Legal

Privacy Policy

This policy explains what PrimeOne AI Marketing Toolkit (“PrimeOne”, “we”) collects when you use the service, why we collect it, and how it is stored, shared and deleted.

1. Account information

When you create an account we store the email address you sign up with and the authentication records needed to sign you in, along with your plan and subscription status. Passwords are handled by our authentication provider and are never stored in readable form by PrimeOne.

2. Generated marketing content

The inputs you provide to the generators (such as product details, tone, audience and goal) and the resulting copy are stored against your account so they appear in your library, batches and usage history. This content is private to your account.

3. AI-generated images, audio and video

Images, voice-over audio and video projects you create are stored against your account, together with the prompts and settings used to generate them. Generation requests are sent to the AI providers that power those features so the output can be produced.

4. Payment and subscription information

Subscriptions are processed by our third-party payment provider. PrimeOne does not receive or store your full card details. We store the subscription identifier, plan, status and billing lifecycle events returned by the payment provider so we can grant the correct access to your account.

5. Connected third-party services

If you choose to connect an external service to PrimeOne, we store only what is required to operate that connection on your behalf: the service’s account or organization identifier, the permissions (scopes) you granted, and the credentials issued to us by that service.

6. Buffer connections and tokens

Connecting Buffer uses the OAuth 2.0 Authorization Code flow with PKCE. You authorise the connection on Buffer’s own site; PrimeOne never sees your Buffer password. Buffer then issues PrimeOne an access token and a refresh token.

These tokens are exchanged and stored entirely on our servers. They are encrypted before being written to a private database table that is not readable by browsers or by other users, and they are never sent to client-side code, logged, or shared. Buffer refresh tokens rotate: when a token is refreshed, the previous refresh token is replaced.

7. Social-media publishing permissions

A Buffer connection grants PrimeOne the permissions you approve on Buffer’s consent screen so that, in future, content you explicitly choose can be sent to Buffer. PrimeOne does not publish, schedule or delete anything without an action you initiate. You can revoke access at any time by disconnecting in PrimeOne or by removing the app in your Buffer account settings.

8. Data security

Data is transmitted over HTTPS and stored in a managed database with row-level access rules that restrict records to their owning account. Provider credentials and third-party tokens are held only in server-side secret storage or in encrypted, server-only tables. Sensitive values are never exposed to the browser or included in application logs.

9. Data retention and deletion

Your content and connection records are retained while your account is active. You can delete individual generations from your library and disconnect third-party services at any time; disconnecting removes the stored tokens for that service. Billing records may be retained where required for accounting purposes.

10. Account deletion

You can request deletion of your account. On deletion we remove your account record, your stored generations and media, and any third-party connection credentials, subject to records we are required to keep for legal or accounting reasons.

11. Third-party service providers

PrimeOne relies on providers for hosting and databases, authentication, AI text, image, speech and video generation, payment processing, and — where you connect it — Buffer for social publishing. These providers process data only to deliver the functionality you request, under their own privacy terms.

12. Your rights

Depending on your location, you may have the right to access, correct, export or delete your personal data, to withdraw consent for a connected service, and to object to certain processing. You can exercise most of these directly in the app; for anything else, contact us using the details below.

13. Contact

For privacy questions or data requests, contact the PrimeOne account owner through the support channel listed in your account. A dedicated privacy contact address will be published here once it is configured; until then, requests made through your account are the authoritative channel.

14. Changes to this policy

We may update this policy as PrimeOne evolves. Material changes will be reflected on this page.

Return to the dashboard