Skip to content
CreatorOS
TermsEarly access
Get early access ↗
[ LEGAL ]

Privacy Policy

Status: Ready for Repository Owner review — not yet effective.
Drafted: 2026-08-17

This is not legal advice, and it is not yet effective. It describes CreatorOS’s actual, current data handling as precisely as possible, including where a described capability (such as a third-party processor) is selected but not yet connected. Have counsel review this before relying on it.

1. Who we are

CreatorOS is operated by Disproportionate Upside, LLC, a Texas limited liability company, United States (“CreatorOS”, “we”, “us”).

Contact: privacy@creator-os.ai

2. Scope

This policy covers the CreatorOS web application, the CreatorOS iOS application, and the CreatorOS API and agent interface. CreatorOS is currently available only as a closed, invite-only beta limited to 50 participants.

3. What we collect

Account information. When you sign in with Google, Apple, Facebook, or TikTok we receive your name, email address, and a provider identifier. We do not receive your password. We store an encrypted access token for each publishing account you connect.

Brand information. Everything you tell us during onboarding: your identity and niche, audience, tone and voice preferences, words you want used and avoided, emoji rules, pacing preferences, visual references, and growth goals. If you ask us to analyse an existing public social account to pre-fill your brand profile, we retrieve publicly available posts from that account, use them to produce that inference, and then delete them.

Media you upload. Video and image files, and everything derived from them: transcripts, timing data, editorial analysis, rendered variants, and cover frames.

Content you create. Captions, hashtags, chat messages exchanged with our editorial assistant, edit decisions, and approvals.

Publishing and performance data. What you published, where, and when; platform permalinks; and the reach, impression, engagement, and aggregate audience-demographic figures each platform returns for your posts. Demographic data is aggregate only. We never receive or store the identity of anyone who views your content.

Technical data. IP address, device and browser type, and application logs. Our logs are structured to exclude media content, transcript text, prompt content, and credentials.

4. What we do with it

PurposeData used
Create and secure your accountAccount information
Generate brand-aligned contentBrand information, media, content
Transcribe and analyse your videoMedia
Publish on your instructionContent, publishing tokens
Report your performancePublishing and performance data
Improve editorial qualityYour “proud of this?” responses, aggregated
Operate, debug, and secure the serviceTechnical data

We do not sell your personal information. We do not serve advertising. We do not use your media to train our own models.

5. Automated processing and AI

CreatorOS uses automated systems to transcribe your video, analyse it, propose edits, generate captions, and score how well output matches your brand. These are proposals. Nothing is published without your explicit approval, and every publishable output requires a human approval action from you.

Where an output was machine-generated or machine-modified, we record that. It is included in your account data export today; a disclosure surface inside the review screens themselves, shown before you approve, is still being built.

AI agents connected through our API can read your data and prepare drafts on your behalf. They cannot approve or publish. Only you can.

6. Who we share it with

We use the following processors today. Each receives only what its function requires.

ProcessorReceivesPurpose
Amazon Web Services (S3)All stored media and dataHosting and storage
Google, Apple, Facebook, TikTokName, email, provider identifierSign-in
Instagram, TikTok, YouTube, XContent you approve for publishingPublishing and performance retrieval

Sign-in and publishing are things you direct us to do — connecting your own account and approving each publish — not automatic data sharing. No live developer credentials are configured for these providers in any environment CreatorOS runs in today, so a live sign-in or a live publish cannot complete end-to-end yet. This will change as each platform’s app review and credential provisioning completes.

We have selected, but not yet connected, further processors for transcription (AssemblyAI), video understanding (Twelve Labs), editorial reasoning (Google Gemini), stock footage (Pixabay), and a music catalogue (Epidemic Sound). None of them is connected in any environment CreatorOS runs in today — no media has been sent to any of them. We will add each to this table, with its verified training, retention, residency, and deletion behavior, before it goes live. We do not publish assumed terms for a processor that isn’t live.

We may also disclose information where legally required, or to protect the rights and safety of our users.

7. International transfers

Once processors outside your country of residence are actually connected (see §6), they may process data outside your country of residence. Each processor’s processing regions and transfer mechanism will be identified here, and this section updated, before that processor goes live. No such transfer is happening today.

8. How long we keep it

Retention periods for media are approved (2026-08-19). Some categories of data have no defined retention period yet — those are stated plainly below, not estimated.

  • Source media you upload (raw video): scheduled for deletion 90 days after upload. This schedule is computed and stored the moment you upload, but the automated job that actually performs that deletion has not been built yet — today, media is only deleted when you delete it yourself or delete your account (see §9).
  • Derived media — transcripts, renders, and variants: retained while your account is active.
  • Temporary uploads (in-progress, not-yet-processed files): deleted after 24 hours.
  • Published post records and performance data: no defined retention period yet; retained for the life of your account.
  • Account data after deletion: none. Deletion is immediate — see §9.
  • Application logs: no defined retention period yet.

Content retrieved from a public account for brand bootstrap is deleted once the inference is produced.

9. Your choices and rights

You can, at any time:

  • view and correct everything in your brand profile;
  • export your profiles, posts, and performance data in a machine-readable form;
  • disconnect any publishing account, which revokes our stored token;
  • delete an individual Post along with its media and derivatives; and
  • delete your account entirely.

Deleting your account removes your stored media, brand profiles, and access tokens, and we request deletion from each processor that received your media. We track the deletion state for each. Deletion does not remove content you have already published to a social platform — you control that on the platform itself.

Depending on where you live you may have additional rights, including access, correction, portability, restriction, objection, and the right to complain to a supervisory authority. Contact us to exercise them.

Beta participants are located in the United States, the European Union, and the United Kingdom, so GDPR, UK GDPR, and CCPA/CPRA may each apply depending on where you live. Our lawful basis for processing your account, brand, and content information is performance of our contract with you (providing the service you signed up for); for technical data, our legitimate interest in operating and securing the service. Where required, we rely on your consent — for example, before retrieving a public account for brand bootstrap (§3). You may withdraw consent at any time without affecting processing already carried out.

10. Security

We encrypt data in transit and at rest. Media is accessible only through short-lived signed URLs. Access tokens are encrypted. We follow least-privilege access and never log credentials, tokens, signed URLs, or transcript content.

No system is perfectly secure, and we cannot guarantee absolute security.

11. Children

CreatorOS is not directed to, and may not be used by, anyone under 18. We do not knowingly collect information from children. If we learn we have, we will delete it.

12. Third-party stock content

We plan to supply B-roll footage through Pixabay under its content licence. Pixabay is not yet connected in any environment CreatorOS runs in today (see §6) — no stock footage is currently being retrieved on your behalf. Once live, Pixabay will not indemnify us or you against claims arising from its catalogue, and we will record which stock assets appear in each of your Posts so that any asset later found to be infringing can be traced and addressed.

13. Changes

We will post any change here and update the date above. Material changes will be notified to you directly before taking effect.

14. Contact

privacy@creator-os.ai

CreatorOS

Beautiful content, without the grind.

TermsPrivacyBack to top ↑© 2026 CreatorOS