OSMO by Commerciax

Privacy Policy

Last updated: August 20, 2026

OSMO is an AI-powered marketing platform built by Commerciax. This Privacy Policy explains what information we collect, how we use it, and how we protect it when you use OSMO at osmo.commerciax.com.

1. Information We Collect

  • Account information: your name, email address, and password when you register.
  • Business information: company name, website, industry, and services you provide to help OSMO personalise your content.
  • Connected social accounts: when you connect Facebook, Instagram, LinkedIn, X, or other platforms, we store access tokens to post content on your behalf.
  • Connected TikTok account: when you connect TikTok, we store your OAuth access and refresh tokens (encrypted), and your TikTok nickname, username, and avatar URL. Immediately before each post we also fetch, but do not separately store, your account’s current posting options from TikTok. See Section 4 for exactly what we do and do not do with it.
  • Connected Google account: if you choose to connect Gmail for outreach, we store the app password you generate in your own Google account, encrypted, together with the email address of that account. See Section 5 for exactly what we do and do not do with it.
  • Content you create: blogs, social posts, outreach emails, and uploaded files processed through OSMO.
  • Usage data: pages visited, features used, and interactions with the AI chat, used to improve the product.

2. How We Use Your Information

  • To operate and personalise the OSMO platform for your business.
  • To post content to your connected social accounts when you approve it.
  • To improve our AI models and content recommendations (using anonymised, aggregated data only). This never includes Google user data — data obtained through Google APIs is never used to develop, improve, or train generalized artificial-intelligence or machine-learning models.
  • To send transactional emails such as reports and notifications you have requested.
  • We do not sell your data to third parties.

3. Social Platform Permissions

When you connect a social account (e.g. Facebook or Instagram), OSMO requests only the permissions needed to manage and publish content on your behalf. We do not access your personal messages, friend lists, or any data beyond what is necessary to operate the features you have enabled. You can disconnect any social account at any time from Settings → Integrations.

4. TikTok

OSMO connects to TikTok through TikTok’s Content Posting API so you can publish videos to your own TikTok account from OSMO. This section explains exactly what we receive, what we store, and what we do with it.

What we receive and store. When you connect TikTok, TikTok issues an OAuth access token and refresh token, which we store encrypted so OSMO can act on your behalf. TikTok also returns your account’s nickname (display name), username, and avatar URL, which we store to show you which account is connected. Immediately before every post, we call TikTok’s Creator Info endpoint to read your account’s current posting options — the privacy levels you are allowed to choose from, whether Comment, Duet, and Stitch are turned off at the account level, and the maximum video length TikTok allows for your account — so you always choose from options TikTok actually offers you right now. Those posting options are fetched fresh for each post; OSMO does not keep a separate stored copy of them.

What we do with it. We use it for one purpose: to publish, only after you have expressly confirmed that specific post, the exact video and caption you approved, with the visibility level you personally chose from your account’s real options, and with Comment, Duet, and Stitch left off unless you turned them on for that post. We show your TikTok nickname, username, and avatar in Settings → Integrations so you can see which account is connected. We do not read your TikTok inbox, messages, followers, or any other TikTok data.

No automatic posting. TikTok requires your active, per-post confirmation before anything is sent, so OSMO never publishes a TikTok post automatically. TikTok is excluded from OSMO’s automated and autopilot publishing paths — any TikTok post those paths would otherwise send is held for you to review and confirm yourself before it goes anywhere. If Direct Post has not yet been approved for your account, your video is delivered as a draft to your TikTok inbox and you finish publishing it inside the TikTok app.

What we never do. We do not use TikTok data to develop, improve, or train generalized artificial-intelligence or machine-learning models. We do not sell your TikTok data, and we do not share it with anyone beyond the sub-processors listed in Section 7.

Retention and deletion. Disconnecting TikTok from Settings → Integrations revokes OSMO’s access with TikTok and erases your stored TikTok access and refresh tokens, so OSMO can no longer act on your behalf. The connection record itself is marked disconnected and retained, including the nickname, username, and avatar URL, so your account history stays intelligible to you; it holds no credentials at that point. Deleting your OSMO account removes that record and its profile information entirely — see our Data Deletion page. You can also revoke OSMO’s access at any time directly from TikTok, independently of OSMO, from your TikTok app’s account settings (Profile → Settings and privacy → Security → Manage app permissions).

TikTok’s own handling of your data is described in TikTok’s Privacy Policy.

5. Google User Data (Gmail)

OSMO connects to your Google account only when you explicitly choose to connect Gmail for outreach. OSMO does not use “Sign in with Google” for this and does not hold a Google authorization grant. Instead, you generate an app password inside your own Google account — a single-purpose credential that you create, and that you can revoke at any time — and provide it to OSMO. OSMO uses it to connect to Google’s standard outgoing mail server (smtp.gmail.com) to send mail.

What we do with it. We use the credential for one purpose only: to send the outreach emails you have written and approved inside OSMO, from your own Gmail address. OSMO does not read, search, download, index, delete, or modify any message in your mailbox, and never connects to your mailbox over IMAP or POP.

An important distinction. A Google app password is not permission-limited the way an authorization grant is — it is a credential for your mail account. Our send-only handling of it is a commitment we make and enforce in our software, not a restriction Google imposes on us. We state this plainly rather than implying a technical guarantee we do not have. If you would rather not extend that trust, you can revoke the app password at any moment and OSMO immediately loses all access.

What we store. We store the app password encrypted at rest using AES-256-GCM, together with the email address of the connected account. The credential is never displayed back to you, never written to logs, and never shared. We do not store, copy, or index the contents of your mailbox.

How we use it. Google user data is used only to provide the outreach emailing feature you asked for. We do not sell it, we do not use it for advertising, and we do not use it to develop, improve, or train generalized artificial-intelligence or machine-learning models. We do not transfer it to third parties except as necessary to operate the Service (our hosting and database providers) or where required by law.

Human access. No OSMO or Commerciax personnel read your Google user data, except where you have given explicit consent for a specific support issue, where it is necessary for security purposes such as investigating abuse, or where required by law.

Revoking access and deletion. You can disconnect Gmail at any time from OSMO’s outreach settings, which deletes the stored credential. You can also revoke it directly in your Google account at myaccount.google.com/apppasswords, which takes effect immediately and independently of OSMO. Note that Google also revokes app passwords automatically whenever you change your Google account password. Deleting your OSMO account removes the stored credential entirely — see our Data Deletion page.

Limited Use. OSMO no longer accesses Google APIs for outreach email, but we hold ourselves to the same standard for any information reached through your connected Google account, consistent with the Google API Services User Data Policy, including the Limited Use requirements.

6. Data Storage and Security

Your data is stored on secured cloud servers. We use encryption in transit (HTTPS) and at rest. Access tokens for connected social accounts (including TikTok), and the app password for a connected Gmail account, are encrypted before storage. We retain your data for as long as your account is active. You may request deletion at any time (see Section 8).

7. Third-Party Services

OSMO uses the following third-party services to operate:

  • Microsoft Azure (AI and cloud infrastructure)
  • MongoDB Atlas (database)
  • Google (Gmail outgoing mail server — sending outreach email from your connected account)
  • Meta (Facebook and Instagram API)
  • LinkedIn API
  • TikTok (Content Posting API — publishing video posts to your connected TikTok account)
  • Stripe (billing)

Each service has its own privacy policy and security standards.

8. Your Rights and Data Deletion

You have the right to:

  • Access the data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your account and all associated data.
  • Disconnect connected social accounts, or your connected Google account, at any time.

To request data deletion, visit our Data Deletion page or email us at dev@commerciax.com.

9. Cookies

OSMO uses essential cookies only — for authentication sessions. We do not use advertising or tracking cookies.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or via a notice in the app. Continued use of OSMO after changes constitutes acceptance of the updated policy.

11. Contact

For any privacy questions or concerns, contact us at: dev@commerciax.com

Commerciax Infotech — commerciax.com