Privacy Policy
Effective 10 August 2026 · Bapla Studio (“we”, “us”), operator of the Envola service.
In short: Envola stores only what it needs to publish on your behalf. Access tokens for your connected accounts are encrypted at rest, passwords are hashed, and we never sell your data or use platform data for advertising. Disconnecting an account or asking us to delete your account removes the associated data.
This policy explains what information Envola collects, how it is used, and your choices. Envola is a tool that publishes content to social media platforms on your behalf and reports metrics for that content.
1. Information we collect
- Account information — your email address, a display name, and a hashed (never plaintext) password used to sign in.
- Connected social accounts — when you connect an Instagram, Threads, YouTube or TikTok account, we receive and store the access and refresh tokens that platform issues, along with basic profile details it returns (such as the account ID, username or channel name, and avatar). Tokens are encrypted at rest.
- Content you provide — media files you upload, captions, titles, and scheduling details for the posts you create.
- Metrics — performance data (such as views, likes, and comments) that the platforms report for content you published through Envola, stored as returned.
- Operational logs — basic technical logs needed to run and debug the service. Tokens and passwords are redacted from logs.
2. How we use information
We use the information solely to provide the service:
- to authenticate you and keep you signed in;
- to publish and schedule the content you create to the accounts you select;
- to refresh your access tokens ahead of expiry so publishing continues to work;
- to show you the status of your posts and the metrics the platforms report.
We do not sell your data, share it with advertisers, or use data obtained from Instagram, Threads, YouTube, or TikTok for any purpose other than operating the service for you.
3. Platform data (Meta, Google/YouTube, TikTok)
Data obtained through a platform’s API is used only to perform the actions you request (publishing your content and reading metrics for it) and is handled in accordance with that platform’s developer requirements. We request the minimum permissions needed: publishing and insights for the accounts you connect. We retain platform tokens only while the account is connected; disconnecting the account, or deleting your account, removes them.
4. YouTube API Services
Envola uses YouTube API Services to do the things you ask it to do with a connected channel: upload your videos, show you which channel you are posting to, and collect the performance figures it reports back to you.
- By connecting a YouTube channel to Envola you agree to be bound by the YouTube Terms of Service.
- Google’s own handling of your information is governed by the Google Privacy Policy.
- You can withdraw Envola’s access to your Google account at any time from the Google security settings page. That works on its own, independently of asking us to delete your data (section 7) — though revoking access will stop scheduled posts to that channel.
What we ask for, and why. When you connect a channel we request four permissions, each tied to a feature you can see in the app:
- Upload videos — to publish the videos you schedule.
- View your account details — to read the channel name and picture, so the app can show you which channel a post is going to.
- View YouTube Analytics reports — to build the metrics view for videos you published through Envola.
- Manage your account — to post the first comment on your own video, when you ask for one.
What we store. The access and refresh tokens Google issues (encrypted at rest), your channel’s ID, name and picture, the video ID of each video Envola published for you, and the metrics Google returns for those videos, kept as returned. We do not copy your existing videos, your subscriber list, or any channel content Envola did not publish.
What we do not do with it. YouTube data is used only to operate the features above for you. We do not sell it, do not use it for advertising or ad targeting, do not use it to build profiles, and do not share it with third parties. No third party serves content or advertisements inside Envola, and no YouTube data is stored on your device — the only thing stored there is the sign-in cookie described in section 8. Tokens are removed when you disconnect the channel or delete your account, and stored YouTube data is deleted with it.
Privacy questions or complaints about any of this: hello@baplastudio.fr.
5. Storage and security
- Data is stored on infrastructure we operate.
- Access and refresh tokens are encrypted at rest using AES-256-GCM; the encryption key is held separately from the database.
- Passwords are stored only as salted scrypt hashes.
- All traffic is served over HTTPS.
6. Sharing
We do not sell or rent your data. The only external transfer of your content is to the social platform you explicitly choose to publish to, which is the purpose of the service. We do not use third-party advertising or analytics trackers.
7. Retention and deletion
We keep your information while your account is active. You can:
- Disconnect a social account at any time, which removes its stored tokens;
- Request deletion of your account and associated data by emailing hello@baplastudio.fr. We will delete your account data, connected-account tokens, and uploaded media, except where we must retain limited records to comply with law.
8. Cookies
Envola uses a single, essential cookie to keep you signed in. It is not used for advertising or cross-site tracking. There are no third-party cookies.
9. Children
The service is not directed to, and may not be used by, anyone under the age required to hold an account on the connected platforms.
10. Changes
We may update this policy; material changes are reflected by updating the effective date above.
11. Contact
Questions or requests: hello@baplastudio.fr.