Legal

Privacy Policy

Last updated: 21 June 2026

This policy applies to Content OS, operated by Content OS ("we", "us", "our"). Contact: support@joincontentos.com

Your data, your rights.Under UK GDPR and the Data Protection Act 2018, you have rights over your personal data. We are the data controller. This policy explains exactly what we collect, why, and how long we keep it.

1. Who we are

Content OS ("Content OS") is the data controller for personal data processed through the Content OS platform (joincontentos.com and related subdomains). We are based in the United Kingdom.

For all data protection enquiries, contact us at support@joincontentos.com. We aim to respond within 5 business days. We are registered with the Information Commissioner's Office (ICO) as required under UK GDPR.

2. What data we collect and why

We collect only the data we genuinely need to provide and improve the service. The table below explains each category, the legal basis under UK GDPR Article 6, the purpose, and how long we keep it.

Data categoryLawful basisPurposeRetention
Account data (name, email, password hash)ContractCreate and manage your account, authenticate accessFor the life of your account, plus 6 months after deletion
Business/organisation nameContractPersonalize the platform and AI-generated content to your brandFor the life of your account, plus 6 months after deletion
Payment and billing data (card last 4, subscription status)Contract + Legal ObligationProcess subscriptions and comply with financial record-keeping law7 years (Companies Act / HMRC requirements)
Connected social accounts (OAuth tokens, platform IDs)ContractPublish and schedule content on your behalf, fetch analyticsUntil you disconnect the account or delete your account
Content you create (scripts, titles, descriptions, thumbnails)ContractStore, display, and AI-process your content within the platformFor the life of your account, plus 90 days after deletion
Brand voice data (example scripts, tone descriptions)ContractImprove AI-generated content quality to match your styleFor the life of your account, plus 90 days after deletion
Usage and analytics data (feature usage counts, quota consumption)Legitimate InterestsEnforce plan limits, detect abuse, improve the platform24 months rolling
Log data (IP address, browser, timestamps)Legitimate InterestsSecurity, fraud prevention, debugging90 days
Cookie / session dataEssential (PECR exempt)Keep you logged inSession duration, renewed on activity

"Contract" means processing is necessary to perform the contract with you (UK GDPR Art. 6(1)(b)). "Legitimate Interests" means we have a legitimate business interest that is not overridden by your rights (Art. 6(1)(f)). "Legal Obligation" means we are required by law (Art. 6(1)(c)).

3. AI processing and your content

When you use AI generation features (scripts, captions, thumbnails), your content data is sent to our AI sub-processors (Anthropic, fal.ai) to generate outputs. Specifically:

  • Your brand voice examples, topic titles, and descriptions are sent to Anthropic to generate scripts and captions.
  • Your title and optional image prompts are sent to fal.ai to generate thumbnail images.
  • Under our agreements with these providers, your content is not used to train their AI models.
  • AI-generated outputs are stored in your account. You can delete them at any time.
  • AI-generated content may contain inaccuracies. You are responsible for reviewing all content before publishing.

4. Social media connections

When you connect a social media account (YouTube, TikTok, Instagram, LinkedIn), we store OAuth access tokens that allow us to:

  • Publish content on your behalf at scheduled times.
  • Read your analytics (followers, views, engagement) to display in your dashboard.
  • Read competitor public content if you have enabled competitor tracking.

We do not access your private messages, contacts, or any data beyond what is necessary for the above. You can revoke access at any time from Settings - Connections, or directly from the platform's own settings.

Google API Services User Data Policy (YouTube)

When you connect a YouTube channel, Content OS requests the youtube.upload, youtube.readonly, and youtube.force-ssl scopes solely to upload and schedule your videos, read the channel and video metadata you authorise, and update the privacy status of videos you publish through the platform.

Content OS's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not transfer or sell Google user data for advertising, we do not allow humans to read your Google user data unless you give explicit consent for a specific message, for security, to comply with law, or as part of internal operations on de-identified/aggregated data, and we use this data only to provide and improve the features you connect YouTube for.

5. Sub-processors (third parties we share data with)

We use the following third-party processors to deliver the service. Each has a Data Processing Agreement with us. We have taken steps to ensure international transfers comply with UK GDPR Chapter V.

ProcessorLocationPurposeSafeguard
Supabase Inc.EU (Frankfurt)Database, authentication, file storageEU-based servers, Standard Contractual Clauses (SCCs)
Stripe Inc.USAPayment processing and billingUK-US Data Bridge adequacy decision; PCI-DSS Level 1
Anthropic PBCUSAAI script, caption, and description generationUK-US Data Bridge adequacy decision; data not used to train models under our agreement
fal.ai Inc.USAAI thumbnail and cover image generationUK-US Data Bridge adequacy decision; Standard Contractual Clauses
Resend Inc.USATransactional email deliveryUK-US Data Bridge adequacy decision; Standard Contractual Clauses
ZernioEUSocial media post scheduling and publishing (TikTok, Instagram, LinkedIn)EU-based processor; Data Processing Agreement in place
Google LLC (YouTube Data API)USAUpload, schedule, and publish videos to the YouTube channel you connect; read the channel and video metadata you authoriseUK-US Data Bridge adequacy decision; use of Google user data adheres to the Google API Services User Data Policy, including the Limited Use requirements
Vercel Inc.USAWeb hosting and edge networkUK-US Data Bridge adequacy decision; Standard Contractual Clauses

The UK-US Data Bridge (adequacy decision, 12 October 2023) permits transfers of personal data from the UK to certified US organisations without additional safeguards. We verify that each US processor holds a valid certification before relying on it.

6. Your rights under UK GDPR

You have the following rights regarding your personal data. To exercise any of them, email support@joincontentos.com with "Data Subject Request" in the subject line. We will respond within one calendar month.

Right of access (Article 15)

Request a copy of all personal data we hold about you. Available via Settings - Account - Export my data.

Right to rectification (Article 16)

Ask us to correct inaccurate or incomplete data. Most account data can be updated directly in Settings.

Right to erasure (Article 17)

Request deletion of your account and all associated personal data. Available via Settings - Account - Delete account. We will action erasure within 30 days, except where we are required by law to retain certain records (e.g., financial records for 7 years).

Right to restriction (Article 18)

Ask us to pause processing of your data in certain circumstances, e.g., while you contest its accuracy.

Right to data portability (Article 20)

Receive your personal data in a structured, machine-readable format (JSON). Available via Settings - Account - Export my data.

Right to object (Article 21)

Object to processing based on our legitimate interests. We will stop unless we have compelling legitimate grounds that override your rights.

Rights related to automated decision-making (Article 22)

We do not make decisions that produce legal or similarly significant effects based solely on automated processing.

7. Cookies

We use only essential cookies required to operate the service (authentication session cookies). We do not use tracking or advertising cookies. For full details, see our Cookie Policy.

8. Data security

We apply appropriate technical and organisational measures to protect your personal data, including:

  • All data in transit is encrypted using TLS 1.2 or higher.
  • Data at rest is encrypted by our infrastructure provider (Supabase / AWS).
  • Passwords are never stored in plain text - they are hashed using bcrypt via Supabase Auth.
  • Access to production systems is restricted to authorised personnel only.
  • OAuth tokens for social accounts are stored encrypted at the database level.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and affected individuals without undue delay, as required by UK GDPR Article 33.

9. Data retention summary

We do not keep your data longer than necessary:

  • Active account data - retained for as long as your account is active.
  • Deleted account data - purged within 90 days of account deletion (except financial records, see below).
  • Payment and invoice records - retained for 7 years to comply with HMRC requirements.
  • Server logs - 90-day rolling window, then automatically deleted.
  • Usage audit logs - 24 months, then automatically deleted.

10. Children's data

Content OS is not directed at children under 18. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact us immediately and we will delete it.

11. Changes to this policy

We may update this policy from time to time. We will notify you of material changes by email (to the address on your account) or by a notice within the platform at least 14 days before changes take effect. The "Last updated" date at the top of this page indicates when it was last revised. Continued use of the service after changes take effect constitutes acceptance of the updated policy.

12. How to complain

If you have concerns about how we handle your data, please contact us first at support@joincontentos.com. We will do our best to resolve the issue.

If you are not satisfied, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's data protection supervisory authority:

Information Commissioner's Office (ICO)

Website: ico.org.uk

Helpline: 0303 123 1113

Live chat: ico.org.uk/contact-us