with first-party analytics.
- Security, fraud prevention, and legal compliance.
For people in the EEA/UK, our legal bases are: performance of a contract (running your account), legitimate interests (first-party analytics, security, B2B follow-up you asked for), consent where required (e.g. non-essential cookies in the EEA/UK), and legal obligations.
We do not sell personal information and we do not share it for cross-context behavioral advertising.
4. Who we share it with
We share personal information only with service providers that help us run Cabana (our subprocessors), with parties you direct us to share with (e.g. a brand paying your invoice via Stripe), and where required by law or in a business transfer.
Instagram, when you connect it for analytics, is not in this table: on that connection the data moves the other way - it comes from Instagram tous at your instruction. The one thing travelling outward is the sign-in request itself, which carries a reference to your Cabana account so the provider can hand you back to the right place afterwards; that is how every “sign in with” button works, and it is the only Cabana data in the exchange. That makes it a source rather than a subprocessor, which is also why it is absent from Annex B of the DPA. Section 2 describes exactly what each connection gives us. Not every connector points that way, though - some are for sending data out on purpose, such as a creator’s own advertising measurement, and those are described where they appear.
Meta appears below because we use it to measure our advertising. Advertising measurement flows to Meta by three routes. In your browser, only if you accept the cookie notice: Meta’s pixel reports your pageviews and your signup to Meta directly, and sets its own cookies (Section 2). From our server, which is not cookie-gated and is described here: when our Meta ad measurement is switched on we send Meta a hashed copy of your email address - once, when we first record your signup - so Meta can credit an ad with it. Your address never leaves us in the clear. But hashing is not anonymising, and we would rather say so than imply otherwise: the hash is deterministic, so Meta can match it against the same address if it already has it. That matching is the mechanism - it is how Meta knows the person who saw an ad is the person who signed up. Alongside the hash, that message carries only what the measurement itself needs: the event name (“CompleteRegistration”), the time it happened, a note that it came from our website, and a scrambled id that exists purely so the same signup is never counted twice. That id is derived from your account, so it is the same every time - but it is one-way, and Meta has nothing to match it against. It carries no name, no readable account identifier of ours, and nothing about what you do inside Cabana. Two things we want to be straight about: it is sent whenever the measurement is configured, not only while a campaign is live; and it is sent without asking, so there is no point beforehand at which you could decline it. Usually that is at signup, but if we switch the measurement on later - or the first attempt failed - it can be sent on a later visit instead, for an account created before then. From our server on a creator’s behalf, if that creator has set up their own Meta advertising measurement: when you send a brand inquiry or sign up to a creator’s list, we pass Meta a hashed copy of the email you entered, so their ad can be credited with it. This one is the creator’s choice and their measurement, not ours - and because it happens on our server rather than in your browser, declining the cookie notice does not stop it. If you would rather we had not, email privacy@cabanastudio.io and we will confirm what was sent and ask Meta to delete it - we cannot un-send it.
| Provider | Purpose | Location |
|---|---|---|
| Vercel | Hosting and content delivery | USA |
| Supabase | Database and authentication | USA/EU |
| Stripe | Payments, subscriptions, payouts, identity verification | USA |
| Phyllo | Social analytics ingestion (Instagram, TikTok, YouTube) | USA |
| Unipile | Inbox and DM ingestion (email, Instagram) | EU |
| Meta (ads measurement) | Browser pixel (only if you accept cookies), plus a hashed email sent once from our server | USA |
| Anthropic | AI recommendations and drafting (Claude) | USA |
| Resend | Transactional and notification email delivery | USA |
We’ll update this list as providers change; creators on the DPA are notified of subprocessor changes with a chance to object (see the DPA).
5. AI processing
Several features send data to Anthropic (Claude) to generate AI output. Under our commercial agreement, Anthropic does not use this data to train its models. AI output can be wrong - treat it as a suggestion, not advice.
- The Growth Brain: your connected analytics, deal, and affiliate data, to generate weekly recommendations, insights, and (where enabled) draft pitches.
- Contract review: the text of a contract you upload, to generate a plain-English summary of its terms. Before this text is sent, we automatically strip the brand’s name, contact details, and any email/phone number found in the document - the AI reviews deal terms, not who the brand is.
- Content planning: a deal’s brand name, product, and usage terms, to draft a content plan and script suggestions for that deliverable.
- Deal extraction: the text of an inbound message (email, DM, or intake-form submission) that may become a deal, to identify deal details like budget and deliverables automatically.
6. Marketing use of your name and likeness; public creator gallery
Two features use your profile data beyond running your own account, and both are off by default, revocable anytime, and controlled from Dashboard → Settings → Permissions:
- Creator gallery & referrals (free). If you opt in, your public page - name, handle, photo, bio, and niche - is listed in our public creator gallery (cabanastudio.io/creators) and may be shown to other creators or prospects as an example.
- Named features & case studies (paid). If you opt in, we may ask to feature your name, quotes, results, or likeness in our own marketing (ads, decks, case studies). Nothing is used until you separately approve that specific use; each use is compensated or credited as agreed with you.
Revoking either consent stops future use and removes your listing from the public gallery; it does not retract uses already published before you revoked.
7. Brand contacts in creator CRMs (are you a brand?)
If a creator stores your details in their Cabana CRM - for example because you emailed them, DM’d them, or filled in their intake form - that creator is the controller of your information and Cabana processes it on their behalf under our Data Processing Addendum. To access, correct, or delete that data, contact the creator directly (their portfolio page has their details). You can also email privacy@cabanastudio.io and we will forward your request to the creator and assist them in honoring it.
If you attach a contract to an intake form, we first strip your company name, contact details, and any email/phone number found in the document, then send that text to our AI (Anthropic) to generate a plain-English summary for the creator, under the same no-model-training terms described in Section 5 - the AI reviews deal terms, not who you are, does not act on your behalf or advise you, and the creator still needs to read the contract itself before relying on that summary.
8. Your rights and choices
- Export: download a complete copy of your account data anytime in Dashboard → Settings → Your data.
- Deletion: delete your account and data in Dashboard → Settings → Danger zone, or email us. We delete or de-identify your data within 30 days, except what we must keep for legal, tax, or security reasons (e.g. payment records).
- Access & correction: most data is editable in your dashboard; for anything else, email us.
- Marketing opt-out: unsubscribe link in any marketing email, or email us.
- US state rights (e.g. California, Colorado, Texas): where applicable, you have rights to know, access, correct, delete, and port your data, and to opt out of sales/sharing (we don’t sell or share for behavioral ads). We honor these requests for all users regardless of state, and we won’t discriminate against you for exercising them. Authorized agents may submit requests by email.
- EEA/UK rights: access, rectification, erasure, restriction, portability, objection, and the right to complain to your supervisory authority. Where we rely on consent you can withdraw it anytime.
9. Retention
We keep your data while your account is active. After deletion or a deletion request, we remove personal data within 30 days, except records we must retain (payment and tax records, security logs) - those are kept only as long as required and then deleted. One specific example: the record of your acceptance of our terms at signup (your email, the terms version, the timestamp, and the IP address and browser it came from) is kept for at least three years even after account deletion, because subscription-law record-keeping rules (e.g. California Business & Professions Code §17602) require it and it is our evidence in any billing dispute. Demo-signup leads that never convert are deleted or de-identified within 24 months of last contact. If you tell us why you are cancelling, the reason you picked from the list (with your plan) is kept as churn statistics - linked to your account while it exists, and unlinked from you if you later delete the account. A connected Instagram account is an exception in the other direction: its access token and connection record are deleted immediately, not within 30 days, whenever you remove Cabana Studio in whichever provider’s settings you granted it - Instagram’s or Facebook’s, as described in Section 2 - or delete your account. Anything you typed in your own words is deleted within 30 days if you deleted your account, and within 180 days if you cancelled but kept it. Backups roll off on a fixed schedule.
10. Security
Data is encrypted in transit (TLS) and at rest with our hosting providers. Access is scoped per creator with row-level security, and payment credentials never touch our servers. No system is perfectly secure - if we learn of a breach affecting your data, we will notify you and regulators as required by law.
11. International transfers
We are US-based and our subprocessors store data primarily in the United States. Where we receive EEA/UK personal data, we rely on appropriate safeguards such as Standard Contractual Clauses with our subprocessors and, where applicable, the EU–US Data Privacy Framework.
12. Children
The Service is for adults 18+ and is not directed to children under 13. We do not knowingly collect children’s data; if you believe a child has provided us data, email us and we will delete it.
13. Changes and contact
We’ll post updates here and, for material changes, notify you by email or in the dashboard before they take effect.
Cabana Studio · privacy@cabanastudio.io