Privacy policy

Privacy follows the customer-controlled architecture.

This draft describes C.C.O.S. version 1.0.0 as standalone software. Bracketed fields require owner and legal approval.

Owner/legal review required before deployment · Effective date: [OWNER TO SUPPLY]

1. Scope and responsible party

This policy applies to the Autonomous Content Creator OS product website, product support, and the standalone C.C.O.S. software. Seller/controller identity and contact: [PUBLIC SELLER NAME, ADDRESS, AND PRIVACY EMAIL TO BE SUPPLIED].

2. Information involved

Customers may provide objectives, brand and audience configuration, generated content, model-provider settings, platform connection settings, account/channel identifiers, and support messages. The local runtime may create workflow state, artifacts, package manifests, logs, and diagnostics. OAuth connections may involve authorization codes, access tokens, refresh tokens, granted scopes, expiry data, and the authorized platform account identifier.

3. Where data is processed

C.C.O.S. is designed to run in the customer's environment. Runtime state and encrypted connection records are stored locally under a customer-selected private directory. Model requests and authorized platform operations transmit the information required for that operation to the provider the customer configures. This public static site has no account system, database, analytics, advertising tracker, or token-exchange service in its qualified build.

4. How information is used

Information is used to configure and operate C.C.O.S., generate and validate requested deliverables, maintain durable recovery state, connect an authorized account, verify scopes and account identity, perform a customer-approved platform operation, troubleshoot support requests, maintain security, and improve documented product functionality.

5. Google and platform API data

Google user data obtained through OAuth is used only to identify the authorized YouTube channel and perform the YouTube operations the customer requests under the granted scopes. Other platform data is used only for connection identity, scope checks, token lifecycle, and customer-approved operations. C.C.O.S. does not use platform data for advertising, sell it, or transfer it to unrelated data brokers. Use of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements, to the extent applicable. [LEGAL REVIEW REQUIRED]

6. Credentials

The standalone runtime stores customer connection tokens in an encrypted local vault protected by a customer-held key and restrictive file permissions. Client secrets are supplied through private environment configuration rather than browser JavaScript or command arguments. Customers are responsible for securing their system, keys, provider credentials, and backups.

7. Providers and disclosure

Customer-selected AI/model providers and connected platforms process data under their own terms and privacy policies. Infrastructure providers may process public-site request metadata after deployment. Support information may be handled by the owner-approved support provider. Current provider list and lawful-transfer details: [OWNER/LEGAL TO SUPPLY BEFORE DEPLOYMENT].

8. Sale, retention, and control

We do not sell customer personal information. Local data remains until the customer deletes it, disconnects a platform, removes the runtime state, or provider retention rules apply. Seller-held support data retention: [OWNER/LEGAL TO DEFINE]. Customers can limit submitted information, revoke platform access, delete local state, and request deletion of eligible seller-held support information.

9. Security

Security measures include local encryption for connection records, private file permissions, state validation, PKCE where configured, account-identity checks, approval-gated publishing, and avoidance of secrets in public browser code. No system can be guaranteed completely secure.

10. Children

C.C.O.S. is a commercial product not directed to children. Minimum customer age and jurisdiction-specific handling: [LEGAL REVIEW REQUIRED].

11. Changes and contact

Material updates will be identified by a revised effective date. Privacy questions or requests: [PUBLIC PRIVACY CONTACT TO BE SUPPLIED].