Legal · Privacy

Privacy Policy

This policy explains what information the AI Content OS platform (“AI Content OS,” “we,” “us,” or “our”) collects when you use our AI-powered content creation and publishing service, how we use it, and the choices you have — including our practices for data accessed through Facebook, Instagram, and Threads.

Effective Date: August 4, 2026Last Updated: August 4, 2026

Questions about this policy or your data? Contact our privacy team at privacy@aicontentos.com. We typically respond within 30 days.

01

Introduction

AI Content OS is an autonomous content operating system that helps creators, marketers, and businesses plan, generate, optimize, schedule, publish, and measure social media content. Our AI agents create posts and then publish them to the social platforms you connect, including Facebook, Instagram, and Threads (together, the “Service”).

This Privacy Policy describes the personal information we collect, how we use and share it, how long we keep it, and the rights you have over it. It applies to everyone who visits our website, creates an account, or uses the Service, regardless of where you are located.

By creating an account or using the Service, you agree to the practices described in this policy. If you do not agree with any part of it, please do not use the Service. Our data practices are designed to comply with the Meta Platform Terms, the Meta Developer Policies, the Instagram Platform Policy, the Threads API policies, the EU General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA), as applicable to you.

02

Information We Collect

We collect three categories of information: (a) information you provide directly, (b) information collected automatically when you use the Service, and (c) information we receive from the social platforms you connect.

a) Information you provide

  • Account data: your name, email address, and password. Passwords are stored only as salted, hashed values — never in plaintext.
  • Billing data: subscription plan, invoice details, and payment transaction records. Full card numbers are processed and stored by our PCI-DSS-compliant payment processors; we never see or store them.
  • Content data: the posts, captions, hashtags, media files, drafts, brand guidelines, and publishing schedules you create or upload through the Service.
  • AI configuration: API keys you provide for third-party AI providers (such as OpenAI or Google Gemini) and your content generation preferences.
  • Communications: messages you send to our support team and any feedback you provide.

b) Information collected automatically

  • Usage data: the pages you visit, features you use, content you generate or schedule, and interaction patterns within the app.
  • Device and log data: IP address, browser type and version, operating system, device identifiers, referring URLs, and timestamps of activity.
  • Cookie and analytics data: as described in the Cookies section below.

c) Information from connected platforms

When you connect a Facebook, Instagram, or Threads account — directly or through Facebook Login — we receive, with your explicit authorization, the minimum data needed to operate the Service: public profile information (name, username, and profile picture), the Pages and accounts you authorize, the content and media you choose to manage, and performance insights such as reach, impressions, engagement rate, and follower counts. We only ever request the permissions required for the features you use.

03

How We Use Information

We use the information we collect for the following purposes:

  • To provide and operate the Service: create and manage accounts, run our AI agents, generate content, schedule and publish posts, and produce analytics and reports.
  • To personalize your experience: tailor content suggestions, templates, and AI behavior to your brand, audience, and preferences.
  • To power AI features: send your prompts, drafts, and brand context to the AI providers you configure so they can generate content on your behalf.
  • To publish to your platforms: transmit content you explicitly approve to Facebook, Instagram, and Threads through their official APIs.
  • To improve the Service: analyze usage patterns, diagnose and fix errors, and develop new features.
  • To communicate with you: respond to support requests, send transactional notices (for example, publishing errors or subscription status), and — with your consent — send product updates and marketing.
  • To ensure security and prevent abuse: detect fraud, unauthorized access, and violations of our Terms of Service.
  • To comply with legal obligations and to enforce our rights.

We do not sell your personal information to anyone. We do not use your content or prompts to train our models or the models of third parties. Nothing in this policy is overridden by the revenue we generate; the Service is funded by subscriptions, not by your data.

04

Data Accessed Through Meta Platforms

Sections 4–6 describe how we handle data accessed from Facebook, Instagram, and Threads, in accordance with Meta's platform requirements.

Facebook Login Data

When you sign in with Facebook Login, Facebook shares your public profile — name, email address, and profile picture — with your permission, to identify you and create your account.

If you connect Facebook Pages, we access them through the Meta Graph API using permissions you explicitly grant, and only for Pages you manage or administer.

We use this data solely to authenticate you, display your Pages, publish content you approve, and retrieve page insights. We never post without your explicit instruction, and we do not use the data for advertising or profiling.

You can revoke access anytime from the Platforms page in the app or in your Facebook settings (Settings → Apps and Websites).

Instagram Data

When you connect an Instagram Business or Creator account, we access it through the Instagram Graph API.

With your authorization we receive your Instagram username, profile details, the published media and captions you manage, and insights such as impressions, reach, profile views, and engagement metrics.

We use this data to schedule and publish posts and Reels you approve and to show performance analytics in your dashboard. We never access private accounts, direct messages, or content you have not chosen to manage through the Service.

Instagram does not sponsor or endorse our Service.

Threads Data

When you connect a Threads account, we access it through the Threads API with your explicit authorization.

With your permission we receive your Threads profile information (username, display name, and profile picture), your posts and threads, and engagement insights such as likes, replies, reposts, quotes, and follower counts.

We use this data to schedule and publish threads you approve and to report engagement analytics in your dashboard. We retain Threads data only as long as needed to deliver these features and never use it for any other purpose.

You can disconnect your Threads account at any time from the Platforms page in the app.

07

Third-Party APIs

The Service relies on third-party APIs to function: the Meta Graph API (Facebook, Instagram, and Threads), the LinkedIn API, the X API, and AI providers such as OpenAI and Google Gemini. Each integration processes only the data required to perform the action you initiate.

When you use AI features, your prompts, content drafts, and brand context are transmitted to the AI provider you have configured, solely to generate content on your behalf. Those providers process the data under their own privacy policies, which we encourage you to review. We do not share your data with AI providers for model training or any purpose beyond generating the content you request.

Infrastructure, analytics, and email-delivery providers may process limited data on our behalf. Every processor is bound by a data processing agreement, may only process data to deliver its services, and never receives your connected-account credentials. API keys are encrypted at rest and used only to authenticate your own integrations.

08

Cookies

Cookies are small text files stored on your device when you visit our website. We use them to keep you signed in, remember your preferences, and understand how the Service is used. The categories we use are:

  • Essential cookies: required for login, session management, and security. These cannot be disabled.
  • Functional cookies: remember your preferences, such as layout and default platform.
  • Analytics cookies: help us understand, in aggregate, how the Service is used so we can improve it.
  • Advertising cookies: used only where you have given consent, to measure the performance of our own campaigns. We never use them to build profiles of you for other advertisers.

You can control or delete cookies through your browser settings at any time. Blocking essential cookies may prevent parts of the Service from working correctly.

09

Data Storage

  • Where we store data: your data is hosted on encrypted cloud infrastructure located in the United States and the European Union. Transfers outside these regions are governed by standard contractual clauses.
  • Encryption: all data is encrypted in transit using TLS 1.2 or higher, and encrypted at rest using AES-256.
  • Retention: account and content data are kept while your account is active. Usage logs are retained for up to 12 months. Backups are retained for up to 30 days after deletion. You may delete your data at any time as described in the Data Deletion Requests section.
  • Access controls: only employees who need access to perform their roles can reach your data, protected by least-privilege permissions, multi-factor authentication, and regular access reviews.
10

User Rights

Depending on where you live, you may have some or all of the following rights under laws such as the GDPR, the CCPA, and similar regulations:

  • Access: receive a copy of the personal information we hold about you.
  • Correction: ask us to fix inaccurate or incomplete information.
  • Deletion: ask us to delete your personal information (see Data Deletion Requests).
  • Portability: receive your data in a structured, machine-readable format and transmit it elsewhere.
  • Restriction and objection: limit or object to certain processing activities, including processing for legitimate interests.
  • Withdraw consent: withdraw any consent you gave at any time, without affecting the lawfulness of prior processing.
  • Non-discrimination: we will never charge different prices or provide a different quality of service because you exercised a privacy right.
  • Lodge a complaint: file a complaint with your local data protection authority if you believe we have not handled your data properly.

To exercise any of these rights, email privacy@aicontentos.com with the subject line “Privacy Request.” We will verify your identity before processing the request and will respond within 30 days.

11

Data Deletion Requests

You can request complete deletion of your data at any time. There are two ways to do it:

  • In-app: disconnect your connected platforms from the Platforms page. This immediately stops all publishing and data collection from those platforms.
  • By email: email privacy@aicontentos.com with the subject line “Delete My Data.”

Once we verify your identity, we will delete within 30 days: your account profile, generated content, publishing schedules, analytics, and logs. Your connected Facebook, Instagram, and Threads accounts will be disconnected through their official APIs, and copies of your data in backups will be purged within an additional 30 days. You can also revoke our access directly through your Facebook settings (Settings → Apps and Websites) at any time.

Deleting your data is permanent and cannot be undone. If you delete your account, your publishing schedules will stop and previously scheduled posts will not be published.

12

Security

We take the protection of your data seriously. Our security measures include encryption in transit and at rest, least-privilege access controls with multi-factor authentication, regular security reviews of our code and infrastructure, dependency monitoring, and a documented incident-response process that includes prompt notification to affected users where required by law.

We also practice data minimization: we collect only what is necessary to operate the Service, and we limit what our AI agents and integrations can access to the minimum permissions you grant. While no method of transmission or storage is 100% secure, we work continuously to protect your data against unauthorized access, alteration, disclosure, or destruction.

13

Contact Information

AI Content OS — Privacy Team

Email: privacy@aicontentos.com

If you are in the EU or UK, you may also contact our data protection representative at the same address, and you may lodge a complaint with your local supervisory authority at any time. We respond to all privacy inquiries within 30 days.

14

Updates to this Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, features, or legal obligations. When we make material changes, we will notify you by email and through an in-app notice, and we will update the “Effective Date” at the top of this page.

Your continued use of the Service after a policy update takes effect constitutes acceptance of the revised policy. We encourage you to review this page periodically to stay informed about how we protect your data.