Legal
Data Compliance
Last updated: 8 August 2026 · Effective: 8 August 2026
Overview
This page summarises how Spoof Kitchen handles data protection, where your data is processed, who we share it with, and what rights you have. It complements our Privacy Policy and Terms of Service. If you’re evaluating Spoof Kitchen for your team and need a signed DPA or vendor questionnaire, jump to Data Processing Agreement.
Regulatory frameworks
We design Spoof Kitchen to meet the requirements of:
- GDPR (EU/UK General Data Protection Regulation) — lawful bases, data-subject rights, processor obligations.
- NDPR (Nigeria Data Protection Regulation, 2019) and the NDPA (2023) — data-subject rights, lawful processing, and audit-ready records. NDPC registration and a formally appointed data protection officer are still in progress; see Certifications.
- CCPA / CPRA (California Consumer Privacy Act) — notice at collection, right to know, delete, correct, and opt out of sale (we do not sell personal data).
- POPIA (South Africa) — for users in the Republic of South Africa.
Spoof Kitchen acts as a data controller for your account and usage data, and as a data processor for content you upload and the audience data you fetch from connected social platforms.
Sub-processors
We use the following vendors to operate the service. Each is bound by data-protection terms equivalent to those we offer you. We update this list before adding any new sub-processor that handles personal data.
| Sub-processor | Purpose | Region |
|---|---|---|
| Supabase | Authentication, database, edge functions | EU / US (Frankfurt, Virginia) |
| Bunny.net | Storage and CDN delivery of user media and AI assets | EU (Ljubljana), global edge |
| Paystack | Subscription billing and card processing | Nigeria, South Africa |
| Zernio | Social publishing provider — holds platform OAuth credentials and delivers scheduled posts and media to each network | US |
| OpenAI | AI inference — transcription, caption and title generation, trend matching. Does not train on our data | US |
| Google (Gemini API) | AI inference — image generation and multimodal analysis. Does not train on our data | US |
| Sentry | Error monitoring — stack traces and diagnostics only. Session replay is disabled and events carry no IP addresses, cookies, or user identifiers | EU (Frankfurt) |
| Resend | Transactional email delivery — only sees recipient email address and message contents | US / EU |
| PostHog | Product analytics — pageviews and feature usage, with a profile keyed to the account after sign-in | US |
| Upstash | Redis rate-limiting counters keyed to account ID or IP address. No content | Global (edge) |
| Hetzner | Application hosting — the servers the product runs on | EU (Germany) |
| Vercel | Analytics and Speed Insights — aggregate page-performance metrics | Global |
To receive email notice of changes, email privacy@spoof.media.
Data residency
Account and content metadata are stored in Supabase’s EU region. Media files are stored on Bunny.net’s EU origin and cached at edge nodes worldwide for delivery performance. The application servers are in Germany, and error monitoring stays in Sentry’s Frankfurt region.
Some processing is not EU-resident, and we want to be direct about it. Product analytics (PostHog), AI inference (OpenAI, Google), and social publishing (Zernio) are processed in the United States. If you use AI features or connect a social account, that data leaves the EU. See International transfers for the safeguards that apply.
We cannot currently offer US-only or EU-only residency as a configurable option. If regional residency is a hard requirement for your organisation, write to compliance@spoof.media.
Security controls
Encryption
- TLS 1.2+ for all data in transit, with HSTS preloaded.
- AES-256 at rest for databases and object storage.
- Platform OAuth credentials are held by Zernio rather than by us, so there is no token store on our side to compromise.
- Passwordless sign-in: short-lived one-time codes emailed per session, so no password is ever stored or transmitted.
Application hardening
- Strict Content-Security-Policy,
frame-ancestors: none, nosniff, and a restrictive Permissions-Policy on every response. - Row-level security on customer data in Supabase.
- Rate limiting on authentication, upload, and AI endpoints.
- Least-privilege access to production credentials.
Software lifecycle
- Code review and CI checks before merge.
- Automated dependency vulnerability scanning.
- Penetration tests performed before each major release.
Resilience
- Managed database backups provided by Supabase on their standard schedule.
- Error monitoring and alerting on production failures.
We are an early-stage team and we would rather understate this than overstate it. We do not yet run a formal quarterly access review, enforce SSO across all staff tooling, or publish a status page. Those are on the roadmap, and this page will change when they are real.
Certifications and attestations
Spoof Kitchen is an early-stage product. We are honest about what we have and what we are working toward:
We hold no certifications or regulatory registrations today.
- NDPC registration — not yet registered with the Nigeria Data Protection Commission. In progress.
- SOC 2 Type I — not started. Observation period planned for Q4 2026.
- ISO 27001 — not started. Gap assessment scheduled for 2027.
Our underlying infrastructure providers (Supabase, Hetzner, Bunny.net, Paystack, OpenAI) maintain their own SOC 2 / ISO / PCI attestations, and we inherit those controls at the infrastructure layer — but that is their attestation, not ours, and we will not present it as ours. If your procurement process requires a certified vendor, we are not one yet.
Data Processing Agreement
If you are an EU/UK customer, or any customer whose jurisdiction requires it, we will sign a Data Processing Agreement that incorporates the Standard Contractual Clauses (2021/914/EU) for international transfers. To request a pre-signed DPA, email compliance@spoof.media. We typically return a signed copy within 5 business days.
International transfers
Where we transfer personal data outside the EEA, UK, or Nigeria, we rely on:
- Standard Contractual Clauses with our sub-processors.
- UK International Data Transfer Addendum where applicable.
- Supplementary technical measures: encryption in transit and at rest, pseudonymisation where feasible.
Breach notification
If we discover a personal-data breach affecting you, we will notify you and the relevant supervisory authority without undue delay and within 72 hours of becoming aware, as required by GDPR and NDPR. The notice will describe what happened, what data was involved, the likely impact, and the steps we are taking.
Data-subject rights
You can exercise the following rights by writing to privacy@spoof.media from your account email address. We respond within 30 days. Self-serve export and deletion are not built yet, so every request below is handled manually by us today — that does not limit the right, only the mechanism.
- Right of access
- Right to rectification
- Right to erasure (“right to be forgotten”)
- Right to data portability (export as JSON / ZIP)
- Right to restrict or object to processing
- Right to withdraw consent
- Right to lodge a complaint with a supervisory authority (e.g. NDPC, ICO, CNIL)
Retention and deletion
Account and content data are kept for as long as your account is active. When you ask us to delete your account, personal data is erased or anonymised within 30 days, except where retention is required by law (for example, tax invoices kept for 7 years). Residual copies in managed backups age out on our providers’ standard rotation.
Deleting your Spoof Kitchen account does not retroactively delete posts already published to a social platform — those live on that platform under its own terms, and you remove them there.
Platform compliance
Spoof Kitchen integrates with social platforms via their official APIs and complies with each platform’s developer policies:
- Meta (Instagram) — Platform Terms, including Limited Use restrictions for tokens and content.
- TikTok — Developer Terms of Service and Content Sharing Guidelines.
- Google (YouTube) — YouTube API Services Terms and Google API Services User Data Policy (including Limited Use).
- X — Developer Agreement and Policy.
- LinkedIn — API Terms of Use.
We only request the OAuth scopes needed to publish your content and read aggregated insights. You can revoke access at any time from Settings → Connections or from the platform’s own connected-apps screen.
Contact
Spoof Kitchen is operated by Spoof Media. For compliance, security, or DPA enquiries:
- Compliance: compliance@spoof.media
- Privacy / DPO: privacy@spoof.media
- Security disclosures: security@spoof.media