Legal
Social Media Studio privacy policy
Last updated 12 September 2026.
Who this covers
This policy is about Social Media Studio, the publishing tool The Ai Web Company provides to its customers. It sits alongside our site's own privacy policy, which covers visitors to theaiwebcompany.co.uk. We are The Ai Web Company, a UK partnership. Write to us at hello@theaiwebcompany.co.uk about anything on this page.
The two kinds of people in this policy
Our customer is the business that uses the studio. Our customer's audience is everybody who sees what the customer posts. We hold accounts and content for customers. We hold nothing about their audience beyond the counts a platform publishes about a post.
What we hold about a customer
The name and email address of each person who signs in, the name of the business, the brand material they give us (logo, colours, tone of voice, the claims they are willing to make), the photographs and video they upload, the posts the studio drafts and the posts it publishes and the results the platforms report.
What we hold when a TikTok account is connected
An access token and a refresh token issued by TikTok, the account's TikTok open id, its display name, its profile picture URL and the date it was connected. Tokens are held on our servers and are never sent to a browser. We use them for three things and nothing else: reading the account's current posting options before a post, posting the customer's approved post and reading back the public counts for that account and its posts.
- We do not read a customer's TikTok inbox, followers or private messages.
- We do not post anything a person has not approved in the studio.
- We do not use TikTok data for advertising and we do not sell or share it.
- We do not combine TikTok data with data from any other source to profile anyone.
Disconnecting
A customer can disconnect a TikTok account in the studio at any time. Disconnecting asks TikTok to revoke our access and deletes the stored tokens. The same can be done from TikTok's own settings, under Manage app permissions. Posts already published stay on TikTok, because they belong to the account, not to us.
How long we keep things
Tokens until the account is disconnected or the customer leaves. Posts, artwork and results for as long as the customer's studio exists, because that history is what the tool is for. When a customer leaves we delete their studio, including tokens, on request and in any case within thirty days of the end of the work.
Who else touches it
We use suppliers to run the studio: Cloudflare (the application and file storage), Supabase (the database and sign in), Anthropic (the models that draft words and check artwork), Resend (email), Vercel (this website). Publishing sends a post to the platform the customer chose: TikTok, Meta for Facebook and Instagram. Each is used for the job named and nothing else.
Security
Access to a studio needs a sign in and every studio is separated from every other in the database itself, not only in the interface. Platform tokens are held in a table our own application reads with a server key; they are not readable by any signed in browser.
Your rights
Ask us for a copy of what we hold, ask us to correct it, ask us to delete it, or object to something we do with it. Write to hello@theaiwebcompany.co.uk. If we cannot resolve it you can complain to the UK Information Commissioner's Office.
Children
The studio is a business tool and is not for anyone under 18.
Changes
We date this page whenever it changes and material changes are told to customers by email.
Read the product page or the terms of service for Social Media Studio.