Privacy Policy

OpenCMO Privacy Policy

Last updated 2026-08-01

This Privacy Policy explains what OpenCMO collects, why it is used, how AI model providers process your workspace context, how long data is kept, and how to exercise export, deletion, and other privacy rights. Maintained by the founder to accurately describe the product; a professional legal review is recommended before real-money billing opens.

Information We Collect

OpenCMO may collect account details (your email address for magic-link sign-in), workspace membership, product URLs, product descriptions, brand context, campaign drafts, approvals, reports, inbound request details, support messages, and product usage events.

When you point OpenCMO at a URL — your product site, competitors, or market-radar targets — OpenCMO fetches publicly available pages through its web-extraction provider and stores the extracted content in your workspace.

If you buy a paid plan, OpenCMO stores subscription records from Stripe (customer and subscription identifiers, plan, and status) — never card numbers.

OpenCMO does not collect or enrich personal contact data about third parties. Its go-to-market tools work on companies and public web content, not people-data; contact enrichment is disabled and stays disabled unless it passes a dedicated compliance review.

Do not submit secrets, passwords, private API keys, service-role keys, or credentials through chat, support messages, product forms, or campaign context fields.

How We Use Information

OpenCMO uses customer information to provide the product, set up workspaces, create draft marketing artifacts, support approval workflows, respond to support requests, maintain security, improve product quality, and handle billing or account administration.

OpenCMO does not sell customer data. Customer-facing work remains approval-led and should not be auto-published by the product.

AI Model Processing

To generate chat answers, campaign drafts, and reports, OpenCMO sends sanitized prompts and workspace context (product descriptions, goals, brand voice) server-side to a third-party AI inference provider. Local file paths, keys, and credential-like strings are redacted before anything leaves OpenCMO.

Model requests are made from OpenCMO's servers with OpenCMO's provider account — your browser never talks to the model provider directly, and OpenCMO does not use your workspace content to train its own models.

The inference provider processes these requests to return generated text, subject to that provider's terms. For usage metering and abuse prevention, OpenCMO records metadata (hashed workspace id, prompt length, redaction counts), not prompt bodies.

To debug and improve model behavior, OpenCMO also sends the sanitized prompt and generated answer — after secrets and credential-like strings are redacted — to its LLM observability provider (Langfuse), along with provider and token-usage metadata.

Google User Data

If you connect a Google account, OpenCMO requests exactly two scopes, both read-only: Google Analytics (analytics.readonly) and Google Search Console (webmasters.readonly). OpenCMO cannot create, change, or delete anything in your Google Analytics property or Search Console account, and it requests no other Google scope.

OpenCMO stores daily aggregate metrics from those two products in your workspace: from Analytics, sessions, active users, key events, engagement rate, top channels, and top pages; from Search Console, clicks, impressions, click-through rate, and average position, broken out by search query and by page. It also stores the email address of the Google account used to connect, and the Analytics property and Search Console site you select. Sync runs once a day. When you first connect, OpenCMO backfills up to 16 months of Search Console history and 90 days of Analytics history.

The refresh token issued by Google is held in Supabase Vault, encrypted at rest. OpenCMO's own application tables store only a pointer to that vault entry — database constraints reject any value that is not a reference — and access tokens are requested per operation and never written to storage.

Google user data is used only to populate the analytics surfaces in your workspace and to ground the assistant's answers about your own traffic and search performance. When the assistant answers a question, OpenCMO includes a short rollup of your Google data in the prompt sent to its AI inference provider: total clicks, total impressions, total sessions, total active users, and the number of days covered. Individual search queries, page URLs, your Google account email, and your property and site identifiers are not included in that prompt. OpenCMO does not use Google user data to train any AI or machine-learning model, its own or a provider's.

Google user data is not sold, not used for advertising or credit assessment, and not shared with any other third party. OpenCMO's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

OpenCMO does not expire Google Analytics or Search Console snapshots on a schedule; they are kept until you disconnect the Google account or delete the workspace. Disconnecting revokes the token with Google, deletes the stored token from the vault, deletes every Analytics and Search Console snapshot held for that workspace, and clears the connected account email, the granted scopes, and the selected property and site. A record that a Google connector once existed remains, marked disconnected and holding no Google-derived values; deleting the workspace removes that record too.

To disconnect, use the integrations settings in your workspace, or write to yuhua@opencmo.ai (or yuhua21223@gmail.com). You can also revoke OpenCMO's access at any time from your Google account's third-party access settings.

Analytics And Service Providers

OpenCMO runs on hosted infrastructure and operational providers: Vercel (application hosting), Supabase (database, authentication, and storage), third-party AI inference providers that process sanitized prompts to generate drafts, Langfuse (LLM observability over redacted prompts and answers), Nimble (extraction of the public web pages you or your market radar point OpenCMO at), Exa (web search for market-radar signals), Ayrshare (delivery of social posts you have approved, which receives the post text and the destination profile), Google (PageSpeed Insights, which receives the page URLs you ask OpenCMO to score), and Inngest (background job execution). PostHog is used for product analytics.

Payments are processed by Stripe. OpenCMO receives subscription status and plan metadata from Stripe but never receives or stores card numbers. RevenueCat may be used later only for mobile subscription signal ingestion; OpenCMO web billing uses Stripe as the source of truth.

Analytics use public-safe event names and sanitized properties. The product does not send raw secrets, private keys, or credential-like values to analytics tools.

Data Retention

Workspace content (products, brand context, drafts, approvals, reports, chat history) is retained while your account is active so your workspace keeps working.

Operational logs and usage metadata are retained for a limited period for security, cost control, and abuse prevention, then deleted or aggregated.

When an account or workspace deletion completes, associated content is removed from production systems. Copies may persist briefly inside infrastructure providers' own storage layers, such as replicas or internal snapshots, until those rotate out. Records may be retained longer when required for security, fraud prevention, legal, tax, or dispute reasons.

International Transfers And Children

OpenCMO is operated from the United States and its providers store data primarily in US regions. If you use OpenCMO from elsewhere, you consent to processing in the US and other locations where our providers operate.

OpenCMO is a business tool and is not directed at children under 16; we do not knowingly collect their data. If you believe a child provided data, contact the address below and we will delete it.

Cookies And Local Storage

OpenCMO may use cookies, local storage, and similar technologies for authentication, session handling, product state, analytics, abuse prevention, and user experience.

Browser settings may let you limit some storage, but doing so can affect login, workspace access, or product functionality.

Your Rights, Export, And Deletion

Send export, deletion, correction, or access requests to yuhua@opencmo.ai (or yuhua21223@gmail.com) with the workspace email, workspace name, and requested action; OpenCMO also records privacy requests submitted through the in-product privacy-request path.

OpenCMO aims to acknowledge requests within 24 hours, verify requester identity and workspace authority, and complete standard exports or deletions within 30 days when feasible.

OpenCMO may reserve up to 45 days for requests involving complex verification, legal review, security review, or technical cleanup. Depending on where you live, you may have additional statutory rights (such as access, portability, correction, deletion, or objection); we honor verified requests to the extent required by applicable law and do not discriminate against you for exercising them.

Security

OpenCMO uses access controls, workspace-scoped row-level security, secret redaction before model calls, rate limits, and operational review to protect customer workspaces.

No online service can guarantee perfect security. Report security concerns to the support inbox at the address on this page and we will prioritize them.

Contact

For privacy, support, billing, export, deletion, or security questions, contact yuhua@opencmo.ai (or yuhua21223@gmail.com).

The second address is a fallback: if the primary opencmo.ai address does not get a response, the Gmail address reaches the founder directly.