Lensis Studio — Privacy Policy
Effective Date: July 29, 2026 (previous version: July 4, 2026)
This Privacy Policy applies to the Lensis Studio application and website (https://lensis.studio).
This Privacy Policy describes how Lensis Studio ("we," "us," or "our") collects, uses, and protects information when you use our internal multi-channel publishing suite (the "Service"). We are committed to protecting the privacy of our users and handling all data responsibly.
1. Information We Collect
1.1 Account Information
When you use Lensis Studio, we collect:
- Your name and email address for authentication purposes
- Your role assignment within the team (manager or editor)
- Channel assignments linked to your account
1.2 OAuth Tokens
When you connect a third-party platform account (TikTok, Instagram, or Threads), we store:
- OAuth access tokens and refresh tokens required to publish content on your behalf
- Basic creator profile information (username, display name, avatar) as returned by the platform API
- Creator capability metadata (e.g., available privacy levels, maximum video duration)
1.3 Publishing Metadata
For each post made through the Service, we store:
- Post status (queued, published, failed)
- Timestamp of publication
- The channel and user who initiated the post
- Post configuration (privacy level, disclosure settings, interaction settings)
1.4 Video Content
Video files uploaded to the Service are temporarily stored solely for the purpose of transmission to the destination platform. Videos are not retained after successful publication or after a configurable retention period (default: 7 days), whichever comes first.
2. How We Use Your Information
We use collected information exclusively for:
- Authenticating your access to the Service
- Publishing content to connected platform accounts on your behalf
- Displaying post status and publishing history within the Service
- Troubleshooting failed posts and maintaining service reliability
3. TikTok API Data
Lensis Studio integrates with the TikTok Content Posting API. We handle TikTok data as follows:
- Data Minimization: We only request and store the minimum data necessary to facilitate content posting (creator info, privacy level options, post status).
- No Third-Party Sharing: TikTok API data is never shared with, sold to, or disclosed to any third party. Data is used exclusively within the Service for its intended publishing function.
- Token Security: OAuth tokens are encrypted at rest using industry-standard encryption (AES-256). Tokens are transmitted only over HTTPS connections.
- No Data Selling: We do not sell, license, or monetize any data obtained through the TikTok API or any other platform API.
- Scope Limitation: We request only the API scopes necessary for content posting functionality (video.publish, video.upload, user.info.basic).
4. Meta Platform Data (Instagram and Threads)
Lensis Studio integrates with the Instagram API with Instagram Login and the Threads API. We handle data obtained from these APIs as follows:
- Scopes Requested: Instagram —
instagram_business_basic,instagram_business_content_publish. Threads —threads_basic,threads_content_publish,threads_manage_insights,threads_manage_replies. We request no scope beyond what is required to publish and manage the account owner's own content. - Data Stored: the connected account's user ID and username, the access token with its expiry, the authorization timestamp, and the granted scopes. We do not collect or store follower lists, direct messages, or any other person's content.
- No Third-Party Sharing: data obtained from Meta APIs is never shared with, sold to, or disclosed to any third party. It is used exclusively within the Service to publish content the account owner authorized.
- Token Security: long-lived tokens are stored server-side in files readable only by the service account (permission 0600) and are transmitted only over HTTPS.
- Deauthorization: when you remove Lensis Studio from your Instagram or Threads account, Meta notifies our deauthorize callback (
/auth/instagram/deauthorize,/auth/threads/deauthorize). We verify the signed request and immediately delete the stored access token for that account. - Data Deletion Requests: deletion requests are received at
/auth/instagram/data_deletionand/auth/threads/data_deletion. On a verified request we delete all stored data for that account — the active token and any archived copy — and return a confirmation code. You may also request deletion directly by email (see Contact below).
5. Data Storage and Security
- All data is stored on secured servers with restricted access
- OAuth tokens are encrypted at rest
- All data transmission uses TLS/HTTPS encryption
- Access to the Service is restricted to authenticated team members only
- We conduct regular reviews of our security practices
6. Data Retention
- Account data: Retained for the duration of your active use of the Service, deleted upon account removal
- OAuth tokens: Retained until you disconnect your account or revoke access; deleted immediately upon disconnection
- Publishing metadata: Retained for operational record-keeping; deleted upon user request
- Video files: Temporarily stored for transmission only; automatically deleted after successful publication or within 7 days
7. Your Rights
You have the right to:
- Access: Request a copy of all data we hold about you
- Deletion: Request deletion of your data, including all stored tokens and publishing history
- Disconnection: Revoke platform connections at any time, which immediately deletes associated tokens
- Portability: Request your publishing history in a machine-readable format
To exercise any of these rights, contact us at the email address below. We will respond to requests within 30 days.
8. Third-Party Platforms
The Service connects to third-party platforms — TikTok, Instagram, and Threads — via their official APIs. Your use of those platforms is governed by their respective privacy policies and terms of service, and we encourage you to review them independently:
9. Children's Privacy
The Service is not intended for use by individuals under the age of 18. We do not knowingly collect information from minors.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated to users via the Service. The "Effective Date" at the top of this page indicates when the policy was last revised.
11. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us:
Email: smarttoyglobal@gmail.com
Entity: Lensis Studio