Effective 7 August 2026
Privacy Policy
1. Who We Are
Cloud Disco Studio is a creator web application operated by Aerelle Home. Questions about this Policy or privacy requests may be sent to support@aerellehome.com.
2. Scope
This Policy describes the current public release of Cloud Disco Studio at studio.aerellehome.com. Its TikTok integration is limited to TikTok Login Kit for Web and the user.info.basic permission. We will update this Policy before materially changing our data practices.
3. Information We Receive When You Sign In
If you choose to continue with TikTok, we receive your TikTok open ID, display name and avatar URL after authorization. We use these fields only to identify the signed-in creator and display their basic profile in the dashboard.
4. Authentication and Cookies
We use cookies that are necessary to complete sign-in and maintain a creator session:
- a short-lived OAuth state cookie that helps protect the sign-in flow from request forgery and expires after ten minutes; and
- a signed session cookie containing the basic profile fields above and an expiry, which lasts for up to seven days.
These cookies are configured as HTTP-only, Secure and SameSite=Lax. Browser JavaScript cannot read them. We do not use cookies for advertising or behavioural tracking in this release.
5. Tokens and Retention
The OAuth authorization code is exchanged server-side. TikTok access and refresh tokens are never sent to browser JavaScript and are discarded after we retrieve the basic profile needed for this release. We do not create a persistent application-level creator profile database in this release.
The OAuth state cookie expires after ten minutes. The session cookie expires after seven days or earlier if you use Disconnect. Technical records may be processed by our infrastructure providers as part of operating and securing the service.
6. Information We Do Not Request Through Login Kit
The current Login Kit integration does not request or retrieve TikTok passwords, private messages, LIVE comments, LIVE joins, gifts, likes, follows, shares, donations, payment information, videos, viewer lists, chat content or music data.
7. Service Providers and Sharing
TikTok processes the authentication request when you choose to sign in. The public site is hosted with Cloudflare Worker infrastructure. Your use of those services is subject to their own policies. When the dashboard displays an avatar URL, your browser requests the image from the HTTPS host identified by that URL.
We do not sell the personal data processed by this release. We may disclose information when required by law or when reasonably necessary to protect the service, its users or its security.
8. Your Choices and Requests
You can use Disconnect to clear the Cloud Disco Studio session from your browser. You can also manage the authorization granted to Cloud Disco Studio through TikTok’s account or application-permission controls. To make a privacy request, contact support@aerellehome.com. Available rights and our obligations may vary by location.
9. Security
We keep OAuth client secrets and token exchanges server-side, use HTTPS in production, and use short-lived state values and signed session cookies. No internet service can guarantee absolute security. Do not send passwords, OAuth codes, access tokens or refresh tokens to support.
10. Changes and Contact
We may update this Policy when the service, integrations or data practices change. The effective date appears at the top of this page. For privacy questions, contact support@aerellehome.com.