Scope and roles
This Privacy Policy applies to OsmoGrowth, including the application at growth.osmosync.com, its APIs, and related support communications. OsmoGrowth is operated by OsmoSync LLC ("OsmoSync," "we," "us," or "our").
OsmoSync is the controller of account, access, security, billing, and service-operations data. When a business customer submits or connects data about its organization, customers, or team, that business may be the controller and OsmoSync may process the data on its instructions. A signed order, data-processing agreement, or other written agreement controls if it conflicts with this policy.
Data we collect
We collect data in the following categories:
- Account and identity data. Name, business email, profile image, authentication provider, provider identity identifier, email-verification status, Google hosted-domain evidence, account status, and sign-in timestamps.
- Workspace data. Organization name, memberships, roles, invitations, entitlements, audit events, preferences, notification settings, and sync settings.
- Content-intelligence data. Creator profiles and URLs you add, labels, notes, saved posts, channel membership, content, media references, public engagement metrics, classifications, analyses, briefs, and feedback.
- Commercial outcome data. If you choose to add it, campaign attribution, appointments, leads, opportunity context, and aggregated performance measures used to connect content with business outcomes.
- Support and communications. Messages, issue details, and other information you send when requesting help or exercising a legal right.
- Technical and security data. IP address and request metadata in infrastructure logs, device and browser information, normalized route names, sampled performance measurements, error events, authentication events, and security audit records.
Please do not submit sensitive personal information, confidential third-party data, or data you are not authorized to use. OsmoGrowth is a business product and is not intended for children or for consumer health, financial, biometric, or similarly sensitive records.
Google account data
Google OAuth is used to authenticate eligible Google Workspace users. We currently request the minimum identity information needed to sign you in and evaluate Workspace eligibility, such as your Google account identifier, name, verified email, profile image, and hosted-domain claim. A hosted-domain claim indicates that Google manages the account for an organization; it does not reveal or prove the organization's subscription tier.
OsmoGrowth does not currently request access to Gmail, Google Drive, Calendar, Contacts, or other Google Workspace content. If a future feature needs additional Google scopes, we will explain the exact data and purpose immediately before asking for consent. We will not use a newly granted scope for an undisclosed purpose.
Google user data is used only to provide or secure user-facing OsmoGrowth features. We do not sell it, use it for advertising, or transfer it to data brokers. You may revoke OsmoGrowth's Google access from your Google Account controls, although revocation may prevent sign-in.
Creator and public-source data
When you add a creator, profile, or public URL, OsmoGrowth may retrieve public profile details, posts, media references, timestamps, and engagement metrics from the source platform or an approved data provider. We preserve source and retrieval information so results can be traced, corrected, refreshed, or removed when the source changes.
Public availability does not remove privacy, copyright, or platform obligations. Provider-backed collection for LinkedIn, YouTube, Instagram, X, and other sources may remain disabled until its source terms and retention rules are approved. We do not treat an inferred identity, audience, or business attribute as a verified fact. Cross-platform identity links remain reviewable and reversible.
If a public creator record is inaccurate or should no longer appear, contact privacy@osmosync.com with the source URL and requested correction. We may ask for reasonable verification before altering another person's record.
How we use data
We use the data described above to:
- authenticate users, establish Workspace eligibility, provision accounts, and enforce organization permissions;
- retrieve, organize, analyze, compare, and present creator and content information requested by a workspace;
- generate evidence-backed recommendations, creative rules, briefs, drafts, and performance insights when those features are enabled;
- operate sync jobs, prevent duplicate work, meter usage, enforce limits, and attribute outcomes;
- secure, troubleshoot, monitor, and improve the reliability and accessibility of the service;
- communicate about the account, service changes, security, support, and requested notifications; and
- comply with law, enforce our Terms, and protect users, OsmoSync, and third parties.
Where applicable law requires a legal basis, we rely on performance of our contract, legitimate interests in operating and securing a B2B service, compliance with legal obligations, or consent where consent is the appropriate basis. You may withdraw consent for future processing without affecting processing already performed lawfully.
AI-assisted features
Some current or planned features use AI to classify public content, summarize evidence, suggest creative rules, draft material, or answer questions. When activated, the relevant workspace context and selected source material may be sent through OsmoSync's controlled AI gateway to the model provider configured for that feature.
We do not use private customer content to train a shared OsmoGrowth model or to create another customer's personality. Outside creators may contribute transferable mechanics, not a user's private voice, claims, or confidential business context. Material AI-provider changes will be disclosed before the new processing begins.
Retention and deletion
We keep account and workspace data while the account is active and for the period reasonably necessary to provide the service, secure it, resolve disputes, meet legal obligations, and enforce agreements. Operational logs and raw provider payloads are retained for shorter periods based on troubleshooting, security, and reprocessing needs. Backups expire on their managed rotation.
Public-source records may be refreshed, tombstoned, or removed when a source becomes private, unavailable, deleted, or materially corrected. We keep private workspace relationships separate from reusable public facts. Removing the last workspace subscription does not automatically prove that a public fact must be erased, but a valid privacy or source-removal request will be reviewed.
Self-service account deletion is not yet available during the controlled beta because identity, workspace ownership, customer data, and required audit history must be handled together. You may request deletion now by email. We will complete valid requests subject to legal, security, fraud, backup-cycle, and dispute-preservation exceptions.
Your privacy rights
Depending on where you live, you may have the right to know or access personal data, correct it, delete it, restrict or object to processing, receive a portable copy, withdraw consent, or appeal a decision. You may also have the right not to be discriminated against for exercising a privacy right. Because we do not sell personal information or share it for behavioral advertising, there is no sale or advertising-sharing activity to opt out of.
Submit a request to privacy@osmosync.com. Describe the account, workspace, source URL, and request. We will verify your identity and authority using information proportionate to the request, and respond within the period required by applicable law. Authorized agents may submit requests where the law permits, subject to verification.
You may lodge a complaint with your local privacy or data-protection authority. Contacting us first gives us an opportunity to address the issue directly, but it is not required.
Security and international transfers
We use organization-scoped authorization, cookie-bound sessions, row-level database controls, encryption in transit, restricted service credentials, audit events, logging redaction, backups, monitoring, and reviewed approval boundaries. No online service can guarantee absolute security. If you believe an account or workspace has been compromised, contact us promptly.
OsmoGrowth and its providers may process data in countries other than your own. Where required, we use contractual, organizational, or other lawful safeguards for international transfers. A business customer may request additional processing terms before adding regulated data.
Changes and contact
We update this policy when product behavior, providers, or legal requirements materially change. We will change the effective date and, when required, provide an in-product notice or request new consent before using data for a materially different purpose.
Privacy requests: privacy@osmosync.com
Legal notices: legal@osmosync.com
Operator: OsmoSync LLC, operating OsmoGrowth