IKIGX Studio · Legal

IKIGX Studio

Privacy Policy

IKIGX Studio — Privacy Policy

Last updated: 2026-07-27

This Privacy Policy explains how Ikigai Systems LLC (“IKIGX,” “we,” “us,” or “our”), doing business as IKIGX Studio, collects, uses, shares, and protects personal data in connection with IKIGX Studio (the “Service”) at studio.ikigx.com, related APIs and apps, and associated marketing pages on ikigx.com.

Related contract terms: Terms of Service. By using the Service or Site, you acknowledge this Policy.


1. Who we are (controller)

Legal nameIkigai Systems LLC
DBAIKIGX Studio
Address30 N Gould St, Ste R, Sheridan, WY 82801, USA
Privacy contactlegal@ikigx.com · hi@ikigx.com
Websitehttps://ikigx.com · https://studio.ikigx.com

For most account, billing, Site analytics, marketing, and security data, Ikigai Systems LLC is the data controller.

For Your Content and personal data of your audience, followers, customers, or message contacts that we process on your instructions to schedule, publish, or analyze posts, we act as a data processor and you are the controller (see Section 6).


2. The Service in brief

IKIGX Studio lets you connect social and messaging accounts and centrally create, store, schedule, publish, analyze, and collaborate on content. Features may include a media library, calendar/queue, team workspaces, analytics, and optional AI-assisted drafting. Available channels depend on your plan and platform APIs.


3. Personal data we collect

3.1 Account and identity

  • Name, email address, password (stored as a salted hash) or SSO identifiers, profile picture, organization/workspace name, role, language, timezone.
  • If you sign in with a third-party identity provider (e.g. Google), the profile fields and email that provider returns.
  • Workspace membership, invitations, and permissions.

3.2 Connected platform data (OAuth)

When you connect a third-party account, we receive and store via that platform’s API, as authorized by you:

  • OAuth access and refresh tokens (encrypted at rest), granted scopes, platform usernames/IDs, page/channel IDs, and basic profile metadata (e.g. avatar, follower counts where exposed);
  • content and engagement data needed to provide the Service: drafts you create, scheduled and published posts, comments/replies/DMs only if you enable those features, and analytics the platform exposes (impressions, clicks, reach, etc.).

YouTube: Features that use YouTube API Services are also subject to the YouTube Terms of Service and Google Privacy Policy. You can revoke access at any time at Google Account permissions.

We do not ask for or store your social-network passwords.

3.3 Content you upload

Text, images, video, audio, captions, links, hashtags, schedules, prompts, comments, approval notes, calendar metadata, and other materials you upload or generate in the Service (“Your Content”).

3.4 Billing

Plan, subscription status, invoices, billing email/address, tax IDs. Card and bank details are collected by payment processors (e.g. Stripe); we typically receive a tokenized reference, last four digits, brand, and expiry — not full PAN.

3.5 Logs, usage, and device data

IP address, user-agent, browser/OS, device identifiers, referrer, language, approximate location from IP (country/region), feature usage, API calls, error/crash reports, login and security events.

3.6 Communications

Support emails, tickets, in-app messages, surveys, and feedback; engagement metrics for marketing emails where permitted.

3.7 Cookies and similar technologies

We use cookies, local storage, and similar technologies for authentication, security, preferences, analytics, and (on marketing pages) attribution. You can manage non-essential cookies via browser settings and any consent banner we display. Disabling strictly necessary cookies will break parts of the Service.


4. How we use data and legal bases (GDPR-style)

Where the GDPR / UK GDPR applies, legal bases are noted in brackets.

PurposeExamplesLegal basis
Provide the ServiceAuth, workspaces, store/publish content, analytics, supportContract
Billing and taxInvoices, fraud prevention, tax recordsContract; legal obligation
Security and abuse preventionDetect account takeover, spam, attacks; enforce TermsLegitimate interests; legal obligation
Operate and improveDebugging, uptime, aggregated product analytics, A/B testsLegitimate interests
CommunicationsTransactional emails; marketing where consented/permittedContract; consent or legitimate interests
Legal complianceRespond to lawful requests; defend claimsLegal obligation; legitimate interests

We do not sell Your Content or connected-platform content. We do not use the content of your private drafts or DMs to advertise third-party products to you.


5. AI-assisted features

Optional AI features (for example drafting, captions, chat assistance, or media analysis) may send your prompts and selected inputs to third-party AI providers that process that data as our subprocessors.

  • We instruct those providers not to train their foundation models on your inputs or outputs, and we enable no-training / zero-retention options where the provider offers them.
  • If we enable a provider that cannot offer that guarantee for customer content, we will disclose that in our subprocessors information before doing so.
  • A current list of AI and other subprocessors is available on request at hi@ikigx.com.
  • AI outputs may be inaccurate; you remain responsible for reviewing them before publishing (see Terms of Service).
  • Automated decision-making: we do not use AI features to make decisions that produce legal or similarly significant effects about you within the meaning of GDPR Article 22 (for example, we do not use AI alone to approve or deny account eligibility). AI features assist with drafting and analysis of content you control. Automated checks that block certain publish destinations (such as Meta or YouTube) are safety controls for those platforms, not Article 22 decisions about you as a person.

6. Controller vs processor

DataOur roleYour role
Account, billing, Site analytics, marketing, securityController—
Your Content and audience/follower/message personal data processed to publish or analyze on your instructionsProcessorController

As controller of audience data, you must have a lawful basis, provide notices, and honor end-user rights. On request we will provide our standard Data Processing Addendum (DPA) incorporating EU SCCs / UK Addendum where required: hi@ikigx.com.


7. Who we share data with

We do not sell personal data. We share data only with:

  1. Subprocessors / infrastructure — cloud hosting and storage, CDN, databases, observability/error monitoring, support tools, transactional email, analytics, payment processors, AI model providers. They process data on our instructions under contractual safeguards.
  2. Connected platforms — when you schedule or publish, we transmit content and necessary metadata to the platform you chose; analytics may be retrieved from that platform. That platform’s privacy policy then applies.
  3. Workspace members — content and activity visible per roles you assign.
  4. Professional advisors — lawyers, accountants, insurers under confidentiality.
  5. Authorities — when legally required or to protect against fraud, abuse, or harm. Where lawful we may try to redirect requests to you first.
  6. Successors — in a merger, acquisition, or asset sale, subject to this Policy or notice of a new policy.

7.1 Subprocessors

CategoryExamples (may change)
Hosting / databaseCloud hosting, database, and object-storage providers
PaymentsPayment processors (for example Stripe)
EmailTransactional email providers
AIThird-party AI providers that process prompts and selected inputs to deliver AI features
ObservabilityError-monitoring and uptime tools

For a current list of subprocessors, contact hi@ikigx.com.


8. International transfers

We are based in the United States (Wyoming). Personal data may be processed in the United States and in other countries where our subprocessors operate. Where GDPR/UK GDPR applies and the destination lacks an adequacy decision, we rely on Standard Contractual Clauses (and UK Addendum where applicable) plus technical measures (encryption in transit/at rest, access controls). Contact hi@ikigx.com for information about safeguards.


9. Retention

DataRetention
Account dataWhile account is active; after closure, typically up to 90 days for recovery, then delete or anonymize (except longer legal holds)
Drafts / media not yet publishedUntil you delete them or the account is purged
Published-post records & analyticsWhile account is active
OAuth tokensWhile connection is active; after disconnect, revoke/delete promptly from live systems
Billing recordsAs required by tax/accounting law (often up to 7 years)
Security / operational logsTypically up to 12 months
AI prompts / AI inputs logged by Studio (debug, abuse, safety)Treated as security/ops logs — typically up to 12 months. Prompts stored as part of drafts/posts remain Your Content under the drafts/media rows above. Provider-side retention follows that provider’s zero-retention / DPA settings where configured
Signup age attestation / DOB (if collected)While account is active + up to 90 days after closure (or longer under legal hold)
BackupsEncrypted backups roll off on normal schedule (about 30–90 days) after live deletion

Legal hold exception: we may retain relevant data beyond the periods above when reasonably necessary for litigation, regulatory inquiry, DMCA or other IP disputes, security incidents, fraud/abuse investigations, or CSAM/NCII reporting and related law-enforcement requests. When the hold ends, ordinary retention/deletion resumes.


10. Security

Measures include TLS in transit; encryption of sensitive data and OAuth tokens at rest; password hashing; least-privilege access; multi-factor authentication for personnel with production access where applicable; vendor contractual controls; and incident-response procedures. No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and regulators as required by applicable law.

Connected-platform access tokens are not written to logs in cleartext and are protected with application-level or vault encryption.


11. Your rights

Depending on your location, you may have rights to:

  • access and receive a copy of your personal data;
  • correct inaccurate data;
  • delete data (subject to legal retention);
  • object to or restrict certain processing;
  • withdraw consent where processing is based on consent;
  • data portability;
  • opt out of “sale” or “sharing” for cross-context behavioral advertising — we do not sell personal data and do not share it for cross-context behavioral advertising as defined under California law;
  • lodge a complaint with a supervisory authority.

Most settings (profile, disconnect platforms, delete content) are available in-product. For other requests: hi@ikigx.com. We will respond within the time required by law (often 30 days) after verifying your identity.


12. California (CCPA/CPRA)

California residents have the rights summarized in Section 11, including know, delete, correct, and non-discrimination. Categories of personal information we collect are described in Section 3; purposes in Section 4. We do not sell personal information and do not share it for cross-context behavioral advertising. To exercise California privacy rights: hi@ikigx.com · subject “Privacy Request”.


13. Children

The Service is not directed to children. We set our contractual age minimum at 18 (see Terms §2 age gate), and we do not knowingly collect personal data from anyone under 18. Separately, for U.S. COPPA, the Service is not designed for, marketed to, or directed at children under 13; if we learn we collected data from a child under 13, we will delete it. If you believe a minor has provided us data, contact hi@ikigx.com.


14. Marketing and cookies choices

Unsubscribe from marketing emails via the link in those emails. Transactional/account emails continue while your account is active. Manage cookies via browser settings and any consent banner.


15. Third-party sites and platforms

Connected platforms and linked sites have their own privacy policies. Review them before connecting accounts. We are not responsible for third-party practices we do not control.


16. Changes

We may update this Policy. Material changes will be announced with reasonable notice (email or in-product). The “Last updated” date will change. Continued use after the effective date means you acknowledge the updated Policy, except where affirmative consent is required.


17. Contact

Ikigai Systems LLC

30 N Gould St, Ste R

Sheridan, WY 82801, USA

PurposeAddress
Privacy requestslegal@ikigx.com · hi@ikigx.com · subject “Privacy Request”
Security incidentslegal@ikigx.com · subject “Security”
Abuse / CSAMlegal@ikigx.com · subject “Abuse”
Generalhi@ikigx.com

For EU/UK residents: you may also contact your local supervisory authority. If we appoint an EU/UK representative, we will update this Policy with those details.

© 2026 IKIGX Studio · Ikigai Systems LLC
TermsPrivacyMeta / YouTube