Legal
Privacy Policy
Last updated: 8 August 2026 · Effective: 8 August 2026
Summary
Spoof Kitchen (“Spoof Kitchen”, “we”, “us”) is a content workspace that helps creators upload once and publish across Instagram, TikTok, YouTube, X, and LinkedIn. This policy explains what we collect, how we use it, and the choices you have. It applies to spoofkitchen.com and the Spoof Kitchen app.
- We collect only what we need to run the product.
- We never sell your personal data.
- You can ask us to export or delete your data at any time by emailing us, and we action it within 30 days.
Data we collect
Account data
When you create an account we collect your email address, your display name, and optional profile details. We do not store a password — you sign in with a one-time code we email you. Authentication is handled by Supabase.
Content data
Anything you upload or create inside Spoof Kitchen — videos, images, captions, transcripts, schedules, ideas, boards, and AI-generated assets. Media files are stored on Bunny.net CDN; metadata lives in our Supabase database.
Connected accounts
When you connect a social platform (Instagram, TikTok, YouTube, X, LinkedIn) the connection is established and held by Zernio, the publishing provider we use to talk to those platforms. Zernio holds the OAuth access and refresh tokens; Spoof Kitchen stores only the resulting profile reference — your handle, platform account ID, avatar URL, and the scopes you granted. We request only the scopes needed to publish and read post performance.
Payment data
Subscriptions are processed by Paystack. We receive your transaction reference, plan, amount, and card brand/last four digits — never your full card number or CVV.
Usage data
Pages visited, features used, device type, browser, IP address, and approximate location (city-level). We use this to fix bugs and improve the product. Product analytics are collected by PostHog, which builds a profile keyed to your account once you sign in. Page-performance metrics are collected by Vercel Analytics and Speed Insights in aggregate.
How we use it
- Operate, maintain, and improve Spoof Kitchen.
- Publish, schedule, and analyse posts on platforms you connect.
- Process payments and prevent fraud.
- Send transactional emails (receipts, security alerts, post failures).
- Send product updates and tips — you can unsubscribe at any time from the email footer.
- Comply with legal obligations.
Third parties we share data with
We share data only with vendors who help us run the product:
- Supabase — authentication and the database holding your account and content metadata.
- Hetzner — the servers the application itself runs on.
- Bunny.net — storage and delivery of your uploaded media and AI-generated images.
- Zernio — the publishing provider that holds your social connections and delivers posts to each platform. Content you schedule or publish passes through Zernio.
- Paystack — subscription billing and card processing.
- Meta, TikTok, Google (YouTube), X, LinkedIn — when you publish or read insights through their APIs, your content and metadata are sent to that platform under their terms.
- OpenAI and Google— AI inference. See “AI processing” below.
- Resend — delivery of sign-in codes and transactional email. Sees your email address and the message.
- PostHog — product analytics, including a profile keyed to your account once you sign in.
- Vercel — Analytics and Speed Insights, aggregate page-performance measurement.
- Upstash — Redis rate-limiting counters keyed to your account or IP address. No content.
- Sentry — error monitoring. We send stack traces and diagnostics only: session replay is disabled and we do not attach IP addresses, cookies, or user identifiers to events.
We do not sell, rent, or trade your personal data. We disclose data to authorities only when legally required.
AI processing
We use AI models from OpenAI and Google to transcribe video, suggest captions, match trends, and generate images. Inputs you submit to AI features (audio, video frames, prompts, and the draft text you ask them to work on) are sent to those providers strictly to return a result for you.
We use these providers under their standard API terms: they do not use your inputs or outputs to train their models. They may retain the request for a limited period — up to 30 days under current OpenAI API terms — for abuse monitoring and legal compliance, after which it is deleted. We do not have a zero-retention agreement in place with either provider today.
Retention
We keep your data for as long as your account is active. When you delete your account, we delete or anonymise your personal data within 30 days, except where we are required to keep records (for example, tax invoices: 7 years).
Your rights
Depending on where you live (GDPR, NDPR, CCPA), you have the right to:
- Access a copy of your data.
- Correct inaccurate data.
- Delete your data.
- Export your data in a portable format.
- Object to or restrict certain processing.
- Withdraw consent at any time.
You can cancel your subscription yourself from Settings → Billing. For everything else — access, correction, export, deletion, or disconnecting a platform — email privacy@spoof.media from your account address and we will action it within 30 days. We are working on self-serve export and deletion; until they ship, the email route is the way to exercise these rights and we honour it in full.
Security
Data is encrypted in transit (TLS 1.2+) and at rest. Accounts have no passwords to steal — every sign-in uses a short-lived one-time code sent to your email. Access to production data is restricted to the smallest possible team and audited. If we discover a breach affecting your data, we will notify you within 72 hours.
Children
Spoof Kitchen is not for anyone under 13 (or under 16 in the EEA). We do not knowingly collect data from children. If you believe a child has signed up, contact us and we will delete the account.
Changes to this policy
We will post updates here and, for material changes, notify you by email at least 14 days before the change takes effect.
Contact
Spoof Kitchen is operated by Spoof Media. For privacy questions or requests:
- Email: privacy@spoof.media
- General: hello@spoof.media
Connected social accounts
Platform credentials are held by Zernio, our publishing provider, and are used only to perform actions you initiate — publish a post, fetch insights, refresh a thumbnail. Spoof Kitchen itself stores the profile reference, not the token.
To disconnect a platform, email privacy@spoof.media and we will revoke the connection and delete the stored profile. You can also revoke our access directly from the security or connected-apps settings of the platform itself, which takes effect immediately.
Spoof Kitchen’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.