Studio stores creator video, captions, and tokens for the social accounts you connect. These are the practices we use to protect that workspace.
1. Encryption: Traffic uses HTTPS (TLS). Files and records are encrypted at rest with AWS-managed keys.
2. Secrets: Platform app keys and tokens are stored in AWS Systems Manager Parameter Store, encrypted, not in the frontend.
3. Sign-in: Access uses signed JWTs with expiration and issuer checks. Teammates work in the creator’s workspace only after an invite.
4. Connected platforms: YouTube, TikTok, Instagram, Facebook, and other tokens are used only to import or publish the content you choose. Deleting a profile in Social Profiles deletes the stored tokens. We try to revoke them with that platform. If that call fails, revoke Studio from the platform’s app settings.
5. Logging: API and job logs go to AWS CloudWatch for debugging and uptime, not for advertising.
6. Least privilege: IAM roles grant only the access each service needs.
7. Deletion: Delete a connected account in Social Profiles to revoke its tokens. Delete your Studio account from Account, or email khim.ung@distributedjava.com to delete your account, library files, and remaining stored tokens.