Skip to content
rakaman

Privacy policy

Rakaman holds your footage, your drafts, and the keys to the social accounts you connect. This explains what we collect, where it goes, who else can see it, and what you can ask us to do about it.

Last updated

1. Who we are

Rakaman is operated by [LEGAL ENTITY NAME] (company number [COMPANY REGISTRATION NUMBER]), registered at [REGISTERED ADDRESS]. Under the Personal Data Protection Act 2010 we are the data user for the personal data described in this policy.

For anything here, including a request to see or correct your data, write to [PRIVACY CONTACT EMAIL]. We answer in English or Bahasa Malaysia.

2. What this covers

This policy covers the Rakaman application, this website, and the accounts we create for customers. It applies to you whether you are the person who signed up, a colleague added to a workspace, or someone whose email address was entered to invite them.

It does not cover the social platforms you publish to. Once a post reaches YouTube, Facebook, Instagram or Threads, that platform holds it under its own terms and its own privacy policy, and we have no control over what it does with it. The same will be true of TikTok and X when publishing to them is switched on.

3. What we collect

What you give us

  • Your email address, and a password if you choose to set one. Passwords are stored only as a hash — we cannot read yours, and nobody here can tell you what it is. If you sign in with a one-time code instead, we email you a six-digit code and keep only what is needed to check it.
  • If you sign in with Google, Google tells us your name, your email address and your profile picture, and nothing else. That sign-in asks only for the openid, email and profile permissions, never for your YouTube channel or any other Google data, and we use what it returns only to create your account and show your name and picture in it.
  • If you sign in with Apple, Apple tells us your email address — or a private relay address, if you chose to hide yours — and, on your first sign-in only, your name.
  • A display name, a profile picture and a time zone, if you set them.
  • The media you upload — video, images, audio — with its original filename, size, format, duration and dimensions.
  • What you write in Rakaman: ideas, research notes, saved reference links and excerpts, drafts and every earlier version of them, comments, captions, and the platform-specific settings attached to a post.
  • The email address of anyone you invite into a workspace.

What the platforms you connect give us

When a workspace owner connects a social account, the platform gives us an access token, the account's identifier, name, handle and profile picture, and later the link to each post we publish and its view, like and comment counts. Exactly what each platform shares, and what we do with it, is set out under Social accounts you connect.

One consequence worth stating plainly: if you never set a display name, we derive one from the part of your email address before the @ sign, and that derived name is shown to everyone else in your workspace. If your email address is your full name, they will see your full name. Setting a display name replaces it everywhere.

What we collect automatically

Our servers write a log line for every request they handle. It records the IP address the request came from, the browser's user-agent string, which endpoint was called, the response status and how long it took. We use these to keep the service running and to investigate faults and abuse.

That is the whole of it. Rakaman runs no analytics, no advertising or tracking scripts, no session recording, no profiling, and no third-party error-reporting service. We do not buy personal data, and we do not combine what you give us with data from anywhere else.

4. Why we use it

Under the PDPA we process your personal data for these purposes and no others:

  1. To provide the service you asked for — storing your media, saving your drafts, showing your calendar, publishing posts when you tell us to, and showing you how those posts are doing.
  2. To let the people in your workspace work together, which necessarily means showing them your name and what you have contributed.
  3. To keep accounts secure and investigate misuse, which is what the server logs are for.
  4. To contact you about the service: account matters, security notices, billing, and material changes to this policy.
  5. To meet legal obligations where they apply to us.

Providing this data is voluntary, but most of it is necessary — without an email address and a password we cannot give you an account, and without your uploads there is nothing for the product to do.

We do not use your media, your drafts or your captions to train machine-learning models, and we do not send them to any third-party AI service. Rakaman contains no such integration.

5. Your media

Uploads do not pass through our servers. When you add a file, our API issues a short-lived signed URL — valid for about fifteen minutes — and your browser sends the file straight to our storage provider, Backblaze B2. The bucket is private: there is no public URL for your media, and every read is a fresh signed link issued to someone we have already checked has access.

Your original filename is kept, both as a field we display and as part of the storage path for the file. If a filename itself contains something sensitive — a client's name, an unreleased title — bear in mind it is stored, not just shown.

Single uploads are capped at 5 GB.

6. Cookies

Rakaman sets one kind of cookie: the session cookie that keeps you signed in. It holds your authentication tokens, it is marked httpOnly so that no script running on the page can read it, and it is refreshed quietly as you browse.

We set no analytics, advertising or tracking cookies at all. Because the only cookie we use is strictly necessary to sign you in, there is no consent banner on this site — there is nothing to consent to. If that ever changes, this clause changes with it and we will tell you before it does.

7. Who we share it with

We do not sell your personal data, and we do not share it for anyone else's marketing. We disclose it only to the following, and only so far as each needs it to do its job:

Supabase
Hosts our database and handles sign-in. It holds your account record, your profile, and everything you write in Rakaman.
Backblaze B2
Stores the media you upload, in a private bucket, as described above.
Our hosting providers
Serve the website and run the API and the background worker. Their systems process requests, which is where the server logs described in clause 3 are written.
Google and Apple
Only if you choose to sign in with them. They confirm who you are; we send them nothing about what you do in Rakaman.
The social platforms you publish to
Only what you choose to publish, sent to the accounts you choose, as described in the next clause.
Professional advisers and authorities
Where we are required by Malaysian law to disclose something, or need advice on a dispute.

8. Social accounts you connect

Only a workspace's owner can connect a social account to it. Connecting sends you to the platform, which shows you what Rakaman is asking for and lets you approve or refuse it. If you approve, the platform gives us an access token, which we encrypt before storing and which nobody — including the people in your workspace — can see.

What each platform shares with us

YouTube
Rakaman uses the YouTube API Services. We ask Google for two permissions: to upload videos to your channel (youtube.upload), and to read your channel (youtube.readonly) so we can show its name and picture, confirm an upload finished, and read each published video's view, like and comment counts.
Facebook
Through Facebook Login we ask to list the Pages you manage (pages_show_list), to post to the ones you pick (pages_manage_posts), and to read those posts' engagement (pages_read_engagement). We receive each Page's identifier, name and picture, and a Page token we use only for that Page.
Instagram
Through the same Facebook Login, for a professional Instagram account linked to one of your Pages, we ask to read the account's username and picture (instagram_basic), publish to it (instagram_content_publish), and read each post's views (instagram_manage_insights).
Threads
Through Threads' own login we ask to read your profile (threads_basic), publish to it (threads_content_publish), and read each post's views, likes and replies (threads_manage_insights). We receive your Threads identifier, username, name and picture.
TikTok and X
Not available yet; Rakaman cannot connect to either today. When it can, connecting will ask TikTok to read your basic profile and to upload and publish videos and read their counts, and X to read your profile and to post on your behalf. This clause will be updated, with the exact permissions, before either is switched on.

What we do with it

  • We use an account's access only to do what you ask in Rakaman: publish the posts you schedule to it, at the time you choose, and show you how they are doing. We do not post anything you did not schedule, and we do not read your messages, followers or anything else on the account.
  • Publishing sends the platform your caption, your settings for that post, and a signed link the platform uses to fetch the media file directly from our storage. The link stops working within a few hours.
  • The account's name and picture, the link to each published post and its counts are shown to the members of the workspace it is connected to, and to no one else.
  • We do not sell data we receive from a platform, use it for advertising, share it with anyone except as this policy describes, combine it with data from other sources, or use it to train machine-learning models.
  • No third party serves content or advertising through Rakaman, and we place no cookies on your device beyond the one described under Cookies.

Google and YouTube

Rakaman's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

By connecting a YouTube channel you are also agreeing to the YouTube Terms of Service, and Google's handling of your data is governed by the Google Privacy Policy.

Meta and TikTok

Facebook, Instagram and Threads handle your data under the Meta Privacy Policy. When TikTok is available, TikTok will handle it under the TikTok Privacy Policy.

Disconnecting, and what is deleted

The workspace owner can remove an account at any time under Settings → Channels, from the account's menu. Removing it immediately:

  • Deletes its access tokens.
  • Deletes every view, like and comment count we read through it, and its profile picture.
  • Stops every post still waiting to go out to it.
  • For YouTube, also withdraws Rakaman's access at Google, so the grant disappears from your Google account too.

The account's name and the links to posts already published stay in the workspace's post history, so it still shows where each post went, until the workspace is deleted or you ask us to remove them.

You can also withdraw our access from the platform's side, which stops Rakaman reaching the account at once: for Google, on the Google security settings page; for Facebook and Instagram, under Business integrations in your Facebook settings; and for Threads, under Settings → Account → Website permissions in the Threads app. When you do it that way, Rakaman marks the account as needing to be reconnected the next time it tries to use it, and you can then remove it as above. To have everything deleted without signing in to Rakaman, follow our data deletion instructions.

9. How we protect it

  • Every table in our database enforces access at the row level, so a query can only ever return rows belonging to a workspace you are a member of. This is applied by the database itself rather than by application code remembering to filter.
  • Social account tokens are encrypted before they are stored, using AES-256-GCM, and are held in a schema that is unreachable from the browser under any circumstances.
  • Session cookies are httpOnly, so no script on the page can read your tokens, and refresh tokens rotate.
  • Media sits in a private bucket reachable only through short-lived signed links.
  • Traffic is encrypted in transit.

No system is perfectly secure, and we will not pretend otherwise. If a breach affects your personal data we will tell you and the relevant authorities without undue delay.

10. Where your data is held

Your database records and your uploaded media are held in [DATA CENTRE REGION]. Our hosting providers may process requests, and hold short-lived server logs, in other countries.

Where personal data is transferred outside Malaysia, section 129 of the PDPA applies. We transfer it only where it is necessary to perform our contract with you, and we require each provider to protect it to a standard comparable to this policy.

When you publish to a connected account, the content you chose to publish is sent to that platform's own infrastructure, wherever in the world that is. That is the point of publishing it, but it is a transfer, and it is worth being explicit that it is one.

11. How long we keep it

We keep your account and its contents for as long as the account is open. We do not currently run any automatic expiry or purge — nothing is deleted on a schedule, so assume that what you upload stays until you or we remove it.

Two consequences you should know about before you rely on deletion:

  • Draft version history is append-only. Earlier versions of a draft cannot be edited or removed from within Rakaman; they go when the draft's workspace goes.
  • A file you have uploaded cannot yet be deleted on its own from within Rakaman. Ask us and we will remove it — see the next clause.

If your workspace is deleted, its content is deleted with it, and its files are erased from storage shortly afterwards. If your user account is deleted but the workspace continues, the things you wrote stay so your colleagues' work is not torn up, but they stop being attributed to you.

We read a published post's counts again hourly for its first two days, daily until it is thirty days old, and not after that. What we keep from a connected account, and what removing one deletes, is set out under Social accounts you connect.

We keep server logs only as long as they are useful for security and fault-finding, and we keep whatever records we are legally required to keep for as long as the law requires.

12. Your rights

Under the PDPA you may ask us to:

  • Give you a copy of the personal data we hold about you.
  • Correct it, if it is wrong or out of date.
  • Limit how we process it, or withdraw a consent you gave us.
  • Delete your account and the data attached to it.

Write to [PRIVACY CONTACT EMAIL] and we will respond within 21 days, which is the period the PDPA allows. We may ask you to confirm who you are first. The PDPA permits a prescribed fee for a data access request; we do not currently charge one.

Some of your own data lives in a workspace you share. Where deleting it would destroy someone else's work — a comment thread they are part of, a draft they co-wrote — we will tell you what we can remove and what we can only de-attribute.

Two honest limitations

Two things you can do yourself: a workspace owner can remove a connected account under Settings → Channels, and can delete the whole workspace, with everything in it, at the bottom of Settings. Everything else — an export, deleting your own account, removing a single file — is handled by a person, not by a button in the product. We would rather say so than imply an automation that does not exist. Our data deletion instructions explain how to ask.

If you are the owner of a workspace, your account cannot be deleted until ownership of that workspace has been transferred to someone else or the workspace itself is deleted. This is a deliberate safeguard against a workspace being orphaned along with everyone else's work in it, but it does mean a deletion request from an owner takes an extra step, and we will walk you through it.

13. What other people in your workspace can see

Rakaman is a shared workspace, and it is worth being clear that shared means shared. Anyone who is a member of a workspace you are in can see:

  • Your display name, your profile picture and your time zone.
  • That you are a member, and what role you hold.
  • Every file, folder, idea, research note, draft, draft version, comment, campaign and scheduled post in that workspace — including ones you created — regardless of whether their role is viewer, editor or admin.
  • The handle and profile picture of any social account connected to the workspace, and the views, likes and comments of what it has published. They cannot see its tokens; nobody can.

Administrators can additionally see the email addresses of people invited to the workspace, and can remove content and change roles. There is no private space inside a workspace: if you want something kept to yourself, it does not belong in a shared one.

14. Age

Rakaman is for people aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, write to [PRIVACY CONTACT EMAIL] and we will delete it.

15. Changes to this policy

We update this policy when what we do changes — in particular, the clause about social accounts will be revisited before TikTok and X are switched on, and the clause about where data is held as that is settled. The date at the top always reflects the current version, and material changes are listed at the end and emailed to account holders before they take effect.

16. Contact us

Questions, requests and complaints about your personal data go to [PRIVACY CONTACT EMAIL], or by post to [LEGAL ENTITY NAME], [REGISTERED ADDRESS].

If you are not satisfied with how we have handled a request, you may complain to the Personal Data Protection Commissioner of Malaysia.

17. Change history

Publishing is now live for YouTube, Facebook, Instagram and Threads: added what each platform shares with us and what we do with it, the Google and YouTube disclosures, and what removing an account deletes. Added sign-in with Google, Apple and a one-time code, and the data deletion instructions.