Privacy Policy
Last updated: May 11, 2026
MagikStack ("we", "our", or "the app") is a social media management and commerce analytics tool operated by Skyfin Studio. This Privacy Policy explains how we collect, use, and protect your information when you use our application.
1. Information We Collect
Account Information
- Email address and display name provided during registration
- Authentication credentials managed securely through Firebase Authentication
Connected Platform Data
- Access tokens and API credentials for X (Twitter), Instagram, Bluesky, TikTok, Facebook, LinkedIn, Pinterest, Threads, and Etsy that you provide to connect your accounts
- Social media handles and profile information associated with your connected accounts
- Post content including text, images, and videos that you create and publish through the app
- Post analytics data such as impressions, likes, shares, and clicks retrieved from platform APIs
- For connected Etsy shops: aggregate commerce metrics (revenue, fees, and order counts) that we compute from your shop's receipts and payment-account ledger. We do not collect or store buyer personal data, individual order details, or item information. (Amazon, Shopify, and eBay connections are coming soon and will follow the same read-only, aggregate handling.)
Usage Data
- Campaign and scheduling data including campaigns you create, posting schedules, and content calendars
- Media files (images and videos) you upload for use in social media posts
2. How We Use Your Information
We use the information we collect to:
- Authenticate your identity and provide access to the application
- Connect to and post content on your behalf to your connected social media accounts
- Schedule and automate social media posts according to your campaign settings
- Retrieve and display analytics about your published posts
- Display commerce analytics (revenue, fees, and order trends) for connected Etsy shops, and for Amazon, Shopify, and eBay when those connections become available
- Manage business portfolios, brands, and team collaboration features
- Refresh social media access tokens to maintain uninterrupted service
3. Data Storage and Security
- All data is stored securely using Google Firebase services (Firestore, Cloud Storage, Firebase Authentication)
- Social media API credentials are stored in secure Firestore subcollections with restricted access rules
- All data is transmitted over HTTPS encrypted connections
- Access to your data is controlled through role-based permissions (owner, editor, viewer) within business portfolios
- Cloud Functions that handle social media API interactions run in Google Cloud's secure infrastructure
4. Data Sharing
We do not sell, rent, or share your personal information with third parties, except:
- Social media platforms: when you publish content, your post text, images, and videos are sent to the platforms you've connected through their official APIs
- Team members: if you share a business portfolio with other users, they will have access to the campaigns, posts, and analytics within that portfolio according to their assigned role
- Service providers: we use Google Firebase and Google Cloud Platform to host and operate the application
- Legal requirements: we may disclose information if required by law or to protect our rights
5. Third-Party Services
MagikStack integrates with the following third-party services. Your use of these platforms is subject to their respective privacy policies:
- X (Twitter): Privacy Policy
- Instagram / Meta: Privacy Policy
- Facebook / Meta: Privacy Policy
- Bluesky: Privacy Policy
- TikTok: Privacy Policy
- LinkedIn: Privacy Policy
- Pinterest: Privacy Policy
- Threads (Meta): Supplemental Privacy Policy
- Etsy: Privacy Policy
- Google Firebase: Privacy Policy
6. TikTok Data
In compliance with TikTok's Developer Terms of Service:
- We access TikTok data solely to upload videos to your TikTok inbox as drafts and to display your account handle for identification
- We request only the permissions necessary for these functions: user.info.basic and video.upload
- Uploaded videos are transmitted directly to TikTok's servers; we do not retain copies of your video files beyond what is already stored in your MagikStack campaign media
- We do not store TikTok user data (such as follower counts, video lists, or profile metadata) beyond what is necessary to operate the posting feature
- You can disconnect your TikTok account at any time through the Integrations page, which immediately removes stored credentials
- TikTok access tokens are refreshed automatically before expiration and can be revoked at any time by disconnecting your account here or by revoking the app from your TikTok account settings
7. Instagram and Facebook Data
In compliance with Meta Platform Terms:
- We access Instagram and Facebook data solely for the purposes of publishing content to your Instagram Business account and/or Facebook Pages on your behalf and retrieving post analytics
- For Instagram we request: instagram_basic, instagram_content_publish, pages_show_list, and business_management
- For Facebook Pages we request: pages_show_list, pages_manage_posts, pages_read_engagement, and public_profile
- We do not store Meta user data beyond what is necessary to operate the posting and analytics features (account identifiers, page identifiers, page names, and access tokens for the Pages you have authorized)
- You can disconnect your Instagram or Facebook account at any time through the Integrations page, which removes stored credentials
- Access tokens are automatically refreshed before expiration and can be revoked at any time by disconnecting your account here or by revoking MagikStack from your Facebook account's Business Integrations settings
8. X (Twitter) Data
In compliance with X's Developer Agreement and Policy:
- We access X data solely to publish Tweets on your behalf and to display your X handle for identification
- We request only the permissions necessary for these functions: tweet.read, tweet.write, users.read, and offline.access (for token refresh)
- We do not store X user data (timelines, follower lists, DMs, or other profile metadata) beyond what is necessary to operate the posting feature
- You can disconnect X at any time through the Integrations page, which removes stored credentials; you may also revoke MagikStack from your X account's "Connected apps" settings
9. Bluesky Data
- Bluesky connections use an app password that you generate in Bluesky and paste into MagikStack; we do not receive or store your main Bluesky password
- We use the app password solely to authenticate with the Bluesky (AT Protocol) API and to publish posts on your behalf
- You can revoke the app password at any time from Bluesky's settings, and you can disconnect Bluesky from MagikStack at any time from the Integrations page
10. LinkedIn Data
In compliance with the LinkedIn API Terms of Use:
Personal profile posting (Sign In with LinkedIn + Share on LinkedIn)
- We access LinkedIn data solely to publish posts on your behalf to your personal LinkedIn profile and to display your name / handle for identification
- We request only the scopes necessary for these functions: openid, profile, email (to identify you), and w_member_social (to publish posts)
- We store your LinkedIn access token, refresh token (when granted), and the member URN returned by LinkedIn's /userinfo endpoint. We do not store other LinkedIn profile data, connections, messages, or company information
Company Page posting (Community Management API)
- We access LinkedIn data solely to list the Company Pages you administer and to publish posts on behalf of the Company Page you select
- We request only the scopes necessary for these functions: r_organization_admin (list admin orgs), r_organization_social (read org content context), and w_organization_social (publish as the org)
- We store your LinkedIn access token, refresh token, the list of Company Page URNs and names you administer, and the specific Page URN you selected as your posting destination. We do not store existing Page posts, follower data, or analytics
Both connection types
- You can disconnect either LinkedIn connection at any time through the Integrations page, which immediately removes stored credentials
- You may also revoke MagikStack's access at any time from LinkedIn → Settings & Privacy → Data privacy → Other applications
- LinkedIn access tokens expire after 60 days; when a refresh token is available, MagikStack refreshes automatically before expiry. Otherwise you will be prompted to reconnect
11. Pinterest Data
In compliance with the Pinterest Developer Terms of Use:
- We access Pinterest data solely to list your boards (so you can choose which one to post to) and to create Pins on the board you select. We display your Pinterest username for identification
- We request only the scopes necessary for these functions: user_accounts:read, boards:read, boards:write, pins:read, and pins:write
- We store your Pinterest access token, refresh token, the IDs and names of your boards, your Pinterest username, and the ID of the board you've selected. We do not store the content of existing Pins, follower data, or other profile information
- You can disconnect your Pinterest account at any time through the Integrations page, which immediately removes stored credentials
- You may also revoke MagikStack's access at any time from Pinterest → Settings → Apps and sessions
- Pinterest access tokens expire after 30 days; MagikStack refreshes automatically before expiry using the stored refresh token
12. Threads Data
In compliance with the Threads Platform Terms (supplemental to Meta Platform Terms):
- We access Threads data solely to identify your Threads account (username + user ID) and to publish posts to your Threads profile on your behalf
- We request only the scopes necessary for these functions: threads_basic and threads_content_publish
- We store your Threads access token, the user ID returned by /me, and your username. We do not store existing Threads posts, followers, or reply data
- You can disconnect your Threads account at any time through the Integrations page, which immediately removes stored credentials
- You may also revoke MagikStack's access at any time from Threads → Settings → Account → Permitted apps
- Threads long-lived access tokens expire after 60 days; MagikStack refreshes them automatically before expiry
13. Etsy Data
In compliance with the Etsy API Terms of Use:
- We access Etsy data solely to show you a read-only commerce dashboard for the shop you connect: revenue, fees, and order-count trends
- We request only the scopes necessary for these functions: shops_r (to identify the shop you authorize) and transactions_r (to read that shop's receipts and payment-account ledger)
- We read only your own shop's data. From each receipt we use only the order total and date; from each ledger entry we use only the fee amount and date. These are aggregated into monthly and 30-day revenue, fees, and order counts
- We do NOT store buyer personal data (names, shipping addresses, messages), individual order line items, or product/listing details. Only aggregate totals, your shop name, and currency are stored
- We do not request or hold any write access to your Etsy shop
- Etsy access tokens are stored encrypted and refreshed automatically before expiry; you can disconnect Etsy at any time from the Integrations page, which immediately removes stored credentials. You may also revoke access from your Etsy account under Account settings → Your apps
- The term 'Etsy' is a trademark of Etsy, Inc. This Application uses Etsy's API, but is not endorsed or certified by Etsy.
14. Amazon Data (Coming Soon)
Amazon connections are not yet available. When you connect an Amazon Selling Partner account, the following will apply:
- We access Amazon data solely to show you a read-only commerce dashboard for the store you connect: revenue, fees, and order-count trends
- We request only read access to your own seller account's order and finance data, scoped to the account you authorize
- From your orders and settlement records we use only monetary totals and dates, aggregated into monthly and 30-day revenue, fees, and order counts
- We do NOT store buyer personal data (names, shipping addresses), individual order line items, or product/listing details. Only aggregate totals, your store name, and currency are stored
- We do not request or hold any write access to your Amazon account
- Access credentials are stored encrypted and refreshed automatically; you can disconnect Amazon at any time from the Integrations page, which immediately removes stored credentials. You may also revoke access from your Amazon Seller Central account
15. Shopify Data (Coming Soon)
Shopify connections are not yet available. When you connect a Shopify store, the following will apply:
- We access Shopify data solely to show you a read-only commerce dashboard for the store you connect: revenue, fees, and order-count trends
- We request only read access to your store's order and financial data, scoped to the store you authorize
- From your orders we use only monetary totals and dates, aggregated into monthly and 30-day revenue, fees, and order counts
- We do NOT store buyer personal data (names, shipping addresses), individual order line items, or product details. Only aggregate totals, your store name, and currency are stored
- We do not request or hold any write access to your Shopify store
- Access tokens are stored encrypted; you can disconnect Shopify at any time from the Integrations page, which immediately removes stored credentials. You may also revoke access from your Shopify admin under Settings → Apps
16. eBay Data (Coming Soon)
eBay connections are not yet available. When you connect an eBay seller account, the following will apply:
- We access eBay data solely to show you a read-only commerce dashboard for the account you connect: revenue, fees, and order-count trends
- We request only read access to your own seller account's order and financial data, scoped to the account you authorize
- From your orders we use only monetary totals and dates, aggregated into monthly and 30-day revenue, fees, and order counts
- We do NOT store buyer personal data (names, shipping addresses), individual order line items, or listing details. Only aggregate totals, your store name, and currency are stored
- We do not request or hold any write access to your eBay account
- Access tokens are stored encrypted and refreshed automatically; you can disconnect eBay at any time from the Integrations page, which immediately removes stored credentials. You may also revoke access from your eBay account settings
17. Cookies and Local Storage
- MagikStack uses Firebase Authentication, which stores a session token and related identifiers in your browser's local storage / IndexedDB so you can remain signed in between visits
- We do not use advertising or third-party tracking cookies
- Clearing site data in your browser will sign you out and remove all client-side state
18. International Data Transfers
MagikStack is operated from the United States and its data is stored in Google Cloud Platform regions we have selected for reliability. If you access the Service from outside the United States, your information will be transferred to, stored in, and processed in the United States and other countries where our service providers operate. By using the Service you consent to such transfers.
19. Data Retention
- Your account data is retained as long as you maintain an active account
- Campaign data, posts, and analytics are retained until you delete them or delete your account
- Social media credentials are deleted immediately when you disconnect a platform
- If you delete your account, all associated data will be removed from our systems
20. Your Rights
You have the right to:
- Access your data through the application interface
- Modify your profile information and campaign data at any time
- Delete your campaigns, posts, brands, and portfolios
- Disconnect social media accounts, which removes stored credentials
- Export your data by contacting us
- Request deletion of your account and all associated data by contacting us
21. Account and Data Deletion
You can request deletion of your MagikStack account and all associated data at any time by emailing hello@magikstack.ai with the subject "MagikStack data deletion request." We will verify the request and remove your account, portfolios, campaigns, uploaded media, stored social-platform credentials, and analytics within 30 days. If your MagikStack account was created through a Meta login, you may also trigger a deletion request from your Facebook account via Settings → Apps and Websites → MagikStack → Remove; Meta will notify us and we will process the deletion in the same manner.
22. Children's Privacy
MagikStack is not intended for use by individuals under the age of 13. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, contact us and we will delete it.
23. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be reflected on this page with an updated "Last updated" date. For material changes we will make a reasonable effort to notify you. Continued use of the application after changes constitutes acceptance of the updated policy.
24. Contact Us
If you have questions about this Privacy Policy or your data, email us at hello@magikstack.ai.