Privacy Policy
Last updated: June 20, 2026
This Privacy Policy explains how REBAN Desarrollo collects, uses, stores, and protects information when authorized users access AI Studio at https://studio.reban.com.
1. App Purpose
AI Studio is REBAN's private workspace for media coordination, production task management, AI-assisted creative workflows, and calendar planning. The application is intended for authorized REBAN users and collaborators.
2. Information We Collect
2.1 Account and access data
- Name, email address, profile image, and identity provider account ID.
- Authentication session data needed to keep users signed in.
- Role, team, medio, and permission information used for access control.
2.2 Workspace content
- Tasks, production items, calendar blocks, status changes, and comments.
- Uploaded or generated media assets used in AI-assisted workflows.
- Prompts, settings, metadata, and operational notes entered by users.
2.3 Technical and security data
- IP address, browser type, device information, and request metadata.
- Application logs, audit events, and error reports.
- Usage analytics used to understand product reliability and adoption.
- Automatically captured interactions with interactive elements (links, buttons, and form controls), including the visible text of the element that was used. Because workspace screens list media, client, and person names, that text can appear in these events. Values typed into form fields are not collected.
3. Google OAuth and Google Calendar Data
When a user connects Google Calendar, AI Studio uses Google OAuth to ask for permission to access Google Calendar on that user's behalf. The Calendar integration is optional and can be disconnected by the user.
Depending on user actions, AI Studio may access:
- Calendar event title, description, start time, end time, and timezone.
- Calendar event identifiers needed to update or delete synced events.
- Google account email address, used to show which account is connected.
- OAuth access and refresh tokens needed to maintain the connection.
AI Studio uses Google Calendar data only to provide calendar connection, event display, event creation, event updates, event deletion, and sync between AI Studio tasks and Google Calendar. Google Calendar data is not sold, rented, or used for advertising.
4. How We Use Information
| Purpose | Use |
|---|---|
| Authentication | Verify user identity and maintain secure sessions. |
| Authorization | Apply role-based access to teams, medios, and admin areas. |
| Product operation | Provide task, calendar, media, and AI workflow features. |
| Calendar sync | Create, read, update, delete, and synchronize Google Calendar events. |
| Security and reliability | Monitor errors, diagnose incidents, prevent abuse, and audit changes. |
5. Service Providers
We use service providers to operate AI Studio. They may process data only as needed to provide their services.
| Provider | Purpose |
|---|---|
| Supabase | Authentication, database, and account management. |
| Railway | Application hosting and backend runtime. |
| OAuth authentication and Google Calendar integration when enabled. | |
| Sentry | Error monitoring and reliability diagnostics. |
| PostHog | Product analytics and usage measurement, including automatically captured interactions with links, buttons, and form controls. |
| Axiom | Application log storage and operational observability. |
| Cloudflare | DNS, CDN, security, and traffic protection. |
6. Data Retention
- Account data is retained while the account remains active.
- Workspace content is retained while needed for REBAN operations or until removed by an authorized user.
- Google Calendar tokens are retained only while the user keeps the calendar connection active.
- Operational logs and error reports are retained for limited security and reliability windows.
7. Security
- Traffic is protected with HTTPS/TLS.
- Access is limited by authentication and authorization controls.
- Secrets are managed through Doppler, not committed to source code.
- Google OAuth tokens are stored server-side and protected from browser JavaScript access.
- Audit and error monitoring are used to investigate security and reliability events.
8. User Choices
- Users can disconnect Google Calendar from within AI Studio.
- Users can revoke Google OAuth access from their Google Account security settings.
- Authorized users can request account or data updates through REBAN support.
9. Children
AI Studio is not directed to children and is intended only for authorized professional users.
10. Changes to This Policy
We may update this Privacy Policy as the product, legal requirements, or service providers change. Updates will be published on this page with a revised date.
11. Contact
For privacy questions or requests, contact danielgarza@reban.com.