Legal

Privacy Policy

Effective October 4, 2026Last updated October 4, 2026 (connections)

The short version

  • SocialMediaPip ("SMP") is an internal tool of UniChat Games. Only our studio uses it, and it connects only to accounts we own.
  • It uses the YouTube, Instagram and TikTok APIs to publish our own videos and read our own statistics.
  • It does not collect personal data about viewers, does not read messages, and sells or shares nothing.
  • Platform sign-in tokens are stored encrypted and only SMP's server can read them; they never reach a browser. The plan and our own videos are kept in a private, staff-only web app (app.studio.unichat.dev).
  • Revoking access deletes what we hold within 7 days. Ask us any time: privacy@unichat.dev.

Who we are

SMP is made and operated by UniChat Games (Ilhan Akbudak, sole proprietor), Türkiye ("we", "us"). We make mobile games, including Skyward. We are the data controller for the information described here.

What SMP is

SMP has two parts. Software on our studio's computer records gameplay from our own games, edits it into short videos and publishes them to our own social media accounts. A private web app at app.studio.unichat.dev lets our staff plan, review and approve those posts from any device. Both read back how our posts performed.

It is not offered to the public. The only people who sign in to it are members of UniChat Games, and the only accounts connected to it are our own: today YouTube @playskyward, Instagram @skywardgame and TikTok @playskyward.

Data we access

When one of our accounts is connected, SMP accesses only the following, through each platform's official API and only with the permissions that account granted:

PlatformWhatWhy
YouTubeThe channel's ID and name; the videos we upload (ID, title, description, privacy status, URL); the comment we post under each; our own channel's and videos' statistics (views, watch time, likes, comments, shares, subscribers gained) and aggregated audience reports (for example views by country), as provided by the YouTube Analytics API.To publish our videos and to measure them.
InstagramThe account's ID, username and account type; the Reels we publish (ID, permalink); the comment we post under each; insights for our own posts and account (views, reach, likes, comments, shares, saves) and aggregated audience reports (for example followers by country).To publish our videos and to measure them.
TikTokThe account's open ID, display name and avatar; the upload and status of videos we send to our drafts; our own videos' public statistics (views, likes, comments, shares) and our account's public counts.To send our videos to our drafts and to measure them.

Aggregated reports are totals the platforms compute; they never identify an individual viewer. SMP does not access other people's accounts or content, direct messages, contacts, or any personal data about the people who watch our videos.

YouTube API Services

SMP uses YouTube API Services. By using SMP's YouTube features you agree to be bound by the YouTube Terms of Service. Google's handling of data is described in the Google Privacy Policy (www.google.com/policies/privacy).

The Google permissions SMP asks for are: uploading videos (youtube.upload), posting comments (youtube.force-ssl), reading our channel and videos (youtube.readonly) and reading our channel's analytics (yt-analytics.readonly). It uses them only for the purposes in this policy.

You can revoke SMP's access to a Google account at any time from the Google security settings page: security.google.com/settings/security/permissions.

How we use it

  • To publish videos we approved, with their title, caption and first comment, at the planned time.
  • To show whether each post went out, and its link, in our planning tool.
  • To produce our own weekly report of how our videos performed, so we can decide what to make next.

We do not use this data for advertising, profiling, or training models, and we do not combine it with data from other sources about individuals.

Where it is kept and how it is protected

  • Sign-in tokens (OAuth access and refresh tokens) are stored encrypted in Supabase Vault (United States), readable only by SMP's server functions and our studio's computer, never by a browser. Older tokens on the studio's computer are kept in the macOS Keychain. Tokens are never written to a file or a repository, and never logged.
  • Post records and statistics are stored as files on the same computer and in the staff app's database (Supabase, United States), readable only by signed-in staff.
  • Our own videos are stored in a private Cloudflare R2 bucket (United States); the staff app hands out links to them that expire within an hour, and only to signed-in staff.
  • The staff app runs on Vercel (United States). All data travels over HTTPS. This website (studio.unichat.dev) is static and receives none of this data.

Sharing

We do not sell, rent or share data obtained through the platform APIs with anyone. The only exception is if the law requires us to disclose it, in which case we disclose only what is required.

Retention and deletion

  • Statistics are kept only as long as we need them for our reports. Data from the YouTube API is refreshed or deleted at least every 30 days, as YouTube's developer policies require; the other platforms' data is treated the same way.
  • Video IDs and links of our own posts are kept while the post exists, so we know what was published.
  • If access to an account is revoked, or you ask us to delete data, we delete the tokens and all data obtained through that platform's API within 7 days.

How to ask for deletion: see Data deletion.

Revoking access

Inside SMP, staff can press Disconnect in Settings → Connections: SMP revokes its access at the platform where the platform allows it and deletes the stored token. You can also revoke it yourself:

  • Google / YouTube: Google security settings → Third-party apps → SocialMediaPip → Remove access.
  • Instagram: Instagram → Settings → Website permissions → Apps and websites → SocialMediaPip → Remove.
  • TikTok: TikTok → Settings and privacy → Security and permissions → Apps and services permissions → SocialMediaPip → Remove access.

The staff web app

app.studio.unichat.dev is open only to members of UniChat Games on our staff list. They sign in with Google (through Supabase Auth). From Google we receive only the basic profile (name, email address, profile picture), which we use to check the staff list; we ask for nothing else with this sign-in. An attempt to sign in with an account that is not on the list is refused and no account is created.

A signed-in staff member gets a session cookie (HttpOnly, valid for one hour, refreshed while they use the app). It is used only to keep them signed in. The app sets no other cookies apart from the theme cookie described below, and runs no analytics or advertising.

A staff member can turn on reminders on a device (Settings → Reminders). SMP then stores that device's push address and keys, a short device label (for example "iPhone · Home Screen app"), its time zone and which staff member turned it on, and sends notifications about our own posting schedule through the push service of the device's browser (Apple, Google or Mozilla). Turning reminders off deletes that record; a device the push service no longer knows is deleted automatically.

The services that run it process data on our behalf: Vercel (hosting), Supabase (database and sign-in) and Cloudflare (video storage). A staff member's account is deleted when they leave the studio, or on request.

This website

studio.unichat.dev is a static website hosted by Netlify. It runs no analytics or advertising and loads nothing from third parties. Its only cookie is smp-theme, set when you pick a light, dark or system theme: it holds just that word, is shared with app.studio.unichat.dev so both follow the same choice, and lasts a year. It identifies no one and is never used for tracking. Netlify processes technical data such as IP addresses in server logs to deliver the site and keep it secure, as described in Netlify's privacy policy.

The page at /auth/callback only displays a one-time sign-in code in your own browser so it can be pasted into SMP; it sends the code nowhere.

Your rights

Depending on where you live (for example under Türkiye's KVKK, the EU or UK GDPR, or US state laws), you may have the right to ask what personal data we hold about you, to have it corrected or deleted, to object to its use, and to complain to a data protection authority. SMP holds no personal data about anyone outside our studio, but if you believe it does, write to us and we will answer within 30 days.

Children

SMP is a tool for our studio's staff. It is not directed at children and collects no data from them.

Changes

If this policy changes, we update this page and its "Last updated" date. If SMP starts to access new kinds of data, we update this policy before it does.

Contact

UniChat Games · privacy@unichat.dev · general questions: support@unichat.dev