1. Who we are
Brand OS (“we”, “us”) is operated by AI Factory. This policy applies to the Brand OS web application and related services. If you connect a Facebook Page or Instagram account, this policy also covers the Meta Platform Data we access to provide the features you enable.
2. Information we collect
- Account & workspace data — your name, email address, workspace and brand names, and settings you configure.
- Content you create — brand profiles, campaigns, targets, drafts, prompts, and instructions you give the assistant.
- Meta Platform Data — when you connect a Facebook Page or Instagram Business account via Facebook Login, we access: Page and account identifiers, access tokens, your posts and their insights, comments and messages on your Pages/accounts, audience and engagement metrics, and (if you enable it) lead-form submissions and ad data. We access this only for accounts you explicitly connect and authorize.
- Market & listening data — publicly available information about topics and competitor brands you choose to track, used to power BrandRadar insights.
- Usage & technical data — logs, device/browser information, and essential cookies used to keep you signed in and secure the service.
3. How we use your information
- Operate the service and your account, and keep it secure.
- Draft, schedule, and (with your authorization) publish content to your connected accounts.
- Generate suggestions, campaign plans, targets, and analytics from your data.
- Read and help you respond to comments and messages on your connected accounts.
- Send you product notifications and the digests you enable.
- Detect abuse, debug issues, and comply with legal obligations.
4. Meta Platform Data — specific commitments
We access Facebook and Instagram data through Facebook Login for Business and the Meta Graph API, and only with the permissions you grant. For this data we commit that:
- We use it solely to provide the features you have enabled inside Brand OS.
- We do not sell it, and we do not use it for advertising to you or building profiles unrelated to the service.
- We handle it in accordance with the Meta Platform Terms and Developer Policies.
- You can disconnect at any time, which revokes our access tokens and stops further access.
- We retain it only as long as needed for the service or as required by law, and delete it on request (see our Data Deletion page).
4a. YouTube and Google data — specific commitments
If you connect a YouTube channel or a Google Ads account, Brand OS uses YouTube API Services and the Google Ads API, with only the permissions you grant on Google's consent screen. By connecting YouTube you agree to be bound by the YouTube Terms of Service, and Google's handling of your data is described in the Google Privacy Policy.
Brand OS's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- Limited Use: we use Google user data only to provide and improve the features you see in Brand OS. We do not transfer it to others except to provide those features, to comply with the law, or as part of a merger or acquisition with your notice; we do not use it to train generalised AI models; and no person reads it unless you ask us to (for example in a support request), it is needed for security, or the law requires it.
- What we access: your channel's identity, videos and their details, comments on your videos, and channel and video analytics (views, watch time, subscribers, likes, comments, shares); for Google Ads, the ad accounts, campaigns and their performance you choose to manage here.
- What we do with it: upload, schedule, edit and delete videos you approve; show and answer comments, hide comments and block commenters when you ask; show analytics in Reports; create and manage the YouTube campaigns you approve. Nothing is published without your confirmation, and we never add text to your titles or descriptions without your consent.
- Competitor tracking uses only public YouTube information (channel names, public videos and their public counts) about channels you choose to follow.
- Retention: data we read from YouTube is kept no longer than 30 days unless we refresh it; analytics kept for your reports are re-confirmed with Google at least every 30 days; public competitor video data is refreshed or deleted, and removed within 30 days when you stop following a channel.
- Deletion: when you disconnect YouTube or Google Ads in Settings we revoke our access at Google immediately and delete the data we stored for that account within 7 days. If you revoke access from your Google account instead, we delete it within 30 days. Videos already published stay on YouTube.
- Revoking access: disconnect in Brand OS Settings, or at any time remove Brand OS from your Google Account security settings.
- We do not sell YouTube or Google data, use it for advertising to you, or combine data from different channel owners.
4b. LinkedIn data: specific commitments
If you connect a LinkedIn company Page, Brand OS uses LinkedIn's APIs with only the permissions you grant on LinkedIn's sign-in screen, and only for the Page you pick. You must be an admin of that Page. Brand OS works with company Pages only: it does not post to, read from or analyse personal LinkedIn profiles.
- What we access: the name of the LinkedIn member who connects the Page; the Page's name, logo, public address and follower count; the Page's posts and the comments, mentions, reactions and shares on them; and Page and post statistics, including follower make-up by industry, seniority, job function and country, in aggregate only. If you also connect a LinkedIn ad account: the ad accounts, campaigns, targeting and results you manage here, and the answers people submit to your LinkedIn lead forms.
- What we do with it: publish the posts you approve as your Page, with an optional first comment; show comments and mentions of your Page in the Interact inbox so you can reply as the Page; show Page and post statistics in Reports; and create and manage the LinkedIn campaigns you approve. Nothing is published or sent without a person confirming it.
- AI: Brand OS drafts a LinkedIn post or reply with AI only when you ask for one, and a person sends it. There is no unattended reply agent on LinkedIn.
- Retention: a LinkedIn member's name and photo on a comment or mention are kept for no more than 24 hours, and the comment text for no more than 48 hours; after that we fetch them again from LinkedIn when you open the conversation. Your Page's own posts and replies are kept for 6 months, and statistics for 12 months.
- What we never do: LinkedIn member data from your Page never becomes a lead, a CRM record, an advertising audience or ad targeting. We never export it, sell it or combine it with other data, and it is shown only to members of your brand's workspace. Answers to your own LinkedIn lead forms are the one exception: people send them to you as leads, so they are stored as leads until you delete them.
- Deletion: when you disconnect the Page in Settings we revoke our access at LinkedIn and delete what we stored for that Page. Posts already published stay on LinkedIn.
5. AI processing
Brand OS uses artificial-intelligence models to draft and improve content and suggestions. Some processing is performed by third-party AI providers under contract, acting only on our instructions. We do not permit your private account or Meta data to be used to train publicly available models. You remain responsible for reviewing AI-generated content before it is published.
7. Data retention
We keep your data while your account is active. When you disconnect a social account, we revoke and delete the associated access tokens. When you delete your workspace or account, or ask us to delete your data, we remove it within 30 days, except where we must retain limited records to meet legal obligations. See the Data Deletion page.
8. Your rights and choices
You can access, correct, export, or delete your information. You can disconnect any social account from within the app, and you can request deletion of your data at any time by contacting us at privacy@aifactory.fyi. Depending on where you live, you may have additional rights under local law.
10. Security
We protect data in transit with encryption, restrict access on a need-to-know basis, and store access tokens with safeguards appropriate to their sensitivity. No system is perfectly secure, but we work continuously to protect your information.
11. Children
Brand OS is a business tool intended for adults and is not directed to children.
12. International processing
We may process and store information in countries other than where you live. Where we do, we take steps to ensure your information remains protected in line with this policy.
13. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the effective date above and, where appropriate, notify you in the app.
14. Contact
Questions about this policy or your data? Email privacy@aifactory.fyi.