Legal

Privacy Policy.

Effective: 2026-05-29 · Operator: Everywherego LLP (India), operating as CreatorOS AI · Contact: support@creatorosai.in · Grievance Officer: privacy@creatorosai.in

1. The short version

We collect what we need to run the product (your account, what you generate, what you publish, basic usage analytics). We do not sell your data. You can delete your account and all associated data at any time — see Profile.

2. What we collect

  • Account data: email, name, profile picture (from your OAuth provider), niche/platform/goal/tone you pick during onboarding.
  • Generated content: hooks, scripts, captions, calendars, viral plans, virality scores, videos, ad briefs you create — stored so you can revisit them.
  • Connected accounts: OAuth access + refresh tokens for LinkedIn / X / YouTube / Instagram / Facebook / TikTok / Telegram / WhatsApp BSP, stored encrypted at rest (AES-256-GCM). We use these only to post on your schedule and read insights about your posts.
  • Billing: Razorpay subscription IDs and status. We do NOT see or store full card data — Razorpay handles that.
  • Usage analytics: aggregate counts (generations per day, model used, render durations) for our cost management and reliability.
  • Logs & analytics: request logs, error traces and (with your consent) product-usage analytics via PostHog, audit log entries for distribution events.

3. What we do with it

  • Generate AI content for you (calls to OpenAI, Pixazo, HeyGen, MS Edge TTS).
  • Publish on your behalf to connected platforms ONLY when you approve a schedule.
  • Bill your subscription via Razorpay.
  • Show you analytics about your own content.
  • Improve product reliability (error monitoring).

We do not: sell your data, share your data with marketers, use your generations to train models without your permission, or post to your accounts unprompted.

Our lawful basis (DPDP Act 2023 / GDPR Art. 6): we process your account, content, and connected-account data to perform our contract with you (running the product you signed up for); your social-platform tokens and publishing actions on the basis of your explicit consent, which you can withdraw at any time by disconnecting a platform or deleting your account; and minimal logs/analytics under our legitimate interest in keeping the service secure and reliable. Withdrawing consent is as easy as giving it.

4. Third-party processors

We share the minimum necessary data with:

  • Supabase (DB + auth + storage) — your full data, hosted in their managed Postgres.
  • Vercel (hosting) — request metadata, no content storage.
  • OpenAI — your prompts when you generate (covered by OpenAI's API data policy — not used for training).
  • Pixazo / HeyGen / MS Edge TTS — scene briefs and voiceover scripts during reel renders.
  • Razorpay — billing identity (email, plan). No card data passes through us.
  • Connected platforms (LinkedIn / X / YouTube / Instagram / Facebook / TikTok / Telegram / WhatsApp via Gupshup BSP) — only your post content + your own access token. Your use of each platform is also governed by that platform's own terms and privacy policy.
  • PostHog (US) — product analytics, error monitoring, and sampled session replay. Receives usage events and, once you sign in, your email as an identifier. It stays off until you accept analytics in our cookie banner, respects Do Not Track, and masks the text you type. See our Cookie Policy.

5. Where your data lives

Primary database: Supabase (default region: AWS Mumbai, ap-south-1 for Indian creators). Backups retained 7 days. Storage: Supabase Storage for rendered videos. Logs & analytics: Vercel (US) + PostHog (US) — request metadata and consented product analytics.

Cross-border transfers: some processors (Vercel, Sentry, OpenAI) operate outside India. Where your personal data is transferred abroad, we rely on the processor's contractual data-protection commitments (including Standard Contractual Clauses where applicable) and, for consent-based features, on your consent. By using the service you acknowledge these transfers, which are limited to the metadata and content described above.

6. How long we keep it

  • Account + generations: until you delete the account.
  • Reel render artifacts (audio/video files): permanent unless you delete the generation.
  • Audit logs (per-scene reel events): 7 days (auto-compressed via daily cron).
  • Anonymous rate-limit rows: 7 days.
  • Billing records: 7 years (Indian Companies Act requirement).

7. Your rights

Under India's DPDPA 2023 and (if applicable) the GDPR, you have the right to:

  • Access — see what we hold. Email us; we respond within 30 days.
  • Correct — edit your profile and onboarding answers any time.
  • Delete — one click from Profile. Fires DELETE /api/account/delete. Hard-deletes your auth row + cascades through `profiles` → `generations` → `social_connections` → `scheduled_posts` → all related rows.
  • Withdraw consent — disconnect any platform, cancel your subscription, or delete the account.
  • Grievance / complaint — our Grievance Officer (under the DPDP Act 2023) is reachable at privacy@creatorosai.in. We acknowledge within 48 hours and resolve within the statutory timeline (90 days). Indian users can also escalate to the Data Protection Board of India; EU users to their local supervisory authority.

7a. Data deletion — Facebook & Instagram users

If you connected CreatorOS AI to your Facebook or Instagram account and want to delete the data we hold on you, there are three paths:

  1. In-app (fastest, ≤ 24 hours): sign in at /dashboard/profile → scroll to Danger zone → click Delete account. This fires DELETE /api/account/delete and cascade-removes every row tied to your user_id.
  2. Via Facebook (automatic): go to Facebook → Settings & privacy → Settings → Apps and websites → find CreatorOS AI → click Remove → tick "Also delete the information that CreatorOS AI has from Facebook". Facebook will POST a signed deletion request to /api/account/delete/meta-callback. You'll get a confirmation code + redirect to a status page at /account/deletion-status/[code]. The same flow works from Instagram → Settings → Apps and Websites.
  3. By email (manual fallback): email support@creatorosai.in from the address tied to your account, with subject "Data deletion request". We complete it within 7 business days.

Whichever path you pick, deletion is permanent — generated content, scheduled posts, scorecards, and Brand Pulse streams cannot be recovered after the cascade completes. Billing records are kept for 7 years for Indian GST compliance but are isolated from identity data (only invoice IDs + amounts, no PII).

8. Security

Tokens encrypted at rest (AES-256-GCM, server-side key rotation policy). HTTPS everywhere. RLS-enforced row isolation in Postgres (your data is isolated from other users by Postgres-level policies). Annual internal pentest + external pentest at launch. We disclose material security incidents within 72 hours.

8a. Cookies

We use only essential and functional cookies / local storage (sign-in, security, UI preferences) plus our payment provider's checkout cookies. No advertising or cross-site tracking. Full detail in our Cookie Policy.

9. Children

CreatorOS AI is for users 18+. We do not knowingly collect data from children. If you believe we have, email support@creatorosai.in and we will delete it.

10. Changes

Material changes will be notified via email at least 14 days before they take effect. The current effective date sits at the top of this page.