Legal · Last updated 11 July 2026

Privacy policy

EditionOS (“we”, “us”) is workspace software for collectible design studios, based in London, United Kingdom. This policy explains what we collect, why, and your rights under UK GDPR and EU GDPR. Contact: privacy@edition-os.com.

What we collect

Account data — your name, email address and workspace membership, used to authenticate you and operate your workspace.

Workspace content — the business records you create: invoices, receipts, clients, contacts, products, stock, editions, production jobs, loan agreements, sign-offs, newsletter campaigns and planner media. This is your data; we store and process it solely to provide the service to you.

Newsletter recipient data — contact details your workspace holds for its own clients and subscribers. Your workspace is the controller of this data; we process it on your instructions. Unsubscribes and bounces are recorded on a suppression list and honoured on every send.

Technical data — server logs (IP address, user agent, timestamps) kept for security, rate limiting and abuse prevention.

Instagram connection

If a workspace owner connects an Instagram professional account, we receive — via Meta’s Instagram API, with your explicit consent on Instagram’s own consent screen — the account’s ID, username, account type, and an access token. We use these solely to show your connection status, load your recent feed into the planner, and publish the posts you schedule or send. Access tokens are encrypted (AES-256-GCM) at rest, scoped to your workspace, never shown to any user or browser, and never used for any purpose other than the actions you take in the planner. We do not read your messages, followers, or any data beyond the permissions listed on the consent screen. Disconnecting (one click in the planner) deletes the token immediately; you can also revoke access from Instagram’s own settings at any time.

Data deletion

Instagram data: click Disconnectabove the planner to delete your access token and connection record immediately, or revoke EditionOS from Instagram (Settings → Website permissions → Apps and websites) — tokens revoked on Instagram’s side stop working immediately and are purged by our expiry sweep. To have all Instagram-related data removed on request, email privacy@edition-os.com from your account email and we will confirm deletion within 30 days.

Workspace data: owners can export the full workspace as JSON from Settings, erase individual contacts from their CRM page, or request complete workspace deletion by email. On deletion we remove all workspace content; the only retained records are suppression-list entries (bare email + opt-out reason), kept as the legal basis for never emailing someone who opted out, and records we must keep by law.

Processors

We use a small set of processors strictly to operate the platform: Vercel (hosting, USA/EU), Supabase (database, storage and authentication, hosted in London), Resend (email delivery), and Meta Platforms (Instagram publishing, only where you connect it). Each processes data only on our instructions. We do not sell personal data or share it with advertisers.

Security

All traffic is encrypted in transit (TLS, HSTS). Data is encrypted at rest. Workspaces are isolated by row-level security enforced in the database and verified by automated cross-tenant tests. Secrets and tokens live server-side only. Access to production systems is limited to the operator.

Retention

Workspace data is retained while your workspace is active and preserved (read-only) if a trial lapses, so nothing is lost. Deleted workspaces are purged after a short recovery window. Logs are kept for up to 30 days.

Your rights

You have the right to access, correct, export, restrict, object to processing of, and erase your personal data, and to complain to the ICO (UK) or your local supervisory authority. Write to privacy@edition-os.com and we will respond within 30 days.