Privacy

Version 2026-09-16. This is the live product policy, not legal advice.

Salamnder Social Studio is a paid multi-tenant drafts and publish service. Each buyer gets a personal workspace. The operator's own studio lock is separate from buyer API keys.

Who is responsible

The controller is Salvatore Sbrega, operating Salamnder Social Studio as a personal product from Vancouver, British Columbia, Canada. This product has its own database and billing.

Contact: use the request-access form on /pricing or the magic-link portal on /account. The planned custom domain is salamndersocialstudio.com. Until that DNS is fully live, the canonical host is https://socials-studio-rho.vercel.app.

What we collect for the service (Tier A)

What we do not do by default

Subprocessors / hosting

Processing may occur in the United States because Vercel, Supabase, and Stripe run there.

MCP hosts

When you connect ChatGPT, Claude, Cursor, Gemini, Grok, or another MCP client, that host also processes the tool arguments and results you send through it, under that host's own policies. Salamnder Social Studio stores what the tools save or publish here.

LinkedIn and X

Tokens are used only to publish when you ask (or to refresh a grant so a later publish can work). Platform API terms still bind you and us. We do not sell API member data.

Your posts

You connect your own LinkedIn and X. What you publish — including views-your-own banking commentary — is yours. See Terms.

Retention

We keep workspace data while the account is active and for a reasonable period after cancel for billing and security. On an account deletion request we delete that workspace's drafts, connections, and media. Stripe may still hold customer and invoice records under Stripe's own retention.

Your rights

You can ask for access, correction, or deletion, and you can withdraw consent for optional future features, from /account (magic-link). Export downloads JSON of that workspace's drafts and post metadata. It never includes OAuth token values.

Cookies

A studio_session cookie keeps the operator dashboard signed in. An account_session cookie keeps the buyer portal signed in after a magic link. Provider OAuth connect uses a short-lived PKCE cookie. There are no advertising or analytics trackers on this site.

Dataset contribution (Tier B) — not enabled

Dataset contribution is not enabled. We do not collect drafts or posts for a research or commercial corpus today. A future optional opt-in for an anonymized research or commercial corpus would require separate express consent. It would never be required to use the paid service. There is no toggle that turns this on.

Operator use

The operator studio password does not create a buyer workspace row. Operator publishing uses the personal studio lock, not the paid-buyer consent table.