Privacy Policy
1. Controller
The controller within the meaning of the EU General Data Protection Regulation (GDPR) is:
Sandro Ieva
Arnimstrasse 13
23566 Lübeck
Germany
Email: support@i7os.com
2. Scope
This Privacy Policy applies to the i7OS marketing website at i7os.com and www.i7os.com and the i7OS web application (the “Service”), available at app.i7os.com and its subdomains. It explains which personal data we process, why we process it, and which rights you have.
3. Definitions
Terms used in this Privacy Policy have the meanings set out in Article 4 GDPR. “Personal data” means any information relating to an identified or identifiable natural person.
4. Data we process
4.1 Account data
When you register through Google OAuth, we process:
- Your first and last name
- Your email address
- Your profile picture, if one is stored with Google
- A unique user ID
4.2 Content you create
We store content that you create or upload in the Service, including workspace and project information, chat messages, tasks, notes, brand profiles, names, logos, colours, descriptions, files, personas, strategy notes and channel connections.
4.3 Google integration data
If you grant i7OS access to your Google account, we process data through the permissions you approve:
auth/calendar.events: reading, creating, changing and deleting events in your primary Google Calendar, only when you actively request the relevant action.auth/drive.file: access to files created by i7OS or explicitly shared with i7OS. The Service cannot access other files in your Drive.
When you actively import a Google Drive file into your assets, a copy of that file is stored in our Supabase storage in the EU region so that it remains available in the Service. Otherwise, we store only references to your Google content, such as file or event IDs, rather than its full content.
4.4 Technical data
We may process your IP address during a session, access timestamps, browser and device information, encrypted authentication tokens, and push-notification endpoints if you enable notifications. IP addresses are not permanently stored by i7OS.
4.5 Cookies and local storage
We use technically necessary cookies and browser local storage for authentication, language and theme preferences, and application state. We do not use tracking, analytics or advertising cookies.
4.6 Marketing website statistics
On i7os.com and www.i7os.com, we count page views, approximate country and the referring website domain to understand use of our marketing website. Vercel processes the IP address to determine the country. Our statistics endpoint derives a daily changing, cryptographically protected identifier from the IP address; full IP addresses are not stored in our statistics. This identifier and daily counters are stored in our existing Supabase database and are accessible only to the operator. These statistics use no cookies or browser storage and do not collect URL query parameters or form inputs. Browsers with Do Not Track or Global Privacy Control enabled are excluded. Entries outside the most recent 90 calendar days are deleted on the next recorded visit.
4.7 Connected social accounts (Meta)
If you directly connect an Instagram or Threads account to i7OS, we store the information needed to provide that connection:
- The access token issued by Meta and its expiry date
- The account ID and username, and the account type for Instagram
- The permissions granted, the workspace associated with the connection, and the member who connected it
- Connection and update timestamps, and the most recent connection error, where applicable
We use these data to maintain the connection, publish content you submit, and display available account statistics and publishing limits. The connection belongs to the workspace; its members can use it to publish.
The direct integration does not import or retain your existing posts, private messages, follower lists or contacts from Instagram or Threads. Available statistics, such as Instagram reach, interactions and follower counts, and the platforms' publishing limits, are requested from Meta when you open the relevant view and are not retained in our database. Content you create or upload in i7OS is processed separately as described in section 4.2.
Legal basis: Article 6(1)(b) GDPR, performance of the contract for the connected-account features you request.
4.8 Connected social accounts (TikTok)
If you directly connect a TikTok account to i7OS, we store the information needed to provide that connection:
- The access token issued by TikTok and its expiry date. TikTok access tokens are valid for 24 hours, so i7OS also stores the refresh token and its expiry date and renews the access token automatically while the connection exists.
- The account identifiers TikTok issues for your account in relation to i7OS (open ID and, where provided, union ID)
- The display name, username and profile picture URL of the connected account
- The permissions granted, the workspace associated with the connection, and the member who connected it
- Connection and update timestamps, and the most recent connection error, where applicable
We use these data to maintain the connection, publish content you submit, and display available account statistics. The connection belongs to the workspace; its members can use it to publish.
The direct integration does not import or retain your private messages, follower lists or contacts from TikTok. Where you have granted the corresponding permissions, account statistics and the numbers for your recent posts are requested from TikTok when you open the relevant view and are not retained in our database. Content you create or upload in i7OS is processed separately as described in section 4.2.
Legal basis: Article 6(1)(b) GDPR, performance of the contract for the connected-account features you request.
5. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Providing the Service | Article 6(1)(b) GDPR — performance of a contract |
| Google integrations | Article 6(1)(a) GDPR — consent through OAuth |
| Transactional emails | Article 6(1)(b) GDPR — performance of a contract |
| Push notifications | Article 6(1)(a) GDPR — consent |
| Security and abuse prevention | Article 6(1)(f) GDPR — legitimate interests |
| Use of processors | Article 28 GDPR |
6. Recipients and processors
6.1 Supabase — database and storage
Supabase, Inc., 970 Toa Payoh North #07-04, Singapore 318992. Our data region is the EU (Frankfurt, Germany). A data processing agreement is in place. Supabase Privacy Policy.
6.2 Vercel — hosting
Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA. Transfers are protected through appropriate safeguards such as EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. Vercel Privacy Policy.
6.3 Resend — transactional email
Resend, Inc., 2261 Market Street #4391, San Francisco, CA 94114, USA. Transfers are protected through EU Standard Contractual Clauses. Resend Privacy Policy.
6.4 Google — OAuth and APIs
For users in the EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google processes login information, calendar events and Drive file metadata only in connection with actions you request. Google Privacy Policy.
i7OS complies with the Google API Services User Data Policy, including its Limited Use requirements.
6.5 AI providers
When you use AI features, the relevant request may be sent to one of the following providers:
- Anthropic (Claude): Anthropic PBC, 548 Market St, PMB 90375, San Francisco, CA 94104, USA
- OpenAI (GPT): OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, Ireland
- Google (Gemini): see section 6.4
Requests are transmitted to provide the requested response. Under the applicable API terms, API data is not used to train general-purpose models.
6.6 Meta
When you use a direct Instagram or Threads connection to publish, i7OS sends the post text and the associated pictures or videos to Meta Platforms Ireland Limited, the provider for users in the European region. Meta also receives the access token and account identifiers needed to carry out the API request.
For media in our private storage, i7OS provides Meta with a temporary download link that expires after one hour. Meta retrieves the media through this link. If you provide an already publicly accessible media URL, that URL is passed to Meta; the one-hour expiry does not apply to public URLs.
Meta returns the connection information described in section 4.7, available account statistics and publishing limits, and publishing results such as post IDs and links. Our hosting and storage providers described above process the connection data as part of operating i7OS. Meta processes data it receives under its own Privacy Policy. Expiry of a media link does not delete media or posts that Meta has already received.
6.7 TikTok
When you use a direct TikTok connection to publish, i7OS sends the post text and the settings you chose for it to TikTok Pte. Ltd. TikTok also receives the access token and account identifiers needed to carry out the API request. The settings sent are the visibility level you selected, whether comments, duets and stitches are switched off, and whether you declared the post as commercial content.
Media is transferred in one of two ways, depending on what you post. Videos are uploaded from your browser directly to the address TikTok provides for that post; the video file does not pass through our servers during this transfer. Pictures are retrieved by TikTok itself. TikTok only retrieves media from a domain verified in its developer portal, so i7OS provides the pictures through app.i7os.com, which reads them from our storage and passes them on.
TikTok returns the connection information described in section 4.8, the publishing status of a post and, where you have granted the corresponding permissions, account statistics and the numbers for your recent posts. TikTok processes data it receives under its own Privacy Policy. Media or posts TikTok has already received are not deleted by disconnecting.
7. International transfers
Some processors may process data outside the European Economic Area. Where required, transfers rely on EU Standard Contractual Clauses, the EU–US Data Privacy Framework where the recipient is certified, and additional technical safeguards such as encryption in transit and at rest.
8. Retention
| Data category | Retention period |
|---|---|
| Account data | For as long as your account remains active |
| Content data | For as long as your account remains active |
| i7OS session authentication tokens | Up to seven days; deleted when you log out |
| Direct Meta connections and access tokens | Until the connection is removed as described in section 8.1. Tokens may be renewed while connected; logging out of i7OS does not remove a workspace connection. |
| Direct TikTok connections and access tokens | Until the connection is removed as described in section 8.2. Tokens are renewed automatically while connected; logging out of i7OS does not remove a workspace connection. |
| Technical logs | 30 days |
| Data following account deletion | 30-day recovery period, followed by permanent deletion |
If you expressly request deletion at support@i7os.com, we will delete your data without undue delay in accordance with Article 17 GDPR, unless a legal retention obligation applies.
8.1 Deleting connected account data
You can remove a direct Instagram or Threads connection and request deletion of its connection data in any of these ways:
- In i7OS: open Settings → Account in the relevant workspace and select Disconnect for Instagram or Threads. This removes that connection's active database record, including its access token and account information, when the disconnect request is processed.
- Through Meta: remove i7OS from the connected apps or website permissions in your Instagram or Threads account settings. When Meta sends us the deauthorization or data-deletion notification, we remove the connection records associated with that platform account.
- By email: if you cannot access i7OS, write to support@i7os.com with the platform, account username and, if known, your workspace name. Do not send passwords or access tokens. We may ask for information needed to verify your authority to request deletion. We process the request within 30 days and confirm completion by email.
Disconnecting removes the stored token, account ID, username and the other connection information listed in section 4.7. It does not delete posts already published on Instagram or Threads; you can delete those in the respective platform. Files and other content you created in i7OS remain subject to the retention rules above.
Because connections belong to a workspace, remove the relevant connections explicitly using one of the options above before deleting your personal i7OS account. This also lets you remove a connection without deleting your i7OS account or the workspace.
8.2 Removing a TikTok connection
You can remove a direct TikTok connection and request deletion of its connection data in either of these ways:
- In i7OS: open Settings → Account in the relevant workspace and select Disconnect for TikTok. This removes that connection's database record, including its access token, refresh token and account information, when the disconnect request is processed.
- By email: if you cannot access i7OS, write to support@i7os.com with the account username and, if known, your workspace name. Do not send passwords or access tokens. We may ask for information needed to verify your authority to request deletion. We process the request within 30 days and confirm completion by email.
Please note: removing i7OS from the connected apps in your TikTok account settings stops i7OS from using the connection, because the tokens stop working. TikTok does not notify us when you do this, so the connection record remains stored in i7OS until you disconnect it there or contact us as described above.
Disconnecting removes the stored tokens, account identifiers, display name, username and profile picture URL listed in section 4.8. It does not delete posts already published on TikTok; you can delete those in the TikTok app. Files and other content you created in i7OS remain subject to the retention rules above.
9. Push notifications
If you enable push notifications, we store your browser or device push endpoint to send transactional messages such as mentions, reminders and project invitations. We do not send marketing push notifications. You can withdraw your permission at any time in your browser or application settings.
10. Security
We use technical and organisational measures appropriate to the risk in accordance with Article 32 GDPR, including:
- TLS/HTTPS encryption for data in transit
- Encryption of stored database data
- Row-level security so that users can access only their own or shared data
- Access controls through established OAuth providers
- Minimal permissions such as
drive.fileandcalendar.events - Regular backups
11. Your rights
Subject to the applicable requirements, you have the right to access your data (Article 15 GDPR), rectify inaccurate data (Article 16), request erasure (Article 17), restrict processing (Article 18), receive portable data (Article 20), object to processing (Article 21), withdraw consent at any time (Article 7(3)), and lodge a complaint with a supervisory authority (Article 77).
Our competent supervisory authority is the Independent State Centre for Data Protection Schleswig-Holstein (ULD). Send requests to support@i7os.com. We generally respond within one month.
12. Changes to this Privacy Policy
We may update this Privacy Policy when features or legal requirements change. We will communicate material changes with reasonable notice by email or within the Service.