PRIVACY
Privacy Policy
Effective date: July 20, 2026 · Data controller: Install Indonesia
This Privacy Policy explains how Buddhist Content Studio collects, uses, stores, and shares information when you use the website, private creator workspace, and connected Google Drive or TikTok features.
1. Information we process
Content and project information
We process project names, deity or subject names, source links, images, file links, lyrics, audio and video references, captions, schedules, cover selections, workflow status, and other information you add to the studio.
Connected-service information
If you authorize a provider, we receive authorization tokens and the minimum account or file information required for the requested feature. We do not ask for your Google or TikTok password.
Technical information
Our server and security infrastructure may process IP address, request time, browser or device information, requested URL, response status, and security events. Browser storage may retain non-secret application configuration such as the Google OAuth Client ID used by the studio.
2. How we use information
We use information to operate and secure the Service; save and display projects; upload files you select; create connected Drive folders; generate previews and links; prepare creator-reviewed drafts; troubleshoot failures; prevent abuse; comply with law; and communicate about privacy, support, or material Service changes.
3. Google API data
Buddhist Content Studio requests the limited https://www.googleapis.com/auth/drive.file scope. This permits the Service to create and manage files it creates, or files the user explicitly opens or selects for use with the Service. It does not request unrestricted access to the user’s entire Google Drive.
When instructed, the Service may create a “Buddhist Content Studio” folder and project subfolders, upload selected media, and receive file identifiers, names, links, and preview information needed to display the connected asset. Google access and refresh tokens are stored on the application server in encrypted form so the connection can continue until it expires, is disconnected, or is revoked. They are not exposed to browser storage and are not used for advertising, creditworthiness, surveillance, or training generalized AI models.
Buddhist Content Studio’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. TikTok data and draft uploads
When TikTok connectivity is enabled and you choose to connect an account, the Service requests user.info.basic and video.upload. We use basic profile data to identify the connected creator account, and we use the upload permission only to transfer the video that you explicitly select as a draft. The Service stores TikTok access and refresh tokens on the application server in encrypted form and refreshes access only as needed for an authorized feature.
A draft is sent only when a user presses the draft-transfer button. A planned date is an internal reminder and does not trigger publication. After transfer, the creator must open the TikTok inbox notification, review or edit the draft, and publish it from TikTok. We do not sell TikTok data, use it for targeted advertising, or publish content silently. TikTok functionality remains subject to TikTok’s terms, privacy policy, community guidelines, and developer policies.
5. When information is shared
We share information only as needed with: (a) Google or TikTok when you request a connected action; (b) infrastructure and security providers that host or transmit the Service; (c) professional advisers under confidentiality where reasonably necessary; or (d) authorities when required by applicable law or to protect rights and safety. We do not sell or rent personal data.
6. Storage and retention
Project records are stored in the Service database until deleted, no longer needed, or deletion is requested. Files uploaded to Google Drive remain in the connected user’s Drive and are controlled through that account. Provider tokens are retained only for the period needed to provide the connection, expire according to provider rules, or are removed when access is revoked. Security logs may be retained for a limited period appropriate to troubleshooting, fraud prevention, and legal compliance.
7. Security
We use HTTPS, restricted workspace access, server firewall controls, isolated application containers, access controls, and other reasonable safeguards. No online system is completely secure, so users should maintain their own backups and promptly report suspected unauthorized access.
8. Your choices and rights
Subject to applicable law, you may request access, correction, deletion, restriction, or a copy of personal data; object to certain processing; or withdraw consent. You may revoke Google access through your Google Account permissions and TikTok access through TikTok settings. Revocation stops future API access but may not automatically delete project records or files already stored in your Drive.
To submit a privacy or deletion request, email supports@installindonesia.org with the subject “Privacy Request.” We may need to verify your authority over the relevant account or project.
9. International services
Connected providers and infrastructure may process information in countries outside your location. Where required, we apply reasonable measures intended to protect information consistent with this Policy and applicable law.
10. Children
The Service is intended for users aged 18 or older and is not directed to children. If you believe a child has provided personal data, contact us so we can take appropriate action.
11. Changes to this Policy
We may update this Policy when features, provider permissions, or legal requirements change. We will update the effective date and provide additional notice or obtain consent where required.
12. Contact
Install Indonesia
Email: supports@installindonesia.org
Website: https://bcs.installindonesia.org