Polymath OS

Privacy Policy

How Content OS collects, uses, protects, retains, and deletes customer and connected-platform data.

Last updated July 17, 2026 Version 2026-07-17

Scope And Data Controller

Content OS is a multi-brand content operations service operated by Polymath Publishing House. This policy applies to our public website, customer workspaces, support interactions, and connected publishing services.

A customer controls the content, people, and social accounts in its workspace. Polymath Publishing House acts as the service provider for that workspace data and as the controller for account, billing, security, and service-administration data.

Information We Collect

  • Account and workspace information, including name, work email, role, organization, login events, invitations, and session metadata.
  • Customer content, including brands, sources, drafts, captions, media, approvals, schedules, comments, publishing results, and performance data.
  • Connected-account information, including platform, handle, provider account or target identifiers, selected pages or boards, authorization state, and token-update timestamps.
  • OAuth tokens or provider credentials required to perform authorized actions. Tokens are stored server-side and are never returned in public APIs or the browser bundle.
  • Billing and plan information supplied by our payment provider, such as customer ID, subscription status, plan, renewal dates, and payment outcome. We do not store complete card numbers.
  • Device, diagnostic, and usage information needed to secure the service, investigate failures, enforce limits, and improve customer workflows.
  • Support communications and deletion requests that a customer chooses to send us.

Why We Use Information

  • Provide the contracted service: authentication, workspace isolation, content review, scheduling, publishing, recovery, analytics, and support.
  • Carry out a customer's instructions to connect platforms and publish approved content.
  • Operate billing, enforce plan limits, prevent abuse, secure accounts, and maintain reliable audit records.
  • Comply with law, resolve disputes, and protect customers, connected platforms, Polymath Publishing House, and the public.
  • Send service messages such as sign-in links, invitations, publishing alerts, and material policy or account notices.

Connected Platforms And Customer Instructions

When an authorized user connects a platform, we request only the permissions needed for the selected workflow, such as reading account identity and available destinations, publishing approved content, and confirming delivery. Platform providers independently govern their services and may collect data under their own policies.

We do not sell customer or connected-platform data, use it for unrelated advertising, or publish content without the workspace's configured approval and scheduling controls. Customers may revoke a connection in Content OS or through the provider.

Service Providers And Subprocessors

We use service providers only to operate Content OS. Depending on the features a customer enables, provider categories may include cloud hosting and databases, object storage, authentication and transactional email, payment processing, monitoring and error logging, content-generation providers, and connected social platforms.

For a current subprocessor list or a data processing addendum, contact polymathpublishinghouse@gmail.com. We require providers to handle data only for the contracted service and applicable legal obligations.

Cookies And Local Storage

We use essential cookies for authenticated sessions and security. The app may use browser storage for interface preferences such as theme, selected workspace, navigation state, and read-notification state. We do not use third-party behavioral advertising cookies in the service.

Retention

Workspace content and account data are retained while the workspace is active and for a reasonable period needed to complete an export, deletion, billing reconciliation, or dispute. OAuth credentials are removed when the connection is deleted, the workspace is deleted, or a verified deletion request requires removal.

Security, billing, consent, and publishing audit records may be retained after account closure when reasonably necessary for fraud prevention, legal compliance, dispute resolution, and proof of customer instructions. Backups expire through normal rotation rather than being edited in place.

Security

We use workspace-scoped authorization, server-side secret storage, restricted runtime access, audit logging, and operational monitoring designed to protect customer data. No service can guarantee absolute security. Report suspected unauthorized access immediately through Support and do not send passwords, OAuth tokens, or API keys by email.

Your Rights And Choices

Depending on where you live, you may have rights to access, correct, export, delete, restrict, or object to certain processing of personal information. Workspace owners can manage much of their workspace directly. For a verified privacy request, use the Data Deletion page or contact Support from the email associated with the account.

You may disconnect platforms, revoke provider authorization, disable optional notifications, and cancel a paid subscription. We will not discriminate against a customer for exercising applicable privacy rights.

International Use, Children, And Policy Changes

Content OS is operated from the United States. Customers are responsible for ensuring their use and transfers comply with laws that apply to them. The service is designed for businesses and adults and is not directed to children under 13.

We may update this policy as the service or law changes. Material updates will be posted with a new version date and, when appropriate, communicated to workspace owners before taking effect.

Privacy And DPA Contact

Email polymathpublishinghouse@gmail.com with the subject “Content OS Privacy Request” or “Content OS DPA Request.” Include the workspace name and account email, but never include a password, access token, or API key.