← OSOA
Privacy Policy
Effective: August 3, 2026 · updated September 10, 2026 · OSOA Labs, Inc.
1. What we collect
- Account data: your name, email, business description, and the intake answers you give at onboarding (including your voice-calibration writing sample).
- Connected accounts: for email, you connect your Google account through Google's official one-click flow and grant a send-only permission: we store that permission token, we never receive your password and we cannot read your inbox. For channels like Instagram, the session is created by you through a guided flow and kept isolated per business; credentials are not stored.
- Reply routing (outbound only): outbound messages we send for you carry a reply address on an OSOA domain, so replies arrive in mailboxes we operate and are processed on your behalf. Those replies are used for your account only.
- Your content: the video files you upload for editing, the captions and posts we publish for you, and the performance numbers the platforms report back. Uploads are kept only as long as needed to edit and publish, and to show you your own history.
- Public research: publicly available information about your business and about comparable businesses near you, used to write your scripts and your calendar.
- People who write to you: the profile information and message history of people who comment on your posts or send you messages, processed on your behalf to answer them and take the conversation to a sale. This is data about people who contacted you first.
- Counterpart data (outbound only): where outbound is unlocked for your account, public profile information of the businesses your outreach contacts, processed on your behalf to write and reply.
- Billing: handled by Stripe; we never see or store full card numbers. At checkout Stripe records that you accepted these documents, together with your purchase. For presale purchases Stripe also keeps your card on file so the subscription can start on the day you get in, without asking you again.
2. How we use it
Only to operate the service: studying your market, writing your scripts, editing and publishing your content, answering the people who write to you, reporting to you, and learning from your own results to do it better (section 9 says exactly how). Where outbound is unlocked, also finding and verifying businesses to contact. We do not sell data. We do not use your data to serve ads. We do not train public models with your content.
3. AI processing
Message drafting and analysis use large language model providers (currently Anthropic) under their commercial API terms. Content sent for processing is not used by the provider to train their models per those terms.
4. Google user data
When you connect your Google account, this is exactly how your Google user data is handled:
- What we access: your Google account email address (to identify the connection) and a send-only permission (gmail.send). We cannot read, modify or delete anything in your mailbox, and we never see your password.
- How we use it: for one user-facing feature only: sending, from your own account, the messages OSOA prepares for your business conversations. Nothing else.
- Transfer: your Google user data is not sold, and not transferred to third parties, except as necessary to provide this feature (Google's own API), to comply with applicable law, or as part of a merger or acquisition with prior notice to you. It is never shared with data brokers or advertisers.
- Protection: the permission token is held in encrypted storage with least-access controls and per-client isolation.
- Retention and deletion: the token is kept only while your account is active. Disconnect in your Google security settings or ask us at hello@osoa.io and the stored token and related Google user data are deleted within 30 days.
- AI/ML: Google user data is never used to develop, improve or train AI or ML models, and is never transferred to third-party AI/ML services for that purpose.
OSOA's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. Retention and deletion
Your data is kept while your account is active. Ask us to delete your account and we remove your intake data, session states and dossiers within 30 days, keeping only what invoicing law requires. Write to hello@osoa.io.
6. Cookies and analytics
This site sets no tracking cookies and runs no third-party ad trackers.
7. Security
Per-client isolation (each client's accounts run in separate browser profiles), least-access infrastructure, and encrypted storage for anything sensitive. No system is perfectly secure; we will notify you without undue delay of any breach affecting your data.
8. Your rights
Access, correction, portability and deletion of your data, at the email above. If you are in a jurisdiction with specific privacy rights (GDPR, CCPA, LFPDPPP in Mexico), we honor requests under those frameworks.
9. It learns, and here is exactly what that means
The system gets better with use. That is most of what you are paying for, so it should be spelled out rather than hidden in a line about "improving the service".
- It learns from your own results. Every night it reads what went out for you in the last week and what came back: which openings got answered, which were ignored, which the quality judge rejected and why. From that it distills a short list of rules that the writer and the closer obey the next day. It is your results teaching your own account.
- What you correct outranks what it learned. When you tell the bot "never say it like that" or "do not contact these people", that becomes a rule of yours, and yours sit above anything the system worked out on its own. You are never arguing with your own tool.
- Your learning is yours. The rules distilled from your results are stored under your account and are not handed to another client, ever. Your voice calibration, your prices, your corrections and what it learned from your customers stay in your account.
- There is a shared layer, and it is ours, not another client's. On top of your rules the system also carries general lessons distilled from OSOA's own operation, the marketing we run for ourselves, where there is the most volume. They are abstract craft rules, the shape of "an opening that leads with a measurable result gets answered more often". They never contain another client's data, content, contacts or numbers, because they are not built from another client's account.
- It remembers the people it has talked to for you. So it does not repeat itself or contradict what it already said, the system keeps a short working note on each person or business it has had a conversation with on your behalf. That note belongs to your account and goes when your account goes.
- What it never does. None of this trains public models. Nothing you or your customers write is used to improve a model anyone else can use. The learning lives in text rules inside your account, not inside a model.
10. If you are a client: we handle that data for you, not for us
This section is the data processing agreement. It is part of these terms and you accept it at checkout, so there is no separate document to sign and nothing to negotiate. It governs the data of the people who write to your business.
- Whose data it is. The information of the people who comment on your posts or message your business is yours, not ours. You decide what it is used for. We only handle it to run the service for you, following your configuration, and never for our own purposes, never to sell, and never to train public models.
- Who else touches it. To run the service we use: Anthropic (writes the drafts), Google (sends mail from your Gmail), Meta (Instagram), Stripe (payments) and Supabase (database). They process it under their own commercial terms and none of them may read it for their own use or train their models on it. If we add a provider that handles this data, we list it here first, and if a new one does not work for you, you can cancel and we refund the unused part of your term.
- Where it lives. Our infrastructure and these providers are in the United States, so if you or the people who write to you are elsewhere, the data travels there to be processed. By connecting an account you are instructing us to do that.
- Confidentiality and security. Only the people who need it get access. Each client runs in an isolated browser profile with separate storage, and anything sensitive is encrypted. We tell you within 72 hours of confirming any breach that affects your data, with what we know and what we are doing.
- When someone asks you to delete them. If a person asks your business to access, correct or delete their data, tell us and we do our part within 10 business days, at no cost, so you can answer them on time.
- When you leave. Ask us and we delete the data we hold for you within 30 days, or hand it back first if you prefer, keeping only what invoicing law makes us keep.
- Proof. Once a year, if you ask in writing, we send you a summary of how this data is handled and who touches it. If your own regulator requires a real audit, we cooperate at your cost.
11. Changes
Material changes to this policy are notified by email to active subscribers before taking effect.