ContentX · Legal
This Privacy Policy explains what information ContentX collects, how we use it, how we share it, and the choices you have. It covers our marketing site, the ContentX Studio product, and Google user data we receive when you connect Google or YouTube (or related Google APIs) through our app.
If we change how we use Google user data, we will update this policy and, where required, ask you to consent again before using that data in a new way.
Effective August 31, 2026
- ContentX is an AI-assisted content production and publishing platform. You can create or upload content, manage brands, and connect social channels (including YouTube via Google) so approved content can be scheduled and published.
- When you register or sign in to ContentX we may collect name, email address, and authentication identifiers.
- Organization / workspace / brand identifiers you create.
- Account preferences and settings.
- Lead form submissions: name, company, work email, and project details you choose to share.
- Campaign context (UTM parameters, click identifiers, referrer, landing path).
- Booking details if you schedule a call (handled by Calendly under its own privacy policy; the widget loads after you choose to open it).
- Payment data for checkout (processed by Stripe; we do not store full card numbers).
- Scripts, briefs, media files, brand kits, logos, and other assets you upload or generate in ContentX for production and publishing.
- When you choose Connect for YouTube or another Google-powered integration, Google may ask you to authorize ContentX (and our publishing bridge described below). Depending on the scopes you approve, we may access and process:
| Category | Examples |
|---|
| Basic Google profile | Google account ID, name, email, profile picture |
| YouTube channel identity | Channel ID, channel title, channel thumbnail, custom URL |
| Authorization credentials | OAuth access tokens and refresh tokens needed to act on your behalf |
| Publishing metadata | Video titles, descriptions, privacy status, upload status, and IDs of content you publish through ContentX |
| Analytics (if you grant analytics scopes) | Channel or video performance metrics such as views, watch time, subscribers, likes, and related report dimensions for the periods you request in-product |
- We only request Google scopes needed for the features you use (connect channel, publish/schedule, and show analytics). We do not request Google user data for unrelated features.
- IP address, device/browser type, approximate location derived from IP, logs, cookies or similar technologies, and product usage events needed to secure and operate the service.
- Site analytics may include Google Analytics 4 and privacy-respecting analytics; advertising pixels may run when campaigns are active.
- Google Analytics and advertising pixels are disabled when your browser sends a Do Not Track or Global Privacy Control signal.
- Create and secure your ContentX account.
- Provide Studio features: brand setup, content generation, calendars, scheduling, and publishing.
- Connect your YouTube (or other Google) channel, keep the connection healthy (including token refresh), and publish or schedule content you approve.
- Show channel or post analytics you request in ContentX or related operator tools.
- Respond to support and sales inquiries.
- Improve reliability, prevent abuse, and comply with law.
- We use Google user data only to provide or improve user-facing features of ContentX that are visible in the application (channel connect, publishing/scheduling, and analytics displays).
- We do not sell Google user data.
- We do not use Google user data for advertising, including personalized or retargeting ads.
- We do not use Google user data to train generalized AI/ML models.
- We do not transfer Google user data to third parties except as disclosed in Section 4 and as needed to operate those features.
We do not sell your personal information. We share data only as described below.
- To operate social connect and publishing, Google user data (including OAuth tokens and channel identifiers) may be processed by:
| Recipient | Role |
|---|
| Google | Identity provider and YouTube / Google API platform; you authorize access on Google’s consent screen |
| Our social publishing / scheduling bridge | Stores connected channel integrations and performs schedule/publish API calls to YouTube on your behalf after you connect |
| Cloud infrastructure providers (currently Amazon Web Services and related hosting for ContentX / Content Factory APIs) | Secure storage and processing of account records, brand social connection maps, logs, and application data |
| Content Factory / ContentX backend APIs | Orchestrate connect, claim, publish, and analytics proxy calls between Studio, Google, and our publishing bridge |
- These parties process data on our instructions to provide the ContentX service, not to sell your Google user data.
- Stripe — payments (card data handled by Stripe).
- Calendly — meeting scheduling if you book a call.
- Analytics / marketing tools — e.g. Google Analytics 4, Plausible or similar, and advertising pixels when campaigns are active (marketing site; separate from Google API limited use).
- Email / support / CRM tooling — to respond to leads and tickets.
- We may disclose information if required by law, regulation, legal process, or governmental request, or to protect the rights, safety, and security of ContentX, our users, or the public.
- If we are involved in a merger, acquisition, or sale of assets, personal data may be transferred as part of that transaction under appropriate confidentiality safeguards. Google user data will remain subject to this policy (or a successor policy with notice).
- We do not share Google user data with unrelated third parties for their own independent marketing.
- We do not allow human reading of Google user data except as needed for security, compliance, or support when you ask us for help, or where required by law.
Google treats many YouTube / OAuth scopes as sensitive. We apply the following protections:
- In transit: TLS (HTTPS) for ContentX Studio, APIs, and connections to Google and our publishing bridge.
- At rest: credentials and application data stored in our cloud environment are protected using provider-managed encryption at rest (industry-standard encryption offered by our cloud host).
- Access to production systems and secrets is limited to authorized personnel with a need to know.
- Administrative access uses authentication controls; secrets (API keys, OAuth client secrets) are stored in secured configuration / secret managers, not in public repositories.
- OAuth access and refresh tokens are stored only as needed to maintain your channel connection and to publish/schedule or fetch analytics you request.
- Tokens are transmitted only to Google and to our publishing bridge as required for those features.
- When you disconnect a channel in ContentX (or revoke access in your Google Account), we stop using those tokens for new actions and delete or invalidate stored connection records in line with Section 6.
- Authentication required for Studio account features.
- Least-privilege design for service-to-service calls.
- Logging and monitoring for abuse and operational failures.
- Dependency and infrastructure updates as part of normal operations.
- Internal access policies and confidentiality expectations for staff and contractors.
- Enterprise customers may request a Data Processing Agreement (DPA) and security questionnaire.
- No method of transmission or storage is 100% secure; we work to protect your information using reasonable administrative, technical, and physical safeguards appropriate to the sensitivity of the data.
- Account data: kept while your account is active and for a reasonable period afterward for backups, disputes, and legal requirements.
- Google OAuth tokens / channel connections: kept while the channel remains connected to your brand/workspace; removed or invalidated when you disconnect or when tokens are revoked / expire and cannot be refreshed.
- Content and publish history: kept according to product retention and your deletion requests, subject to legal holds.
- Marketing leads: kept as needed to respond and for legitimate business records, or until you request deletion.
- Access, correction, deletion: contact us via the studio contact form to access, correct, or delete personal data we hold about you. We aim to honor deletion requests within 30 days where applicable law allows.
- Revoke Google access: use Google Account → Security → Third-party access to revoke ContentX / related app access at any time. Also disconnect the channel inside ContentX Connected Accounts when available.
- Marketing analytics opt-out: enable Do Not Track or Global Privacy Control to opt out of Google Analytics and advertising pixels on the marketing site.
- Regional rights: depending on where you live (for example GDPR/UK GDPR, CCPA/CPRA), you may have additional rights to object, restrict processing, or receive a portable copy of your data. Contact us to exercise these rights.
- We may process data in the United States and other countries where we or our processors operate. Where required, we use appropriate transfer mechanisms (such as Standard Contractual Clauses) for cross-border transfers.
- ContentX is not directed to children under 13 (or under 16 where that is the applicable age). We do not knowingly collect personal information from children.
- We will post updates on this page and change the effective date. For material changes to how we use Google user data, we will provide additional notice and obtain consent when required by Google policy or applicable law.
- Questions about this Privacy Policy or Google user data: studio contact form.
- Companion document: Terms of Service.
- Studio homepage: content-x.ai/studio.
- Governing law reference for contractual terms appears in our Terms of Service (State of Delaware, USA), without limiting mandatory consumer protections that may apply where you live.
Read the companion document: Terms of Service →
Or head back to the studio homepage →