Legal
Privacy policy
Last updated 4 October 2026
Tari Studio (“we”, “the service”) is managed by PhineTech Ltd, a company in Kenya, which is the data controller for the information described here. This policy explains what we collect, why, who we share it with and what choices you have. We follow the Kenya Data Protection Act, 2019.
What we collect
- Account details: your name, email address, optional phone number, and a password stored only as a salted hash. If you sign in with Google we receive your name, email address and Google account identifier.
- Team details: the teams you create or join, your role in each, and the people you invite (their email address and role).
- What you make and send: prompts, briefs, images you upload (templates and characters), generated images and videos, campaigns, tracked links, posts and WhatsApp conversations you connect.
- Orders and payments: for a done-for-you order, your name, phone number, optional email and business name, and the brief. For payments we keep the amount, status and the receipt reference from M-Pesa or Paystack. We never see or store your M-Pesa PIN or card number.
- Technical data: sign-in times, security events (failed sign-ins, password changes), and the address your device used, kept in audit and rate-limit records so we can protect accounts.
Why we use it
- To create your account, sign you in and keep it secure (including one-time codes and password recovery by email or SMS).
- To provide the service: generate media, publish posts, answer messages, track which ad led to a sale, and produce your reports.
- To take payment, issue receipts and prevent fraud.
- To contact you about your account, orders and security, and to give support.
Our lawful bases are performing our contract with you, our legitimate interest in running a secure service, compliance with the law, and your consent where we ask for it.
Who we share it with
We use service providers (processors) only to run the service. They receive just what they need:
- Safaricom (M-Pesa Daraja) and Paystack, to collect payments.
- AI providers, to generate images, video and text from your prompts and uploaded reference material.
- Meta (Facebook, Instagram, WhatsApp), only for the accounts you connect.
- Bonga SMS and our email provider, to send one-time codes and notifications.
- Google, if you choose Google sign-in.
- Our hosting provider, which stores the database and uploaded files.
We do not sell personal data. We disclose it to authorities only when the law requires.
International transfers
Some providers process data outside Kenya. Where that happens we rely on appropriate safeguards, such as contractual protections, as required by the Data Protection Act.
How long we keep it
We keep account and team data while your account is active. Payment and order records are kept for the period tax and accounting law requires. Security logs are kept for a limited time. When you ask us to delete your account we remove or anonymise your personal data, except records we must keep by law.
Security
Passwords are hashed, secrets such as provider keys are encrypted, sessions use secure cookies, sign-in and one-time-code attempts are rate-limited, and two-factor authentication is available. No system is perfectly secure; if a breach affects you we will tell you and the Data Commissioner as the law requires.
Your rights
You may ask to see, correct, delete or move your personal data, to object to or restrict some uses, and to withdraw consent. Write to phinetechltd@gmail.com. We answer within the time the law allows. You may also complain to the Office of the Data Protection Commissioner of Kenya.
Cookies
We use only the cookies the service needs to work. See the cookie policy.
Children
The service is for businesses and is not directed at children under 18. We do not knowingly collect their data.
Changes and contact
We will update this page when our practices change and show the date above. Questions: phinetechltd@gmail.com, PhineTech Ltd, phinetech.co.ke.