Privacy Policy
Last updated: 12 August 2026
This policy explains what personal data CMOOS collects when you use our marketing platform, why we collect it, how we protect it, and the rights you have over it.
1. Who we are
CMOOS provides an AI-assisted marketing department platform ("CMOOS", "we", "us"). We act as data controller for account data, and as data processor for the marketing data you connect to the platform.
You can reach us about any privacy matter at privacy@cmoos.ai.
2. Data we collect
Account data: name, email address, company name, language preference and authentication identifiers provided when you sign in with email or Google.
Workspace data: onboarding answers, business goals, competitors, campaigns, content, meeting notes and chat messages you exchange with the CMOOS team.
Connected platform data: metrics and records we retrieve on your behalf from services you explicitly connect (for example Google Analytics 4, Google Search Console, YouTube, Meta Ads, LinkedIn, Shopify or HubSpot).
Billing data: subscription plan and payment status. Card details are handled by Stripe and never stored by CMOOS.
Technical data: log entries, error reports and basic usage information needed to operate and secure the service.
3. Why we use your data
To provide the service: generate briefings, opportunities, content, reports and answers from your marketing team.
To keep your account secure and to prevent abuse.
To handle billing and support requests.
To improve reliability and quality of the product. We do not sell your personal data, and we do not use your workspace content for advertising.
4. Legal basis
We process data to perform our contract with you (delivering the service), on the basis of your consent (for optional integrations and marketing emails), and for our legitimate interests in operating a secure and reliable platform. Where required by law we also process data to meet accounting and compliance obligations.
5. Sub-processors
We use a limited set of providers to run CMOOS: cloud hosting and database services, Stripe for payments, and AI model providers used to generate marketing output. Providers only receive the data needed for their function and are bound by contractual confidentiality and data-protection terms.
6. Connected accounts and tokens
When you connect a third-party platform, we store the access and refresh tokens needed to read your data. Tokens are encrypted at rest. You can disconnect any integration at any time from the Integrations page, which revokes our stored tokens.
7. Retention
We keep account and workspace data for as long as your account is active. If you close your account, we delete or anonymise personal data within 90 days, except where we must keep records for legal or accounting reasons.
8. Your rights
Depending on where you live, you may have the right to access, correct, export, restrict or delete your personal data, and to object to certain processing. To exercise any of these rights, contact us and we will respond within the timeframe required by applicable law.
If you are in the EU/EEA you also have the right to lodge a complaint with your local data protection authority.
9. International transfers
Some of our providers operate outside the EU/EEA. Where that is the case, transfers are covered by appropriate safeguards such as the EU Standard Contractual Clauses.
10. Cookies and local storage
We use strictly necessary cookies and browser storage to keep you signed in and to remember your language preference. We do not use third-party advertising cookies on this site.
11. Changes to this policy
If we make material changes, we will update the date at the top of this page and, where appropriate, notify you by email or inside the product.
Questions about this policy? Email privacy@cmoos.ai.