Privacy Policy

Effective 25 September 2026

Something Good Inc, which trades as Supermix (“Supermix”, “we”, “us”), produces podcasts and other content for creators and companies. We also run the Supermix Studio, where our customers review that work, download finished deliverables and publish them to the YouTube, Instagram and TikTok accounts they connect. This policy explains what personal information we collect, how we use it, and who we share it with.

It covers supermix.io, the Supermix Studio at studio.supermix.io, and the integrations we offer: publishing to YouTube, Instagram and TikTok. Questions go to ops@supermix.io.

1. Information we collect

  • Contact details you give us when you enquire, book a call, email us or are invited to the Supermix Studio: your name, email address and company.
  • Billing details such as billing contacts, addresses and tax identifiers. Card details are entered directly with our payment provider and we do not store full card numbers.
  • Content you ask us to produce, including recordings, footage, transcripts and artwork, which may include personal information about hosts and guests.
  • Technical data such as your IP address and browser type, used to keep our website and the Supermix Studio secure and working.
  • Information from services you connect, such as a YouTube channel, an Instagram professional account or a TikTok account. Sections 3 to 5 describe this in detail.

2. How we use information

We use personal information to provide the services you ask for, including producing content for you and letting you publish it to the accounts you connect in the Supermix Studio; to communicate with you about that work; to manage accounts and invoices; and to keep our systems secure. You and your team choose what is published. Supermix team members may also connect an account for you, or publish to an account connected to your workspace, but only with your authorisation. We do not sell personal information, and we do not use it for third-party advertising.

3. YouTube channels and Google user data

Supermix uses YouTube API Services to publish videos to YouTube channels our customers connect. By connecting a YouTube channel you agree to be bound by the YouTube Terms of Service, and Google’s handling of your data is described in the Google Privacy Policy.

What we ask for

When you or another member of your workspace connects a channel, we request three permissions from Google:

  • Upload videos (youtube.upload). Lets us upload videos, set their titles, descriptions, thumbnails and privacy status, and schedule them, on the channel you connect.
  • View your channel (youtube.readonly). Used only to look up the identity of the channel you connected (its ID, name, handle and avatar) so you can confirm the right channel is linked, and to check the status of videos we uploaded (scheduled, live or removed). We do not read your other videos, comments, subscribers, watch history or analytics.
  • Manage your YouTube account (youtube). Used only to change the scheduled publish time of a video we uploaded when you move its release date. YouTube offers no narrower permission for editing a video, so this is the permission Google requires for that one action. We do not edit videos we did not upload, and we never delete videos, comments or playlists.

What we store

We store the channel ID, name, handle and avatar, the permissions Google actually granted, the OAuth access and refresh tokens Google issues, who connected the channel and when, and the connection’s health. Tokens are encrypted at rest. They are decrypted only inside our backend, when we use the connection to publish, check on videos we uploaded, refresh the connection or revoke it. They are never shown to Supermix team members and never sent to a browser.

How we use it

We use this access only to publish the videos you choose, or that Supermix team members publish for you with your authorisation, with the title, description, thumbnail, schedule and privacy status you set, and to keep the connection working. We do not use Google user data for advertising, we do not sell it, and we do not use it to train machine-learning or AI models.

Who we share it with

Google user data is sent to Google to perform the actions you request and is stored with the infrastructure providers that host our systems. Members of your workspace in the Supermix Studio, and Supermix team members, can see which channel is connected and what has been published to it. We do not otherwise share Google user data with anyone.

Revoking access and deleting data

You can disconnect a channel at any time from Settings → Connections in the Supermix Studio, or ask us to disconnect it for you. We then ask Google to revoke the grant and delete our copy of the tokens. You can also remove Supermix’s access from your Google Account permissions. Google does not tell us when you do that: the tokens stop working and stay stored, encrypted, until you disconnect the channel in the Supermix Studio or ask us to delete them. After a disconnect we keep the channel’s ID, name, handle, avatar link and who connected it, so previously published posts remain readable in your history; ask us and we will delete them.

Google Calendar

Members of the Supermix team may connect their own Google Calendars to the Supermix Studio so colleagues can see their availability. This uses read-only calendar access together with basic profile information (name, email and photo). Tokens are handled the same way as described above, and calendar data is used only to display availability inside the Supermix Studio.

Limited Use

Supermix’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. Instagram professional accounts

The Supermix Studio uses the Instagram API with Instagram Login, provided by Meta, to publish Reels to Instagram professional accounts (Business or Creator) that our customers connect. Personal Instagram accounts cannot be connected. Using Instagram is subject to the Instagram Terms of Use, and Meta’s handling of your data is described in the Meta Privacy Policy.

What we ask for

When you connect an account, we request two permissions from Instagram:

  • View your profile (instagram_business_basic). Lets us read the account’s Instagram user ID, username, name, account type and profile picture, so the Supermix Studio can show which account is connected. We check the account type when you connect, to confirm it is a professional account, and store whether it is a Business or Creator account so the Supermix Studio can show it.
  • Publish content (instagram_business_content_publish). Lets us publish a Reel to the account when you press Publish, check the account’s publishing limit, follow the Reel while Instagram processes it, and get its link once it is live.

We do not read your comments, messages, followers or insights, and we never edit or delete posts. Instagram offers no way to schedule a post through its API, so a Reel goes out when Publish is pressed.

What we store

We store the account’s Instagram user ID and the separate ID Meta gives it for the Supermix Studio, its name, username, whether it is a Business or Creator account, a link to its profile picture (not the image itself), the permissions Instagram granted, an access token and its expiry date, who connected the account and when, and the connection’s health. For each Reel published through the Supermix Studio we keep its Instagram media ID, its link, the caption and settings it was published with, and who pressed Publish.

The access token is encrypted at rest, is never sent to a browser and is never shown to Supermix team members. Instagram tokens last about 60 days. While the account stays connected we renew the token automatically once a day, so the connection keeps working even when nothing is being published.

How we use it

We use this access only to publish the Reels you choose, or that Supermix team members publish for you with your authorisation, with the caption you write and your choice of whether the Reel also appears in your feed, and to keep the connection working. Two checks run in the background. Once a day we look up each Reel published through the Supermix Studio to see whether it is still live. And if Instagram’s reply to a publish is lost, we read the account’s 10 most recent posts, including their captions, only to find the Reel we just published; we keep nothing from that read except the matching Reel’s ID and link.

We do not use Instagram data for advertising, we do not sell it, and we do not use it to train machine-learning or AI models.

Who we share it with

To publish a Reel we send Instagram the caption, your feed choice and a public link to the video file in our storage; Instagram downloads the video from that link itself. Instagram data is stored with the infrastructure providers that host our systems. Members of your workspace in the Supermix Studio, and Supermix team members, can see which account is connected and what has been published to it. We do not otherwise share Instagram data with anyone.

Revoking access and deleting data

You can disconnect the account at any time from Settings → Connections in the Supermix Studio, or ask us to disconnect it for you. We then delete our copy of the access token and stop publishing to the account. Instagram offers no way for us to revoke the permission ourselves, so to remove Supermix’s access completely, also remove Supermix Publisher in Instagram:

  • In the Instagram app: tap your profile picture at the bottom right, then Menu (the three lines at the top right) to open Settings and activity. Under Your app and media, tap Website permissions, then Apps and websites, then Active, and tap Remove next to Supermix Publisher.
  • On instagram.com: click More at the bottom left, then Settings. Under Your app and media, click Website permissions, then Apps and websites, then Active, and click Remove next to Supermix Publisher.

When Meta notifies us that you removed Supermix Publisher in Instagram, we delete the access token straight away. When Meta sends us a data deletion request for your account, we also delete the account’s IDs, name, username, account type, profile picture link and permissions, and clear the Instagram IDs and links stored on the posts published to it, including in each post’s activity history in the Supermix Studio, which keeps who published the post and when. You get a confirmation code and a link to a page on studio.supermix.io that shows the status of your request. We keep a record of the request itself (its confirmation code, the ID Meta sent us, how many connections it affected and when it was completed) so that page keeps working.

Otherwise, after a disconnect we keep the account’s IDs, name, username, account type, profile picture link and who connected it, so posts published to it stay readable in your history; ask us and we will delete them. Content published to your account stays on Instagram under your control.

5. TikTok accounts

The Supermix Studio uses TikTok’s Login Kit and Content Posting API to publish videos to TikTok accounts our customers connect. Using TikTok is subject to the TikTok Terms of Service, and TikTok’s handling of your data is described in the TikTok Privacy Policy.

What we ask for

When you connect an account, we request two permissions from TikTok:

  • Your basic profile (user.info.basic). Lets us read the ID TikTok gives the account for the Supermix Studio (its open ID), its display name and avatar, so the Supermix Studio can show which account is connected. TikTok also returns a union ID, which we do not store.
  • Publish videos (video.publish). Lets us post a video directly to the account when you press Publish, and check its progress until it is live. With this permission we also read the account’s creator settings each time you open the TikTok post form and again just before publishing: its username and nickname, the privacy options it offers, whether comments, Duets and Stitches are turned off, and the longest video it can post. These settings decide what the form lets you choose. We keep only the username, nickname and avatar.

We do not read your other videos, followers, likes, comments, messages or statistics, and we never edit or delete posts. TikTok offers no way to schedule a post through its API, so a video goes out when Publish is pressed.

What we store

We store the account’s open ID, its nickname or display name, its username, a link to its avatar (not the image itself), the permissions TikTok granted, an access token and a refresh token with their expiry times, who connected the account and when, and the connection’s health. For each video published through the Supermix Studio we keep TikTok’s publish ID, the video’s link (which includes the account’s username), the caption and post settings it was published with, and who pressed Publish.

Both tokens are encrypted at rest, are never sent to a browser and are never shown to Supermix team members. TikTok access tokens last 24 hours and refresh tokens up to a year. While the account stays connected we renew the access token automatically about once a day, so the connection keeps working even when nothing is being published.

How we use it

We use this access only to publish the videos you choose, or that Supermix team members publish for you with your authorisation, with the caption you write and the settings you pick in the post form: who can view the video, whether others can comment on it, Duet it or Stitch it, whether it promotes your own brand or is branded content, and whether it is labelled as AI-generated. We also check each post’s status until TikTok finishes processing it and, if TikTok has not yet returned the video’s public link, look for it once a day for up to seven days.

We do not use TikTok data for advertising, we do not sell it, we do not use it to build profiles of anyone, and we do not use it to train machine-learning or AI models.

Who we share it with

To publish a video we send TikTok the caption, the settings above and a public link to the video file in our storage; TikTok downloads the video from that link itself. TikTok data is stored with the infrastructure providers that host our systems. Members of your workspace in the Supermix Studio, and Supermix team members, can see which account is connected and what has been published to it. We do not otherwise share TikTok data with anyone.

Revoking access and deleting data

You can disconnect the account at any time from Settings → Connections in the Supermix Studio, or ask us to disconnect it for you. We then ask TikTok to revoke our access, delete our copy of both tokens and stop publishing to the account. If TikTok cannot be reached, we still delete the tokens, and you can remove Supermix Publisher in TikTok yourself:

  • In the TikTok app: tap Profile, then Menu (the three lines at the top), then Settings and privacy. Tap Security & permissions, then Apps and services permissions, choose Supermix Publisher and tap Remove access.

When TikTok notifies us that access was removed in TikTok, or that the TikTok account was deleted, we delete the tokens and the account’s open ID, name, username, avatar link and permissions, and clear the TikTok links and IDs stored on the posts published to it, including in each post’s activity history in the Supermix Studio, which keeps who published the post and when.

Otherwise, after a disconnect we keep the account’s open ID, name, username, avatar link and who connected it, so posts published to it stay readable in your history; ask us and we will delete them. Content published to your account stays on TikTok under your control.

6. How we share information

We share personal information only as needed to run Supermix: with service providers that host and run our systems on our behalf and under our instructions, such as our hosting, database, file storage and error-monitoring providers; with the platforms you publish to, such as Google (YouTube), Meta (Instagram) and TikTok, which receive the content and settings of each post; with other members of your workspace in the Supermix Studio; and where the law requires it.

7. Retention and security

We keep personal information for as long as we are working with you and as long as tax and accounting law requires afterwards. We return or delete your content on request. For connected accounts:

  • Tokens are kept, encrypted, while an account is connected, and renewed automatically so the connection keeps working. We delete them when you disconnect the account in the Supermix Studio, and when Instagram or TikTok notifies us that access was removed. A connection that stops working, for example because access was removed in a Google Account, keeps its tokens stored, encrypted, until the account is reconnected or disconnected, or until you ask us to delete them.
  • Account details (the account’s IDs, name, handle, profile picture link, an Instagram account’s type, the permissions granted and who connected it) are kept after a disconnect so posts published to the account stay readable in your history. We delete them when you ask us to. When Meta sends us a data deletion request for an Instagram account, or TikTok notifies us that access to a TikTok account was removed, we delete all of them except who connected the account, which stays with your workspace’s records.
  • Post history (the platform IDs and links of posts published through the Supermix Studio, and who published them) is kept with your workspace’s records. When Meta sends us a data deletion request for an Instagram account, or TikTok notifies us that access to a TikTok account was removed, we clear the IDs and links of the posts published to it and keep only who published them and when.
  • Data deletion requests from Meta are kept as a record, as described in section 4.

We do not delete account details or post history automatically after a set period; ask us and we will delete them.

We protect personal information with encryption in transit, encryption at rest for credentials such as access and refresh tokens, and access controls that limit each customer’s workspace in the Supermix Studio to that customer’s members and Supermix team members. Tokens reach our servers over an encrypted connection when an account is connected and are encrypted before they are stored. They are decrypted only inside our backend, when we use the connection.

8. Your rights

You can ask us for a copy of the personal information we hold about you, ask us to correct or delete it, or disconnect a connected account at any time. This includes the details we keep about a YouTube, Instagram or TikTok account after it is disconnected: email us the account’s handle and we will delete them. To remove Supermix’s access to an Instagram or TikTok account yourself, follow the steps in section 4 or section 5. These rights are open to everyone, wherever you live. Email ops@supermix.io and we will respond within the timeframes required by applicable law.

9. Changes to this policy

We may update this policy from time to time. We will post the new version on this page and update the effective date at the top.

10. Contact

Something Good Inc, which trades as Supermix. You can reach us at ops@supermix.io.