Hermes Studio Hermes Studio

Privacy Policy — SiteUP Agendador de Posts (Hermes Studio)

Last updated: 2026-06-18

This Privacy Policy explains how the application registered with the social platforms as "SiteUP Agendador de Posts" (product name: Hermes Studio, hereinafter "the App") collects, uses, stores and protects information when it connects to social networks on behalf of the account owner. The App is an internal, self-hosted tool that creates, schedules and publishes content only to the account owner's own connected accounts. It is not a multi-tenant SaaS open to arbitrary users.


1. Who we are — Controller and Processor

Two distinct roles apply to the personal data processed through the App, under both the Brazilian General Data Protection Law (LGPD, Lei nº 13.709/2018) and the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679):

SiteUP, as Processor/Operator, does not use the data for its own purposes. For privacy matters, including requests to exercise the rights described below, our Data Protection contact (DPO/Encarregado) is: contato@siteup.com.br.

2. What data we access — by network and by scope

When the account owner connects a social network through OAuth, the App requests only the minimum permissions required to publish and schedule content on the owner's own account. The data accessed depends on the authorized scopes for each network:

We do not access private messages or direct messages, follower lists, or any personal data unrelated to the publishing function. We only access what is strictly necessary to publish and schedule content on the account owner's own accounts.

3. Purpose and legal basis

We process the data described above for a single purpose: to create, schedule and publish the content that the team itself produces and approves, on the account owner's own connected accounts. We do not process data for advertising, profiling, audience building, or any unrelated purpose.

The legal bases for this processing are:

4. Storage and security

OAuth access and refresh tokens are stored encrypted at rest using AES-256-GCM on our own backend (hosted on Supabase). Tokens are never exposed to the browser, never embedded in client-side code, and never shared with any third party other than the respective network's official API to perform the requested publishing action. All data in transit is protected with HTTPS. Generated media is kept in our own private storage.

5. Retention

Access tokens are retained only while the account remains connected. When the account owner disconnects a network (or requests deletion), the corresponding encrypted token is removed. We keep only what is strictly necessary to operate the publishing and scheduling feature.

6. Sharing and sub-processors

We do not sell, rent or share personal data with third parties for their own purposes, and we do not perform profiling or targeted advertising. Data is transmitted only to the following parties, strictly to deliver the service:

7. Your rights

As a data subject, and to the extent applicable under LGPD and GDPR, you may exercise the following rights regarding your personal data:

To exercise any of these rights, contact contato@siteup.com.br. You also have the right to lodge a complaint with the competent supervisory authority — in Brazil, the ANPD (Autoridade Nacional de Proteção de Dados); in the EU/EEA, your local Data Protection Authority.

8. Data deletion

You can delete your data at any time. The fastest way is to disconnect the account inside the App (Settings > Connections > Disconnect), which immediately removes the encrypted OAuth token. For full, step-by-step instructions, the categories of data deleted, and the deletion timeframe, see our dedicated page: Data Deletion Instructions (/data-deletion.html).

9. Cookies

The App uses only strictly necessary cookies for session and authentication (to keep the authorized user logged in). We do not use analytics cookies, advertising cookies, or third-party tracking technologies. For this reason, no cookie-consent banner is presented. Should we ever introduce non-essential cookies (for analytics or similar purposes), we will update this Policy and request your consent beforehand, where required by law.

10. International transfers

Some of our providers (such as Supabase and Anthropic (Claude)) and the official APIs of the connected networks may process or store data on servers located outside Brazil and the European Economic Area (EEA). Where this occurs, such transfers are carried out under adequate safeguards, including, where applicable, the European Commission's Standard Contractual Clauses (SCC) and the safeguards required by the LGPD for international data transfers.

11. Google Limited Use

SiteUP Agendador de Posts (Hermes Studio) use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

12. Contact / DPO and effective date

For any question about this Privacy Policy, or to exercise your rights, contact our Data Protection contact (DPO/Encarregado): contato@siteup.com.br.

Last updated: 2026-06-18. We may update this Policy from time to time; the effective date above always reflects the current version.


Resumo em Português (PT-BR)

O SiteUP Agendador de Posts (produto: Hermes Studio) é uma ferramenta interna e self-hosted que cria, agenda e publica conteúdo apenas nas próprias contas conectadas do cliente Jan Val Ellam (marca "MENTALMA"). Não é um SaaS multi-tenant.

Papéis (LGPD/GDPR): o Controlador é Jan Val Ellam (dono das contas); a SiteUP atua como Operador, tratando dados somente em nome e sob instruções do Controlador. Contato/Encarregado (DPO): contato@siteup.com.br.

O que acessamos, por rede e escopo: Pinterest (boards:read, boards:write, pins:read, pins:write, user_accounts:read); TikTok (user.info.basic, video.publish); YouTube/Google (youtube.upload, youtube.readonly); Meta/Instagram (instagram_basic, instagram_content_publish, pages_show_list, pages_read_engagement, business_management). Não acessamos mensagens privadas, listas de seguidores nem dados pessoais não relacionados.

Finalidade e base legal: publicar/agendar o conteúdo criado e aprovado pela equipe, nas contas do próprio dono, com base no consentimento (LGPD Art. 7º, I; GDPR Art. 6(1)(a)) e na execução de contrato / legítimo interesse do titular (LGPD Art. 7º, V; GDPR Art. 6(1)(b)). Sem publicidade ou profiling.

Segurança e retenção: tokens OAuth cifrados em repouso com AES-256-GCM no nosso backend (Supabase), nunca expostos ao navegador, sempre via HTTPS. O token é mantido apenas enquanto a conta estiver conectada e removido ao desconectar.

Compartilhamento: não vendemos nem compartilhamos dados. Enviamos dados somente às APIs oficiais das quatro redes, ao Supabase, à OpenAI e à Anthropic (Claude) (apenas quando você opta por gerar conteúdo), estritamente para prestar o serviço.

Seus direitos: confirmação, acesso, correção, portabilidade, eliminação e revogação do consentimento. Você pode reclamar à ANPD (Brasil) ou à autoridade de proteção de dados da UE. Exclusão de dados: veja a página dedicada /data-deletion.html.

Cookies: apenas os estritamente necessários de sessão/autenticação; sem analytics, anúncios ou rastreadores, e por isso sem banner de consentimento. Transferências internacionais: provedores (Supabase, OpenAI, Anthropic) e as APIs das redes podem operar fora do Brasil/EEE, com salvaguardas adequadas (incluindo SCC quando aplicável).

Última atualização: 2026-06-18. Contato/DPO: contato@siteup.com.br.