This Application Privacy Policy explains how CO8 (“CO8”, “we”, “us”, “our”) collects, uses, shares, stores, and protects information in the CO8 application at app.co8.ai (the “Application”), including data obtained from Google when you connect a Google account.
It complements the website Privacy Policy and should be read with the Application Terms of Service and Cookie Policy. Data controller: CO8. Contact: privacy@co8.ai.
1. Information we collect
- Account data — name, email address, profile picture, password hash or federated sign-in identifier, workspace and role, locale.
- Workspace content — brand assets, product data, prompts, briefs, generated creatives, comments, and files you upload.
- Billing data — plan, credit balance, invoices, and transaction identifiers. Card details are handled by our payment processor; CO8 never stores full card numbers.
- Connected-platform data — data retrieved from services you connect (Google, Meta, and others), as described in section 2.
- Technical and usage data — IP address, device and browser type, pages and features used, timestamps, error and audit logs, used to operate, secure, and improve the Application.
- Cookies and similar technologies — session and preference cookies, plus analytics as described in the Cookie Policy.
2. Google account connections and Google user data
Connecting a Google account is optional and always initiated by you through Google’s OAuth consent screen, which shows the exact scopes requested. You can decline any scope, and you can revoke access at any time.
Depending on the scopes you grant, CO8 may access:
- Google Sign-In profile — your Google account name, email address, language, and profile picture, used to create and authenticate your CO8 account.
- Google Ads — accounts, campaigns, ad groups, ads and creative assets, audiences, and performance metrics, used to import creative context and report performance, and — only if you grant write access — to create or update campaign objects at your instruction.
- Google Analytics — aggregated property and reporting data, used to correlate creative performance with site outcomes.
- Google Drive / Sheets — only the specific files or folders you select, used to import brand assets, product feeds, or export reports.
- YouTube — channel and video metadata and, where you grant it, upload permission used solely to publish videos you explicitly choose to publish.
We request the narrowest scopes needed for the feature you enable and do not use Google data for any purpose other than delivering that feature. OAuth tokens are stored encrypted at rest and are never shared with other customers.
3. Google API Services User Data Policy — Limited Use
CO8’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, CO8 does not:
- transfer or sell Google user data to advertising platforms, data brokers, or information resellers;
- use Google user data to serve advertisements, including retargeting or personalised advertising;
- use Google user data to develop, train, or improve generalised or foundation AI/ML models;
- allow humans to read Google user data, unless you give explicit consent for specific data, it is necessary for security purposes such as investigating abuse, it is required by applicable law, or the data has been aggregated and de-identified.
4. How we use information
- Provide, operate, and secure the Application and your workspace.
- Authenticate you and manage sessions and permissions.
- Generate, store, and deliver creative output you request.
- Sync and display performance data from platforms you connected, and execute actions you instruct.
- Process payments, credits, and invoices; prevent fraud and abuse.
- Provide support and send service notices; send marketing only with your consent, which you can withdraw at any time.
- Improve reliability and features using aggregated or de-identified usage data. We do not train generalised AI models on your workspace content or on Google user data.
5. Legal bases (EEA/UK)
Where GDPR applies, we rely on: contract (providing the Application), consent (connecting third-party accounts, marketing, non-essential cookies), legitimate interests (security, abuse prevention, service improvement), and legal obligation (tax and accounting records).
6. Sharing
We do not sell personal data. We share it only with:
- Service providers (processors) — cloud hosting and storage, content delivery, database and queue infrastructure, error monitoring, email delivery, payment processing, and AI model providers used to generate the output you request — each bound by contract and permitted to process data only on our instructions.
- Connected platforms — when you instruct CO8 to publish or update assets on Google, Meta, or another connected service.
- Your workspace members — content is visible to users you invite, per their role.
- Legal and corporate — where required by law or valid legal process, to protect rights and safety, or in connection with a merger or acquisition (with notice).
Google user data is never shared with advertising platforms, data brokers, or model-training pipelines.
7. International transfers
Data may be processed in jurisdictions other than your own, including the United States, the European Union, and Hong Kong. Where required, transfers rely on appropriate safeguards such as the EU Standard Contractual Clauses.
8. Retention
- Account and workspace content — while your account is active, and up to 30 days after deletion in backups.
- OAuth tokens — until you disconnect the integration or revoke access; then deleted promptly.
- Synced platform data (including Google Ads/Analytics metrics) — for the reporting window you configure, and deleted on disconnection or account deletion.
- Billing records — as required by tax and accounting law (typically 7 years).
- Security and audit logs — typically up to 12 months.
9. Security
We use TLS in transit, encryption at rest for credentials and OAuth tokens, role-based access control, least-privilege internal access, audit logging, and regular dependency and infrastructure patching. No system is perfectly secure; report concerns to security@co8.ai.
10. Your rights and choices
- Access, correct, export, or delete your personal data.
- Object to or restrict certain processing, and withdraw consent at any time.
- Disconnect any integration from within the Application, or revoke CO8’s Google access at myaccount.google.com/permissions.
- Request full deletion — see the Data Deletion Instructions; we normally complete requests within 30 days.
- Lodge a complaint with your local data-protection authority.
Exercise rights by emailing privacy@co8.ai from your account address.
11. Children
The Application is not directed to children under 16, and we do not knowingly collect their data. If you believe a child has provided data, contact privacy@co8.ai and we will delete it.
12. Changes
We may update this policy. Material changes will be announced in the Application or by email before they take effect; the “last updated” date above always reflects the current version.
13. Contact
CO8 — privacy enquiries: privacy@co8.ai. You can also reach us via the contact page.