Sojiwa Studio
Features Contact Terms of Service
ENBM中文
Sign in ↗

Legal

Privacy Policy

Last updated: 4 August 2026 · Version 2026-08-04

This Policy covers the Sojiwa Studio admin portal — a business tool used by your organization's admins and team members to manage social media content. It is separate from, and does not apply to, the Sojiwa mental-health/journaling consumer app, which handles different data (journal entries, mood data) under its own policy.

1. Who this applies to

Sojiwa Studio is a B2B tool: the people using it are your organization's own admins and team members (system administrators, team administrators, and restricted team members), not end consumers. It is not directed at children and is not intended for use by anyone under 18.

2. Information we collect

Account information

  • Username, email address, and a bcrypt-hashed password (we never store your plaintext password);
  • Your assigned role and which team/product(s) you have access to.

Login & consent records

  • Each login's timestamp, the IP address and browser/user-agent it came from, and which version of these Terms/Privacy Policy you accepted (the checkbox required at sign-in) — kept as evidence of consent.

Website enquiries

  • When you use our public contact form, we collect the name, email address, phone number, and message you submit, together with technical anti-abuse information from reCAPTCHA. We use this only to respond to your enquiry and protect the form from spam or abuse.

Your team's business data

  • Brand/product configuration, campaigns, characters, and assets your team uploads or configures;
  • Connected platform credentials (e.g. a Facebook access token) and your team's own AI provider API key — encrypted at rest (AES-256-GCM), never stored or logged in plaintext;
  • AI-generated content and the prompts used to generate it (captions, image/video briefs, revision notes), so your team can review, audit, and improve future generations;
  • Comments/replies fetched from connected platforms for the engagement/reply workflow;
  • Uploaded media (product photos, character avatars, generated images/video).

3. How AI processing works

Content generation is powered by third-party AI models accessed through OpenRouter, using your team's own API key — never a key shared across other customers. Prompts and responses are logged (see retention below) so your team can see exactly what was sent and generated, for review and troubleshooting. We do not use your team's content to train our own models.

4. Third-party services we use

  • OpenRouter — AI text/image/video/speech generation, called with your team's own key;
  • Meta/Facebook Graph API — publishing, stats, and comment retrieval for connected Facebook Pages;
  • Telegram Bot API — draft-approval, alert, reporting, and public-contact-form messages to the relevant connected group;
  • Google reCAPTCHA — bot and abuse prevention for login and public contact forms. Google may process technical information such as IP address, device/browser characteristics, and interaction signals under its own privacy terms;
  • Media storage — either local disk or an S3-compatible bucket (e.g. DigitalOcean Spaces), for generated/uploaded images and video;
  • Uptime Kuma (where configured) — service monitoring/maintenance-window scheduling;
  • MySQL — the underlying application database.

We do not sell your data, and we do not share it with third parties except the service providers above (each acting on our instructions to operate the service) or where required by law.

5. Data retention

Retention windows are configured per deployment; typical defaults are: AI call logs (prompts/responses) retained 90 days, intermediate generation media (e.g. video segments, narration audio) retained 30 days, and completed background-task records retained 30 days, after which they are pruned automatically. A final published post's own image/video is kept for as long as your team's account is active. Consent-log entries (Section 2, "Login & consent records") are retained for as long as needed to serve as evidence of acceptance.

6. Security

  • Platform tokens and AI provider keys are encrypted at rest with AES-256-GCM;
  • Passwords are hashed with bcrypt, never stored in plaintext;
  • Sessions use signed JWT bearer tokens (not cookies) — the token lives in your browser's local storage, not a cookie, and can be individually revoked (e.g. on logout);
  • Access is scoped by role and team/product, enforced on every request.

No system is perfectly secure; if we become aware of a breach affecting your data, we will notify affected teams without undue delay.

7. Cookies

The admin portal itself does not use cookies for authentication — it uses a bearer token stored in your browser. The public marketing pages may use minimal, non-tracking technical storage. Google reCAPTCHA may place or read cookies and process technical data needed for fraud and abuse prevention; we do not use third-party advertising cookies or sell data for behavioural advertising.

8. Your rights

Depending on your jurisdiction, you may have rights to access, correct, export, or request deletion of your personal data, and to withdraw consent (noting that acceptance of these terms is required to continue using the service). To exercise these rights, contact support.studio@sojiwa.com. Requests are handled by your organization's system administrator where the data in question belongs to your team's account.

9. International data

Depending on deployment configuration, media storage may be hosted in a specific region (e.g. Singapore, when using DigitalOcean Spaces' `sgp1` region). Where data is transferred internationally, we take reasonable steps to protect it consistent with this Policy.

10. Changes to this Policy

We may update this Policy from time to time; the "Last updated" date and version above will change accordingly, and — because acceptance is required on every login — you will be asked to accept the current version the next time you sign in.

11. Contact

Sojiwa Studio is operated by an individual operator in Malaysia. Questions about this Policy or your data: support.studio@sojiwa.com. Website: studio.sojiwa.com.

This document is a general template describing the service as built and is not a substitute for legal advice; your organization should have it reviewed by qualified counsel before relying on it, particularly for GDPR/CCPA/PDPA-specific obligations that depend on where your team and its users are located.

← Back to sojiwa studio
Sojiwa Studio

AI-assisted social, with people at the centre.

© 2026 Sojiwa. All rights reserved.

TermsPrivacyBM中文
Studio sign in