Privacy Policy

Last updated: August 27, 2026

This Privacy Policy describes how Producer.center (the “Service”, “we”) collects, uses, stores, and protects personal data of its users, as well as data obtained from connected social-platform accounts. The data controller is Anton Liahun, sole proprietor (autónomo), Spain (NIF: Z0775907F). By using the Service you agree to this Policy.

1. Who we are and how to contact us

Data controller: Anton Liahun, sole proprietor (autónomo), Spain, address: Creu Roja 1, Bloque 7, Planta Baja, Pta 8, 46014, Valencia, España. For any questions about personal data or to exercise your rights, contact info@producer.center. For general support, contact info@producer.center.

The seller under the contract and the data controller are one and the same person, named in this section, and it is the same person for every buyer regardless of country: the infrastructure, the database and the sub-processors are shared. Processing is governed by the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and the Spanish LOPDGDD (Ley Orgánica 3/2018). Payment data is processed by the Stripe platform: card details are entered on its page and never reach us, and for fraud prevention and financial-law compliance Stripe acts as an independent controller its processing is described in Stripe's privacy policy (https://stripe.com/privacy).

2. Data we collect

2.1. Account and workspace data

  • name, email address, company name provided at sign-up;
  • password stored only as a cryptographic hash (we never store plaintext passwords; authentication is handled by Supabase);
  • workspace data: team members, roles, projects, scripts, strategy documents, uploaded files, and other content you create in the Service.

2.2. Data from connected social-platform accounts

When you connect your own account through the platforms' official APIs, we receive and process only the data necessary for the Service's features, and only within the scope of the permissions you grant:

  • Instagram / Facebook (Meta): profile id and username, post metrics and insights (reach, likes, comments, shares, saves, views, retention), aggregated audience demographics, post comments, and access tokens to perform actions on your behalf (including publishing content if you granted that permission);
  • YouTube / Google via the YouTube Data API v3 and the YouTube Analytics API: the channel id, title, and avatar; channel statistics (subscribers, video count, total views); aggregated audience demographics for the last 90 days (age groups and countries as percentages, with no data about individual viewers); for your recent videos id, title, publication date, thumbnail, views, likes, comments, average view duration, shares, playlist additions, and subscribers gained from the video; and access tokens to perform actions on your behalf (including uploading videos and thumbnails if you granted that permission);
  • TikTok via the official TikTok APIs: the account id (open_id), username and display name, avatar; account statistics (followers, following, total likes, number of videos); for your videos id, description or title, cover image, publication date, duration, link, views, likes, comments, and shares; and access tokens to act on your behalf (including publishing videos if you granted that permission).

2.3. Public data of the accounts you ask us to analyse

The Competitors and Viral videos sections work with public data of other people's accounts the ones you add yourself and the ones matched to your niche. For YouTube we call the YouTube Data API v3 with our server key and receive public information only: the channel title, avatar, and subscriber count, and a video's id, title, thumbnail, publication date, and public counters (views, likes, comments). We neither request nor receive private analytics for other people's channels. This data is kept for no longer than 30 days after the last refresh and is then deleted automatically.

2.4. Content processed by artificial intelligence

For generation and analysis features (ideas, scripts, insights, strategy documents, cover images) we send the text you enter and task-related data to third-party AI providers (see Section 4). We do not use your content to train third-party models.

2.5. Technical data

  • access logs and technical events (IP address, device/browser type, request time) for security and diagnostics;
  • strictly necessary cookies and browser local storage (authentication session, selected interface language, your cookie choice) the Service does not work without them, so they do not require consent;
  • analytics cookies of the Yandex Metrica web-analytics service (including _ym_uid and _ym_d) traffic statistics: pages viewed, referral source, device and browser type, approximate region derived from the IP address, as well as session recording (cursor movements, clicks, scrolling and the content of the page being viewed) via the “Webvisor” feature. On the public pages of the site (home, pricing, legal documents, sign-in page, support pages) analytics and session recording start when the page opens, before you answer the cookie banner: this is how we see what is unclear or inconvenient on the site. If you choose “Necessary only”, we stop the collection and delete the Yandex Metrica cookies. Inside your account, on the sign-up form, on password recovery pages and on links carrying tokens from our emails, analytics and session recording do not run without your consent; sign-in form fields are hidden from the recording. You can withdraw consent at any time via the “Cookie settings” link in the site footer. We use no advertising cookies and share no data with ad networks.

3. How and why we use data (purposes and legal bases)

We process data on the following legal bases under the GDPR (EU Regulation 2016/679):

  • performance of a contract (Art. 6(1)(b)) providing the Service's features: dashboard and analytics, scripts, strategy, and publishing content on your behalf;
  • consent (Art. 6(1)(a)) connecting social-platform accounts and accessing their data; you may withdraw consent at any time by disconnecting the account;
  • consent (Art. 6(1)(a)) analytics cookies, traffic statistics and session recording inside your account and on pages where you enter your own data; you give consent in the cookie banner and may withdraw it at any time via “Cookie settings” in the site footer, after which collection stops;
  • legitimate interest (Art. 6(1)(f)) traffic statistics and session recording on the public pages of the site before you answer the cookie banner: we need to understand how visitors use the public part of the site and where they struggle. You end this processing with a single click on “Necessary only” in the banner;
  • legitimate interests (Art. 6(1)(f)) ensuring security, preventing abuse, and improving and supporting the Service;
  • compliance with legal obligations (Art. 6(1)(c)) where processing is required by law.

4. Who we share data with (sub-processors)

We do not sell your data and do not share it with third parties for advertising. To operate the Service we use sub-processors acting on our behalf under appropriate agreements:

  • Supabase authentication, database, and file storage;
  • hosting infrastructure (servers in the EU, Frankfurt) application hosting;
  • Stripe (for the EEA Stripe Payments Europe, Limited, Ireland) card payment acceptance and refunds; we share the buyer's name, email address, country, tax details and the payment amount. Card details are entered on Stripe's page and never reach us. For fraud prevention and financial-law compliance Stripe acts as an independent controller see https://stripe.com/privacy;
  • Anthropic (Claude) text content generation and analysis;
  • Google (Gemini) image generation (cover images);
  • Yandex Metrica website traffic statistics and session recording on public pages (including the content of those pages in the recording); inside your account data is shared only if you consent to analytics cookies, so without consent the recording contains none of the content you create in the Service;
  • social platforms (Meta, Google/YouTube, TikTok) when performing actions on your behalf.

We may also disclose data where required by law, court order, or to protect rights and safety.

5. Platform compliance

Use of data obtained through social-platform APIs is limited to providing and improving the features visible to you in the Service. We do not share this data with advertising networks or data brokers, nor use it for purposes unrelated to the Service.

Meta (Instagram and Facebook)

We comply with the Meta Platform Terms and Developer Policies. Data obtained via Meta platforms is used only for the features you requested and is deleted when you disconnect the account or upon your request (see the separate “Data Deletion” page).

Google and YouTube

Features that work with YouTube use YouTube API Services. By using them you agree to the YouTube Terms of Service (https://www.youtube.com/t/terms). Google's handling of data is governed by the Google Privacy Policy (https://policies.google.com/privacy). Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can revoke the app's access to your Google account at https://myaccount.google.com/permissions or in your Google security settings at https://security.google.com/settings/security/permissions.

How long we keep YouTube data follows the YouTube API Services rules. Data about your channel and videos is kept while the permission you granted remains valid and is refreshed from the API regularly normally once a week. As soon as access is revoked you disconnect the account in the Service or withdraw the permission on Google's side we delete everything we obtained from the YouTube API for that channel: statistics snapshots, video metrics, stored thumbnails and the avatar, audience demographics, and access tokens. The Service checks for revoked permissions daily. Public YouTube data obtained with our server key (competitors' channels and videos, the viral-videos feed) is kept for no longer than 30 days after the last refresh and is deleted automatically.

Data obtained from the YouTube API is not used to train artificial-intelligence models neither ours nor anyone else's. We pass it to the AI providers listed in Section 4 solely to produce the result you asked for: channel analytics, ideas, and scripts. We do not sell this data and do not share it with ad networks or data brokers.

TikTok

Features that work with TikTok use the official TikTok APIs Login Kit, the Display API and the Content Posting API in accordance with the TikTok Developer Terms of Service (https://www.tiktok.com/legal/page/global/tik-tok-developer-terms-of-service/en). How TikTok itself handles data is described in the TikTok Privacy Policy (https://www.tiktok.com/legal/privacy-policy). You can revoke the app's access at any time in your TikTok account security settings.

Data obtained from the TikTok API is used only for the features you see in the Service: the dashboard and content analytics, ideas and scripts, and publishing the videos you queue yourself. It is kept while the permission you granted remains valid and is refreshed from the API regularly. As soon as access ends you disconnect the account in the Service or withdraw the permission on TikTok's side we delete everything obtained for that account: statistics snapshots, video metrics, stored covers and the avatar, and the access tokens.

Data obtained from the TikTok API is not used to train artificial-intelligence models neither ours nor anyone else's. We pass it to the AI providers listed in Section 4 solely to produce the result you asked for: account analytics, ideas, and scripts. We do not sell this data and do not share it with ad networks or data brokers.

6. International data transfers

Core infrastructure is located in the EU. Some sub-processors (e.g., AI providers and the web-analytics service) may be located outside the EEA. In such cases transfers rely on the EU Standard Contractual Clauses (SCCs) or other mechanisms provided by the GDPR that ensure an adequate level of protection.

7. Retention periods

  • account and workspace data while your account is active; after deletion, erased within 30 days (except data we must retain by law);
  • connected-account data and tokens while the account is connected; when you disconnect an account in the Service or revoke the app's access on the platform's side, the tokens are wiped and the data obtained from the platform API (statistics snapshots, video metrics and thumbnails, the avatar, audience demographics) is deleted;
  • public data of other people's accounts collected for the Competitors and Viral videos sections: YouTube data no longer than 30 days after the last refresh, as required by the YouTube API Services rules; the viral-videos feed for other platforms no longer than three months; competitors you added while the competitor remains in your workspace;
  • backups stored encrypted and automatically overwritten, typically within 30 days;
  • technical logs for a limited period necessary for security and diagnostics.

8. Security

We apply technical and organizational safeguards: encryption in transit (TLS), encryption of access tokens at rest (AES-256-GCM), row-level security in the database (RLS), role-based access control, and data minimization. No method of transmission or storage is fully secure, but we continually improve our security measures.

9. Your rights and data deletion

Under the GDPR you have the right to access, rectification, erasure (“right to be forgotten”), restriction of and objection to processing, data portability, and withdrawal of consent. You can exercise these rights as follows:

  • disconnect an individual social-platform account in “Settings Accounts”; that account's tokens and related data are deleted;
  • delete a workspace or account by contacting us;
  • submit an access or deletion request at info@producer.center.

See the “Data Deletion” page for details. You also have the right to lodge a complaint with a supervisory authority (in Spain the Agencia Española de Protección de Datos, AEPD, www.aepd.es).

10. Children

The Service is intended for businesses and is not directed at individuals under 18. We do not knowingly collect children's data.

11. Changes to this Policy

We may update this Policy. We will notify you of material changes in the Service or by email. The last-updated date is shown at the top of the page.

12. Contact

Privacy enquiries: info@producer.center. Controller: Anton Liahun, sole proprietor (autónomo), Spain, Creu Roja 1, Bloque 7, Planta Baja, Pta 8, 46014, Valencia, España.