Daily Studio
Privacy Policy
1. Introduction
Daily Studio is an iPhone camera app for creators shooting vertical social video, operated by UZELABS YAZILIM ÇÖZÜMLERİ TİCARET VE SANAYİ LİMİTED ŞİRKETİ ("we", "us").
You can use Daily Studio without an account. Recording, the teleprompter, the safe-zone guides and script links ask you for no name, email address or phone number, and nothing you write or shoot leaves your phone.
An account buys exactly two things, and you switch each one on yourself:
- Publishing: connecting an Instagram, Facebook, YouTube or TikTok account so Daily Studio can post a video for you.
- Your content plan: keeping your scripts on your account instead of on one phone only, so the plan is readable on the web and an AI assistant you have connected can add to it. This is off by default and stays off until you turn it on.
If you use neither, sections 5, 6 and 7 below do not apply to you.
2. Data We Collect
We collect only what the service needs to work:
- Subscription data: purchase history, entitlement status, and an anonymous app user ID assigned by RevenueCat. Payment is taken by Apple — we never see your card details.
- Usage data: which features are used, screen events and session events (Mixpanel).
- Device information: device model, OS version, app version and anonymous device identifiers.
- Connection data: requests to the server that serves script links carry an IP address, used transiently for rate limiting and not stored.
The first name you may enter during onboarding is stored on your device only and is never sent to us.
Only if you use direct publishing, we additionally process:
- Account data: your email address, or your Sign in with Apple identifier, to create the Daily Studio account the publishing feature hangs on.
- Connected account details: for each platform you connect, the user id that platform issues, your username and your profile picture. Username and picture are processed because platforms such as TikTok require us to show you which account a post is going to before you publish it.
- Access tokens: the OAuth access and refresh tokens the platforms issue us. They are stored encrypted on our server and used only to publish on your behalf, on your instruction. A token is not your password: we never see and never ask for your social media passwords.
- The takes you choose to publish: when you send a recording for publishing, that video file is uploaded to our server so it can be delivered to the platform. It is deleted seven days after the post goes out — see section 9.
- Publishing records: the caption you wrote, the audience you picked, the time you scheduled, and the post id the platform returned.
Only if you turn on the content plan, we additionally store:
- Your scripts: the text of each script, its title, the day you planned it for, and how far it has got. Unlike script links (section 4), these are stored in a form our server can read — that is what lets the plan be shown on a web page, edited there, and written to by your assistant. We do not read them for any other purpose, and they are never used for advertising or to train AI models.
3. Camera, Microphone and Photos
Camera and microphone access is used solely to record video. Recording, stitching and saving all happen on the iPhone, and the result is written straight to your own Photos library.
Your footage stays on your device unless you publish it. Your gallery and the takes you shoot are not transferred to us — with one exception you make yourself, one take at a time: when you send a specific recording for publishing, that video is uploaded so the platform can receive it, and it is deleted seven days after the post goes out. There is no cloud library: we do not keep a copy of your recordings, and connecting an account gives us permission at that platform, not access to your videos.
Photos access powers the in-app gallery preview and saving. Your media is never used for advertising, never used to train AI models, and never shared with any third party other than the platform you chose.
4. Script Links and Encryption
Your AI assistant (Claude, ChatGPT, Gemini, or any other assistant that speaks MCP) sends the script it wrote as a one-tap link. In that flow:
- The script is encrypted with AES-GCM before it reaches our server.
- The decryption key travels in the link's fragment (after the # sign). Browsers never send that part to a server, so the key never reaches us and we cannot read your scripts.
- The stored ciphertext is deleted after 30 days.
- The script-link service has no account, no sign-in and no user database, and request bodies are never logged. It is separate from the content plan in section 5, which does have an account and which you have to turn on.
While you are writing the script with your AI assistant, that provider's own privacy policy applies. Daily Studio is not affiliated with them.
5. Your Content Plan (optional)
This section applies only if you turned the content plan on. It is off by default, and signing in is not enough on its own — it is a separate switch, in the app under Account > Your plan or on the website.
What it is: your scripts, with their titles, the day each is meant to go out and how far each has got, kept on your Daily Studio account instead of on one phone only. It exists so a plan survives a lost phone, so you can read and edit it at dailystudio.app, and so an AI assistant you have connected can add to it.
It is not encrypted the way script links are, and the difference is real. A script link's key never reaches us, so we cannot read it. A plan has to be drawn on a web page, edited there and written to by an assistant, so its text is stored in a form our server can read. We do not read it for any other purpose. It is never used for advertising, never used to train AI models, and never shared with anyone else.
Turning it off deletes it. Switch it off and everything stored is deleted from our server at that moment. The scripts on your phone are untouched — they were always yours and always there.
Deleting one script removes its text and its title immediately. A note that it was deleted is kept for up to 30 days, so a phone that was offline learns the script is gone instead of uploading it again.
6. Connecting Your Social Accounts
This section applies only if you chose to connect social media accounts. If you never use the feature, we have no access to any of your accounts.
How you connect: you are sent to the platform's own sign-in screen and grant permission to the platform directly. We never see, ask for, or store your social media password. The platform hands us only a limited token that lets us publish on your behalf.
What we do not touch: we do not read your connected accounts' messages, follower lists, existing posts or ad accounts. The permissions we request are the minimum needed to publish and to show you which account you are publishing to.
Disconnecting: you can disconnect an account at any time from Settings > Connected Accounts in the app, which deletes that platform's tokens from our server. You can also revoke our access from the platform itself:
- Google / YouTube: myaccount.google.com/permissions
- Instagram and Facebook: Settings > Security > Apps and websites in the relevant app
- TikTok: Settings and privacy > Security > Manage app permissions
About the platform services: Daily Studio uses YouTube API Services to upload to YouTube. By using that feature you agree to the YouTube Terms of Service; how Google handles your data is described in the Google Privacy Policy. Instagram and Facebook posts go through Meta Platforms' APIs, and TikTok posts through TikTok's, each under their own privacy policy.
7. How We Use Your Data and Who Processes It
We use your data to provide and maintain the app, fix problems, understand which features matter, and manage subscriptions. Our processors are:
- RevenueCat, Inc.: subscription and purchase state.
- Mixpanel, Inc.: feature-usage analytics and product development.
- Apple: in-app purchases and payment processing.
- Cloudflare, Inc.: the server and database that hold encrypted script blobs, your account, your connected account details, your content plan if you turned it on, and takes waiting to be published.
If you use direct publishing, only the platform you chose receives your video and caption. Those platforms are not our processors: they are independent controllers that receive the content at your direction and handle it under their own privacy policies:
- Meta Platforms, Inc. / Meta Platforms Ireland Ltd.: Instagram and Facebook posts.
- Google LLC: YouTube uploads.
- TikTok Ltd. and its affiliates: TikTok posts.
There is no advertising network, no advertising identifier, and no data sharing for tracking purposes in Daily Studio. Your connected account details and your videos are never sold, never used for advertising, and never used to train AI models.
8. International Transfers
The processors above operate servers outside Türkiye, principally in the United States and on Cloudflare's global network. By using the app you agree that your subscription and usage data may be transferred to and processed in those locations as necessary to provide the service.
Your video recordings are not part of any transfer unless you publish one: a take you send for publishing is uploaded to Cloudflare's network and delivered to the platform you chose. Everything you do not publish stays on your device.
9. Retention
- Encrypted script blobs: 30 days, then deleted.
- Access tokens: until you disconnect the account or delete your account. Disconnecting deletes them immediately.
- Takes uploaded for publishing: deleted seven days after the post goes out. A take you never publish stays until you delete it — there is a button for that on its script in your plan — or until you delete your account.
- Publishing records (caption, audience, schedule, post id): for as long as your account exists.
- Content plan: for as long as your account exists, or until you turn the plan off — which deletes it at that moment. A deleted script's text goes immediately; a note that it was deleted is kept for up to 30 days.
- Subscription records: for the life of the subscription and any period required by law.
- Usage analytics: kept in aggregate, not linked to your identity.
- Everything on your device (your scripts, settings and name): removed completely when you delete the app.
10. Your Rights
Depending on where you live, you may have the right to access, correct, delete, or restrict the processing of your personal data, and to object to it.
If you don't use publishing there is no account, so please include the anonymous user ID shown at the bottom of the app's Settings screen so we can locate your records.
If you do have a Daily Studio account, you can disconnect your accounts and delete all of your data yourself from inside the app; the steps are on our Data Deletion page. Contact: [email protected]
11. Children
Daily Studio is not directed at children under 13, and we do not knowingly collect personal data from them.
12. Changes and Contact
We may update this policy; material changes will be published on this page.
- General Support: [email protected]
- Privacy/Legal: [email protected]
- Company: UZELABS YAZILIM ÇÖZÜMLERİ TİCARET VE SANAYİ LİMİTED ŞİRKETİ