Privacy Policy
How we collect, use, share, and protect your information.
Last updated: 17 May 2026
1. Introduction
This Privacy Policy explains how PT Holixora Teknologi Indonesia (“Griya Studio”, “we”, “us”, or “our”) collects, uses, shares, and protects personal information when you use Griya Studio (the “Service”), an architectural AI rendering and BOQ platform.
By using the Service, you agree to the practices described in this Policy.
2. Information We Collect
Information you provide
- Account information: your name, email address, password, and profile details.
- Project content: architectural drawings, sketches, images, 3D model exports, and related data you upload or create.
- Payment information: billing details processed by our payment providers. We do not store full payment card numbers.
- Communications: messages you send to support, and optional contact details such as a WhatsApp number if you choose to link one.
Information collected automatically
- Usage data: features used, renders and BOQ jobs created, credits consumed, and activity logs.
- Device and log data: IP address, browser and device type, and session metadata.
- Cookies and similar technologies used to authenticate you and keep you signed in.
Information from third parties
If you sign in with Google or TikTok, we receive basic profile information from that provider. See the next section for details specific to TikTok.
3. TikTok Data
If you choose to connect a TikTok account, the Service integrates TikTok’s developer products, which may include TikTok Login, the Content Posting API, and the Display API. We access TikTok data only after you grant permission through TikTok’s authorization (OAuth) screen, and only for the scopes you approve.
What we receive from TikTok
- TikTok Login: your TikTok user identifier (open ID), display name, username, and profile picture (the basic profile scope).
- Display API: your public TikTok videos and profile information, retrieved so we can display them within the Service at your request.
- Access tokens issued by TikTok that allow the Service to act on your behalf for the permissions you granted.
Publishing content to TikTok
When you use the content posting feature, we upload and publish photos or videos to your TikTok account only when you explicitly initiate and confirm the action. You choose what is posted and when.
How we use TikTok data
We use TikTok data solely to provide the features you request — to authenticate you, display your TikTok content, and publish content you direct us to publish. We do not sell TikTok data, use it for advertising or profiling, or share it with third parties except service providers strictly necessary to operate the Service.
TikTok’s own handling of your data
Your use of TikTok, and TikTok’s own collection and use of your information, are governed by TikTok’s Terms of Service and Privacy Policy, available at tiktok.com/legal/privacy-policy. We handle data obtained through the TikTok integration in accordance with the TikTok Developer Terms of Service and the TikTok Developer Guidelines.
4. How We Use Information
- To provide, operate, and maintain the Service, including generating renders, BOQ reports, and other output you request.
- To process payments, manage subscriptions, and track credit usage.
- To authenticate you and keep your account secure.
- To communicate with you about your account, support requests, and important service updates.
- To monitor, analyze, and improve the Service and to develop new features.
- To detect, prevent, and address fraud, abuse, and security incidents.
- To comply with our legal obligations.
5. How We Share Information
We do not sell your personal information. We share it only as described below:
- Service providers (subprocessors): cloud hosting, AI processing providers (such as Google Gemini, Anthropic, Replicate, Kling, and Stability AI), payment processors (Stripe and Midtrans), email delivery, and bot-protection services, each acting on our instructions.
- TikTok: when you use the TikTok integration, as described in Section 3.
- Collaboration: information you choose to share through projects, organizations, share links, or client portals.
- Legal and safety: when required by law, or to protect the rights, safety, and integrity of the Service, our users, or the public.
- Business transfers: in connection with a merger, acquisition, or sale of assets, subject to this Policy.
6. Data Retention
We retain personal information for as long as your account is active or as needed to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. When you delete your account or disconnect an integration, we delete or anonymize the associated data within a reasonable period, as described in Section 9.
7. Data Security
We use technical and organizational measures to protect your information, including encrypted data transport, hashed passwords, access controls, and session management. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Your Rights and Choices
Depending on your location, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can update most account information directly in the Service or by contacting us. We handle requests in line with applicable law, including Indonesia’s Personal Data Protection Law (Law No. 27 of 2022).
9. Revoking TikTok Access and Deleting Your Data
- You can disconnect your TikTok account from Griya Studio at any time in your account settings.
- You can also revoke Griya Studio’s access directly from TikTok, under Settings and privacy → Security and permissions → Apps and websites.
- When you disconnect TikTok, or on request to support@griya.studio, we delete the TikTok access tokens and TikTok profile data we hold within 30 days, except where we must retain limited records to comply with law.
- To delete your entire Griya Studio account and its associated data, contact support@griya.studio.
10. International Data Transfers
Griya Studio is operated from Indonesia, and our service providers may process data in other countries. Where information is transferred across borders, we take steps to ensure it remains protected consistent with this Policy and applicable law.
11. Children's Privacy
The Service is not directed to children under 18, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, please contact us so we can delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the Service or by email and update the date above. Your continued use of the Service after the changes take effect constitutes your acceptance of the revised Policy.
13. Contact Us
For privacy questions or to exercise your rights, contact us at support@griya.studio.
PT Holixora Teknologi Indonesia — Indonesia