Effective Date: April 17, 2026
Badass Studio ("Studio," "we," "us," or "our") is a marketing content management platform operated by Badass Platform LLC. This Privacy Policy explains how we collect, use, store, and protect information when you use Badass Studio to manage your Instagram Business Account and marketing content.
By connecting your Instagram Business Account to Badass Studio, you agree to this Privacy Policy.
1. Who We Are
Badass Studio is owned and operated by:
Badass Platform LLC
11921 Freedom Drive, Reston, VA 20190
privacy@badassplatform.com
This Privacy Policy applies specifically to Badass Studio, our marketing content management tool.
2. What Badass Studio Does
Badass Studio is a marketing content management platform that allows authorized users to:
- Connect Instagram Business Accounts via Meta OAuth
- Generate marketing content using AI technology
- Create, schedule, and publish posts to Instagram
- View Instagram Insights and analytics for published content
- Manage content calendars across multiple brands
Badass Studio is an internal business tool, not a consumer-facing application.
3. Information We Collect
3.1 Information from Meta/Instagram
When you connect your Instagram Business Account, we collect:
| Data Type | Description | Purpose |
|---|---|---|
| Instagram Business Account ID | Your unique Instagram account identifier | Required to publish content and fetch insights |
| Instagram Username | Your public @handle | Display in Studio dashboard |
| Profile Picture URL | Your public profile image | Display in Studio dashboard |
| Facebook Page ID & Name | The Facebook Page linked to your Instagram | Required by Meta API for publishing |
| Access Tokens | OAuth tokens to access Instagram API | Authenticate API requests on your behalf |
3.2 Instagram Insights Data
With your permission (instagram_manage_insights), we collect:
Account-Level Metrics:
- Follower count
- Media count
- Impressions and reach
- Profile views
- Website clicks
- Accounts engaged
Post-Level Metrics:
- Impressions and reach
- Engagement (likes, comments, shares, saves)
This data is fetched from Instagram's Insights API and stored to display analytics in your Studio dashboard.
3.3 Content You Create
When you use Badass Studio, we store:
- Post content (captions, hashtags, text)
- Generated marketing images (stored in Firebase Storage)
- Images and media URLs
- Scheduled publish times
- Post status (draft, scheduled, published, etc.)
- Campaign organization data
3.4 Instagram Content Sync
To display your content library, we fetch and store:
- Your published Instagram posts (media URLs, captions, timestamps)
- Post IDs for analytics correlation
- This data is fetched from YOUR account only, not from followers or other users
3.5 AI-Generated Content
When you use our AI content generation feature:
- We send your content prompts to Google's Gemini API
- We store the generated content
- We track token usage for cost monitoring
- We do NOT send any Instagram user data or follower information to AI services
3.6 Technical Data
- Timestamps of actions (publishing, scheduling, analytics refresh)
- Error logs for troubleshooting
- Token expiration and refresh timestamps
4. How We Use Your Information
We use the information we collect to:
| Purpose | Legal Basis |
|---|---|
| Publish content to your Instagram account | Your consent via OAuth |
| Display analytics from your Instagram account | Your consent via OAuth |
| Generate AI-powered marketing content | Legitimate business interest |
| Refresh access tokens automatically | Necessary to maintain service |
| Monitor system health and fix errors | Legitimate business interest |
| Track AI usage costs | Legitimate business interest |
We do NOT:
- Sell your data to third parties
- Use your data for advertising purposes
- Share your Instagram credentials with anyone
- Access your followers' personal information (we only access aggregate metrics like follower count, not individual follower profiles or identities)
- Access information about who specifically liked, commented on, or engaged with your posts (we only see counts, not individual users)
- Read your direct messages
- Use your data for any purpose not described in this policy
5. Instagram/Meta Permissions We Request
When connecting your Instagram Business Account, we request these permissions:
| Permission | Why We Need It |
|---|---|
instagram_basic | Access your Instagram Business Account ID and username |
instagram_content_publish | Publish posts to your Instagram account |
instagram_manage_insights | Fetch performance metrics for your posts and account |
instagram_manage_comments | Future feature: respond to comments |
pages_show_list | Find your Facebook Page linked to Instagram |
pages_read_engagement | Read engagement data from your Page |
You can revoke these permissions at any time through your Meta account settings.
6. Third-Party Services
Badass Studio uses the following third-party services:
6.1 Meta/Facebook (Instagram Graph API)
- Purpose: OAuth authentication, content publishing, insights retrieval
- Data Shared: Your Instagram account ID, access tokens, content you publish
- Privacy Policy: Meta Privacy Policy
6.2 Google Cloud (Gemini AI)
- Purpose: AI-powered marketing content generation
- Data Shared: Content prompts and generation parameters only
- NOT Shared: Instagram account data, follower information, analytics
- Privacy Policy: Google Cloud Privacy
6.3 Firebase/Google Cloud (Data Storage)
- Purpose: Secure data storage
- Location: United States (us-east4)
- Privacy Policy: Firebase Privacy
6.4 Firebase Storage (Image Hosting)
- Purpose: Store generated marketing images for Instagram publishing
- Data Stored: AI-generated marketing images (PNG format)
- NOT Stored: Personal photos, user-uploaded content from Instagram followers
7. Automated Processes
Badass Studio runs the following automated background processes:
| Process | Frequency | Purpose |
|---|---|---|
| Scheduled Publisher | Every 5 minutes | Publishes posts you've scheduled for a specific time |
| Token Refresh | Daily at 3 AM EST | Automatically refreshes Instagram tokens before they expire |
| Analytics Sync | On-demand | Fetches latest insights from Instagram for your posts |
| Content Library Sync | On-demand | Syncs your published Instagram posts for display in Studio |
These processes run automatically to maintain your connection and deliver scheduled content without manual intervention.
8. Data Storage and Security
8.1 Where We Store Data
Your data is stored in Google Cloud Firebase (Firestore) in the United States.
8.2 How We Protect Data
- Access tokens are stored securely in our database
- All data transmission uses HTTPS/TLS encryption
- Access to production data is restricted to authorized personnel
- We use Google Cloud's security infrastructure
8.3 Token Management
- Instagram access tokens are long-lived (60 days)
- We automatically refresh tokens before expiration
- If a token cannot be refreshed, we notify you to reconnect
- You can disconnect your account at any time
9. Data Retention
| Data Type | Retention Period |
|---|---|
| Instagram connection data | Until you disconnect your account |
| Access tokens | Refreshed every 60 days; deleted on disconnect |
| Post content | Until you delete it or disconnect |
| Analytics snapshots | Retained indefinitely for historical reporting |
| AI generation logs | 90 days |
10. Your Rights
10.1 All Users
You have the right to:
- Access: Request a copy of your data
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your data
- Disconnect: Revoke Instagram access at any time
- Portability: Request your data in a portable format
10.2 European Users (GDPR)
If you are in the European Economic Area, you also have the right to:
- Object to processing based on legitimate interests
- Restrict processing in certain circumstances
- Lodge a complaint with your local data protection authority
10.3 California Users (CCPA)
If you are a California resident, you have the right to:
- Know what personal information we collect
- Request deletion of your personal information
- Non-discrimination for exercising your rights
We do not sell personal information.
11. How to Exercise Your Rights
To exercise any of your rights, contact us at:
Email: privacy@badassplatform.com
Subject Line: "Privacy Request - Badass Studio"
We will respond to verified requests within 30 days.
To Disconnect Your Instagram Account:
- Go to Badass Studio Settings
- Click "Disconnect Instagram"
- Your access tokens will be deleted immediately
You can also revoke access through Meta:
- Go to Facebook Settings > Business Integrations
- Find Badass Studio and remove it
12. Children's Privacy
Badass Studio is a business tool and is not intended for use by individuals under 18 years of age. We do not knowingly collect information from children.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make changes:
- We will update the "Last Updated" date at the top
- For material changes, we will notify you via email or in-app notification
- Continued use after changes constitutes acceptance
We retain all previous versions of this policy and will provide them upon request.
14. Contact Us
If you have questions about this Privacy Policy or our data practices:
Badass Platform LLC
Email: privacy@badassplatform.com
11921 Freedom Drive, Reston, VA 20190
For Meta-specific concerns, you may also contact Meta directly through their Help Center.
15. Meta Platform Terms Compliance
This application complies with:
We only use Instagram data as described in this Privacy Policy and in accordance with Meta's terms.