Skip to content

Engage Studio · Legal

Privacy Policy

Effective July 1, 2026

Effective date: July 1, 2026 Operator: Cairnworks AI, a project operated by Brandon Goddard, Maine, USA Contact: [email protected]

This policy explains what data Cairnworks AI (“Cairnworks,” “we,” “us,” or “our”) collects when you use the Engage Studio platform (“the Service”), how we use that data, who we share it with, and the choices you have about it.

Scope. This policy governs Engage Studio specifically. Our general marketing website at cairnworks.ai has its own separate Privacy Policy.

1. Who this policy applies to

This policy applies to two groups of people:

  • Account holders — businesses and creators who sign up for Engage Studio to automate their content publishing and social engagement.
  • End users — people who interact with an account holder’s social presence (comment on posts, receive automated replies, join email lists, visit blog content) that is operated through the Service.

If you are an end user interacting with a specific account holder’s business, that business is the primary controller of your data. Cairnworks processes the data on their behalf and applies the safeguards described here. The account holder may have their own privacy policy that adds to (but does not replace) this one.

2. Information we collect

From account holders

  • Account credentials — email address and password (stored hashed with Argon2), or Google account ID if you sign in with Google
  • Account profile — business name, brand assets you upload (logos), color preferences
  • Service connections — encrypted credentials for the third-party services you connect (Google Drive/Sheets, WordPress, Metricool, MailerLite, Meta Facebook/Instagram Pages). We store OAuth tokens and API keys encrypted at rest using AES-256-GCM.
  • Content plans — data you import from your Google Sheets (post titles, publish dates, platform assignments, keywords, lead magnet URLs, media file references)
  • Media files — videos and images you provide via Google Drive or direct upload for us to process and publish
  • Usage data — batch history, publish history, audit logs, error logs

From end users (people who interact with an account holder’s content)

  • Comments and reactions on the account holder’s Facebook Page or Instagram Business account, retrieved via Meta’s Graph API
  • Direct message content you send to or receive from the account holder’s Page when an automated engagement flow is active
  • Contact information you volunteer — for example, if you provide an email address in response to an automated message offering a lead magnet, we send that email address to the account holder’s email service provider
  • Publicly available Meta profile information — display name, profile picture URL, Meta user ID — as returned by the Graph API when you interact with an account holder’s Page

Automatically

  • Basic server logs (IP address, request timestamp, user agent) retained for 30 days for security and troubleshooting
  • Session cookies for account holder authentication (HttpOnly, Secure, SameSite=Lax)

3. How we use your information

  • Deliver the Service — process your content, publish to the platforms you’ve connected, run engagement automation flows on your behalf
  • Authenticate you — verify your identity when you log in, keep you signed in
  • Communicate with you — respond to support requests, notify you about important service changes
  • Improve the Service — analyze aggregate usage patterns (not linked to individual identities) to prioritize product work
  • Protect the Service — detect abuse, prevent unauthorized access, enforce our terms

We do not use your data to train AI models. We do not sell your data. We do not use your data for advertising.

4. Google User Data

Engage Studio integrates with Google Drive and Google Sheets when you connect your Google account. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Scopes we request

  • drive.file — to read the specific source files you select (through the Google Picker) or that Engage Studio itself creates, and to write completed outputs (final videos, blog banners, post copy) back to the working folder you designate. This scope does not give us access to any other files in your Google Drive.
  • spreadsheets.readonly — to read your content plan spreadsheet (post titles, dates, platform assignments, and related metadata)

How we use Google user data

  • Source files you select (or that Engage Studio creates) are downloaded on demand, processed on our servers (or a worker machine we operate), and the outputs are written back to the working folder you designate
  • We can only access the files and folders you explicitly select through the Google Picker, plus files Engage Studio creates — never anything else in your Drive
  • Spreadsheet data is read to build the content plan you approve for processing
  • We do not share Google user data with third parties except (a) service providers strictly necessary to deliver the Service (e.g., our hosting infrastructure), (b) when required by law, or (c) with your explicit consent

Data retention

  • Google OAuth tokens are stored encrypted at rest and used only when the Service needs to access your Drive or Sheets on your behalf
  • Downloaded file content is retained only for the duration of processing (typically minutes to hours), then deleted
  • You can revoke our access at any time by visiting your Google Account permissions page or by clicking “Disconnect” on the Engage Studio Settings page. Revocation immediately invalidates the tokens we hold.

5. Meta Platform Data

When an account holder connects a Facebook Page or Instagram Business account, Engage Studio uses Meta’s Graph API to:

  • Read comments on posts to detect keyword triggers
  • Send direct messages to users who trigger automated engagement flows
  • Retrieve basic public profile information (name, profile picture) about users who interact with the account holder’s content

What we don’t do

  • We do not read Messenger conversations that are unrelated to an active engagement flow
  • We do not access private data of users who have not interacted with the account holder’s public content
  • We do not share Meta Platform Data with third parties beyond what is necessary to deliver the Service to the account holder

Data deletion

Meta users may request deletion of their data by:

  • Contacting us at [email protected] with the subject line “Data Deletion Request”
  • Or, initiating a data deletion request through Meta’s platform, which will call our data deletion callback URL and trigger the same deletion process

Our data deletion callback is hosted at https://engageapi.cairnworks.ai/api/webhooks/meta/data-deletion and is documented in our Meta App configuration.

6. Third-party services we use

The Service depends on third-party providers. Each has its own privacy policy governing their use of the data we share with them.

System-level services (operated by Cairnworks, shared across all Engage Studio account holders):

  • OpenRouter — AI text generation (post copy, blog content, image search queries). We send content-related prompts; we do not send end-user personal data, and we use zero-retention settings where available. OpenRouter Privacy Policy
  • Pexels — stock imagery for blog banners. We send search queries; we do not send end-user data. Pexels Privacy Policy

Per-account services (connected by the account holder using their own credentials):

7. How we share information

We do not sell your data. We share it only in these situations:

  • With service providers we contract to help deliver the Service (hosting, error monitoring, email delivery). These providers are contractually required to use the data only for the purposes we authorize.
  • With third-party services you connect (Google, Meta, WordPress, Metricool, MailerLite) — the specific data we send to each is described in Section 6 and in the Terms of Service.
  • When required by law — subpoena, court order, or other valid legal process. We will attempt to notify you unless prohibited from doing so.
  • To protect rights and safety — of Cairnworks, our users, or the public.
  • In a business transfer — if Cairnworks is acquired or merged, your data may transfer to the successor entity, subject to this policy.

8. Data retention

  • Account holder data — kept for as long as you have an active account. When you delete your account, we delete your data within 30 days, except for records we’re legally required to retain (billing records, security logs) which are kept up to 7 years.
  • Content and media files — kept for as long as you keep them in the Service. Downloaded working copies are deleted after processing.
  • End user data — messages, emails captured via engagement flows, and profile information are kept for as long as the account holder wants to retain them. Individual end users can request deletion at any time (see Section 5 and Section 10).
  • Server logs — 30 days
  • Session cookies — 30 days

9. Data security

We use industry-standard safeguards, including:

  • All service credentials (API keys, OAuth tokens) encrypted at rest with AES-256-GCM
  • Passwords hashed with Argon2
  • All web traffic served over HTTPS (TLS 1.2 or higher)
  • Access to production systems restricted to the Cairnworks operator on a need-to-know basis
  • Session cookies marked HttpOnly, Secure, and SameSite=Lax

No system is perfectly secure. If we discover a breach that affects your data, we will notify affected users promptly (within 72 hours where applicable) and cooperate with any regulatory requirements.

10. Your rights

Depending on where you live, you may have some or all of the following rights:

  • Access — request a copy of the personal data we hold about you
  • Correction — ask us to correct inaccurate data
  • Deletion — ask us to delete your data (with limited exceptions for legal retention requirements)
  • Portability — receive your data in a structured, machine-readable format
  • Objection — object to certain processing
  • Withdrawal of consent — for any processing based on consent, withdraw that consent
  • Complaint — file a complaint with a data protection authority

To exercise any of these rights, email us at [email protected]. We will respond within 30 days.

11. Children

The Service is not intended for children under 13 (or the minimum age of digital consent in your country, which may be higher — up to 16 in parts of the EU). We do not knowingly collect data from children below that age. If we learn we have done so, we will delete it. If you are a parent or guardian and believe your child has provided data to us, please contact [email protected].

12. International users

Cairnworks is operated from the United States. If you access the Service from outside the U.S., your data will be transferred to and processed in the U.S., which may have different data protection standards than your country of residence.

13. Changes to this policy

We may update this policy from time to time. When we do, we will update the “Effective date” at the top and, for material changes, we will notify account holders by email or a prominent notice in the Service at least 30 days before the change takes effect.

14. Contact

Questions, requests, or complaints about this policy or our data practices:

  • Email: [email protected]
  • Subject line for data deletion requests: “Data Deletion Request”
  • Mailing address: Available on request via email

Cairnworks AI is not currently a formed legal entity. It is operated by Brandon Goddard as a sole proprietor based in Maine, USA. This will be updated when the entity is formed.