Privacy Policy
Last updated: September 18, 2026
This Privacy Policy explains how Smaipa (“we,” “us,” or “the App”) collects, uses, stores, and shares information when you use our application, including when you connect an Instagram Business (or Facebook Page) account, or a calendar, to the App.
By connecting your Instagram Business account or a calendar, or otherwise using the App, you agree to the practices described in this policy.
1. Who we are
Smaipa is a content and client-management tool for independent beauty and tattoo professionals. It helps artists turn before/after photos into ready-to-publish social media content and manage client conversations and records.
2. Information we collect
2.1 Information you provide directly
- Account details — name, email address, and password or sign-in credentials.
- Profile and business information — studio name, service categories, and branding preferences (fonts, colors, logo).
- Content you upload — before/after photos, videos, captions, and other media you create or import into the App.
- Client records you enter or import — client names, contact details, treatment history, and consent forms you choose to store in the App.
- Waitlist sign-ups — if you join the beta waitlist on our website, the email address you enter and the date you signed up, used only to tell you when a place opens. You can ask us to remove it at any time (see Contact us).
2.2 Information from Meta / Instagram, when you connect your account
If you choose to connect an Instagram Business account (via Facebook Login), we request access to a limited set of Meta Graph API permissions, and we access only the data those permissions provide:
- instagram_basic — your Instagram Business account ID, username, and basic profile information, so we can identify which account is connected.
- pages_show_list and business_management — the list of Facebook Pages and Instagram Business accounts you manage, so you can select which one to connect.
- instagram_content_publish — permission to publish content (for example, image carousels and captions) directly to your connected Instagram Business account, at your explicit request.
We access Instagram direct messages only for the client inbox described in Section 3. We do not access personal (non-Business) accounts, followers’ personal data, or any account you have not explicitly connected and authorized.
2.3 Information from your calendar, when you connect one
Connecting a calendar is optional. Its purpose is to let the App work out when you are free, so that a reply you are drafting can offer appointment times you can actually keep. What we take from a calendar is deliberately narrow.
We store only busy periods — a start time, an end time, and whether the entry lasts all day. We do not store, and in most cases are not permitted to read, the title of an event, its notes, its location, or who else is attending. This applies to every calendar you connect, whoever provides it.
- Apple Calendar is read on your device by the App itself, using the calendar permission you grant in iOS. Apple provides no way for our servers to reach it, so it is read only while the App is open, and only the busy periods described above are sent to us.
- Google Calendar is read by our servers, using three narrowly-scoped permissions you grant through Google: calendar.freebusy, which returns only the periods you are busy and no event details at all; calendar.calendarlist.readonly, which returns the names of your calendars so you can choose which ones to read; and calendar.app.created, which allows the App to write only to a calendar it created itself and gives it no access to your other calendars. To keep this working we store a Google authorization token on our servers; it is never sent to your device.
Appointments you confirm are stored by us — the date and time, the service where you have recorded one, and a link to the client record or conversation it came from. Where an appointment was agreed in a client conversation, we also store the client’s own message asking for it, so the appointment says what was actually requested. That message is your client’s personal data, and it is kept and deleted on the same terms as the rest of your client records (Sections 5 and 8).
You choose which calendars are read. The App creates a separate calendar of its own for appointments you confirm, so that it never alters entries you did not create through it.
3. How we use your information
We use Instagram/Meta data solely to operate the features you request, specifically:
- Publishing content on your behalf. When you create a carousel, image, or caption in the App and choose to publish or schedule it, we use the Instagram Content Publishing API to post that content to your connected Instagram Business account. We never publish anything without an explicit action from you (a “Publish” or “Schedule” action, or an automation you have configured and approved in advance).
- Displaying account status. We show your connected account name and connection status inside the App so you know which account content will be published to.
- Unified inbox (where enabled). If you enable the client inbox feature, we retrieve Instagram messages associated with your Business account so you can view and reply to client conversations from within the App.
We also use information you provide directly to:
- Operate core features — content creation, client records, reminders, and automations.
- Maintain and secure your account and prevent abuse.
- Provide customer support and respond to your requests.
- Improve the App’s reliability and features.
We do not sell your data, and we do not use Instagram/Meta data for advertising or for any purpose unrelated to the features described above.
We use calendar information solely to work out your availability and to record appointments you confirm. Specifically, we compare your busy periods against the working hours you set in order to suggest appointment times, and we add appointments you confirm to a calendar the App creates. Suggested times are shown to you and are only ever sent to a client when you send them. We do not use calendar information for advertising, profiling, or any purpose unrelated to the features you are using.
AI features
Three optional features are written by Claude, an AI model provided by Anthropic, PBC: suggested replies in the client inbox, the scan of past conversations that proposes saved answers, and caption suggestions. None of them sends anything until you allow AI features in the App, which asks you the first time you use one. You can withdraw that permission at any time in Settings → AI & your data; from then on nothing further is sent.
When you use them, each feature sends Anthropic only what it needs:
- Suggested replies — the most recent messages of the conversation you are answering, which contain your client’s own words, together with your knowledge base and the appointment times the App offers.
- The conversation scan — your past Instagram conversations with clients.
- Caption suggestions — the treatment type, your studio name, and any note you add.
Photographs and client records are never sent to Anthropic. Anthropic processes this content as our service provider, to produce the reply, answers or captions you asked for.
4. How we share information
We share information only in the following circumstances:
- With Meta Platforms, Inc., as necessary to publish content to your connected Instagram Business account or retrieve messages you’ve asked us to display, via the official Meta Graph API.
- With Google LLC, if you connect a Google Calendar, as necessary to read your busy periods and to write appointments you confirm, via the official Google Calendar API. Connecting an Apple Calendar involves no such sharing: it is read on your device only.
- With Anthropic, PBC, only if you allow AI features, and only the content described under “AI features” in Section 3, so that it can write the suggestions you ask for.
- With service providers who host our infrastructure and process data on our behalf (for example, our database and file storage provider), under contractual confidentiality obligations, and only to the extent needed to operate the App.
- For legal reasons, if required to comply with applicable law, regulation, legal process, or a valid governmental request.
- With your consent, for any other purpose you explicitly approve.
We do not sell or rent your personal information to third parties.
5. Data retention
We retain account data, content, and client records for as long as your account is active, or as needed to provide the App’s features. Instagram access tokens are stored only while your account remains connected and are deleted immediately when you disconnect. You can request deletion of your data at any time (see Section 8).
Calendar busy periods are held only for a rolling window of the next several weeks, and each sync replaces the previous one rather than adding to it, so we do not accumulate a history of where you have been. Disconnecting a calendar deletes the busy periods read from it, and any Google authorization token, immediately and in full. Appointments you have already confirmed are kept as part of your client records until you delete them.
6. Data security
We use industry-standard safeguards — including encryption in transit, access-controlled databases, and restricted-scope API tokens — to protect your information. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
7. Disconnecting an account or calendar
You can disconnect your Instagram Business account from the App at any time, either from within the App’s settings or via your Facebook Business Integrations settings. Disconnecting immediately revokes our access token and stops any further publishing or message retrieval on your behalf. Content already published to Instagram is not affected.
A connected calendar can be disconnected in the App’s Calendar settings at any time, and a Google Calendar can also be disconnected from your Google account permissions. Disconnecting stops all further reading, deletes the busy periods we hold from that calendar, and deletes any stored authorization token. Entries already written to your own calendar are not removed by disconnecting; you can delete them, or the calendar the App created, from your calendar app.
8. Your rights
You can delete your account and all data associated with it yourself, at any time, in the App under Settings → Delete account. Deletion takes effect immediately and also removes any stored Meta and Google access tokens. See our data deletion page for exactly what is deleted.
Depending on where you live, you may also have the right to access, correct, export, or delete your personal data, or to object to or restrict certain processing. To exercise any of these rights, or if you can no longer sign in to delete your account, contact us at development@unicornfounder.ai. We will respond within a reasonable timeframe and in accordance with applicable law.
9. Children’s privacy
The App is intended for professional use by beauty and tattoo artists and is not directed to children. We do not knowingly collect information from anyone under 16.
10. International data transfers
Your information may be processed in countries other than your own. Where this occurs, we take reasonable steps to ensure appropriate safeguards are in place consistent with applicable data protection law.
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by an updated “Last updated” date above, and where required, we will provide additional notice.
12. Contact us
If you have questions about this Privacy Policy or how we handle your data, contact us at development@unicornfounder.ai.