Elele Social Studio

Privacy Policy

Last updated: 10 August 2026

Elele Social Studio is the internal content workspace of the small team behind Elele, a free real-chat app. We use it to plan, review and publish our own social posts. It is not a product we sell and it is not open to the public: only invited members of our team can sign in, and accounts are created by an administrator.

This policy covers the workspace at studio.elele.app and every social platform it connects to. The Elele chat app has its own policy at elele.me/privacy.

What we store

Team accounts
Email address, display name and role. There is no public sign-up, and no tracking or advertising identifiers anywhere in the panel.
Content our team creates
Campaign briefs, captions, hashtags, schedules and the images and videos we upload. Held in Google Cloud (Firestore and Cloud Storage) in the europe-west1 region.
Connections to social accounts
Access and refresh tokens for the accounts we connect, plus the account, page or channel name so the owner can see which account is linked. Tokens are kept in Google Secret Manager, one secret per connection, and are never sent to the browser.
Results of our own publications
For each published post, the id and public URL returned by the platform, whether it succeeded or failed, and — where the platform offers it — the reach, impressions and engagement counts of that post.

Connected platforms

We connect one account per platform, always our own, always through the platform's official authorization screen. In every case the account holder chooses what to grant, and we ask for the narrowest set of permissions that lets us publish. We never read other people's accounts, we do not search or index any platform, and we do not buy, sell or exchange data with anyone.

YouTube

Elele Social Studio uses YouTube API Services. By connecting a channel, you also agree to the YouTube Terms of Service, and Google's handling of your data is described in the Google Privacy Policy.

We do not read, store or display statistics, comments or playlists from YouTube. Of an upload we keep only the video id and watch URL. Access can be withdrawn at any time from myaccount.google.com/permissions, or with "Bağlantıyı kaldır" (Remove connection) in the panel, which deletes the stored tokens.

Facebook, Instagram and Threads

These run on Meta's APIs and are authorized through Facebook Login.

We do not read messages, comment threads, follower lists or anyone else's content. Access can be withdrawn from Facebook settings or by removing the connection in the panel.

TikTok

Access can be withdrawn in the TikTok app under Settings → Security → Manage app permissions, or by removing the connection in the panel.

Pinterest

We do not read other people's pins, boards or profiles. Access can be withdrawn on Pinterest under Settings → Security → Connected apps, or by removing the connection in the panel.

X (Twitter)

We do not read timelines, search, direct messages or anyone else's posts. Access can be withdrawn on X under Settings → Security and account access → Apps and sessions → Connected apps, or by removing the connection in the panel.

AI providers

Draft copy and images are generated with third-party AI models. What we send is the brief and the draft text of the post we are writing. We do not send platform tokens, data read from connected accounts, or personal data about anyone outside our team.

Deleting your data

Everything we hold about a connected account can be removed by you, at any time, in two ways:

To have the rest deleted — the campaign content, media files, published post records or a team account — write to cenkledigital@gmail.com and we will delete it within 30 days and confirm by email.

How long we keep things

Who else sees the data

Nobody outside the team. We do not sell or share anything. The data sits with our infrastructure providers — Google Cloud and Firebase — and, for the drafting step described above, with our AI providers. Publishing sends the post to the platform you connected, which is the point of the tool.

Security

Sign-in goes through Firebase Authentication, and every call from the panel is verified with Firebase App Check. Tokens are stored in Secret Manager rather than the database so that they never appear in backups, exports or logs, and they are read server-side only, inside a Cloud Function.

Changes

When we add a platform or ask for a new permission, we update this page before the change goes live, and the date at the top changes with it.

Contact

Questions, or a request to delete something: cenkledigital@gmail.com.