Privacy Policy
INNERA LABS LLC · Effective August 12, 2026
This policy explains what data Worth It AI — Slideshow Factory collects, why it collects it, and what it does with it. The service is operated by INNERA LABS LLC ("we", "us"). For any privacy question, write to support@inneracorp.com.
1. What this service is
Worth It AI — Slideshow Factory is an internal content-production tool operated by INNERA LABS LLC. It assembles social media posts for our own brand and sends them to our own accounts on Instagram, our own Facebook Page, and our own TikTok account.
It is not a public service. Access is restricted to people authorized by the company and protected by a password login. There is no public sign-up, no subscription, and we do not host third-party content.
2. Data we collect
We collect only what the system needs to work:
- Account data for authorized operators: name, email address, and role (administrator or editor). Passwords are never stored — we keep only the output of a key derivation function (scrypt) with a per-account salt.
- A signed session cookie, strictly necessary to keep the user logged in. We use no advertising, analytics, or tracking cookies.
- Content created by the team: uploaded images, generated text, captions, and the publishing history.
- Credentials for connected social accounts (Instagram, Facebook Page, and TikTok access tokens), stored server-side only.
- Basic information about connected accounts as returned by the platforms themselves: account or Page name, username, and platform identifier.
3. What we do NOT collect
We do not collect data about people who view the posts. We have no access to followers, direct messages, comments, contacts, or friend lists. We use no third-party trackers, advertising pixels, or behavioral analytics tools.
We do not collect data from minors, and the service is not directed to anyone under 18.
4. How we use the data
Account data is used to authenticate operators and to record who scheduled each post. Content is used to build and publish the posts. Tokens are used solely to publish to the brand's own accounts, at the operator's request.
We do not use any of this data for advertising, profiling, training our own models, or any purpose beyond what is described here.
5. Data obtained from the platforms (Meta and TikTok)
When an operator connects an account, the platform gives us an access token and basic account information. This data is used only to publish to the account holder's own accounts. It is never sold, rented, shared with third parties, or used for any other purpose.
Tokens stay on the server and are never sent to the browser. The account holder can disconnect the account at any time from the system's Accounts screen, or revoke access directly in their Facebook, Instagram, or TikTok settings. On disconnection, we delete the token.
6. Who we share data with
We do not sell personal data and we do not share it for behavioral advertising. We share with the following providers, only as needed for the service to operate:
- Railway — hosting for the server and the disk where data is stored (United States).
- Meta Platforms, Inc. — receives the content to be published to Instagram and the Facebook Page.
- TikTok Pte. Ltd. — receives the content to be sent to TikTok.
- The AI provider selected by the administrator (Anthropic, Google, or OpenAI) — receives only the text prompts used to write captions. No personal data or credentials are sent in those requests.
7. How long we keep it
Content is kept while it is useful to the operation and may be deleted by the team at any time. Video files are deleted automatically after publishing. Tokens are deleted as soon as the account is disconnected. Operator account data is deleted when the account is removed.
8. Security
All traffic is encrypted with HTTPS. Passwords are protected with a per-account salted key derivation function. Files that the platforms need to download are served through signed, short-lived links valid for a few hours and for a single file. No social media token is ever exposed to the browser.
No system is perfectly secure, but we keep the surface deliberately small: the service has no public sign-up and no open area.
9. International transfers
Data is processed and stored on servers in the United States. If you are in Brazil or the European Economic Area, your data may be transferred outside your country. We rely on the performance of our agreement with you and on the rights described below.
10. Your rights
Wherever you are, you may request access to your data, correction, deletion, portability, restriction of processing, or object to processing. Write to support@inneracorp.com; we respond within the applicable legal deadlines.
If Brazil’s LGPD applies to you, these rights are set out in Article 18 and you may complain to the ANPD. If the GDPR applies, you may also complain to your national data protection authority. If the CCPA/CPRA (California) applies, we confirm that we do not sell or share personal information as those laws define it, and that you will not be discriminated against for exercising your rights.
11. Changes to this policy
If we change this policy, the new version takes effect on the date shown at the top of the page. Material changes are communicated to the system operators.
12. Contact
INNERA LABS LLC — support@inneracorp.com. Write in English or Portuguese; we answer in both.