Last updated: 11 October 2026
This policy explains how PWRFULLY Studio ("Studio") collects, uses, stores and shares information, including information it receives from Google (YouTube and Google Drive), Meta (Instagram and Facebook), LinkedIn and TikTok. Studio is run by Mina Amso, trading as PWRFULLY, in Auckland, New Zealand ("we", "us").
It covers Studio only. Our main privacy policy covers the PWRFULLY website and services.
What Studio is and who uses it
Studio is a private web app that Mina Amso uses to run PWRFULLY's own content: storing videos and images, making short clips from podcast episodes, writing captions, and scheduling and publishing posts to her own YouTube, Instagram, LinkedIn and TikTok accounts.
It is not offered to the public. Only Mina and team members she invites can sign in, using a sign-in link emailed to an address on Studio's access list. Each person has a role: owner, editor (can create and publish) or viewer (can look but not change anything). For each person, Studio keeps their email address, role and who invited them.
Studio uses YouTube API Services
Studio uses YouTube API Services to upload videos to, and read information from, the YouTube channel connected to it. By connecting a YouTube channel to Studio you agree to the YouTube Terms of Service. Google's own handling of your information is covered by the Google Privacy Policy.
What Studio accesses from each platform, and why
Studio connects to an account only when an owner or editor presses Connect and approves the platform's own permission screen. It asks only for the permissions below and uses them only for the purposes listed.
YouTube (Google). Permissions: youtube.upload, youtube.readonly, youtube.force-ssl, and your Google account's email address and sign-in identity (openid, email). Studio uses them to:
- read the channel's name, handle, profile picture and channel ID, so you can choose the channel when posting;
- upload the videos you schedule, with the title, description, privacy setting and thumbnail you chose, and add a first comment if you asked for one;
- read the view, like and comment counts of the videos Studio posted, so you can see how they did (refreshed about once an hour while the channel is connected);
- read the channel's own uploads from the last 60 days, and videos scheduled in YouTube Studio (video ID, title, thumbnail link and publish time), so Studio's calendar shows everything going out on the channel;
- look up a YouTube video you paste in to make clips from (title, description, length and chapters) and, for videos on your own channel only, download its captions to use as the transcript;
- search public YouTube videos on a topic to suggest tags and titles that are working now (searches are kept for six hours and deleted within three days).
Studio never downloads videos from YouTube.
Google Drive. A separate, optional connection. Permissions: either drive.readonly (see and download your Drive files, never change them) or drive.file (only the files you pick in Google's own window), plus openid and email. Studio uses it to show your Drive folders and files so you can choose episodes and photos, and to copy the files you choose into Studio's storage. It keeps the Drive account's email, name and profile picture. Studio never changes, moves or deletes anything in your Drive.
Instagram and Facebook (Meta). Permissions: instagram_basic, instagram_content_publish, instagram_manage_comments, instagram_manage_insights, pages_show_list, pages_read_engagement and business_management. Studio uses them to find the Instagram professional accounts linked to your Facebook Pages (account ID, username, name, profile picture, and the linked Page's name and ID), publish the Reels, posts and Stories you schedule, add a first comment if you asked for one, and read the account's published posts and the Page's scheduled posts for the calendar. When you tag someone, Studio can look up the public name, profile picture and follower count of an Instagram business or creator account (Meta's Business Discovery); that look-up is kept for up to three days.
LinkedIn. Permissions: openid, profile, email and w_member_social. Studio uses them to read your name, profile picture, email address and member ID, to show which account is connected, and to publish the posts (text, images and videos) you schedule, with a first comment if you asked for one. Studio cannot read your LinkedIn posts or their results.
TikTok. Permissions: user.info.basic, video.upload and video.publish. Studio uses them to read your display name, profile picture and account ID, to read your account's posting settings (handle, privacy options and longest allowed video) before each post, and to send the videos you schedule either straight to your profile or to your TikTok inbox as a draft. Studio does not read your TikTok videos or their results.
For every platform, Studio keeps a record of each post it sends: the platform, the account, the time, the post's ID and link, and any result it can read.
Your content, and the services that process it
Studio stores what you put into it: videos, images and audio you upload or bring in from Google Drive, transcripts, clips, captions, the posting plan and schedule, tags, notes, and a People list of guests and sponsors (names, Instagram handles and LinkedIn profile links) used to credit and tag them. It also keeps an activity log of what was done in Studio and by whom.
Studio uses these service providers, only to run the features described here:
- Lovable and Lovable Cloud (Supabase) host the app, its database, file storage and sign-in.
- AssemblyAI transcribes episode audio into a transcript with word timings.
- Anthropic (the Claude API) receives transcripts or parts of them (including captions downloaded from your own YouTube videos), captions and a few still frames from videos, to suggest clip moments, headlines, captions, hashtags and tags, and to check thumbnails. Its suggestions are drafts for you to review.
- Modal runs Studio's video worker, which brings in the episode files you add (from Google Drive or a direct link), converts them, finds the people on screen in the chosen moments, and renders clips and thumbnails. For a Drive file it receives a short-lived access key for that job only, and its working files are deleted when each job ends.
- Google Fonts serves the typefaces Studio's pages use, so your browser contacts Google when a page loads.
If Mina connects Claude (Anthropic's assistant app) to Studio through Studio's own connector, Claude can see what a Studio user can see and draft or schedule posts when she asks. That connection is made and removed in Studio's settings.
How Studio keeps it safe
- The access keys the platforms give Studio are stored only on Studio's server, in database tables that the browser cannot read. They are never shown on screen and never written to logs.
- Files are kept in private storage and reached only through short-lived signed links. To publish a video, Studio gives the platform a short-lived link so it can fetch the file.
- All traffic is encrypted (HTTPS).
- Sign-in is by emailed link, and only for addresses on Studio's access list. Viewers cannot change anything.
Sharing
We do not sell any information from Studio, use it for advertising, or give it to data brokers or anyone else. Studio shows no advertising and does not let third parties serve ads in it.
Information leaves Studio only:
- when you publish, to the platform you publish to (the post itself);
- to the service providers listed above, to run Studio;
- when an editor makes a share link for one clip, which anyone with the link can watch until it expires (30 days by default) or is turned off;
- when the law requires it.
Google user data and Limited Use
PWRFULLY Studio's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice, Studio uses information from YouTube and Google Drive only to provide the features described in this policy. It does not use that information for advertising, does not sell it, and does not use it to develop, improve or train general artificial intelligence or machine learning models. It is passed only to the service providers named above, to run those features. No one outside the people you work with in Studio reads it unless you ask us to (for example, to fix a problem), it is needed for security, or the law requires it.
How long Studio keeps information
- Connection details and access keys: until the account is disconnected, when they are deleted straight away.
- Posts imported from a connected account for the calendar: deleted when that account is disconnected.
- Your content, posts, transcripts and results: kept while Studio is in use, until an editor deletes them or you ask us to delete them.
- YouTube trend searches: kept for six hours, deleted within three days. Instagram look-ups: deleted after three days.
- Clip share links: expire after 30 days by default.
Disconnecting and revoking access
In Studio. On the Connections page, an owner or editor can disconnect any account. Studio then deletes that account's stored access keys and the posts it imported from that account for the calendar. For Google Drive, disconnecting also asks Google to revoke Studio's access. Posts already published stay on the platform, and Studio's own record of them stays until it is deleted.
At the platform. You can remove Studio's access at any time:
Once access is removed, Studio can no longer post to or read from that account.
Deleting your data
To have your information deleted from Studio, email mina@minaamso.com with the subject "Delete my Studio data" and tell us which accounts it concerns. We will delete it from Studio within 30 days and confirm by email. This covers information received from Google, Meta, LinkedIn and TikTok, and the content stored in Studio.
Owners and editors can also delete items in Studio themselves at any time, and disconnecting an account deletes its access keys straight away.
Cookies and browser storage
Studio uses no advertising or analytics cookies. It keeps your sign-in session in your browser's local storage, sets a short-lived cookie (10 minutes) while you connect an account, to check the connection request really came from you, and sets a cookie that remembers whether the side menu is open.
Your rights under the New Zealand Privacy Act 2020
We handle personal information in line with the Privacy Act 2020. You can ask to see or correct the personal information Studio holds about you by emailing mina@minaamso.com. Some of Studio's service providers store and process information outside New Zealand, including in the United States. If you are not happy with how we have handled your information, you can complain to the Office of the Privacy Commissioner.
Changes to this policy
If Studio starts handling information differently, we will update this policy and the date at the top before the change takes effect.
PWRFULLY, podcast guesting and communication coaching. Auckland, New Zealand.