Privacy Policy — SiteUP Agendador de Posts (Hermes Studio)
Last updated: 2026-06-18
This Privacy Policy explains how the application registered with the social platforms as "SiteUP Agendador de Posts" (product name: Hermes Studio, hereinafter "the App") collects, uses, stores and protects information when it connects to social networks on behalf of the account owner. The App is an internal, self-hosted tool that creates, schedules and publishes content only to the account owner's own connected accounts. It is not a multi-tenant SaaS open to arbitrary users.
1. Who we are — Controller and Processor
Two distinct roles apply to the personal data processed through the App, under both the Brazilian General Data Protection Law (LGPD, Lei nº 13.709/2018) and the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679):
- Data Controller (Controlador): Jan Val Ellam (brand "MENTALMA"), the owner of the social media accounts connected to the App. The Controller decides which content is published and on which of its own accounts, and is the holder of the connected accounts' data.
- Data Processor / Operator (Operador): SiteUP (marketing agency), which develops and operates the App and processes personal data solely on the Controller's behalf and under its instructions, exclusively to provide the publishing and scheduling service.
SiteUP, as Processor/Operator, does not use the data for its own purposes. For privacy matters, including requests to exercise the rights described below, our Data Protection contact (DPO/Encarregado) is: contato@siteup.com.br.
2. What data we access — by network and by scope
When the account owner connects a social network through OAuth, the App requests only the minimum permissions required to publish and schedule content on the owner's own account. The data accessed depends on the authorized scopes for each network:
- Pinterest — scopes boards:read, boards:write, pins:read, pins:write, user_accounts:read: read the connected account's boards (to choose where to publish), create and read Pins on the owner's behalf, and read basic public account information needed to identify the connected account.
- TikTok — scopes user.info.basic, video.publish (Content Posting API): read the connected account's basic profile information (to confirm which account is connected) and publish videos to the owner's own TikTok account.
- YouTube / Google — scopes youtube.upload, youtube.readonly: upload videos to the owner's own YouTube channel and read the channel's own resources (such as the channel and its videos) needed to manage and schedule publishing.
- Meta / Instagram — scopes instagram_basic, instagram_content_publish, pages_show_list, pages_read_engagement, business_management: read basic profile information of the connected Instagram professional account, publish content to that account, list the Facebook Pages the owner manages (to identify the linked account), read basic engagement of the owner's own content, and access the Business assets the owner manages so the correct account can be selected for publishing.
We do not access private messages or direct messages, follower lists, or any personal data unrelated to the publishing function. We only access what is strictly necessary to publish and schedule content on the account owner's own accounts.
3. Purpose and legal basis
We process the data described above for a single purpose: to create, schedule and publish the content that the team itself produces and approves, on the account owner's own connected accounts. We do not process data for advertising, profiling, audience building, or any unrelated purpose.
The legal bases for this processing are:
- Consent — granted by the account owner when authorizing the OAuth connection (LGPD Art. 7º, I; GDPR Art. 6(1)(a)).
- Performance of a contract / legitimate interest of the data subject — to deliver the publishing and scheduling service requested by, and operated for, the account owner (LGPD Art. 7º, V; GDPR Art. 6(1)(b)).
4. Storage and security
OAuth access and refresh tokens are stored encrypted at rest using AES-256-GCM on our own backend (hosted on Supabase). Tokens are never exposed to the browser, never embedded in client-side code, and never shared with any third party other than the respective network's official API to perform the requested publishing action. All data in transit is protected with HTTPS. Generated media is kept in our own private storage.
5. Retention
Access tokens are retained only while the account remains connected. When the account owner disconnects a network (or requests deletion), the corresponding encrypted token is removed. We keep only what is strictly necessary to operate the publishing and scheduling feature.
6. Sharing and sub-processors
We do not sell, rent or share personal data with third parties for their own purposes, and we do not perform profiling or targeted advertising. Data is transmitted only to the following parties, strictly to deliver the service:
- The official APIs of the four connected networks (Pinterest, TikTok, YouTube/Google, Meta/Instagram), to perform the publishing and scheduling actions requested by the account owner.
- Supabase, our hosting and database provider (backend infrastructure and encrypted storage).
- OpenAI (image generation) and Anthropic (Claude), used only when the account owner chooses to generate content (such as images) inside the App; only the content/prompt necessary for generation is sent, not OAuth tokens or connected-account credentials.
7. Your rights
As a data subject, and to the extent applicable under LGPD and GDPR, you may exercise the following rights regarding your personal data:
- Confirmation that processing exists, and access to your data;
- Correction of incomplete, inaccurate or outdated data;
- Data portability;
- Deletion / erasure of the data processed with consent;
- Withdrawal of consent at any time (without affecting the lawfulness of processing carried out before withdrawal);
- Information about with whom the data has been shared.
To exercise any of these rights, contact contato@siteup.com.br. You also have the right to lodge a complaint with the competent supervisory authority — in Brazil, the ANPD (Autoridade Nacional de Proteção de Dados); in the EU/EEA, your local Data Protection Authority.
8. Data deletion
You can delete your data at any time. The fastest way is to disconnect the account inside the App (Settings > Connections > Disconnect), which immediately removes the encrypted OAuth token. For full, step-by-step instructions, the categories of data deleted, and the deletion timeframe, see our dedicated page: Data Deletion Instructions (/data-deletion.html).
9. Cookies
The App uses only strictly necessary cookies for session and authentication (to keep the authorized user logged in). We do not use analytics cookies, advertising cookies, or third-party tracking technologies. For this reason, no cookie-consent banner is presented. Should we ever introduce non-essential cookies (for analytics or similar purposes), we will update this Policy and request your consent beforehand, where required by law.
10. International transfers
Some of our providers (such as Supabase and Anthropic (Claude)) and the official APIs of the connected networks may process or store data on servers located outside Brazil and the European Economic Area (EEA). Where this occurs, such transfers are carried out under adequate safeguards, including, where applicable, the European Commission's Standard Contractual Clauses (SCC) and the safeguards required by the LGPD for international data transfers.
11. Google Limited Use
SiteUP Agendador de Posts (Hermes Studio) use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
12. Contact / DPO and effective date
For any question about this Privacy Policy, or to exercise your rights, contact our Data Protection contact (DPO/Encarregado): contato@siteup.com.br.
Last updated: 2026-06-18. We may update this Policy from time to time; the effective date above always reflects the current version.
Resumo em Português (PT-BR)
O SiteUP Agendador de Posts (produto: Hermes Studio) é uma ferramenta interna e self-hosted que cria, agenda e publica conteúdo apenas nas próprias contas conectadas do cliente Jan Val Ellam (marca "MENTALMA"). Não é um SaaS multi-tenant.
Papéis (LGPD/GDPR): o Controlador é Jan Val Ellam (dono das contas); a SiteUP atua como Operador, tratando dados somente em nome e sob instruções do Controlador. Contato/Encarregado (DPO): contato@siteup.com.br.
O que acessamos, por rede e escopo: Pinterest (boards:read, boards:write, pins:read, pins:write, user_accounts:read); TikTok (user.info.basic, video.publish); YouTube/Google (youtube.upload, youtube.readonly); Meta/Instagram (instagram_basic, instagram_content_publish, pages_show_list, pages_read_engagement, business_management). Não acessamos mensagens privadas, listas de seguidores nem dados pessoais não relacionados.
Finalidade e base legal: publicar/agendar o conteúdo criado e aprovado pela equipe, nas contas do próprio dono, com base no consentimento (LGPD Art. 7º, I; GDPR Art. 6(1)(a)) e na execução de contrato / legítimo interesse do titular (LGPD Art. 7º, V; GDPR Art. 6(1)(b)). Sem publicidade ou profiling.
Segurança e retenção: tokens OAuth cifrados em repouso com AES-256-GCM no nosso backend (Supabase), nunca expostos ao navegador, sempre via HTTPS. O token é mantido apenas enquanto a conta estiver conectada e removido ao desconectar.
Compartilhamento: não vendemos nem compartilhamos dados. Enviamos dados somente às APIs oficiais das quatro redes, ao Supabase, à OpenAI e à Anthropic (Claude) (apenas quando você opta por gerar conteúdo), estritamente para prestar o serviço.
Seus direitos: confirmação, acesso, correção, portabilidade, eliminação e revogação do consentimento. Você pode reclamar à ANPD (Brasil) ou à autoridade de proteção de dados da UE. Exclusão de dados: veja a página dedicada /data-deletion.html.
Cookies: apenas os estritamente necessários de sessão/autenticação; sem analytics, anúncios ou rastreadores, e por isso sem banner de consentimento. Transferências internacionais: provedores (Supabase, OpenAI, Anthropic) e as APIs das redes podem operar fora do Brasil/EEE, com salvaguardas adequadas (incluindo SCC quando aplicável).
Última atualização: 2026-06-18. Contato/DPO: contato@siteup.com.br.