1. Who we are
CreativeOS is a creative production workspace operated by Yuvabe Studios, Auroville, Tamil Nadu 605101, India. In this policy, “CreativeOS”, “we”, “us” and “our” refer to Yuvabe Studios as the operator of the CreativeOS service.
CreativeOS is a business tool used by creative and marketing agencies to produce reels and static posts for their clients. Most information we hold is business information belonging to an agency and its clients, rather than information about consumers.
For any privacy question, or to make a request about your data, contact studios@yuvabe.com.
2. What we collect
Account information
The name, work email address and organisation of each person we create a CreativeOS account for, together with their role in the workspace. Accounts are provisioned for agencies we work with; CreativeOS is not open to public self-signup.
Content you put into the workspace
CreativeOS stores the material you create and upload while producing an asset. This includes:
- Brand context for your clients — tone of voice, product details, claims, and similar reference material.
- Scripts, briefs and text you write or paste into a canvas, and the structured fields extracted from them.
- Files you upload, and reference images you collect, including the source URL a reference image came from.
- Prompts, generation settings, every generated image and video attempt, and the edits, corrections and approvals recorded against them.
Retaining attempts and approvals is a core function of the product, not an incidental log: it is what lets later work start from what already worked. If material you upload contains personal information — a person's likeness in a photograph, for example — we process it on your behalf as described in this policy.
Technical information
Standard service data: IP address, browser and device type, pages requested, timestamps, and error diagnostics. We use this to keep the service running, secure and debuggable.
3. Meta Platform Data
CreativeOS can publish approved content directly to an Instagram Business account. This is optional. It applies only if you choose to connect an account, and only for as long as that connection remains active.
When you connect, you authorise us through Meta's standard login flow. We never see or store your Facebook or Instagram password. Meta issues us an access token, which we store in encrypted form and use only to carry out the actions below.
Permissions we request, and why
- instagram_basic
- Read the connected Instagram Business account's ID, username, profile picture and account type, so the workspace can show you which account you are publishing to.
- instagram_content_publish
- Publish the reels and static posts you have reviewed and approved inside CreativeOS to your connected Instagram Business account.
- pages_show_list
- List the Facebook Pages you manage, so you can select the one linked to the Instagram Business account you want to connect.
- pages_read_engagement
- Confirm that you hold a publishing role on the selected Page, which Meta requires before content can be published to its linked Instagram account.
What we store
- The connected Instagram Business account's ID, username, account type and profile picture, so the workspace can show you which account you are publishing to.
- The IDs and names of Facebook Pages you manage, so you can pick the one linked to that Instagram account.
- A record of what CreativeOS published, when, and to which account, together with the identifier Instagram returns for the published post.
- The encrypted access token, and its expiry.
What we do not do with it
- We do not sell Meta Platform Data, and we never will.
- We do not use it for advertising, ad targeting, audience building or profiling.
- We do not use it to train machine-learning models, ours or anyone else's.
- We do not transfer it to data brokers, information-resale services or any party not listed in section 6.
- We do not read your direct messages, and we do not request permission to.
- We do not publish anything you have not explicitly approved inside CreativeOS.
Our handling of this data is governed by the Meta Platform Terms and Developer Policies, in addition to this policy.
Disconnecting
You can disconnect an Instagram account from CreativeOS at any time in the workspace settings. You can also revoke our access from Meta directly, under Settings → Apps and Websites on Facebook or Instagram. On disconnection we delete the stored access token immediately and delete the associated account metadata within 30 days. See section 8 for full deletion.
4. How we use information
- To provide the workspace and produce the assets you ask it for.
- To carry forward approved prompts, references and settings into your later work, which is the product's central purpose.
- To publish approved content to accounts you have connected, at your instruction.
- To secure the service, prevent abuse and diagnose faults.
- To support you, and to bill the agency we contract with.
- To meet legal and regulatory obligations.
We do not sell personal information. We do not serve advertising in CreativeOS.
5. AI model processing
CreativeOS coordinates third-party AI models to generate text, images and video. When you run a generation, the relevant prompt, context and input images are sent to the provider of the model you are using in order to produce the output you requested.
We select providers that offer business or enterprise terms under which submitted content is not used to train their models. Providers change, so we do not name them in this policy; we will tell you which providers are in use for your workspace on request to studios@yuvabe.com.
Content received from the Meta Platform is never sent to an AI model provider. The publishing integration is one-directional: CreativeOS sends approved assets to Instagram, and does not draw Instagram content into generation.
6. Sharing and disclosure
We share information only with:
- Infrastructure providers — cloud hosting, databases and object storage that run the service, acting on our instructions under contract.
- AI model providers — as described in section 5, and only the content needed for the generation you requested.
- Meta — the content and metadata required to publish a post you approved, sent to the account you connected.
- Professional advisers and authorities — where we are legally required to disclose, or need to establish or defend a legal claim.
- A successor — if the business is acquired or reorganised, under terms no less protective than this policy.
Each agency's workspace is a separate context boundary. We do not expose one agency's brand context, references or generations to another.
7. Retention
- Workspace content — kept for as long as your agency holds an account with us, because its value is cumulative. Deleted within 90 days of the account closing, unless you ask us to delete it sooner.
- Meta Platform Data — kept only while the connection is active. Access tokens are deleted on disconnection; account metadata and publishing records within 30 days.
- Technical logs — kept for a limited operational period, then deleted or aggregated so they no longer identify anyone.
- Billing and tax records — kept as long as applicable law requires.
8. Deleting your data
You can ask us to delete your data at any time, and you do not need an account to make the request.
Email studios@yuvabe.com with the subject line Data deletion request, telling us the workspace or Instagram account concerned. We will confirm receipt within 5 working days and complete the deletion within 30 days, then confirm in writing when it is done.
To remove only the Instagram connection, disconnect it in the workspace settings, or revoke CreativeOS from Settings → Apps and Websites on Facebook or Instagram. Revoking from Meta stops all further access immediately; email us as above if you also want the stored account metadata and publishing history erased ahead of the 30-day window.
We may retain the minimum needed to meet a legal obligation or resolve a dispute. Where we do, we will tell you what and why.
9. Security
We encrypt data in transit and at rest, store access tokens encrypted, restrict internal access to staff who need it, and separate each agency's workspace.
We describe the controls we actually operate, and we will not claim a certification we do not hold. CreativeOS is an early-stage product; as the security programme develops we will state publicly what has been implemented. No system is perfectly secure, and we cannot guarantee absolute security.
10. Your rights
Depending on where you live, you may have the right to access a copy of your personal information, correct it, delete it, object to or restrict how we use it, ask for it in a portable format, and complain to your data protection regulator.
Exercise any of these by emailing studios@yuvabe.com. We do not charge for a reasonable request, and we will not treat you differently for making one.
Where we hold information on behalf of an agency using CreativeOS, that agency directs how it is handled. We will refer your request to them and support them in answering it.
11. International transfers
We operate from India, and our providers may process data in other countries. Where information moves across borders we rely on appropriate safeguards, such as standard contractual clauses, so it remains protected to the standard described here.
12. Children
CreativeOS is a business tool and is not directed at children. We do not knowingly create accounts for anyone under 18. If you believe a child has provided us with personal information, contact us and we will delete it.
13. Changes
If we change this policy we will update the date at the top of this page. Where a change materially affects how we handle your information, we will tell account holders directly before it takes effect.
14. Contact
Yuvabe Studios
Auroville, Tamil Nadu 605101, India
studios@yuvabe.com