Privacy Policy
Last updated: July 28, 2026
MagikStack ("we", "our", or "the app") is a social media management and commerce analytics tool operated by Skyfin Studio. This Privacy Policy explains how we collect, use, and protect your information when you use our application.
1. Information We Collect
Account Information
- Email address and display name provided during registration
- Authentication credentials managed securely through Firebase Authentication
Connected Platform Data
- Access tokens and API credentials for Instagram, Bluesky, TikTok, Facebook, LinkedIn, Pinterest, Threads, Etsy, Amazon, and Shopify that you provide to connect your accounts
- Social media handles and profile information associated with your connected accounts
- Post content including text, images, and videos that you create and publish through the app
- Post analytics data such as impressions, likes, shares, and clicks retrieved from platform APIs
- For connected Etsy and Amazon shops: aggregate commerce metrics (revenue, fees, and order counts) that we compute from your shop's receipts and ledger. For these platforms we do not collect or store buyer personal data, individual order details, or item information. (eBay connections are coming soon and will follow the same aggregate handling.)
- For connected Shopify stores: an order record per order, used to report revenue and to attribute sales to the posts that drove them. Each record holds the Shopify order id, the order date, its total and currency, line items (product reference, SKU, quantity, and price), any discount codes applied, and the landing and referring URLs Shopify records on the order. We do not collect or store buyer names, email addresses, phone numbers, or shipping or billing addresses.
- For connected Shopify stores: the product catalog you choose to import (titles, descriptions, images, prices, and inventory counts), which becomes part of your MagikStack product library.
Usage Data
- Campaign and scheduling data including campaigns you create, posting schedules, and content calendars
- Media files (images and videos) you upload for use in social media posts
2. How We Use Your Information
We use the information we collect to:
- Authenticate your identity and provide access to the application
- Connect to and post content on your behalf to your connected social media accounts
- Schedule and automate social media posts according to your campaign settings
- Retrieve and display analytics about your published posts
- Display commerce analytics (revenue, fees, and order trends) for connected Etsy, Amazon, and Shopify shops, and for eBay when that connection becomes available
- Attribute sales from connected Shopify stores to the posts that drove them, by matching an order's landing URL, referring site, or discount code against the tracked links and codes in your posts
- Import your product catalog from a connected Shopify store into your MagikStack product library, so posts can be written about what you actually sell
- Manage business portfolios, brands, and team collaboration features
- Refresh social media access tokens to maintain uninterrupted service
3. Data Storage and Security
- All data is stored securely using Google Firebase services (Firestore, Cloud Storage, Firebase Authentication)
- Social media API credentials are stored in secure Firestore subcollections with restricted access rules
- All data is transmitted over HTTPS encrypted connections
- Access to your data is controlled through role-based permissions (owner, editor, viewer) within business portfolios
- Cloud Functions that handle social media API interactions run in Google Cloud's secure infrastructure
4. Data Sharing
We do not sell, rent, or share your personal information with third parties, except:
- Social media platforms: when you publish content, your post text, images, and videos are sent to the platforms you've connected through their official APIs
- Team members: if you share a business portfolio with other users, they will have access to the campaigns, posts, and analytics within that portfolio according to their assigned role
- Service providers: we use Google Firebase and Google Cloud Platform to host and operate the application
- Legal requirements: we may disclose information if required by law or to protect our rights
5. Third-Party Services
MagikStack integrates with the following third-party services. Your use of these platforms is subject to their respective privacy policies:
- Instagram / Meta: Privacy Policy
- Facebook / Meta: Privacy Policy
- Bluesky: Privacy Policy
- TikTok: Privacy Policy
- LinkedIn: Privacy Policy
- Pinterest: Privacy Policy
- Threads (Meta): Supplemental Privacy Policy
- Etsy: Privacy Policy
- YouTube / Google: Privacy Policy
- Google Firebase: Privacy Policy
6. TikTok Data
In compliance with TikTok's Developer Terms of Service:
- We access TikTok data solely to publish videos you schedule to your TikTok account (or, for connections without direct-post permission, to upload them to your TikTok inbox as drafts), to display your account handle for identification, and to show you the performance of the videos you published through MagikStack
- We request only the permissions necessary for these functions: user.info.basic, user.info.stats, video.list, and video.publish
- Before publishing directly, we query your creator settings and honor them: posts use a privacy level your account allows, and we never enable comments, Duet, or Stitch where you have disabled them
- Uploaded videos are transmitted directly to TikTok's servers; we do not retain copies of your video files beyond what is already stored in your MagikStack campaign media
- We store engagement metrics (views, likes, comments, shares) only for videos you published through MagikStack, plus your follower count, to power your own analytics dashboard; we do not store metrics for any other account's content or other profile metadata
- You can disconnect your TikTok account at any time through the Integrations page, which immediately removes stored credentials
- TikTok access tokens are refreshed automatically before expiration and can be revoked at any time by disconnecting your account here or by revoking the app from your TikTok account settings
7. Instagram and Facebook Data
In compliance with Meta Platform Terms:
- We access Instagram and Facebook data solely for the purposes of publishing content to your Instagram Business account and/or Facebook Pages on your behalf and retrieving post analytics
- For Instagram we request: instagram_basic, instagram_content_publish, pages_show_list, and business_management
- For Facebook Pages we request: pages_show_list, pages_manage_posts, pages_read_engagement, and public_profile
- We do not store Meta user data beyond what is necessary to operate the posting and analytics features (account identifiers, page identifiers, page names, and access tokens for the Pages you have authorized)
- You can disconnect your Instagram or Facebook account at any time through the Integrations page, which removes stored credentials
- Access tokens are automatically refreshed before expiration and can be revoked at any time by disconnecting your account here or by revoking MagikStack from your Facebook account's Business Integrations settings
8. Bluesky Data
- Bluesky connections use an app password that you generate in Bluesky and paste into MagikStack; we do not receive or store your main Bluesky password
- We use the app password solely to authenticate with the Bluesky (AT Protocol) API and to publish posts on your behalf
- You can revoke the app password at any time from Bluesky's settings, and you can disconnect Bluesky from MagikStack at any time from the Integrations page
9. LinkedIn Data
In compliance with the LinkedIn API Terms of Use:
Personal profile posting (Sign In with LinkedIn + Share on LinkedIn)
- We access LinkedIn data solely to publish posts on your behalf to your personal LinkedIn profile and to display your name / handle for identification
- We request only the scopes necessary for these functions: openid, profile, email (to identify you), and w_member_social (to publish posts)
- We store your LinkedIn access token, refresh token (when granted), and the member URN returned by LinkedIn's /userinfo endpoint. We do not store other LinkedIn profile data, connections, messages, or company information
Company Page posting (Community Management API)
- We access LinkedIn data solely to list the Company Pages you administer and to publish posts on behalf of the Company Page you select
- We request only the scopes necessary for these functions: rw_organization_admin (list the Pages you administer), r_organization_social (read org content context), and w_organization_social (publish as the org)
- We store your LinkedIn access token, refresh token, the list of Company Page URNs and names you administer, and the specific Page URN you selected as your posting destination. We do not store existing Page posts, follower data, or analytics
Both connection types
- You can disconnect either LinkedIn connection at any time through the Integrations page, which immediately removes stored credentials
- You may also revoke MagikStack's access at any time from LinkedIn → Settings & Privacy → Data privacy → Other applications
- LinkedIn access tokens expire after 60 days; when a refresh token is available, MagikStack refreshes automatically before expiry. Otherwise you will be prompted to reconnect
10. Pinterest Data
In compliance with the Pinterest Developer Terms of Use:
- We access Pinterest data solely to list your boards (so you can choose which one to post to) and to create Pins on the board you select. We display your Pinterest username for identification
- We request only the scopes necessary for these functions: user_accounts:read, boards:read, boards:write, pins:read, and pins:write
- We store your Pinterest access token, refresh token, the IDs and names of your boards, your Pinterest username, and the ID of the board you've selected. We do not store the content of existing Pins, follower data, or other profile information
- You can disconnect your Pinterest account at any time through the Integrations page, which immediately removes stored credentials
- You may also revoke MagikStack's access at any time from Pinterest → Settings → Apps and sessions
- Pinterest access tokens expire after 30 days; MagikStack refreshes automatically before expiry using the stored refresh token
11. Threads Data
In compliance with the Threads Platform Terms (supplemental to Meta Platform Terms):
- We access Threads data solely to identify your Threads account (username + user ID) and to publish posts to your Threads profile on your behalf
- We request only the scopes necessary for these functions: threads_basic and threads_content_publish
- We store your Threads access token, the user ID returned by /me, and your username. We do not store existing Threads posts, followers, or reply data
- You can disconnect your Threads account at any time through the Integrations page, which immediately removes stored credentials
- You may also revoke MagikStack's access at any time from Threads → Settings → Account → Permitted apps
- Threads long-lived access tokens expire after 60 days; MagikStack refreshes them automatically before expiry
12. YouTube Data
MagikStack uses YouTube API Services. By connecting a YouTube channel you agree to the YouTube Terms of Service, and Google's Privacy Policy applies to Google's handling of your data:
- YouTube Terms of Service: youtube.com/t/terms
- Google Privacy Policy: policies.google.com/privacy
- We access YouTube data solely to identify the channel you connected and to upload videos you have created and scheduled in MagikStack to that channel on your behalf
- We request only the scopes necessary for these functions: youtube.upload (to upload your scheduled videos) and youtube.readonly (to confirm which channel you connected, to show your subscriber count, and to read public view, like, and comment counts for videos MagikStack itself uploaded). We deliberately do not request youtube.force-ssl, which would also grant rights to edit or delete your videos
- We store your YouTube access token and refresh token, your channel ID and channel title, and the video IDs of uploads MagikStack made along with their public statistics. We do not store the video files after upload, your subscriber list, your comments, your watch history, or any video MagikStack did not upload
- We never read, modify, or delete videos that MagikStack did not upload, and we never access another user's YouTube data
- We do not sell YouTube data, use it for advertising, or share it with third parties. It is used only to operate the publishing and analytics features you asked for
- You can disconnect your YouTube account at any time through the Integrations page, which immediately removes stored credentials
- You may also revoke MagikStack's access at any time from your Google security settings: myaccount.google.com/permissions
- Stored YouTube data is deleted when you disconnect the channel or delete your MagikStack account, and aggregated YouTube API data is refreshed or deleted at least every 30 days
13. Etsy Data
In compliance with the Etsy API Terms of Use:
- We access Etsy data solely to show you a read-only commerce dashboard for the shop you connect: revenue, fees, and order-count trends
- We request only the scopes necessary for these functions: shops_r (to identify the shop you authorize) and transactions_r (to read that shop's receipts and payment-account ledger)
- We read only your own shop's data. From each receipt we use only the order total and date; from each ledger entry we use only the fee amount and date. These are aggregated into monthly and 30-day revenue, fees, and order counts
- We do NOT store buyer personal data (names, shipping addresses, messages), individual order line items, or product/listing details. Only aggregate totals, your shop name, and currency are stored
- We do not request or hold any write access to your Etsy shop
- Etsy access tokens are stored encrypted and refreshed automatically before expiry; you can disconnect Etsy at any time from the Integrations page, which immediately removes stored credentials. You may also revoke access from your Etsy account under Account settings → Your apps
- The term 'Etsy' is a trademark of Etsy, Inc. This Application uses Etsy's API, but is not endorsed or certified by Etsy.
14. Amazon Data
When you connect an Amazon Selling Partner account:
- We access Amazon data for two purposes: a read-only commerce dashboard for the account you connect (revenue, fees, and order-count trends), and importing your listings into your MagikStack product library
- We request only read access to your own seller account's order, finance, listing, and inventory data, scoped to the account you authorize
- From your orders and settlement records we use only monetary totals and dates, aggregated into monthly and 30-day revenue, fees, and order counts
- We do NOT store buyer personal data (names, shipping addresses) or individual order line items. From orders, only aggregate totals, your store name, and currency are stored
- Listings you choose to import (titles, descriptions, bullet points, images, and inventory counts) become part of your MagikStack product library and are retained until you delete them or delete your account
- We do not request or hold any write access to your Amazon account
- Access credentials are stored encrypted and refreshed automatically; you can disconnect Amazon at any time from the Integrations page, which immediately removes stored credentials. You may also revoke access from your Amazon Seller Central account
15. Shopify Data
When you connect a Shopify store:
- We access Shopify data for three purposes: a commerce dashboard for the store you connect (revenue, fees, and order-count trends), importing your product catalog into your MagikStack product library, and attributing sales back to the social posts that drove them
- We request read access only, in exactly three scopes: read_orders, read_products, and read_inventory. We do not request or hold any write access to your Shopify store
- From each order we store the Shopify order id, the order date, its total and currency, line items (product reference, SKU, quantity, and price), any discount codes applied, and the landing and referring URLs Shopify records on the order. The landing URL carries the tracking parameters from links MagikStack generated for your posts, which is how a sale is matched to the post that earned it
- We do NOT collect or store buyer names, email addresses, phone numbers, or shipping or billing addresses. We do not request the protected customer fields those come from
- Order records are retained for 120 days from the order date and then deleted. The aggregate metrics and post-level attribution computed from them are retained while your account is active
- Product data you import (titles, descriptions, images, prices, and inventory counts) becomes part of your MagikStack product library and is retained until you delete it or delete your account
- Access tokens are stored encrypted; you can disconnect Shopify at any time from the Integrations page, which immediately removes stored credentials. You may also revoke access from your Shopify admin under Settings → Apps
- If you uninstall MagikStack from your Shopify admin we delete the stored credentials immediately, and we erase the store's records when Shopify sends us its shop data erasure request
16. eBay Data (Coming Soon)
eBay connections are not yet available. When you connect an eBay seller account, the following will apply:
- We access eBay data solely to show you a read-only commerce dashboard for the account you connect: revenue, fees, and order-count trends
- We request only read access to your own seller account's order and financial data, scoped to the account you authorize
- From your orders we use only monetary totals and dates, aggregated into monthly and 30-day revenue, fees, and order counts
- We do NOT store buyer personal data (names, shipping addresses), individual order line items, or listing details. Only aggregate totals, your store name, and currency are stored
- We do not request or hold any write access to your eBay account
- Access tokens are stored encrypted and refreshed automatically; you can disconnect eBay at any time from the Integrations page, which immediately removes stored credentials. You may also revoke access from your eBay account settings
17. Cookies and Local Storage
- MagikStack uses Firebase Authentication, which stores a session token and related identifiers in your browser's local storage / IndexedDB so you can remain signed in between visits
- We do not use advertising or third-party tracking cookies
- Clearing site data in your browser will sign you out and remove all client-side state
18. International Data Transfers
MagikStack is operated from the United States and its data is stored in Google Cloud Platform regions we have selected for reliability. If you access the Service from outside the United States, your information will be transferred to, stored in, and processed in the United States and other countries where our service providers operate. By using the Service you consent to such transfers.
19. Data Retention
- Your account data is retained as long as you maintain an active account
- Campaign data, posts, and analytics are retained until you delete them or delete your account
- Social media credentials are deleted immediately when you disconnect a platform
- Shopify order records used for sales attribution are retained for 120 days from the order date and then deleted; the aggregate metrics computed from them are retained while your account is active
- When a connected store is uninstalled or its platform sends us an erasure request, we delete that store's credentials and records
- If you delete your account, all associated data will be removed from our systems
20. Your Rights
You have the right to:
- Access your data through the application interface
- Modify your profile information and campaign data at any time
- Delete your campaigns, posts, brands, and portfolios
- Disconnect social media accounts, which removes stored credentials
- Export your data by contacting us
- Request deletion of your account and all associated data by contacting us
21. Account and Data Deletion
You can request deletion of your MagikStack account and all associated data at any time by emailing hello@magikstack.ai with the subject "MagikStack data deletion request." We will verify the request and remove your account, portfolios, campaigns, uploaded media, stored social-platform credentials, and analytics within 30 days. If your MagikStack account was created through a Meta login, you may also trigger a deletion request from your Facebook account via Settings → Apps and Websites → MagikStack → Remove; Meta will notify us and we will process the deletion in the same manner.
22. Children's Privacy
MagikStack is not intended for use by individuals under the age of 13. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, contact us and we will delete it.
23. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be reflected on this page with an updated "Last updated" date. For material changes we will make a reasonable effort to notify you. Continued use of the application after changes constitutes acceptance of the updated policy.
24. Contact Us
If you have questions about this Privacy Policy or your data, email us at hello@magikstack.ai.