Who we are and what this policy covers
Re:SCOOP Studio operates rescoopstudio.com and the Re:SCOOP Publisher company-pilot application. This policy covers information handled through those services. Publisher is currently an internal pilot used by studio operators, not a public self-service account platform.
Questions and privacy requests can be sent to wutsgoodrescoop@gmail.com.
Information from the public website
The Contact page provides direct contact routes and does not submit a contact form. If you use the quote builder, we process the details needed to prepare and deliver the estimate.
- Name, email address, company, project brief, requirements, and selected project options.
- Requested platforms, budget range, package, timeline, estimate, currency context, quote identifier, and submission time.
- Ordinary request metadata that hosting or network logs may contain, such as time, route, IP address, and user agent.
Browser storage, location, and exchange rates
The quote builder stores an unfinished quote in local storage so the browser can restore it. Currency selection uses session storage, and theme preference may use local storage. These controls support continuity and preferences; we do not currently use them for behavioural advertising.
When the host does not provide a country header, our geo endpoint can send the requesting IP address to ipwho.is to infer a country for currency selection. Exchange rates are retrieved from open.er-api.com without sending your quote or contact details.
Information processed by Publisher
Publisher keeps the working records needed to plan, generate, approve, schedule, publish, and learn from Re:SCOOP social content.
- Brand and campaign briefs, calls to action, draft text, schedules, approvals, automation policies, and operator edits.
- Generated, uploaded, selected, and rendered images or videos, including provenance, rights, and disclosure records.
- Publication snapshots, destination state, remote post URLs, provider resource identifiers, errors, retries, and operational tasks.
- Permitted performance observations such as views, reach, impressions, engagement, likes, comments, shares, saves, and clicks, plus recommendations derived from comparable history.
How we use information
We use information to answer enquiries, prepare and email quotes, operate requested social connections, create and review content, publish approved packages, run saved schedules, diagnose failures, protect the services, and compare permitted performance signals so future recommendations can improve.
We do not sell personal information. We do not use connected-account information to publish outside the destinations and permissions selected by the operator.
AI and media services
Requested prompts, campaign context, drafts, and media can be processed by OpenAI through the operator's Codex and ChatGPT subscription for text or image generation. If the operator separately configures and selects an advanced video workflow, relevant prompts and media can be sent to BytePlus or Seedance.
Temporary public media delivery can use configured S3-compatible storage when a social provider must retrieve a file over HTTPS. Optional providers receive data only when their dependent feature is configured and used.
Services that receive information
We share only what is needed with services that perform the requested function: TikTok, Meta services, Threads, and X for account authorization, publishing, status, and permitted insights; Resend for quote-email delivery; OpenAI for requested generation; optional media and storage providers; and hosting, DNS, network, and infrastructure providers.
Each social platform independently processes information under its own terms and privacy policy. A person can refuse an OAuth permission or revoke an existing authorization through the platform and Publisher connection controls.
Storage, security, and international processing
The pilot stores application records in its controlled Docker volume and, after migration, its configured VPS storage. Provider secrets are separated from ordinary records and encrypted at rest. Diagnostics are designed to exclude access tokens, API keys, and vault values.
Internet and cloud services can process information in countries other than Malaysia. We use reasonable technical and operational safeguards, but no online system can promise absolute security.
Retention, disconnect, and deletion
Disconnecting a social account revokes or removes its stored token secrets, but it does not automatically erase campaign, media, publication, or metric history. Those records remain in controlled storage until they are no longer needed, the operator removes them, or Re:SCOOP fulfils a verified deletion request.
Expired OAuth state, abandoned temporary job directories, expired public-delivery objects, and eligible provider tasks use the application's cleanup workflow. Submitted quote emails and attachments can remain under Re:SCOOP's and Resend's email-retention practices.
Your choices and rights
Subject to applicable law, you may ask what personal information we hold, request access or correction, withdraw consent, object to direct marketing, request deletion, or ask us to stop processing that causes likely damage or distress. We may need to verify your identity or authority over a connected account before acting.
Send requests to wutsgoodrescoop@gmail.com. You can also clear local or session storage in your browser and revoke provider access in the relevant social platform.
Children's privacy
The website's project services and Publisher pilot are intended for adults and authorized business operators. We do not knowingly use Publisher to collect personal information from children. Contact us if you believe a child has provided information that should be removed.
Changes and contact
We may update this policy when the website, Publisher capabilities, providers, or legal requirements change. The effective date at the top identifies the current version.
Contact Re:SCOOP Studio at wutsgoodrescoop@gmail.com for questions, complaints, access requests, corrections, disconnection support, or deletion requests.
Connected social accounts and OAuth
When an operator connects TikTok, Meta services, Threads, or X, Publisher stores the provider, account identifier, account or display name, approved scopes, token expiry, and connection health. Publisher never asks for or stores the social-account password.
OAuth access and refresh tokens are stored server-side in AES-256-GCM encrypted envelopes. Plaintext tokens are retrieved only for an authorized provider request and their in-memory buffers are cleared afterward. Disconnect attempts provider revocation and deletes the stored token secret references.