This Privacy Policy explains how My A.I - OS(“the Service”, “we”, “us”), operated by Digital Jockey, collects, uses, shares, and protects your information. My A.I - OS is a social-media management platform that lets you connect your social accounts, create and schedule posts, generate content with AI tools, and view advertising analytics across your connected ad accounts.
By creating an account or connecting a third-party platform, you agree to the practices described here. If you do not agree, please do not use the Service.
1. Information We Collect
Account information
When you register we collect your email address, a username and/or full name, and a securely hashed password. If you sign in with Google, we receive your Google account identifier, name, email address, and profile picturefrom Google’s Sign-In service. We never receive or store your Google password.
Connected social & advertising accounts (OAuth)
When you connect a platform — Facebook, Instagram, TikTok, Pinterest, LinkedIn, YouTube, Google Business Profile, or Google Ads— we receive and store the access and refresh tokens that authorize the Service to act on your behalf, together with the identifiers needed to publish and read data (for example: Facebook Page IDs and Page tokens, Instagram business-account IDs, your YouTube channel handle, TikTok open ID and username, and your Pinterest boards). These tokens are encrypted at rest. We request only the permission scopes required for the features you use.
Content you create and upload
We store the content you create in the Service: post titles, captions, keywords, scheduling times, and the images and videos you upload. Uploaded media is held in our cloud storage and transmitted to the platforms you explicitly select as publishing targets.
AI tool inputs and outputs
The Service provides AI-assisted creation tools. When you use them we process the prompts, briefs, and any reference material you provide, and we store the generated results:
- Video Scripts & captions— generated with Google’s Gemini models.
- Image Generation— generated with Cloudflare Workers AI.
- Video Generation— generated via a hosted Hugging Face model.
- SEO Optimizer— your product/topic brief, seed keywords, optional target location, and any reference files you upload (PDF, text, or images) are processed with Google’s Gemini models to generate headlines, meta tags, keyword clusters, and content. Uploaded reference files and the generated results are not stored by the Service — they exist only for the duration of the request.
- Marketplace Lister browser extension— if you install our Chrome extension, then on pages where you click Extractit reads that product page’s public details (title, price, description, brand/SKU, category, tags and image addresses) and saves them to your account as a listing you can edit. We store those listing details, their status history (draft, queued, posted, sold) and the address of the page they came from. Chrome grants the extension access to websites when you install it (Chrome describes this as permission to read and change your data on sites you visit), because the browser cannot ask for site-by-site access from a side panel. That access is only ever used when you click Extract: the extension does not read pages in the background, track your browsing history, or collect anything from sites where you never click Extract. It signs in with a device token you create in the app; we store only a one-way hash of that token, and you can revoke any install at any time from the Marketplace page. When you choose to fill a Facebook Marketplace form, the listing you approved and its photos are placed into that form in your own browser— we never receive your Facebook credentials, and the extension does not publish anything: you review the form and press Publish yourself.
- Website URL analysis— when you enter a page address in the SEO Optimizer’s Analyze Website URLbar, our servers fetch that page as an ordinary visitor would and read its public content: title tag, meta description, canonical and OpenGraph tags, headings, image ALT text, and the visible body copy. That extracted content, together with any target keywords you type, is sent to Google’s Gemini models to produce the audit. We only request pages that are publicly reachable, and we do not storethe URL, the fetched page, or the audit — they exist only for the duration of the request. Analyze only pages you own or are authorized to audit.
- Ad Studio— the ad designs you create are stored on our servers so you can reopen and edit them: the design document (its title, target month, the client it is filed under, and the full canvas contents — text, colors, positions, and links to any images you place), plus a rendered preview image of each size. When you use Create with AI, your text prompt and any reference images you upload are sent to Google’s Gemini models, which analyze the reference’s layout structure, color palette, and typography so the design can be rebuilt as editable layers. Reference images are not stored— they are held only for the duration of the request. What we do retain is the design preferences learned from them (color palettes, typography choices, and anonymous layout skeletons containing no copy), so later generations better match your brand. You can view and delete these learned preferences at any time from within the Ad Studio.
- Brand guidelines documents— if you upload a brand-guidelines file (PDF, DOCX, TXT or MD) in the Ad Studio’s Brand panel, its contents are sent to Google’s Gemini models to extract your brand rules: color hex codes, fonts and type hierarchy, visual do’s and don’ts, tone of voice, taglines and key terminology. The uploaded file itself is not stored— it is held only for the duration of that request. What we retain is the extracted rules, saved alongside your other learned design preferences so later generations stay on brand. They are shown to you in the Brand panel and you can delete them there at any time.
- Web research for AI designs— when you explicitly turn on research for an AI generation, we send a search query(built from the brand name, website or industry you provide — never from your designs, files or account data) to a web search provider: Tavily or Serper if configured, otherwise DuckDuckGo. Only the query leaves our servers. The public results are used to inform that one design and are not stored. Research is off unless you ask for it.
- Web images in AI designs— with the same opt-in switch, a generation may also fetch a publicly available imagematching your description and place it as the design’s background layer. We download that image and store a copy on our own storage, for two reasons: a hotlinked image would break your design when the original moves or is deleted, and browsers block canvas exports of images loaded from other sites. Only your search text leaves our servers. You are responsible for the rights to any image you keep in a published design— search results are not licence-cleared, so replace anything you are not entitled to use. Deleting the artwork deletes the copy.
Advertising performance data
If you use the Ad Manager, we perform a read-only sync of performance metrics — such as impressions, reach, clicks, spend, conversions, and (for Meta) the aggregate e-commerce results of your ads: conversion value (revenue), add-to-cart and purchase counts and values, plus campaign settings such as budget, bid strategy and attribution window — for the Google Ads and Meta (Facebook/Instagram) Ads accounts you connect. This is used to display analytics and generate optimization recommendations.
To find those accounts we read the list of ad accounts your connection can access, including the ad accounts held inside your Meta Business Portfolios(we request Meta's ads_read, ads_management and business_managementpermissions for this), together with each account's name, ID, currency, status and campaign list. The sync itself never writes to your ad accounts. The only change we can make on your behalf is a Google Ads recommendation you explicitly choose to apply from the Recommendations tab; nothing is applied automatically.
Technical information
We use a single HttpOnly authentication cookie to keep you signed in, and we retain standard server logs for security and reliability. We do not use third-party advertising or cross-site tracking cookies.
2. How We Use Your Information
- Authenticate you and keep your account secure.
- Publish and schedule posts to the platforms you choose, at the times you set.
- Generate scripts, images, video, and SEO content on your request.
- Sync and display advertising analytics for your connected ad accounts.
- Provide audit and optimization recommendations.
- Operate, maintain, secure, and improve the Service.
3. Third-Party Platforms & API Compliance
The Service integrates with third-party platforms through their official APIs. Your use of those integrations is also subject to each platform’s own terms and policies, and our use of their APIs complies with them, including:
- Meta Platform Termsand Developer Policies (Facebook & Instagram).
- TikTok Developer Terms and Content Posting / Content Sharing guidelines.
- Pinterest Developer Guidelines and API Terms of Service.
- LinkedIn API Terms and Google API Services User Data Policy (YouTube, Google Business Profile, Google Ads, and Google Sign-In).
My A.I - OS’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
We rely on the following service providers to process data on our behalf: Supabase (database and media storage), Render (application hosting), the AI providers named above (Google Gemini, Cloudflare Workers AI, and Hugging Face), and a web search provider (Tavily, Serper or DuckDuckGo) which receives only the search queries described above, solely to fulfil the requests you make. We do not sell your personal information, and we do not use your content to train our own advertising or profiling models.
4. How We Share Information
We disclose information only:
- To the social platforms you connect, to carry out the actions you request (for example, publishing a post you scheduled).
- To the service providers listed above, acting under our instructions.
- Where required by law, or to protect the rights, safety, and security of our users and the Service.
5. Data Retention
We retain your account information for as long as your account is active. OAuth tokens are kept until you disconnect the relevant profile, after which the stored token is deleted. Posts and uploaded media are retained until you delete them or your account. Deleting a post from the Service removes the local record and its associated media where it is no longer referenced. Ad Studio designs, their individual sizes, and their rendered previews are retained until you delete them or your account; learned design preferences are retained until you delete them individually or delete your account.
6. Your Rights & Choices
- Disconnect a platformat any time from the scheduler — this deletes the OAuth tokens we hold for it and removes its scheduled posts.
- Delete content— you can delete individual posts and their media from the dashboard.
- Revoke accessdirectly in each platform’s own settings (for example, the Business Integrations or connected-apps section of Facebook, Instagram, TikTok, Pinterest, LinkedIn, or your Google Account).
- Access or delete your account and data — use our Data Deletion & Privacy Requests page to request access to, correction of, or deletion of your personal data. We will respond within a reasonable timeframe.
7. Data Security
We protect your data with encryption of stored OAuth tokens, HttpOnly authentication cookies, and encrypted transport (HTTPS/TLS) for all traffic between your browser, the Service, and the platforms we integrate with. No method of transmission or storage is completely secure, but we work to protect your information using industry-standard safeguards.
8. Children’s Privacy
The Service is intended for professional and business use and is not directed to individuals under 18. We do not knowingly collect personal information from children. If you believe a child has provided us information, please contact us and we will delete it.
9. International Data Transfers
We and our service providers may process and store your information in countries other than your own. Where we transfer data internationally, we take steps to ensure it remains protected consistent with this Policy.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above and, where appropriate, notify you within the Service.
11. Contact Us
For any privacy question, data-access request, or account deletion, please use our Data Deletion & Privacy Requests page, which explains how to delete your data yourself and how to submit a formal request.