1. Information we collect
We collect the account information needed to operate your Creator Money OS account, including your email address, authentication information managed by our authentication provider, and service activity such as connection and synchronization status.
If you authorize Google access, we receive basic Google account and connection information, such as the email address associated with the authorized account and the permissions granted.
2. Google data we access
Creator Money OS requests only the read-only Google permissions shown during authorization:
- Gmail read-only: we search for business and money-related messages and retrieve message identifiers, subject, sender, recipient, date, and Google-provided short preview snippets. The current synchronization process does not retrieve full message bodies.
- YouTube read-only: when a YouTube channel is available for the authorized account, we retrieve the user’s channel details, channel statistics, uploads playlist, and uploaded-video identifiers, titles, descriptions, and publication dates.
We do not use these permissions to send or modify email, manage videos, read comments, or access YouTube Analytics or YouTube revenue data.
3. Why and how we use this information
We use authorized Google data to provide the features you request: identifying evidence of payments, invoices, sponsorship offers, affiliate or commission activity, refunds, contracts, pending or overdue amounts, and other creator-business money signals.
The current analysis uses deterministic searches, keyword rules, and pattern matching. It does not send Gmail or YouTube content to an external generative-AI model. Signals are normalized and may be matched to a YouTube upload only when actual identifiers, URLs, or sufficiently strong title evidence support that match. Creator Money OS does not infer YouTube revenue from video metadata.
4. Information we store
We may store your account record, Google connection status, encrypted authorization tokens, synchronization checkpoints, source records derived from relevant Gmail metadata and snippets or YouTube metadata, extracted business and financial signals, evidence used to support findings, and the resulting transactions, findings, opportunities, and activity history.
Stored source excerpts are limited by the synchronization process. Your records are associated with your user account and the application is designed to isolate one user’s data from another user’s data.
5. Google authorization and token security
Google access begins only after you choose Connect Google and approve the permissions on Google’s authorization screen. Google OAuth token bundles are encrypted before database storage using authenticated encryption. The encryption key is kept server-side, and tokens are not returned to the browser. Access tokens are refreshed and used by server-side services to make the authorized read-only requests.
We use technical safeguards including signed authorization state, a short-lived secure nonce, authenticated sessions, encrypted credentials, user-scoped records, and restricted server-side access. No system can guarantee absolute security.
6. Sharing and service providers
Creator Money OS does not sell Google user data or use it for advertising. Google data is processed to provide and protect the service. We use infrastructure providers for authentication, application hosting, and database storage, and those providers may process data on our behalf under their service terms. We may also disclose information when required by law or when necessary to protect users, the service, or legal rights.
Creator Money OS’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We do not use Gmail or YouTube data to develop, improve, or train generalized or non-personalized AI or machine-learning models.
7. Your control, disconnecting, and deletion
You choose whether to connect Google. While signed in, open Connections and select Disconnect to stop future synchronization. Creator Money OS then attempts to revoke the Google grant and removes the stored Google connection and encrypted token records.
Disconnecting does not automatically delete information synchronized before disconnection. To request deletion of synchronized Google data or your Creator Money OS account data, follow the instructions on the Contact / Support page. We may need to verify that you control the account before completing a request.
8. Retention
Creator Money OS does not currently promise a fixed automatic deletion schedule. We retain account and synchronized records while needed to provide the service, maintain security and integrity, resolve disputes, or meet legal obligations. A verified deletion request is the available method for requesting removal of stored account or synchronized data.
9. Your rights and choices
Depending on where you live, you may have rights to request access, correction, deletion, restriction, or a copy of personal information. You may also withdraw Google access through Creator Money OS or your Google Account permissions. Use the Contact / Support page to submit a privacy request.
10. Changes and contact
We may update this policy as the service changes. The effective date above identifies the current version. Questions, privacy requests, and data-deletion requests can be submitted using the instructions on our Contact / Support page.
