Privacy
Version 2026-09-16. This is the live product policy, not legal advice.
Salamnder Social Studio is a paid multi-tenant drafts and publish service. Each buyer gets a personal workspace. The operator's own studio lock is separate from buyer API keys.
Who is responsible
The controller is Salvatore Sbrega, operating Salamnder Social Studio as a personal product from Vancouver, British Columbia, Canada. This product has its own database and billing.
Contact: use the request-access form on /pricing or the magic-link portal on /account. The planned custom domain is salamndersocialstudio.com. Until that DNS is fully live, the canonical host is https://socials-studio-rho.vercel.app.
What we collect for the service (Tier A)
- Email, Stripe customer and subscription ids, plan, a hash of the buyer API key, and monthly API/MCP call counts.
- Drafts and media you or your agent save (captions, thread parts, titles, hosted file metadata and bytes you uploaded).
- OAuth tokens for the LinkedIn, X, and other accounts you connect, so the studio can publish when you ask.
- Publish results for posts you asked to send (status, platform ids, URLs, errors).
- Short security logs (IP, time, errors) used to rate-limit and debug failed calls.
What we do not do by default
- We do not sell or license drafts for model training or datasets.
- We do not return OAuth tokens to MCP clients.
- We do not scrape LinkedIn or X feeds for resale.
- We do not run ad trackers or advertising cookies on this site.
Subprocessors / hosting
- Stripe — billing, Checkout, Customer Portal, subscription status.
- Supabase — database and file storage for workspaces, drafts, connections, and media (United States).
- Vercel — application hosting and request logs (United States).
- Resend — transactional email (API keys, magic-link sign-in, founder alerts) when configured.
Processing may occur in the United States because Vercel, Supabase, and Stripe run there.
MCP hosts
When you connect ChatGPT, Claude, Cursor, Gemini, Grok, or another MCP client, that host also processes the tool arguments and results you send through it, under that host's own policies. Salamnder Social Studio stores what the tools save or publish here.
LinkedIn and X
Tokens are used only to publish when you ask (or to refresh a grant so a later publish can work). Platform API terms still bind you and us. We do not sell API member data.
Your posts
You connect your own LinkedIn and X. What you publish — including views-your-own banking commentary — is yours. See Terms.
Retention
We keep workspace data while the account is active and for a reasonable period after cancel for billing and security. On an account deletion request we delete that workspace's drafts, connections, and media. Stripe may still hold customer and invoice records under Stripe's own retention.
Your rights
You can ask for access, correction, or deletion, and you can withdraw consent for optional future features, from /account (magic-link). Export downloads JSON of that workspace's drafts and post metadata. It never includes OAuth token values.
Cookies
A studio_session cookie keeps the operator dashboard signed in. An account_session cookie keeps the buyer portal signed in after a magic link. Provider OAuth connect uses a short-lived PKCE cookie. There are no advertising or analytics trackers on this site.
Dataset contribution (Tier B) — not enabled
Dataset contribution is not enabled. We do not collect drafts or posts for a research or commercial corpus today. A future optional opt-in for an anonymized research or commercial corpus would require separate express consent. It would never be required to use the paid service. There is no toggle that turns this on.
Operator use
The operator studio password does not create a buyer workspace row. Operator publishing uses the personal studio lock, not the paid-buyer consent table.