Legal

Privacy Policy

This policy explains what data Content OS processes, why it is processed, and how connected platform authorizations can be revoked. Content OS does not sell personal data.

Effective date: 2026-09-26 · Last updated: 2026-09-26

1. Data processed

Content OS processes only the data needed to run the workspace:

  • Account identifiers and basic profile metadata from connected platforms.
  • OAuth access and refresh tokens, stored server-side only.
  • Content, captions, media references, schedules, and publishing status.
  • Analytics metrics returned by connected platforms, stored as snapshots.
  • Operational and security logs needed to run and diagnose the service.

2. Purposes of processing

Data is used to operate the workspace: managing brands and content, connecting platform accounts, executing scheduled publishing, syncing analytics, securing access, and troubleshooting failures.

3. Third-party services

Depending on which integrations are connected, the app interacts with TikTok, Meta/Instagram/Facebook, Google/YouTube, Supabase (database and authentication), Cloudinary (media storage), and Vercel (hosting). Each provider processes data under its own privacy policy when the owner connects an account or publishes content.

4. Tokens and credentials

Provider OAuth secrets and tokens are kept server-side and are never sent to the browser or exposed through normal read interfaces. Disconnecting an account stops local use of its credentials; provider-side authorization should also be revoked in the provider's own settings where available.

5. Retention and deletion

Content, scheduling records, and analytics snapshots are retained while the account is active so history, calendars, and trends remain available. Disconnecting a platform account stops future processing for that account; deletion of workspace data can be requested through the support contact below. Contact details voluntarily provided when requesting access are used only to review the request and communicate the decision.

6. Security practices

Access is limited to authorized accounts, and each account can access only its own workspace data. Data access is scoped to the signed-in user, elevated keys stay server-side, and secrets are kept out of client code and logs. No security measure is absolute, and provider-side incidents remain subject to the provider's own controls.

7. Data sharing

Data is shared only with the third-party services listed above as required to operate the connected features the owner enables. Data is not sold and is not shared for third-party advertising.

8. Changes to this policy

This policy may be updated as the product or its integrations change. The effective date above reflects the current version.

9. Contact

For privacy questions or deletion requests, contact kaystudio331@gmail.com.