This Privacy Policy explains how Sinabro (the “Company”) handles data in Sinabro Studio (the “Tool”), an internal publishing automation tool that runs locally on the operator's own computer and publishes short-form video to the operator's own social accounts. The Tool is not distributed to the public and has no users other than the Company's authorised operators.
1. Scope of This Policy
This Policy covers Sinabro Studio only. The Company's consumer applications — Dunit, KnotNote, and Malwakey — are each governed by their own separate privacy policy, available at Sinabro Privacy Policy. Use of the Tool is additionally governed by the Sinabro Studio Terms of Service.
2. Who We Are
The Tool is operated by Sinabro, an independent software studio based in the Republic of Korea. For any question about this Policy or about the data described in it, contact sinabro.support@gmail.com.
3. What Data the Tool Processes
The Tool processes only what is strictly necessary to authenticate to, and publish to, the operator's own accounts:
- Authorisation credentials: the OAuth access token and refresh token issued by the platform when the operator authorises the Tool
- Basic account identifiers returned at authorisation, such as the TikTok open ID, the display name, and the account avatar, used to confirm which account is connected
- Publishing content: the video files, captions, and metadata the operator chooses to publish
- Publishing results: the status, identifier, and any error returned by the platform for a submitted upload
The Tool does not collect names, email addresses, phone numbers, payment details, contact lists, location data, or the content or account data of any other platform user.
4. Where Data Is Stored
All of the above is held on the operator's own computer, where the Tool runs. Authorisation credentials are stored locally on that machine and are never committed to source control.
The Company operates no server, database, or hosted backend for the Tool. No credential, video file, caption, or account identifier is transmitted to any infrastructure controlled by the Company, and the Company therefore holds no copy of this data anywhere outside the operator's machine.
5. Why the Data Is Processed
Data is processed for one purpose only: to authenticate the Tool against the operator's own accounts and to publish the operator's own content to them. The Tool performs no other processing with the data it holds.
6. What the Tool Does Not Do
The Company confirms that, in connection with the Tool:
- No data is sold, rented, or shared with any third party for that party's own purposes
- No advertising, remarketing, audience-building, or profiling is carried out
- No third-party analytics, tracking, or telemetry SDK is embedded
- Data obtained from TikTok is not used for any purpose other than publishing to the connected account, and is not combined with data from any other source
- No automated decision-making producing legal or similarly significant effects is performed
7. Third Parties Involved
Because the Tool's sole function is to publish to external platforms, those platforms necessarily receive data as part of that process:
- TikTok Pte. Ltd. and its affiliates (ByteDance Ltd.): receive the authorisation request and the video, caption, and metadata submitted for publishing — see the TikTok Privacy Policy
- Meta Platforms, Inc.: receives the equivalent data when publishing to Instagram Reels — see the Meta Privacy Policy
Processing by these platforms is governed by their own privacy policies, not by this one. No other third party receives data from the Tool.
8. Retention
Authorisation credentials are retained on the operator's machine until they expire, are refreshed, or are revoked. They are removed when the operator disconnects the Tool from the platform, deletes the local credential store, or removes the Tool from the machine. Video files and captions remain on the operator's machine under the operator's own control and are deleted by the operator. Content already published to a platform is retained by that platform under its own policy and must be removed there.
9. Rights and Deletion
Authorisation can be withdrawn, and the associated data removed, at any time and without contacting the Company:
- Revoke the Tool's access in the platform's own settings — on TikTok, under Settings and privacy → Security and permissions → Manage app permissions; for Instagram, under Settings → Website permissions → Apps and websites
- Delete the local credential store on the machine running the Tool, which removes every stored token and account identifier
- Delete published content directly in the platform's app
Requests to access, rectify, or delete data, or any other question about this Policy, may also be sent to sinabro.support@gmail.com.
10. Children
The Tool is internal software operated by the Company's authorised operators. It is not directed at children, is not distributed publicly, and cannot be signed up for. The Company does not knowingly process any personal information of children through the Tool.
11. Security
Because the Tool holds data only on the operator's own machine and the Company runs no backend for it, the exposure surface is limited to that machine. Credentials are kept out of source control, transmitted only over encrypted connections to the platform APIs, and scoped to the minimum permissions needed to publish. No security measure is absolute, and the Company makes no guarantee of absolute security.
12. Changes to This Policy
If this Policy is amended, the Company will update the “Last updated” date on this page. Where a change materially affects how data is handled, the amended Policy will be published here before the change takes effect.
13. Contact
Inquiries regarding this Policy or requests concerning the processing of personal information should be addressed to:
- Operator: Sinabro
- Contact: sinabro.support@gmail.com
This Policy takes effect on August 15, 2026.