Privacy Policy

Last updated: August 8, 2026

This Privacy Policy explains how Bardiyah collects, uses, stores, and protects personal information when you use our website and content production platform.

Information We Collect

We may collect the following categories of information:

  • Account information such as your name, email address, and encrypted password.
  • Workspace data that you create inside the platform, including projects, scripts, schedules, tags, and content records.
  • Integration data that you choose to connect, such as Meta page/account identifiers and access tokens required to fetch social performance metrics.
  • Technical information such as browser type, IP address, device information, and usage logs.
  • Communication data when you contact us through forms or support channels.

How We Use Your Information

We use collected information to:

  • provide and maintain the platform,
  • authenticate users and secure accounts,
  • save and display your content workspace data,
  • fetch connected platform metrics when you explicitly link external accounts,
  • improve performance, reliability, and product features,
  • respond to support requests and operational issues,
  • comply with legal obligations and prevent abuse.

Legal Basis

Where required by applicable law, we process information based on one or more of the following grounds:

  • your consent,
  • performance of a contract with you,
  • compliance with legal obligations,
  • our legitimate interests in operating and securing the service.

Meta and Social Integrations

If you connect Facebook or Instagram through Meta, we store the minimum information required to maintain that connection and retrieve the metrics you requested. This may include:

  • your Meta user identifier,
  • selected Facebook page identifier,
  • selected Instagram business account identifier,
  • encrypted access tokens,
  • granted scopes and connection timestamps.

We use this information only to support the connected features in your account. You can disconnect the integration from your settings at any time.

Social Platform Connections

Connecting a social platform is optional and always starts with you. Nothing is connected automatically, and the platform is only contacted after you have signed in there and approved the connection.

What we read

For TikTok, we read the connected account’s profile, meaning its username, avatar, and follower count, together with that account’s own videos and the public performance metrics those videos report. We read nothing else, and we never read another account’s data.

Meta connections are described in the section above. YouTube works differently and is worth understanding: it needs no account connection at all. You paste a public video URL, and we read that video’s public figures through the YouTube Data API using our own developer credentials. You are never asked to sign in to YouTube, no authorization screen appears, and we hold no access token for your channel. Because this uses YouTube API Services, Google’s handling of the data it receives is governed by the Google Privacy Policy.

Read only

Every social platform connection is read only. We never post, upload, edit, schedule, or delete anything on your behalf on any connected platform. The connection exists to bring numbers in, not to send anything out.

How access tokens are stored

Access tokens are encrypted at rest in our database. They are never shared with third parties, never sent to your browser, and never exposed to any client application. They are used only by our servers, only to make the read requests described above.

Performance records over time

Platforms report the figures they hold today, not a history. So that you can see how a video performs over time, we record a daily snapshot of the metrics for the content you have linked. These records live in your workspace and are kept for as long as your account is active. They are removed when you delete the record, delete the content it belongs to, or delete your account.

Disconnecting

You can disconnect any platform at any time from the Integrations settings page. Disconnection takes effect immediately: we revoke the access token with the platform where the platform supports it, we delete the stored token, and we stop collecting any further data from that account.

Performance records already collected stay in your workspace, because they are part of your own reporting history. Delete them, the content they belong to, or your account, and they go with it.

The platforms' own policies

Once you connect an account, that platform’s own privacy policy governs how it handles your data on its side. Please review the policy of any platform you connect.

MCP and AI Assistant Integrations

What an MCP connection is

MCP, the Model Context Protocol, is an open standard that lets an AI assistant work with an external service on your behalf. Connecting Bardiyah over MCP means an assistant such as ChatGPT or Claude can read and write your ideas, projects, and scripts while you talk to it, instead of you moving between two applications. In plain terms, it is a door between that assistant and your Bardiyah account, and you decide whether it is open.

You open the connection, not us

Every MCP connection is started and authorized by you. We never create one on your behalf. No assistant reaches your account until you have signed in to Bardiyah and approved the connection on our consent screen, where the requested permissions are listed before you agree to them.

What moves, and what we do with it

When a user connects Bardiyah to ChatGPT, Claude, or any other MCP client, the requests and the data needed to carry out those commands may be sent to Bardiyah.

We process that data for operating the service, providing the features the user requests, maintaining them, and improving their operational functionality, without using user content to train AI models except with explicit consent. Bardiyah does not use user content to train its own AI models unless explicitly stated and consented to.

What a connected client can reach

A connected client can reach only your own content, and only within the permissions you granted when you approved the connection. It cannot reach another user’s workspace, and it cannot exceed the permissions you granted. Narrower permissions mean a narrower door.

The assistant’s policy governs its own handling

Once data reaches ChatGPT, Claude, or any other client, that client’s privacy policy governs how it is stored, processed, and used from that point on. We cannot control, audit, or undo how a third-party assistant handles data after it leaves our systems, and we cannot delete it there on your behalf. Please read the privacy policy of any assistant before you connect it.

Disconnecting

You can disconnect any MCP connection at any time from the MCP server page in your settings. Disconnection takes effect immediately: the client’s access token is revoked, and that client can make no further requests to your account.

Retention after disconnection

Disconnecting deletes the stored authorization for that client. Your own workspace content is unaffected and stays exactly as you left it, because the connection was a way in, not a copy.

Anything the assistant already received sits with that assistant, under its own policy and its own retention rules. Removing it there is done through that service, not through Bardiyah.

Data Retention

We retain your information for as long as your account remains active or as needed to provide the service, resolve disputes, enforce agreements, and comply with legal obligations.

When you remove integrations or delete content, related records may be removed or anonymized according to operational and legal requirements.

Sharing of Information

We do not sell your personal information. We may share information only in the following cases:

  • with service providers who help operate the platform,
  • when required by law or valid legal process,
  • to protect the rights, security, and integrity of the platform and its users,
  • in connection with a merger, acquisition, or asset transfer.

Security

We apply reasonable technical and organizational safeguards to protect data, including encryption for sensitive stored credentials where applicable. However, no method of transmission or storage is completely secure.

Your Rights

Depending on your location, you may have rights to:

  • access your personal information,
  • correct inaccurate data,
  • request deletion of your data,
  • object to or restrict certain processing,
  • withdraw consent where processing is based on consent.

You may contact us to exercise these rights.

Third-Party Services

Our service may link to or integrate with third-party platforms such as Meta, YouTube, TikTok, and others. Their privacy practices are governed by their own policies, and you should review those separately.

Contact

If you have questions about this Privacy Policy or your personal data, please contact us through the website contact form or the support channel made available by the service.