IKIGX Studio — Privacy Policy
Last updated: 2026-07-27
This Privacy Policy explains how Ikigai Systems LLC (“IKIGX,” “we,” “us,” or “our”), doing business as IKIGX Studio, collects, uses, shares, and protects personal data in connection with IKIGX Studio (the “Service”) at studio.ikigx.com, related APIs and apps, and associated marketing pages on ikigx.com.
Related contract terms: Terms of Service. By using the Service or Site, you acknowledge this Policy.
1. Who we are (controller)
| Legal name | Ikigai Systems LLC |
| DBA | IKIGX Studio |
| Address | 30 N Gould St, Ste R, Sheridan, WY 82801, USA |
| Privacy contact | legal@ikigx.com · hi@ikigx.com |
| Website | https://ikigx.com · https://studio.ikigx.com |
For most account, billing, Site analytics, marketing, and security data, Ikigai Systems LLC is the data controller.
For Your Content and personal data of your audience, followers, customers, or message contacts that we process on your instructions to schedule, publish, or analyze posts, we act as a data processor and you are the controller (see Section 6).
2. The Service in brief
IKIGX Studio lets you connect social and messaging accounts and centrally create, store, schedule, publish, analyze, and collaborate on content. Features may include a media library, calendar/queue, team workspaces, analytics, and optional AI-assisted drafting. Available channels depend on your plan and platform APIs.
3. Personal data we collect
3.1 Account and identity
- Name, email address, password (stored as a salted hash) or SSO identifiers, profile picture, organization/workspace name, role, language, timezone.
- If you sign in with a third-party identity provider (e.g. Google), the profile fields and email that provider returns.
- Workspace membership, invitations, and permissions.
3.2 Connected platform data (OAuth)
When you connect a third-party account, we receive and store via that platform’s API, as authorized by you:
- OAuth access and refresh tokens (encrypted at rest), granted scopes, platform usernames/IDs, page/channel IDs, and basic profile metadata (e.g. avatar, follower counts where exposed);
- content and engagement data needed to provide the Service: drafts you create, scheduled and published posts, comments/replies/DMs only if you enable those features, and analytics the platform exposes (impressions, clicks, reach, etc.).
YouTube: Features that use YouTube API Services are also subject to the YouTube Terms of Service and Google Privacy Policy. You can revoke access at any time at Google Account permissions.
We do not ask for or store your social-network passwords.
3.3 Content you upload
Text, images, video, audio, captions, links, hashtags, schedules, prompts, comments, approval notes, calendar metadata, and other materials you upload or generate in the Service (“Your Content”).
3.4 Billing
Plan, subscription status, invoices, billing email/address, tax IDs. Card and bank details are collected by payment processors (e.g. Stripe); we typically receive a tokenized reference, last four digits, brand, and expiry — not full PAN.
3.5 Logs, usage, and device data
IP address, user-agent, browser/OS, device identifiers, referrer, language, approximate location from IP (country/region), feature usage, API calls, error/crash reports, login and security events.
3.6 Communications
Support emails, tickets, in-app messages, surveys, and feedback; engagement metrics for marketing emails where permitted.
3.7 Cookies and similar technologies
We use cookies, local storage, and similar technologies for authentication, security, preferences, analytics, and (on marketing pages) attribution. You can manage non-essential cookies via browser settings and any consent banner we display. Disabling strictly necessary cookies will break parts of the Service.
4. How we use data and legal bases (GDPR-style)
Where the GDPR / UK GDPR applies, legal bases are noted in brackets.
| Purpose | Examples | Legal basis |
|---|---|---|
| Provide the Service | Auth, workspaces, store/publish content, analytics, support | Contract |
| Billing and tax | Invoices, fraud prevention, tax records | Contract; legal obligation |
| Security and abuse prevention | Detect account takeover, spam, attacks; enforce Terms | Legitimate interests; legal obligation |
| Operate and improve | Debugging, uptime, aggregated product analytics, A/B tests | Legitimate interests |
| Communications | Transactional emails; marketing where consented/permitted | Contract; consent or legitimate interests |
| Legal compliance | Respond to lawful requests; defend claims | Legal obligation; legitimate interests |
We do not sell Your Content or connected-platform content. We do not use the content of your private drafts or DMs to advertise third-party products to you.
5. AI-assisted features
Optional AI features (for example drafting, captions, chat assistance, or media analysis) may send your prompts and selected inputs to third-party AI providers that process that data as our subprocessors.
- We instruct those providers not to train their foundation models on your inputs or outputs, and we enable no-training / zero-retention options where the provider offers them.
- If we enable a provider that cannot offer that guarantee for customer content, we will disclose that in our subprocessors information before doing so.
- A current list of AI and other subprocessors is available on request at hi@ikigx.com.
- AI outputs may be inaccurate; you remain responsible for reviewing them before publishing (see Terms of Service).
- Automated decision-making: we do not use AI features to make decisions that produce legal or similarly significant effects about you within the meaning of GDPR Article 22 (for example, we do not use AI alone to approve or deny account eligibility). AI features assist with drafting and analysis of content you control. Automated checks that block certain publish destinations (such as Meta or YouTube) are safety controls for those platforms, not Article 22 decisions about you as a person.
6. Controller vs processor
| Data | Our role | Your role |
|---|---|---|
| Account, billing, Site analytics, marketing, security | Controller | — |
| Your Content and audience/follower/message personal data processed to publish or analyze on your instructions | Processor | Controller |
As controller of audience data, you must have a lawful basis, provide notices, and honor end-user rights. On request we will provide our standard Data Processing Addendum (DPA) incorporating EU SCCs / UK Addendum where required: hi@ikigx.com.
7. Who we share data with
We do not sell personal data. We share data only with:
- Subprocessors / infrastructure — cloud hosting and storage, CDN, databases, observability/error monitoring, support tools, transactional email, analytics, payment processors, AI model providers. They process data on our instructions under contractual safeguards.
- Connected platforms — when you schedule or publish, we transmit content and necessary metadata to the platform you chose; analytics may be retrieved from that platform. That platform’s privacy policy then applies.
- Workspace members — content and activity visible per roles you assign.
- Professional advisors — lawyers, accountants, insurers under confidentiality.
- Authorities — when legally required or to protect against fraud, abuse, or harm. Where lawful we may try to redirect requests to you first.
- Successors — in a merger, acquisition, or asset sale, subject to this Policy or notice of a new policy.
7.1 Subprocessors
| Category | Examples (may change) |
|---|---|
| Hosting / database | Cloud hosting, database, and object-storage providers |
| Payments | Payment processors (for example Stripe) |
| Transactional email providers | |
| AI | Third-party AI providers that process prompts and selected inputs to deliver AI features |
| Observability | Error-monitoring and uptime tools |
For a current list of subprocessors, contact hi@ikigx.com.
8. International transfers
We are based in the United States (Wyoming). Personal data may be processed in the United States and in other countries where our subprocessors operate. Where GDPR/UK GDPR applies and the destination lacks an adequacy decision, we rely on Standard Contractual Clauses (and UK Addendum where applicable) plus technical measures (encryption in transit/at rest, access controls). Contact hi@ikigx.com for information about safeguards.
9. Retention
| Data | Retention |
|---|---|
| Account data | While account is active; after closure, typically up to 90 days for recovery, then delete or anonymize (except longer legal holds) |
| Drafts / media not yet published | Until you delete them or the account is purged |
| Published-post records & analytics | While account is active |
| OAuth tokens | While connection is active; after disconnect, revoke/delete promptly from live systems |
| Billing records | As required by tax/accounting law (often up to 7 years) |
| Security / operational logs | Typically up to 12 months |
| AI prompts / AI inputs logged by Studio (debug, abuse, safety) | Treated as security/ops logs — typically up to 12 months. Prompts stored as part of drafts/posts remain Your Content under the drafts/media rows above. Provider-side retention follows that provider’s zero-retention / DPA settings where configured |
| Signup age attestation / DOB (if collected) | While account is active + up to 90 days after closure (or longer under legal hold) |
| Backups | Encrypted backups roll off on normal schedule (about 30–90 days) after live deletion |
Legal hold exception: we may retain relevant data beyond the periods above when reasonably necessary for litigation, regulatory inquiry, DMCA or other IP disputes, security incidents, fraud/abuse investigations, or CSAM/NCII reporting and related law-enforcement requests. When the hold ends, ordinary retention/deletion resumes.
10. Security
Measures include TLS in transit; encryption of sensitive data and OAuth tokens at rest; password hashing; least-privilege access; multi-factor authentication for personnel with production access where applicable; vendor contractual controls; and incident-response procedures. No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and regulators as required by applicable law.
Connected-platform access tokens are not written to logs in cleartext and are protected with application-level or vault encryption.
11. Your rights
Depending on your location, you may have rights to:
- access and receive a copy of your personal data;
- correct inaccurate data;
- delete data (subject to legal retention);
- object to or restrict certain processing;
- withdraw consent where processing is based on consent;
- data portability;
- opt out of “sale” or “sharing” for cross-context behavioral advertising — we do not sell personal data and do not share it for cross-context behavioral advertising as defined under California law;
- lodge a complaint with a supervisory authority.
Most settings (profile, disconnect platforms, delete content) are available in-product. For other requests: hi@ikigx.com. We will respond within the time required by law (often 30 days) after verifying your identity.
12. California (CCPA/CPRA)
California residents have the rights summarized in Section 11, including know, delete, correct, and non-discrimination. Categories of personal information we collect are described in Section 3; purposes in Section 4. We do not sell personal information and do not share it for cross-context behavioral advertising. To exercise California privacy rights: hi@ikigx.com · subject “Privacy Request”.
13. Children
The Service is not directed to children. We set our contractual age minimum at 18 (see Terms §2 age gate), and we do not knowingly collect personal data from anyone under 18. Separately, for U.S. COPPA, the Service is not designed for, marketed to, or directed at children under 13; if we learn we collected data from a child under 13, we will delete it. If you believe a minor has provided us data, contact hi@ikigx.com.
14. Marketing and cookies choices
Unsubscribe from marketing emails via the link in those emails. Transactional/account emails continue while your account is active. Manage cookies via browser settings and any consent banner.
15. Third-party sites and platforms
Connected platforms and linked sites have their own privacy policies. Review them before connecting accounts. We are not responsible for third-party practices we do not control.
16. Changes
We may update this Policy. Material changes will be announced with reasonable notice (email or in-product). The “Last updated” date will change. Continued use after the effective date means you acknowledge the updated Policy, except where affirmative consent is required.
17. Contact
Ikigai Systems LLC
30 N Gould St, Ste R
Sheridan, WY 82801, USA
| Purpose | Address |
|---|---|
| Privacy requests | legal@ikigx.com · hi@ikigx.com · subject “Privacy Request” |
| Security incidents | legal@ikigx.com · subject “Security” |
| Abuse / CSAM | legal@ikigx.com · subject “Abuse” |
| General | hi@ikigx.com |
For EU/UK residents: you may also contact your local supervisory authority. If we appoint an EU/UK representative, we will update this Policy with those details.