Privacy policy
Studio Artisan (https://laras.studioartisan.my) is a service run by Aidan Partners Sdn Bhd. It takes the photos and short videos a business sends in, together with the caption it writes for each one, and posts them to that business's own social accounts with its permission. This policy says what we keep, why, who else sees it, and how to have it deleted.
Last updated: 28 September 2026.
Who we are
- Aidan Partners Sdn Bhd (Registration No. 202603095602), Level 30, Menara Prestige, Jalan Pinang, 50450 Kuala Lumpur, Federal Territory of Kuala Lumpur.
- Questions, or a request about your data: aidanpartners23@gmail.com.
What we keep, and why
From a business that uses the service
- The business's name, time zone and settings, so we know what to post and when.
- The photos and videos it sends us, the note that comes with each one, and the captions it writes for them.
We need these to make the posts, and to show what went out.
- The posts themselves: what was published, where, and when.
- Who approved, edited or rejected each post, and at what time. This is how we can show a post was agreed to.
- Alerts about anything that was held or failed.
From the people who sign in
- Name and email address, so they can be sent a sign-in link. There are no passwords: a link works once and only
for a few minutes, and we keep only a one-way hash of it, never the link itself.
From the social accounts a business connects
- The access tokens those platforms give us, so we can post to the accounts the business chose. They are stored
encrypted, we never see or store the password to any platform account, and a business can disconnect at any time on its Platforms page.
- How each post is doing on Facebook, Instagram and Threads: the number of likes, comments and shares, read every few
hours for a month after it goes out, so the business can see it on its dashboard. We ask for the totals and nothing else — who liked a post and what anybody wrote under it never reach us.
Automatically
- Ordinary server logs: what was done, when, and whether it worked. They never contain a caption's media, a
password, a token or an API key.
Location data in photos and videos
Photos and videos from a phone usually carry the place they were taken, the model of the phone and the moment it was recorded. Nothing we send anywhere carries any of it. Every copy we publish, and every copy sent for the safety check, has that information removed first.
What you sent us stays as it arrived, that information included, until it is deleted on the schedule below. It is your photo: it comes back to you whole when you download your data, and nobody outside Aidan Partners Sdn Bhd is ever given it.
Who else sees it
We send only what is needed to do the job, and only to:
- «OpenAI, whose moderation service checks each caption, and one photo from each batch, for anything unsafe
before it goes out. It receives the caption text and that photo with its location already removed. It is not sent your name, your email address or anything about who you are. — Keep this line only while `moderation.provider` is `openai`, and delete it otherwise. Where the business writes its own captions there is usually no such service at all and nothing is sent anywhere to be checked, and a policy that names a company we never call is false in the direction that matters most: it tells a business their words and their photos go somewhere they do not.»
- The social platforms a business has connected (Facebook, Instagram, Threads, TikTok, X), which receive the
post and its media — that is the point of the service.
- Railway, which runs the server this service is on and carries every connection between your browser and
us. Everything in this policy sits on machines they operate.
- Supabase, which stores the photos and videos you send us.
- Google, whose mail service delivers your sign-in links. It receives the address the link goes to.
Every caption is written by the business itself; nothing here generates one for you. We do not sell anything to anybody, we do not use any of it for advertising, and we do not use a business's photos or captions to train anything.
Where it is kept
Your photos and videos are stored in Singapore.
Everything else — your captions, your posts and the record of who approved what — is on the server that runs this service, in Singapore.
How long we keep it
- Original photos and videos: 90 days after a post is finished, then deleted automatically.
- Posts, captions and the record of who approved what: while the business uses the service.
- Server logs: 90 days.
- Backups: the newest 30 daily copies, so a deleted item can persist in a backup for up to 30 days before it
ages out.
How to have your data deleted
Whenever you like, at no cost:
- Ask us: email aidanpartners23@gmail.com from the address you sign in with, and say which business it is.
- Or ask whoever set your business up here to delete it for you.
We delete the business's photos and videos, its posts, its captions, the record of what was decided, its alerts, and the access tokens for its connected accounts, and we remove the accounts of anybody who was only there for that business. It is done within 30 days, and backups made before then age out within a further 30 days.
Two things we cannot delete for you:
- Posts already published. They are on the platform, not here. Delete them in that platform's own app.
- Records the law requires us to keep, such as invoices once you are paying for the service. These never include
your photos, your captions or your posts.
You can also disconnect any social account at any time without deleting anything else.
How to get a copy of it
Sign in, open your business's Settings page, and choose Download everything. You get a single file holding your photos and videos, the captions written for them, every post and what happened to it, who approved or edited what, and who can sign in for you. No waiting, no fee, no need to ask us.
The only things it leaves out are the ones we can't give: passwords and account logins (we keep no passwords, and the logins for your connected accounts are encrypted and never exported), posts already published on a platform, and anything belonging to anybody else.
Your rights
We are established in Malaysia, so the Personal Data Protection Act 2010 is the law that governs what we do with your data.
We hold and use it for one purpose only: to run this service for you — to make the posts you ask for, to send you the sign-in link that is the only way into your account, and to show you what went out. We do that on the basis of your consent, which you give by signing up, and because we cannot perform the agreement between us without it. You can withdraw that consent at any time by asking us to delete your business, as above; doing so ends the service, because there is nothing left to run it on.
You may ask to see a copy of what we hold, to correct it, to have it deleted, or to limit how we use it. The copy is a button, above; for anything else write to aidanpartners23@gmail.com and we will answer within 30 days. If you are not satisfied with our answer, you can complain to the Personal Data Protection Commissioner of Malaysia.
«Two things for somebody qualified to settle before this page is published. First, whether consent and contractual necessity are the right basis to name for what this service actually does — the paragraph above is a draft, not advice. Second, whether you will take on businesses in the UK or the EU: if you will, this section needs GDPR wording as well, and that is a larger change than adding a sentence.»
Cookies
One cookie, to keep you signed in. Nothing for advertising, and nothing that follows you to other sites.
Changes
If this policy changes, the new version appears on this page with a new date. If the change matters to you, we will say so by email.