← BackWingspan

Last updated: June 15, 2026

Privacy Policy

This policy describes how Caowl Studios (“we”, “us”) collects and processes personal data when you use Wingspan, our internal social media management platform (“the Service”).

1. Who is responsible?

The data controller for the Service is Caowl Studios. For privacy-related questions, contact us at team@caowlstudios.com.

2. Who this policy applies to

This policy applies to:

  • Workspace members who sign in to Wingspan (admins, editors, viewers)
  • People invited to a workspace via email invitation
  • Visitors to public pages hosted by Wingspan (link-in-bio pages and shared reports)

3. What data we collect

Account and workspace data

  • Name, email address, and password (stored as a one-way hash — we never store plain-text passwords)
  • Workspace name, slug, timezone, brand settings, and your role in each workspace
  • Session cookies used to keep you signed in

Connected social accounts

When you connect a platform (e.g. Meta, Instagram, LinkedIn, TikTok, Google, Pinterest), we store account identifiers, display names, usernames, profile images, granted permissions (scopes), and OAuth access and refresh tokens. Tokens are encrypted at rest using a server-side encryption key.

Content you create

  • Post drafts, captions, schedules, and publishing history
  • Images and videos you upload for posts (stored in our configured object storage)
  • Link-in-bio pages, links, and click counts
  • Website domains you add for monitoring, and optional analytics property IDs

Analytics and reporting

  • Performance metrics synced from connected platforms (reach, impressions, engagement, ad spend, etc.)
  • Share-token view counts and last-viewed timestamps for shared reports

Technical data

  • Server logs (IP address, request time, error messages) for security and troubleshooting
  • OAuth state tokens during the connect flow (short-lived, deleted after use)

4. How we use your data

We process personal data to:

  • Provide, operate, and secure the Service
  • Authenticate users and manage workspace access
  • Publish and schedule content on your behalf to connected platforms
  • Sync analytics and generate performance reports
  • Send workspace invitation emails (when email delivery is configured)
  • Respond to support requests and comply with legal obligations

Our legal bases under the GDPR are typically contract (providing the Service), legitimate interests (security, product improvement), and consent where required (e.g. connecting third-party accounts).

5. Third-party services

Depending on which features you use, data may be shared with:

  • Social platforms — Meta, LinkedIn, TikTok, Google, Pinterest (OAuth and API publishing)
  • Hosting and database — our infrastructure provider(s) where the app and Postgres are deployed
  • Object storage — S3-compatible storage for uploaded media
  • Resend — transactional email for workspace invitations (if enabled)

Each third party processes data under its own terms and privacy policy. When you connect an account, you authorize us to exchange data with that platform on your behalf within the scopes you approve.

6. Public pages

Link-in-bio pages (/u/:slug) and shared reports (/report/:token) are accessible without signing in. Do not include sensitive personal data in public bio content. Anyone with a valid share link can view the report it points to until the token expires or is revoked.

7. Retention

  • Account data is kept while your account is active
  • Connected account tokens are kept until you disconnect the account or delete your workspace access
  • OAuth state records expire automatically after 10 minutes
  • Server logs are retained for a limited period for security purposes

You may request deletion of your account and associated data by contacting team@caowlstudios.com.

8. Security

We use industry-standard measures including HTTPS, hashed passwords, encrypted OAuth tokens, workspace-scoped access controls, and role-based permissions. No method of transmission or storage is 100% secure; we work to reduce risk proportionate to the data we handle.

9. Your rights

If you are in the EEA, UK, or another jurisdiction with similar laws, you may have the right to:

  • Access the personal data we hold about you
  • Request correction or deletion
  • Restrict or object to certain processing
  • Data portability, where applicable
  • Withdraw consent where processing is consent-based
  • Lodge a complaint with your local data protection authority

To exercise these rights, email team@caowlstudios.com. We will respond within the timeframes required by applicable law.

10. International transfers

Your data may be processed in countries outside your own, including where our hosting or third-party providers operate. Where required, we rely on appropriate safeguards such as standard contractual clauses.

11. Children

Wingspan is a business tool not directed at children under 16. We do not knowingly collect data from children.

12. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the date at the top of this page. Continued use of the Service after changes constitutes acceptance of the updated policy.

CaowlWingspan · A Caowl Studio Product