Legal

Privacy Policy

Effective: June 10, 2026 · Goat Studio (Puya Ventures LLC, New York)

What Goat Studio is

Goat Studio is a done-for-you short-form content service. We take your data, run it through a scoring engine, and produce and publish video content on your behalf. This policy explains what personal data we handle in that process, how we use it, and your rights.

Data we collect

We collect only what is necessary to operate the service:

  • Lead submissions. When you fill out the contact form, we collect your name, email address, company (optional), a description of your data, and an optional budget range. We use this solely to respond to your enquiry.
  • Operator authentication. The studio console uses Google OAuth. We store only the email address returned by Google to gate access. We do not store passwords.
  • Client platform credentials. If you engage as a client, we may store OAuth tokens or API keys for the social platforms you want us to publish to on your behalf (e.g. YouTube, TikTok). These are encrypted at rest using AES-256-GCM and are used solely to publish and retrieve performance metrics on your channels. We do not share or sell them.
  • Client data. Any structured data you provide as source material (catalogs, stats, feeds) is used solely to produce the agreed content. It is not used for any other purpose, not shared with third parties, and deleted on request.

Social media accounts you connect

If you connect a social media account (for example Instagram or TikTok) so Goat Studio can publish on your behalf, we access and store the following via that platform’s official API:

  • Account identifiers. The platform-assigned account, page, or profile ID and username.
  • Profile metadata. Basic public profile/page information needed to display which account is connected and to address publishing requests to the right destination.
  • Content we publish for you. The video, caption, and post metadata you approve, which we submit to the platform on your instruction.
  • Post performance metrics. Engagement data (views, likes, comments, shares, etc.) the platform makes available for posts published through Goat Studio, used to power your analytics dashboard.

We use this data solely to operate the publishing and analytics features you’ve enabled — never for advertising, profiling, or resale. We do not sell this data to anyone. Access tokens are encrypted at rest. You can disconnect an account at any time from Settings, or request full deletion — see our Data Deletion Instructions. Handling of data obtained through Meta and TikTok’s APIs also follows those platforms’ own developer/platform terms, in addition to this policy.

How we use data

  • To respond to your lead submission.
  • To authenticate the studio operator (Puya Rahmanian).
  • To operate the content pipeline on behalf of active clients.
  • To publish scored content to client-authorised channels.
  • To retrieve performance metrics from those channels for reporting.

We do not use your data for advertising, profiling, or any purpose beyond the service you engaged us for.

Subprocessors

The following third-party services process data as part of the Goat Studio pipeline, as currently deployed. This is the complete active set, grouped by purpose — we add or remove a subprocessor only when the underlying integration changes, and we update this list when that happens.

  • Vercel — hosting, serverless compute, and blob storage for rendered assets (US).
  • Neon — PostgreSQL database (US).
  • AWS (us-east-1) — video render compute via Remotion Lambda.
  • Upstash — Redis-backed rate limiting (in-memory fallback if not configured).
  • Anthropic (Claude) — AI text generation for scripts, scoring, and QA gate reasoning.
  • OpenAI — AI text generation (secondary/backup model).
  • Google (Gemini) — holistic AI video review (advisory scoring only) and, for operator sign-in, Google OAuth identity verification.
  • ElevenLabs — AI voiceover synthesis.
  • Suno and fal.ai (aggregating multiple upstream model providers) — AI-generated music, image, and video assets, where a client’s concept configuration uses them.
  • Postiz — social publishing relay used for some connected-channel publishing flows.
  • Meta (Instagram) and TikTok — publishing APIs and analytics APIs for channels you connect and authorize us to publish to.
  • Stripe — payment processing and usage-based billing, for engagements billed that way.

Each subprocessor is covered by its own DPA and privacy policy. We select only services that offer adequate data protections. We do not use a subprocessor to sell your data or to train that vendor’s general-purpose models on your data beyond what that vendor’s own API terms already govern.

Retention

Lead submissions are kept for as long as necessary to manage the enquiry, then deleted. Client data and credentials are deleted within 30 days of engagement end, or immediately on written request.

Security audit logs (records of credential lifecycle events and publish-gate decisions — not your content or channel data) are retained for 2 years for security and dispute purposes. Entries are anonymized — actor and tenant identifiers stripped — 30 days after the engagement they relate to ends, so what persists for the full 2 years is a de-identified security trail, not personal data tied to you. This is the single retention figure that governs audit logs across our policies and contracts; it supersedes any shorter figure quoted elsewhere prior to this update.

Your rights

You may request access to, correction of, or deletion of any personal data we hold about you. To exercise any of these rights, email privacy@goatstudio.ai. We will respond within 30 days.

Cookies

Goat Studio uses a session cookie set by NextAuth for authenticated studio access. No tracking cookies, analytics cookies, or third-party advertising cookies are set on the public storefront.

Governing law

This policy is governed by the laws of the State of New York, United States, without regard to conflict of law principles.

Contact

Puya Rahmanian, Puya Ventures LLC, New York. privacy@goatstudio.ai

Privacy Policy — Goat Studio