Privacy Policy

Last updated: September 1, 2026

Cabana Studio is operated by CabanaStudio.io LLC, a limited liability company registered in the United States. You can reach us at privacy@cabanastudio.io.

Plain-English summary: we collect what you give us (account, portfolio, and demo-signup details), what your connected tools send us (social analytics, inbox messages, payment events), and basic first-party usage analytics. We use it to run Cabana Studio - we don’t sell personal information. Advertising scripts belonging to third parties - ours on our site, and a creator’s own on the pages we host for them - load only if you accept the cookie notice (Section 2). One exception, stated plainly because the sentence above would otherwise be wrong: we may run Plausible, a cookieless analytics service that sets nothing on your device and records no personal data, and it is not gated behind the notice. Contacts stored in your CRM belong to you; we process them only on your instructions. You can export or delete your data anytime from Dashboard → Settings.

1. Who we are and what this covers

This policy explains how CabanaStudio.io LLC, trading as Cabana Studio (“Cabana,” “we”) handles personal information for: visitors to cabanastudio.io, people who request the demo, creators with accounts, visitors to creator Link Pages we host, and brand contacts whose details creators store in their CRM. Contact us anytime at privacy@cabanastudio.io.

2. Information we collect

  • Account & profile: name, email, social handles, niche, photo, brand colors, portfolio content (work samples, rates, testimonials, bio).
  • Demo access request: the current web demo gate collects your email and records when you accept the Terms, Privacy Policy, and 18+ requirement, so we can grant access and follow up about Cabana. Where abuse prevention is enabled for this form we also keep a keyed, truncated hash of the submitting IP address together with your browser’s user-agent string, solely to tell repeated automated submissions apart from real visitors. We never store the address itself. But hashing is not anonymising, and as with the advertising hash described in Section 4 we would rather say so than imply otherwise: the hash is made with a secret key we hold, and because there are only about four billion possible IPv4 addresses, anyone holding that key could work back from a hash to the address it came from. We keep that key out of the database. But we do not want to overstate what that protects: the hash is a stable stand-in for your address, so anyone who can read our lead table can tell that two submissions came from the same place, key or no key - that is exactly what we use it for. Changing the key does not rewrite hashes we have already stored, so it does not undo that; it only stops new records being linked to old ones, and destroying the old key only removes our ability to work back to the addresses behind them. What actually ends it is deletion, under the retention rule in Section 9. We treat all of it as information about you, not as anonymous data. A separate programmatic demo-request endpoint used by direct integrations currently accepts name, email, Instagram/TikTok/YouTube handles, audience size, niche, and the tool in use, and, where the same abuse prevention is enabled, records the same IP hash and user-agent described above; earlier versions of the web form asked for those details too. If you submit either full-field path, we may retain those details with your lead record.
  • Payments & billing: subscription plan and status, and Stripe identifiers. Card numbers and bank details go directly to Stripe - we never see or store them.
  • Connected accounts: when you connect social analytics (via Phyllo) we receive engagement metrics - reach, impressions, saves, followers, per-post stats. When you connect your inbox or DMs (via Unipile) we receive inbound messages so they can become tracked deals: sender name, email/handle, subject, and message content.
  • Instagram, connected directly (no Facebook): the only DIRECT route - Instagram sends the data to us with no Facebook account, no Facebook Page, and no analytics vendor in between. (The vendor-backed Instagram analytics and Instagram DM connectors described in the bullet above are separate, and still available.) On this route we read your Instagram username, account type, and follower and post counts, plus the two id numbers Instagram issues for the connection - one identifying your Instagram account, the other identifying you to our app specifically - which is how we recognise your account later and how Instagram tells us if you remove us. We also store an access token, encrypted, so the connection keeps working. That token is what lets us read your account’s insights for your weekly brief, and those reads are now switched on: at account level, how many people you reached over the past 28 days and how that reach splits between followers and non-followers; and for your posts, the post itself (its type, caption, link and time), how many people it reached, how many saved, shared, viewed, liked or commented on it, and for Reels the average time people watched. We read your posting history rather than only recent posts, because a rate or a trend computed from a short window is not a rate or a trend. In practice that means all of it, up to a ceiling of a few thousand posts. We do not read anyone else’s posts, and we do not read who liked or commented, only how many did. This connection is for analytics, plus one inbox feature: when someone comments on one of your posts, Instagram notifies us and we file that comment - its text and the commenter’s username - into your Cabana inbox so you can see it alongside your other messages (see “Instagram notifications” below for exactly what is kept and for how long). This connection also now carries your Instagram direct messages into the same inbox: when someone messages your connected professional account, we store the message text, when it was sent, and the sender’s username or, when Instagram doesn’t supply one, the numeric sender id Instagram uses for the conversation - that id is the address a reply is sent to, the same way an email needs an address. DMs and comments stored this way follow the same retention as the rest of your inbox (up to 90 days, deleted sooner if you delete them in the app, destroyed with your account, and deleted when you disconnect the Instagram account they came through). Instagram only lets us send a plain reply within 24 hours of the other person’s last message. There is one exception, and it is worth knowing because it reaches someone a different way: if a person comments on one of your posts, Instagram lets us send a private reply addressed to that comment, and that is not bound by the 24-hour window. It arrives in their direct messages, and it is only ever a reply to a comment they chose to leave on your post - we cannot start a conversation with someone who has not contacted you. (The vendor-connected Instagram inbox described in “Connected accounts” above remains a separate, optional route.)
  • Instagram, connected through Facebook (retired): we no longer offer this route - Instagram connects directly, as described above. It is kept here because it read different things from anyone who used it while it was available, and this describes what that was: your Facebook user id, and - because finding your Instagram account meant asking Facebook which Pages you manage - we briefly received the id, name, and an access token for each of those Pages, then looked up which one your Instagram account was attached to. What we kept from that was the Page we end up using and its access token, your Facebook user id, and the id of the Instagram account attached to that Page - the Facebook id being what lets us revoke our access when you remove us. We discarded the other Pages’ details, and we never read any Page’s posts, followers, or messages. This route did not read the profile fields listed above.
  • Disconnecting Instagram: the quickest way is Dashboard → Connections, which deletes the token and the connection immediately. You can also remove Cabana Studio wherever you granted it: Instagram → Settings → Apps and websites. If you connected through Facebook before that route was retired, it is Facebook → Settings → Business integrations instead, because that is where the permission was granted and removing it in Instagram will not revoke it. Either way the provider notifies us and we delete the token and the connection immediately, without you having to come back here. Deleting your Cabana account destroys the token and the connection record - though not server log lines already written, which age out on their own schedule as described below. Be aware of one more asymmetry, because it decides whether disconnecting here is the whole story: for a Facebook-route connection made before that route was retired we additionally tell Facebook to revoke our access, while for a direct Instagram one we cannot, because Instagram offers apps no way to do it. So disconnecting a direct connection here means we hold nothing and can reach nothing - disconnecting deletes the Instagram comments and direct messages that connection had filed into your Cabana inbox, and the Instagram analytics we had collected through it, so those numbers do not stay in your dashboard (if you also connect Instagram through one of the analytics vendors described above, that is a separate connection with its own data and its own disconnect) - yet Cabana Studio stays listed in your Instagram settings until you remove it there - which is why the app tells you so at the moment you disconnect rather than leaving you to find it later. The same is true if you delete your account without removing us in Instagram first. Anything we already used to build your past weekly briefs stays part of those briefs until you delete your account.
  • YouTube, connected directly: like the direct Instagram route above, YouTube sends the data straight to us, with no analytics vendor in between. When you connect we read your channel’s name, handle, id, and subscriber and video counts from Google, and we store two access credentials, both encrypted - a short-lived one and the longer-lived one Google issues so the connection keeps working. Google’s consent screen shows you exactly the two read-only permissions we ask for (your channel details and its analytics), and you can see or withdraw the grant at any time at myaccount.google.com → Security → Third-party apps. The connection exists to read your channel’s analytics for your weekly brief - your videos and their view, like, comment, share and watch-time numbers, and how your audience splits between subscribers and non-subscribers. We never read anyone else’s channel, your comments, or who watched - only how many did.
  • Disconnecting YouTube: Dashboard → Connections deletes the connection and, unlike most services, we can and do tell Google to revoke our access at the same moment - so there is normally nothing left to clean up on Google’s side (the disconnect message tells you if that revoke didn’t confirm, and where to check). Disconnecting also deletes the YouTube analytics we had stored from your channel - YouTube’s API terms require exactly that, and we apply the same rule to a direct Instagram disconnect, so on either route your past numbers do not stay in your dashboard after you disconnect.
  • Instagram notifications: Both routes above share one notification endpoint, so this applies to a direct connection and to a Facebook-route one made before that route was retired. When Instagram notifies us that something happened on your connected account, what we keep depends on what it was and how the account is connected. A comment on one of your posts, when your account is connected directly (the direct route described above - the only route we offer today), is kept as a message in your Cabana inbox: the comment’s text, the commenter’s username, which of your accounts and posts it was on, and when - that is the feature, a comment you can read has to be stored. Inbox messages are kept for up to 90 days and then deleted on a daily schedule, are deleted sooner if you delete them in the app, and are destroyed with your account. Your own comments and replies are recognised and not filed as incoming. A direct message to your connected account is kept the same way (text, sender identity, time - it is your inbox). Everything else - mentions, message reactions, and every notification for a connection made through the retired Facebook route - is logged as an event only: the id of YOUR connected Instagram account in readable form, Instagram’s own reference numbers for the objects involved, timing and length information, the names of the fields the notification contained, and a scrambled tag standing in for the other person - never the content, name, or handle, which our server reads long enough to measure and file the event, then discards. The tag lets us see that two events came from the same person without recording who they are, and these event logs age out on our hosting provider’s normal schedule.
  • CRM data you store: brand contacts’ names, business emails, companies, deal terms, and notes. You control this data; we process it on your behalf (see Section 7).
  • Contracts you upload: the deal contracts (PDFs) you or a brand attach to a deal, for storage and AI-assisted review (see Section 5).
  • Goals you set (optional): if you use the Goals feature, any income target, follower/growth milestones, and free-text notes you enter about your own business goals.
  • Usage analytics: first-party pageview and click events on our public pages - a random visitor ID (cookie cab_vid), session ID, pages viewed, referrer, UTM parameters, and the “instant” or “email” demo arm shown. After a recorded demo view, a signed first-party cookie can connect that arm to signup and portfolio activation reporting. This part is first-party only and runs only with your consent. See the Cookie Policy.
  • Plausible (if we have it switched on): a privacy-focused analytics service that counts visits to our public pages. It does not load on your dashboard or any other signed-in workspace, and it never records one. It is third-party - the script comes from plausible.io - but it is cookieless: it sets nothing on your device, records nothing personal about you, and cannot follow you to other sites. What it does record is which page was viewed, plus any campaign tags in the link you followed (utm_*, and the click ids ad networks append to their own links) so a visit can be credited to the ad that brought it. On a creator’s public page that address contains their handle - the public name of a public page, not something we look up about the visitor. Pages whose address is itself private, such as a contract link, are never reported at all. For that reason it is not behind the cookie notice and runs on every visit while it is enabled. We mention it because “third-party scripts only run if you accept” would otherwise be an overstatement.
  • Meta’s pixel (only if you accept cookies): if you accept the cookie notice and we have advertising switched on, we load Meta’s pixel script in your browser. From then on it tells Meta which pages of our site you visit, and that you signed up if you do, and it sets Meta’s own _fbp/_fbc cookies for 90 days. It is Meta’s script, so Meta receives that directly - decline the notice and it never loads. Details in the Cookie Policy.
  • A creator’s own pixels, on the pages we host for them: creators can add their own Meta, TikTok, or Google Analytics measurement ids to their public page and media kit. If you accept the cookie notice while visiting one, we load that creator’s chosen scripts and they report your visit to Meta, TikTok, or Google directly - so those companies receive it, not us, and what they do with it is governed by their policies and that creator’s. The creator chooses whether to use this and which services; we host the page it runs on. Declining the notice stops these scripts - though a creator can also set up measurement that runs on our server instead, which the notice does not govern; see Section 4.
  • Product usage (signed in): when you use your dashboard we record which pages you visit and which features you click, tied to your account, so we can see what’s working, improve the product, and help with support. First-party only - never shared with or sold to anyone.
  • Signup attempts: if a signup form submission fails (for example the email already has an account) we keep the attempted email/handle and the failure reason for up to 90 days, to prevent abuse and help you if you get stuck.
  • Logs & events: an audit trail of actions in your account (e.g. deal approved, invoice sent) for security and support.

3. How we use information

  • Provide and operate the Service: portfolios, CRM, media kits, payments, and integrations.
  • Generate analytics-based recommendations, including with AI (see Section 5).
  • Process subscriptions, transaction fees, and payouts through Stripe.
  • Communicate with you: service messages (always) and marketing about Cabana (with opt-out - every marketing email includes an unsubscribe link, honored within 10 business days; or email us to opt out).
  • Measure and improve our site with first-party analytics.
  • Security, fraud prevention, and legal compliance.

For people in the EEA/UK, our legal bases are: performance of a contract (running your account), legitimate interests (first-party analytics, security, B2B follow-up you asked for), consent where required (e.g. non-essential cookies in the EEA/UK), and legal obligations.

We do not sell personal information and we do not share it for cross-context behavioral advertising.

4. Who we share it with

We share personal information only with service providers that help us run Cabana (our subprocessors), with parties you direct us to share with (e.g. a brand paying your invoice via Stripe), and where required by law or in a business transfer.

Instagram, when you connect it for analytics, is not in this table: on that connection the data moves the other way - it comes from Instagram tous at your instruction. The one thing travelling outward is the sign-in request itself, which carries a reference to your Cabana account so the provider can hand you back to the right place afterwards; that is how every “sign in with” button works, and it is the only Cabana data in the exchange. That makes it a source rather than a subprocessor, which is also why it is absent from Annex B of the DPA. Section 2 describes exactly what each connection gives us. Not every connector points that way, though - some are for sending data out on purpose, such as a creator’s own advertising measurement, and those are described where they appear.

Meta appears below because we use it to measure our advertising. Advertising measurement flows to Meta by three routes. In your browser, only if you accept the cookie notice: Meta’s pixel reports your pageviews and your signup to Meta directly, and sets its own cookies (Section 2). From our server, which is not cookie-gated and is described here: when our Meta ad measurement is switched on we send Meta a hashed copy of your email address - once, when we first record your signup - so Meta can credit an ad with it. Your address never leaves us in the clear. But hashing is not anonymising, and we would rather say so than imply otherwise: the hash is deterministic, so Meta can match it against the same address if it already has it. That matching is the mechanism - it is how Meta knows the person who saw an ad is the person who signed up. Alongside the hash, that message carries only what the measurement itself needs: the event name (“CompleteRegistration”), the time it happened, a note that it came from our website, and a scrambled id that exists purely so the same signup is never counted twice. That id is derived from your account, so it is the same every time - but it is one-way, and Meta has nothing to match it against. It carries no name, no readable account identifier of ours, and nothing about what you do inside Cabana. Two things we want to be straight about: it is sent whenever the measurement is configured, not only while a campaign is live; and it is sent without asking, so there is no point beforehand at which you could decline it. Usually that is at signup, but if we switch the measurement on later - or the first attempt failed - it can be sent on a later visit instead, for an account created before then. From our server on a creator’s behalf, if that creator has set up their own Meta advertising measurement: when you send a brand inquiry or sign up to a creator’s list, we pass Meta a hashed copy of the email you entered, so their ad can be credited with it. This one is the creator’s choice and their measurement, not ours - and because it happens on our server rather than in your browser, declining the cookie notice does not stop it. If you would rather we had not, email privacy@cabanastudio.io and we will confirm what was sent and ask Meta to delete it - we cannot un-send it.

ProviderPurposeLocation
VercelHosting and content deliveryUSA
SupabaseDatabase and authenticationUSA/EU
StripePayments, subscriptions, payouts, identity verificationUSA
PhylloSocial analytics ingestion (Instagram, TikTok, YouTube)USA
UnipileInbox and DM ingestion (email, Instagram)EU
Meta (ads measurement)Browser pixel (only if you accept cookies), plus a hashed email sent once from our serverUSA
AnthropicAI recommendations and drafting (Claude)USA
ResendTransactional and notification email deliveryUSA

We’ll update this list as providers change; creators on the DPA are notified of subprocessor changes with a chance to object (see the DPA).

5. AI processing

Several features send data to Anthropic (Claude) to generate AI output. Under our commercial agreement, Anthropic does not use this data to train its models. AI output can be wrong - treat it as a suggestion, not advice.

  • The Growth Brain: your connected analytics, deal, and affiliate data, to generate weekly recommendations, insights, and (where enabled) draft pitches.
  • Contract review: the text of a contract you upload, to generate a plain-English summary of its terms. Before this text is sent, we make a best-effort pass that removes the known brand and contact names plus email addresses and US phone numbers. Unusual spellings, addresses, or names not entered with the deal may remain. Scanned PDFs that cannot be safely extracted and redacted are not sent to the AI.
  • Content planning: a deal’s brand name, product, and usage terms, to draft a content plan and script suggestions for that deliverable.
  • Deal extraction: the text of an inbound message (email, DM, or intake-form submission) that may become a deal, to identify deal details like budget and deliverables automatically.
  • Compose assistance: when you explicitly ask for a draft or rewrite, the recipient’s email address or handle, subject (for email), current message draft, and your drafting instruction, to return an editable suggestion. Nothing is sent to the recipient until you review it and press Send.

6. Marketing use of your name and likeness; public creator gallery

Two features use your profile data beyond running your own account, and both are off by default, revocable anytime, and controlled from Dashboard → Settings → Permissions:

  • Creator gallery & referrals (free). If you opt in, your public page - name, handle, photo, bio, and niche - is listed in our public creator gallery (cabanastudio.io/creators) and may be shown to other creators or prospects as an example.
  • Named features & case studies (paid). If you opt in, we may ask to feature your name, quotes, results, or likeness in our own marketing (ads, decks, case studies). Nothing is used until you separately approve that specific use; each use is compensated or credited as agreed with you.

Revoking either consent stops future use and removes your listing from the public gallery; it does not retract uses already published before you revoked.

7. Brand contacts in creator CRMs (are you a brand?)

If a creator stores your details in their Cabana CRM - for example because you emailed them, DM’d them, or filled in their intake form - that creator is the controller of your information and Cabana processes it on their behalf under our Data Processing Addendum. To access, correct, or delete that data, contact the creator directly (their portfolio page has their details). You can also email privacy@cabanastudio.io and we will forward your request to the creator and assist them in honoring it.

If you attach a contract to an intake form, we make a best-effort pass that removes the known company and contact names plus email addresses and US phone numbers before sending the extracted text to our AI (Anthropic). Unusual spellings, addresses, or names not entered with the deal may remain; a scanned PDF that cannot be safely extracted and redacted is not sent. The AI generates a plain-English summary under the same no-model-training terms described in Section 5, does not act on your behalf or advise you, and the creator still needs to read the contract itself before relying on it.

8. Your rights and choices

  • Export: download a complete copy of your account data anytime in Dashboard → Settings → Your data.
  • Deletion: delete your account and data in Dashboard → Settings → Danger zone, or email us. We delete or de-identify your data within 30 days, except what we must keep for legal, tax, or security reasons (e.g. payment records).
  • Access & correction: most data is editable in your dashboard; for anything else, email us.
  • Marketing opt-out: unsubscribe link in any marketing email, or email us.
  • US state rights (e.g. California, Colorado, Texas): where applicable, you have rights to know, access, correct, delete, and port your data, and to opt out of sales/sharing (we don’t sell or share for behavioral ads). We honor these requests for all users regardless of state, and we won’t discriminate against you for exercising them. Authorized agents may submit requests by email.
  • EEA/UK rights: access, rectification, erasure, restriction, portability, objection, and the right to complain to your supervisory authority. Where we rely on consent you can withdraw it anytime.

9. Retention

We keep your data while your account is active. After deletion or a deletion request, we remove personal data within 30 days, except records we must retain (payment and tax records, security logs) - those are kept only as long as required and then deleted. One specific example: the record of your acceptance of our terms at signup (your email, the terms version, the timestamp, and the IP address and browser it came from) is kept for at least three years even after account deletion, because subscription-law record-keeping rules (e.g. California Business & Professions Code §17602) require it and it is our evidence in any billing dispute. Demo-signup leads that never convert are deleted or de-identified within 24 months of last contact. If you tell us why you are cancelling, the reason you picked from the list (with your plan) is kept as churn statistics - linked to your account while it exists, and unlinked from you if you later delete the account. A connected Instagram account is an exception in the other direction: its access token and connection record are deleted immediately, not within 30 days, whenever you remove Cabana Studio in whichever provider’s settings you granted it - Instagram’s or Facebook’s, as described in Section 2 - or delete your account. Anything you typed in your own words is deleted within 30 days if you deleted your account, and within 180 days if you cancelled but kept it. Backups roll off on a fixed schedule.

10. Security

Data is encrypted in transit (TLS) and at rest with our hosting providers. Access is scoped per creator with row-level security, and payment credentials never touch our servers. No system is perfectly secure - if we learn of a breach affecting your data, we will notify you and regulators as required by law.

11. International transfers

We are US-based and our subprocessors store data primarily in the United States. Where we receive EEA/UK personal data, we rely on appropriate safeguards such as Standard Contractual Clauses with our subprocessors and, where applicable, the EU–US Data Privacy Framework.

12. Children

The Service is for adults 18+ and is not directed to children under 13. We do not knowingly collect children’s data; if you believe a child has provided us data, email us and we will delete it.

13. YouTube API Services

When you connect a YouTube channel directly (Section 2), Cabana Studio acts as an API Client of YouTube API Services. What we read, why, and how long we keep it is described in Sections 2, 3, and 9; this section collects the disclosures YouTube’s developer policies require us to make in one place.

  • By connecting a channel you also agree to the YouTube Terms of Service.
  • Google’s handling of the data it holds about you is governed by the Google Privacy Policy, not by this one.
  • You can revoke our access at any timefrom Google’s security settings, at myaccount.google.com/permissions (Security → Third-party apps with account access). Disconnecting inside Dashboard → Connections normally does this for you - we ask Google to revoke the grant at that moment - but that request can fail, and when it does the disconnect message says so and points you here to finish it by hand.
  • Disconnecting in your dashboard deletes that channel’s stored analytics immediately - its per-video numbers, and every channel-level total we hold for YouTube. Be aware of what that second part means if you have several channels connected: those totals are stored combined rather than per channel, so disconnecting one channel clears the whole stored YouTube history, including the part contributed by channels you are keeping. Syncing resumes from that day forward for the channels still connected; the earlier history is gone, not recalculated.
  • Revoking at Google instead takes longer, and we want to be straight about why.Google does not notify us when you withdraw a grant from your account settings - we find out when our next scheduled sync fails, and we then stop using the connection and delete that channel’s stored per-video analytics within 30 days, which is the window YouTube’s policies allow for data revoked this way. If you want it gone the same day, disconnect in Dashboard → Connectionsrather than only at Google.
  • We also delete a channel’s stored per-video analytics on our own if its connection stops refreshing for 30 days for any other reason, because YouTube’s policies require data to be re-authorized on that cadence rather than kept indefinitely. One honest exception: if you have more than one channel connected, your channel-leveltotals (overall YouTube audience and views over time) are combined across channels rather than kept per channel, so a lapsed channel’s contribution to that combined history remains until your last YouTube connection has been dark for 30 days. Disconnecting the lapsed channel yourself clears it immediately.
  • Audience demographics. Where your channel is large enough for YouTube to report them, we also retrieve aggregate age bands, gender split, and top viewer countries for your audience, and show them on your dashboard and (if you choose to publish it) your media kit. YouTube provides these only as percentages across your whole audience - never per viewer - and suppresses them entirely below its own reporting threshold.
  • We read your channel’s own details and analytics only. We never read another channel’s data, the content of comments, or the identity of individual viewers - the demographics above are percentages of an audience, not facts about people.
  • Questions about any of this: privacy@cabanastudio.io.

14. Changes and contact

We’ll post updates here and, for material changes, notify you by email or in the dashboard before they take effect.

Cabana Studio · privacy@cabanastudio.io