1. Scope
This Policy applies to information processed through the Services. It does not control the independent privacy practices of third parties such as LinkedIn, Google/YouTube, Stripe, hosting providers, email providers, artificial-intelligence providers, or other platforms that you choose to connect. Their policies govern their own processing.
When an organization provides you access to a BLOS tenant workspace, that organization may be the primary decision-maker for information entered into its workspace. We process that information to provide the Services to the organization and its authorized users.
2. Information we collect
Account and organization information
We may collect your name, email address, password hash, organization name, tenant role, account status, communication preferences, and information you submit when registering, signing in, requesting support, or managing a workspace.
Workspace and content information
We process brand profiles, campaign data, prompts, drafts, articles, images, media references, approval records, calendars, publishing schedules, tracking parameters, analytics, notes, and other content that authorized users create, upload, generate, or store in the Services.
Billing and subscription information
We process plan selections, subscription status, billing interval, amounts, invoice references, payment status, renewal and cancellation dates, and Stripe customer or subscription identifiers. Payment card details are collected and processed by Stripe; we do not store complete payment-card numbers or security codes.
Connected-account information
When you connect a third-party service, we may receive account identifiers, profile or organization names, authorized organization Pages or channels, permissions or scopes, access-token information, token expiration dates, post or video identifiers, publishing results, and API response data needed to operate the connection.
Device, usage, and security information
We may collect IP address, browser and device information, session identifiers, login and audit events, request timestamps, error messages, health-check results, usage counters, and activity needed to secure, operate, diagnose, and improve the Services.
Communications and marketing information
We process sender and recipient information, delivery status, campaign participation, unsubscribe choices, support correspondence, and whether you consented to marketing or product-update messages.
3. How we use information
We use information to:
- create and administer accounts, tenants, roles, and workspaces;
- provide content generation, approval, scheduling, publishing, analytics, billing, and communication functions;
- authenticate users and connected accounts and maintain secure sessions;
- process subscriptions, invoices, renewals, cancellations, refunds, and entitlement limits;
- send welcome, service, billing, security, publishing, and consent-based marketing communications;
- prevent fraud, abuse, duplicate transactions, unauthorized access, and security incidents;
- maintain audit trails, diagnose errors, enforce agreements, and comply with law;
- improve the Services using operational, aggregated, or de-identified information; and
- carry out other purposes disclosed when information is collected or with your consent.
Where applicable law requires a legal basis, we rely on performance of a contract, consent, legitimate business interests, compliance with legal obligations, and protection of users and the Services.
4. LinkedIn and connected services
Before you connect LinkedIn, you choose whether to authorize the connection and review the permissions requested by LinkedIn. Depending on the permissions granted to the application, we may receive your LinkedIn member identifier, name, email address, organization Page identifiers and names, administrative relationship to a Page, authorization scopes, access tokens, token expiration information, and publishing results.
We use LinkedIn information only to authenticate the connection, display eligible organization Pages, perform actions you request, verify connection health, diagnose publishing failures, and maintain required operational and audit records. We do not sell LinkedIn member data or use LinkedIn data for unrelated advertising.
Access credentials are treated as confidential, stored in encrypted form where supported by the Services, and not displayed back to tenant users or platform administrators after storage. LinkedIn may independently process information under the LinkedIn Privacy Policy and its user and developer agreements.
You may withdraw authorization by disconnecting the LinkedIn connection in the Publishing Center, revoking access through LinkedIn, or contacting us. Disconnecting stops future API access but does not automatically remove records we must retain for billing, security, legal compliance, dispute resolution, or reliable audit history.
5. Google and YouTube connected services
Information we receive. When you authorize the connection, and depending on the scopes you grant, we may receive your Google account identifier, YouTube channel identifier and name, authorization scopes, OAuth access and refresh tokens, token expiration information, uploaded video identifiers, upload and processing status, and API response data needed to operate the connection.
How we use it. We use Google user data only to authenticate the connection you initiated, display your connected channel, upload videos you explicitly select and submit, apply the title, description, tags, and privacy status you choose, verify connection health, diagnose publishing failures, and maintain required operational and audit records. All uploads default to Private visibility; the Services never make a video public automatically or without your explicit selection. We do not use Google user data to train artificial-intelligence or machine-learning models. We do not read, download, or analyze videos or channel content beyond what is required to perform the actions you request.
Limited Use disclosure. BLOS Content Intelligence's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Storage and protection. OAuth tokens are treated as confidential, stored in encrypted form, and are not displayed back to tenant users or platform administrators after storage. Google user data is not sold, is not used for advertising, and is not shared with third parties except as necessary to operate the connection you authorized or as described in "How information is shared."
Revoking access. You may withdraw authorization at any time by disconnecting the YouTube connection in the Publishing Center or by revoking BLOS Content Intelligence's access in your Google security settings. Disconnecting stops future API access and invalidates stored tokens, but does not automatically remove operational records we must retain for billing, security, legal compliance, dispute resolution, or reliable audit history.
8. Retention and deletion
We retain information for as long as reasonably necessary to provide the Services, maintain tenant records, fulfill transactions, comply with legal and accounting obligations, resolve disputes, enforce agreements, preserve security and audit evidence, and support backups and disaster recovery.
Retention periods vary by data type and purpose. Connected-account tokens may be removed or invalidated when a connection is deleted, revoked, or expires. Billing, invoice, security, and audit records may be retained after an account or connection ends when required for legitimate business or legal purposes.
To request access, correction, export, disconnection, or deletion, email support@balthroplogic.com with the subject "Privacy or Data Deletion Request." We may need to verify your identity and authority over the relevant account or tenant. Deletion from active systems may not immediately remove information from encrypted backups, although backup data will be protected and removed through ordinary retention cycles. See also our Data Deletion Instructions.
9. Security
We use administrative, technical, and organizational safeguards designed to protect information, including access controls, tenant isolation, password hashing, encrypted credential storage, HTTPS transport, session protections, audit logging, webhook signature verification, and limited administrative roles. No system can guarantee absolute security, and users are responsible for protecting passwords, devices, connected accounts, and access granted to team members.
10. Privacy choices and rights
Depending on your location, you may have rights to request access, correction, deletion, portability, restriction, or objection to certain processing. You may also withdraw consent where processing relies on consent.
- You may update account and organization information within the Services where available.
- You may disconnect LinkedIn, YouTube, or another integration in the Publishing Center and revoke authorization at the connected platform (for Google, via your Google security settings).
- You may unsubscribe from marketing through the link in a marketing email or your communication preferences.
- Unsubscribing from marketing does not stop essential account, billing, security, legal, or service communications.
We will not discriminate against you for exercising applicable privacy rights. Requests may be limited or denied where permitted by law, including when we cannot verify identity or when retention is required.
11. Children
The Services are designed for businesses and adults and are not directed to children under 18. We do not knowingly collect personal information from children through the Services.
12. International processing
Information may be processed in the United States and other locations where we or our service providers operate. Those locations may have data-protection laws different from the laws where you live. Where required, we use appropriate contractual or legal safeguards.
13. Changes to this Policy
We may update this Policy as the Services, integrations, business practices, or legal requirements change. The updated Policy will be posted at this URL with a revised effective date. Material changes may also be communicated through the Services or by email.
14. Contact us
Balthrop Logic Technologies LLC
BLOS Content Intelligence
Email: support@balthroplogic.com
Billing inquiries: billing@balthroplogic.com