1. Who We Are
CNG Studios LLC ("CNG Studios," "we," "us," or "our") is an independent entertainment and technology studio based in Miami, Florida, United States. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you interact with our websites, applications, and services — including cngstudios.com, mypixiesuite.com, our entertainment brand websites, our SaaS applications (collectively, My Pixie Suite), and any subdomains or affiliated properties we operate from time to time (collectively, the "Services").
For questions about this Policy, contact us at [email protected].
2. Information We Collect
Information You Provide Directly
- Newsletter subscriptions: Email address and, optionally, a display name.
- Contact form / inquiries: Name, email address, and message content you voluntarily submit.
- SaaS account registration: Name, email address, hashed password, organization name, and billing information processed by our payment processor.
- Connected platform credentials: OAuth access tokens from platforms you authorize (TikTok, Instagram, Facebook, YouTube, LinkedIn, Pinterest, Bluesky, Threads, and others). We never receive or store your social media passwords.
- Content you create: Posts, captions, images, videos, scheduling data, and business records you enter into our SaaS applications.
Information Collected Automatically
- Essential cookies: A minimal set of first-party cookies necessary for the Services to function (session management, security, consent preference storage). See our Cookie Policy.
- Server logs: IP address, browser type and version, operating system, pages visited, timestamps, and referrer URLs — used for security, fraud prevention, and infrastructure operations.
- Analytics (if enabled): As of the last-updated date above, we do not use third-party analytics or advertising trackers on our marketing websites. If and when we add analytics, this Policy will be updated and — where required — consent will be requested before any non-essential cookies or trackers are placed.
3. How We Use Your Information
- Provide, maintain, and improve the Services;
- Publish content to your connected platforms on your behalf at your instruction;
- Generate AI-powered content suggestions using your own brand settings and instructions (see Section 5);
- Process payments and manage subscriptions;
- Send service-related notifications, account communications, and security alerts;
- Respond to inquiries, support requests, and legal notices;
- Monitor and analyze aggregate usage patterns to improve reliability and performance;
- Detect, prevent, and respond to security incidents, fraud, and violations of our Terms.
4. Legal Bases for Processing (EU/UK/EEA)
If you are in the European Union, United Kingdom, European Economic Area, or Switzerland, we rely on the following legal bases under the General Data Protection Regulation (GDPR):
- Performance of a contract — to provide the Services you request (account data, connected platform operations, content publishing).
- Consent — newsletter subscriptions, any future use of non-essential cookies or trackers. You may withdraw consent at any time.
- Legitimate interests — security, fraud prevention, service improvement, and aggregate analytics that do not override your rights.
- Legal obligation — tax, accounting, and compliance with lawful requests from public authorities.
5. AI Features and Data Isolation
Self-Hosted AI Infrastructure
CNG Studios uses self-hosted open-source AI models to power content suggestions, analytics, automation, and strategic features across our SaaS applications. These models are hosted on CNG Studios' own private infrastructure — dedicated physical servers on our private network. The AI models are not hosted by any cloud provider or third-party AI service.
Connected Platform Data
Data obtained from connected platform APIs — including but not limited to YouTube, TikTok, Instagram, Facebook, LinkedIn, Pinterest, Bluesky, and Threads — is stored exclusively in our own databases on our own servers. This platform data is never transmitted to, processed by, or shared with any third-party AI service. AI content suggestions are generated using only user-provided brand settings and user-composed instructions.
Google API Services User Data Policy
Our use of information received from Google APIs (including the YouTube Data API) adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used exclusively to provide the Services (for example, publishing content to YouTube on your behalf at your instruction). It is never used for AI model training, advertising personalization, or any purpose other than operating the Services as described in this Policy.
6. How We Share Your Information
We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising. We do not rent or trade your information to third parties for their own marketing purposes.
We share information only in these limited circumstances:
- Connected platforms: We transmit your content to the platforms you have connected, using their official APIs, for the sole purpose of publishing on your behalf.
- Service providers: Limited infrastructure providers who act as our processors under contract — for example, Stripe for payment processing, Brevo for transactional email delivery, and Cloudflare for DNS/security. These providers are contractually bound to use data only to provide services to us.
- Legal requirements: Where required by law, court order, subpoena, or other valid legal process, or to protect the rights, property, or safety of CNG Studios, our users, or the public.
- Business transfer: If CNG Studios is involved in a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction; we will notify you of any such change.
- With your consent: For any disclosure outside the above categories, we will ask for your explicit consent.
6.1 Meta Platform Data Deletion Callback
In accordance with the Meta Platform Terms, EchoPixie implements a Data Deletion Callback endpoint at https://api.echopixie.com/api/oauth/deauthorize. When a user removes the EchoPixie application from their Facebook, Instagram, or Threads account — or when Meta otherwise initiates a deauthorization — Meta sends a signed request to this endpoint. Upon receiving a validly signed request (verified via HMAC-SHA256 using our Meta app secret), we:
- Immediately revoke and wipe the associated OAuth access tokens and refresh tokens for the affected Facebook, Instagram, and Threads connections;
- Mark the affected connections as deauthorized in our database and halt all further API calls on the user's behalf;
- Queue any remaining associated user data for permanent deletion, which completes within 30 days of the request date (backup copies are purged within an additional 30 days);
- Return a confirmation code and a publicly accessible status URL so that the user and Meta may verify deletion progress, per Meta's required response format.
Users may also trigger this deletion at any time by disconnecting their Meta-family accounts from EchoPixie via app.echopixie.com account settings, or by emailing [email protected].
7. Your Rights and Choices
All Users
Regardless of jurisdiction, you may:
- Unsubscribe from our newsletter using the link in every email or by emailing [email protected];
- Request access to, correction of, or deletion of your personal information;
- Disconnect any connected platform from your SaaS account at any time via your account settings;
- Close your SaaS account, which triggers deletion of associated account data within 30 days except where retention is required by law.
United States — CCPA / CPRA (California) and Similar State Laws
If you are a resident of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware, Iowa, Tennessee, Indiana, New Hampshire, New Jersey, Kentucky, Maryland, Minnesota, Rhode Island, or any state with a comprehensive privacy law, you have rights that may include:
- Right to know what personal information we collect, use, disclose, and retain about you;
- Right to access a portable copy of your personal information;
- Right to delete your personal information, subject to lawful exceptions;
- Right to correct inaccurate personal information;
- Right to opt out of "sale" or "sharing" — as defined by these laws. CNG Studios does not sell or share your personal information for cross-context behavioral advertising. See our Your Privacy Rights page for details.
- Right to limit the use of sensitive personal information — we do not use sensitive personal information for purposes beyond providing the Services;
- Right to non-discrimination for exercising any of these rights.
We honor the Global Privacy Control (GPC) browser signal. If your browser or extension transmits a GPC signal, we will treat it as an opt-out request from "sale" and "sharing" for your browser/device as required by applicable law.
To exercise these rights, see our Your Privacy Rights page or email [email protected]. You may designate an authorized agent to submit requests on your behalf.
European Union / United Kingdom / EEA — GDPR / UK-GDPR
If you are in the EU, UK, or EEA, under the GDPR / UK-GDPR you have the rights to: access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, objection to processing, and withdrawal of consent, as well as the right to lodge a complaint with your local supervisory authority.
To exercise these rights, email [email protected]. We will respond within 30 days.
Brazil — LGPD
If you are in Brazil, under the Lei Geral de Proteção de Dados (LGPD) you have the rights to: confirmation of processing, access, correction of incomplete or outdated data, anonymization/blocking/deletion of unnecessary or excessive data, portability, information about sharing, revocation of consent, and review of automated decisions.
To exercise these rights, email [email protected].
8. Data Storage and Security
Your data is stored on secure servers managed by CNG Studios on our self-hosted infrastructure in the United States. We use industry-standard security measures including encrypted connections (HTTPS/TLS), hashed passwords (bcrypt or equivalent), encrypted OAuth tokens at rest (AES-256-GCM), and role-based access controls.
While we take reasonable measures to protect your information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
9. Data Retention
We retain personal data for as long as necessary to provide the Services and fulfill the purposes described in this Policy, unless a longer retention period is required or permitted by law. Specific retention windows:
- SaaS account data: retained while your account is active; deleted within 30 days after account closure, except where retention is required by law (for example, tax records).
- Newsletter subscriptions: retained until you unsubscribe or request deletion.
- Contact form submissions: retained up to 24 months for reference and audit.
- Server logs: retained up to 90 days for security and troubleshooting.
- Consent records: retained for the duration of the consent plus the applicable statute of limitations.
10. Children's Privacy
The Services are not directed to individuals under 16 years of age. We do not knowingly collect personal information from children under 16. Account creation is not offered to the public on our marketing and brand websites; our SaaS applications require users to be at least 16 to register. Newsletter subscription requires an affirmation that the subscriber is 16 or older.
If you believe a child under 16 has provided us with personal data, please contact us at [email protected] and we will delete it promptly.
Some CNG Studios brands (specifically Alix Alora) contain adult content and are strictly for audiences 18 and older.
11. Third-Party Services and Embedded Content
The Services integrate with, link to, or embed content from third-party platforms. Your use of those platforms is governed by their respective privacy policies, which we do not control. We encourage you to review those policies. Third-party services we commonly interact with include: TikTok, Instagram, Facebook, YouTube, LinkedIn, Pinterest, Bluesky, Threads, Spotify, Apple Music, Amazon, Stripe, Brevo, and Cloudflare.
12. International Data Transfers
The Services are operated from the United States. If you access the Services from outside the United States, your information will be transferred to and processed in the United States. By using the Services, you acknowledge and consent to this transfer.
For transfers from the EU/UK/EEA, we rely on applicable safeguards including, where necessary, Standard Contractual Clauses or equivalent mechanisms.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated Policy on this page and updating the "Last updated" date. For significant changes affecting registered SaaS users, we will provide email notice where reasonable. Your continued use of the Services after changes take effect constitutes acceptance of the updated Policy.
14. Contact Us
For questions, requests, or complaints about this Privacy Policy or our data practices:
- Privacy inquiries & data-subject requests: [email protected]
- General legal: [email protected]
- Copyright / DMCA: [email protected]
- Postal: CNG Studios LLC, Miami, FL, USA