Privacy Policy
Last updated 22 September 2026This explains what we do with personal data when you use Spoolt. For the GDPR and Türkiye's KVKK, the operator named above is the data controller.
Spoolt is operated by Orhan Ege Bilge, a sole proprietor (şahıs şirketi) based in Antalya, Türkiye. In these pages “Spoolt”, “we” and “us” mean that operator, and “you” means the person or business using the service.
What we collect
Account details you give us — your name, email and password (stored hashed), or the details Google shares if you sign in that way. Brand material — the websites, product pages and descriptions you add, and what we extract from them. Content — the scripts, videos and captions you generate, keep or discard. Connections — which social accounts you've linked and what those platforms report back about your posts. Billing — your plan and subscription status; card details go to our payment provider, never to us. Technical data — IP address, browser and device information, and error reports when something breaks.
Website demo without an account
The public page you submit is read automatically. Its address, title, description and a limited amount of text are processed to prepare three example ideas. Query parameters and URL fragments are removed from the demo request. No external AI provider is used for this demo; processing takes place on Spoolt servers. Results and the continuation reference are held in Redis for one hour; a reference is stored in your browser tab to reopen the result. If you choose to save it to your account, the brand/content retention periods apply. Your IP address is processed for abuse prevention; demo rate-limit records last up to 24 hours. Cloudflare Turnstile performs bot checks when enabled. Demo telemetry excludes the submitted site address and page text. Submit only brand/product pages you are authorized to use, without personal or sensitive data. Processing serves the demo you requested and abuse prevention. Contact [email protected] to exercise your rights.
Product feedback
When you submit feedback, we store your message, account identifier, page path (without query parameters) and contact preference for up to 180 days to improve the product. A copy of your message and page path is sent to our support inbox for review. Your account email is included only if you allow follow-up. The 180-day automatic deletion applies to the app record; you can request deletion of support correspondence at [email protected]. Do not include sensitive information.
Connected AI assistants
If you connect an AI assistant or MCP client (for example Claude) to Spoolt, either by signing in (OAuth) or with a personal token, it can use Spoolt's tools on your behalf. Through them it receives what those tools return: your plan and usage, brands and connected channels (handles, never your social logins), drafts, ideas, posts with their captions and TikTok settings, posting times and results. What the assistant does with that data is governed by its provider's terms and privacy policy, not ours. When an app connects by signing in, we store what it registers about itself (such as its name, website and redirect addresses), the permissions you granted it, and the tokens it uses, which are stored hashed; personal tokens are also stored only as a hash. Access tokens expire after 15 minutes; a refresh token lasts up to 30 days and is replaced each time it's used. Your consent and tokens are kept until you disconnect the app, revoke the token or delete your account. To disconnect, open Settings → AI agents and disconnect the app under Connected apps, or revoke a personal token; access stops right away.
Why we use it, and on what basis
To provide the service you signed up for — learning your brand, generating and rendering video, publishing on your behalf and showing your analytics (performance of a contract). To run the business — billing, support, fraud and abuse prevention, security and keeping the service reliable (our legitimate interest, and legal obligation for tax records). To send you service email such as password resets and important notices (performance of a contract). We don't sell your personal data, and we don't use it to train our own AI models.
Where your data is
Spoolt runs on servers in Finland, inside the EU. Some processors listed above operate outside the EU or Türkiye, including in the United States; where that's the case, transfers rely on the European Commission's standard contractual clauses or an equivalent safeguard offered by that provider.
How long we keep it
Account, brand and content data is kept while your account is open. Delete your account and we remove it, along with your brands, content and social connections; backups age out within 30 days. Raw analytics events and finished generation jobs are pruned after 90 days. Billing records are kept as long as tax law requires, which in Türkiye is ten years.
Your rights
Under the GDPR and the KVKK you can ask us to:
- give you a copy of the personal data we hold about you
- correct anything inaccurate
- delete your data — you can do this yourself from Settings
- restrict or object to a use of it, including any based on legitimate interest
- send your data to another provider in a portable form
- withdraw consent where processing rests on it
Write to [email protected] and we'll answer within 30 days. If you're unhappy with the outcome, you can complain to your local data protection authority — in Türkiye that's the KVKK Authority (KVKK Kurumu), and in the EU the supervisory authority where you live.
Security
Traffic runs over HTTPS, passwords are stored hashed and never in plain text, API credentials for the services we use are held server-side, and access to production is limited. No system is perfectly secure; if a breach affects your personal data we'll notify you and the relevant authority as the law requires.
Children
Spoolt isn't for anyone under 18 and we don't knowingly collect their data. If you believe a child has an account, tell us and we'll remove it.
Contact
Questions about your data, or a request about your rights: [email protected]. For anything else legal: [email protected].
Changes to this policy
We'll update this page when what we do with data changes, and the date at the top always shows the current version. For material changes we'll tell you by email or in the app before they take effect.