Legal

Data Compliance

Last updated: 8 August 2026 · Effective: 8 August 2026

Overview

This page summarises how Spoof Kitchen handles data protection, where your data is processed, who we share it with, and what rights you have. It complements our Privacy Policy and Terms of Service. If you’re evaluating Spoof Kitchen for your team and need a signed DPA or vendor questionnaire, jump to Data Processing Agreement.

Regulatory frameworks

We design Spoof Kitchen to meet the requirements of:

  • GDPR (EU/UK General Data Protection Regulation) — lawful bases, data-subject rights, processor obligations.
  • NDPR (Nigeria Data Protection Regulation, 2019) and the NDPA (2023) — data-subject rights, lawful processing, and audit-ready records. NDPC registration and a formally appointed data protection officer are still in progress; see Certifications.
  • CCPA / CPRA (California Consumer Privacy Act) — notice at collection, right to know, delete, correct, and opt out of sale (we do not sell personal data).
  • POPIA (South Africa) — for users in the Republic of South Africa.

Spoof Kitchen acts as a data controller for your account and usage data, and as a data processor for content you upload and the audience data you fetch from connected social platforms.

Sub-processors

We use the following vendors to operate the service. Each is bound by data-protection terms equivalent to those we offer you. We update this list before adding any new sub-processor that handles personal data.

Sub-processorPurposeRegion
SupabaseAuthentication, database, edge functionsEU / US (Frankfurt, Virginia)
Bunny.netStorage and CDN delivery of user media and AI assetsEU (Ljubljana), global edge
PaystackSubscription billing and card processingNigeria, South Africa
ZernioSocial publishing provider — holds platform OAuth credentials and delivers scheduled posts and media to each networkUS
OpenAIAI inference — transcription, caption and title generation, trend matching. Does not train on our dataUS
Google (Gemini API)AI inference — image generation and multimodal analysis. Does not train on our dataUS
SentryError monitoring — stack traces and diagnostics only. Session replay is disabled and events carry no IP addresses, cookies, or user identifiersEU (Frankfurt)
ResendTransactional email delivery — only sees recipient email address and message contentsUS / EU
PostHogProduct analytics — pageviews and feature usage, with a profile keyed to the account after sign-inUS
UpstashRedis rate-limiting counters keyed to account ID or IP address. No contentGlobal (edge)
HetznerApplication hosting — the servers the product runs onEU (Germany)
VercelAnalytics and Speed Insights — aggregate page-performance metricsGlobal

To receive email notice of changes, email privacy@spoof.media.

Data residency

Account and content metadata are stored in Supabase’s EU region. Media files are stored on Bunny.net’s EU origin and cached at edge nodes worldwide for delivery performance. The application servers are in Germany, and error monitoring stays in Sentry’s Frankfurt region.

Some processing is not EU-resident, and we want to be direct about it. Product analytics (PostHog), AI inference (OpenAI, Google), and social publishing (Zernio) are processed in the United States. If you use AI features or connect a social account, that data leaves the EU. See International transfers for the safeguards that apply.

We cannot currently offer US-only or EU-only residency as a configurable option. If regional residency is a hard requirement for your organisation, write to compliance@spoof.media.

Security controls

Encryption

  • TLS 1.2+ for all data in transit, with HSTS preloaded.
  • AES-256 at rest for databases and object storage.
  • Platform OAuth credentials are held by Zernio rather than by us, so there is no token store on our side to compromise.
  • Passwordless sign-in: short-lived one-time codes emailed per session, so no password is ever stored or transmitted.

Application hardening

  • Strict Content-Security-Policy, frame-ancestors: none, nosniff, and a restrictive Permissions-Policy on every response.
  • Row-level security on customer data in Supabase.
  • Rate limiting on authentication, upload, and AI endpoints.
  • Least-privilege access to production credentials.

Software lifecycle

  • Code review and CI checks before merge.
  • Automated dependency vulnerability scanning.
  • Penetration tests performed before each major release.

Resilience

  • Managed database backups provided by Supabase on their standard schedule.
  • Error monitoring and alerting on production failures.

We are an early-stage team and we would rather understate this than overstate it. We do not yet run a formal quarterly access review, enforce SSO across all staff tooling, or publish a status page. Those are on the roadmap, and this page will change when they are real.

Certifications and attestations

Spoof Kitchen is an early-stage product. We are honest about what we have and what we are working toward:

We hold no certifications or regulatory registrations today.

  • NDPC registration — not yet registered with the Nigeria Data Protection Commission. In progress.
  • SOC 2 Type I — not started. Observation period planned for Q4 2026.
  • ISO 27001 — not started. Gap assessment scheduled for 2027.

Our underlying infrastructure providers (Supabase, Hetzner, Bunny.net, Paystack, OpenAI) maintain their own SOC 2 / ISO / PCI attestations, and we inherit those controls at the infrastructure layer — but that is their attestation, not ours, and we will not present it as ours. If your procurement process requires a certified vendor, we are not one yet.

Data Processing Agreement

If you are an EU/UK customer, or any customer whose jurisdiction requires it, we will sign a Data Processing Agreement that incorporates the Standard Contractual Clauses (2021/914/EU) for international transfers. To request a pre-signed DPA, email compliance@spoof.media. We typically return a signed copy within 5 business days.

International transfers

Where we transfer personal data outside the EEA, UK, or Nigeria, we rely on:

  • Standard Contractual Clauses with our sub-processors.
  • UK International Data Transfer Addendum where applicable.
  • Supplementary technical measures: encryption in transit and at rest, pseudonymisation where feasible.

Breach notification

If we discover a personal-data breach affecting you, we will notify you and the relevant supervisory authority without undue delay and within 72 hours of becoming aware, as required by GDPR and NDPR. The notice will describe what happened, what data was involved, the likely impact, and the steps we are taking.

Data-subject rights

You can exercise the following rights by writing to privacy@spoof.media from your account email address. We respond within 30 days. Self-serve export and deletion are not built yet, so every request below is handled manually by us today — that does not limit the right, only the mechanism.

  • Right of access
  • Right to rectification
  • Right to erasure (“right to be forgotten”)
  • Right to data portability (export as JSON / ZIP)
  • Right to restrict or object to processing
  • Right to withdraw consent
  • Right to lodge a complaint with a supervisory authority (e.g. NDPC, ICO, CNIL)

Retention and deletion

Account and content data are kept for as long as your account is active. When you ask us to delete your account, personal data is erased or anonymised within 30 days, except where retention is required by law (for example, tax invoices kept for 7 years). Residual copies in managed backups age out on our providers’ standard rotation.

Deleting your Spoof Kitchen account does not retroactively delete posts already published to a social platform — those live on that platform under its own terms, and you remove them there.

Platform compliance

Spoof Kitchen integrates with social platforms via their official APIs and complies with each platform’s developer policies:

  • Meta (Instagram) — Platform Terms, including Limited Use restrictions for tokens and content.
  • TikTok — Developer Terms of Service and Content Sharing Guidelines.
  • Google (YouTube) — YouTube API Services Terms and Google API Services User Data Policy (including Limited Use).
  • X — Developer Agreement and Policy.
  • LinkedIn — API Terms of Use.

We only request the OAuth scopes needed to publish your content and read aggregated insights. You can revoke access at any time from Settings → Connections or from the platform’s own connected-apps screen.

Contact

Spoof Kitchen is operated by Spoof Media. For compliance, security, or DPA enquiries: