Privacy Policy
This Privacy Policy governs the manner in which the SELF MASTERY AI Content Agent collects, processes, secures, and handles information across our automated workflow, AI content generation, human approval, and social media publishing operations.
1. Overview & Application Purpose
The SELF MASTERY AI Content Agent is an AI-assisted, human-in-the-loop content engineering application. The primary purpose of the application is the automated and assisted creation, editorial review, human approval, version control, and distribution of educational and self-mastery content to authorized external social media platforms (including LinkedIn, Meta/Instagram, Facebook, WhatsApp, and YouTube channels).
Our core architecture is built upon the principle of strict human governance: no content is ever distributed to an external platform without passing through human review gates, explicit authorization, and validated state checks.
2. Information We Process (Data Collection)
To perform our content generation and publishing workflows, the application processes only the specific categories of data necessary for operation:
- Account & Workspace Information: Internal workspace identifiers, tenant configurations, agent run settings, and operator preferences.
- Authentication Information: Application session identifiers, cryptographic state parameters, and access permissions required to operate the administrative interface.
- User-Authored & Edited Content: Content topics, editorial notes, manually revised drafts, version differentials, and human authoring inputs.
- AI-Generated Content: Synthesized drafts, quality revision records, pillar alignments, and scoring metadata produced by artificial intelligence models.
- Approval Records & Workflow State: Explicit review decisions (
pending,approved,rejected), reviewer identifiers, timestamps, and version references. - Connected Social-Platform Information: Platform member IDs, public profile names, organization URNs, and channel identifiers returned by connected third-party platforms.
- OAuth Authorization Information: Server-side authorization codes, temporary cryptographic state tokens, token expiry timestamps, and encrypted access credentials necessary to interact with third-party social APIs.
- Technical & Operational Telemetry: System execution logs, API response codes, idempotency keys, error diagnostics, and timestamps required for security, bug tracking, and duplicate-prevention.
3. Use of Information
Information collected or processed by the SELF MASTERY AI Content Agent is used strictly for the following purposes:
- Operating the visual workflow engine, topic generator, and AI revision loop.
- Displaying content drafts, version history, and quality analytics within the Approval Center.
- Verifying human approvals before any publishing action can proceed.
- Executing authorized publishing dispatches to connected external channels solely when directed by the operator.
- Maintaining idempotency records to prevent accidental duplicate posts.
- Securing the system against unauthorized access, replay attacks, and state tampering.
The SELF MASTERY AI Content Agent does not sell, rent, lease, trade, or monetize personal information, content drafts, or platform credentials to third parties, data aggregators, or marketing networks under any circumstances.
4. OAuth & Social Integrations (Token Security & Isolation)
Connecting external social channels (such as LinkedIn) enables the application to publish approved content on your behalf. We enforce strict security protocols regarding integration data:
All OAuth authorization exchanges, token acquisitions, refreshes, and API dispatches are executed strictly server-side. Client secrets and raw access tokens are never transmitted to the client browser.
Tokens, secrets, and authorization codes are never rendered in React UI state, stored in browser localStorage / sessionStorage, exposed in client API responses, or printed in application telemetry logs.
Stored credentials are encrypted at rest using an AES-256-GCM authenticated vault architecture. Plaintext access tokens are never stored directly in database records.
We only request the minimum OAuth scopes necessary for content publication (e.g., w_member_social for member posts on LinkedIn). We do not request unrelated personal or contact permissions.
5. Artificial Intelligence Processing
The SELF MASTERY AI Content Agent utilizes enterprise-grade AI models (such as Google Gemini 3.8 Flash) via authenticated backend APIs to research, draft, critique, and refine educational content.
- Prompt Ingestion: Content topics, pillar guidelines, and author tone parameters are securely processed to construct generation prompts.
- Model Isolation: Sensitive credentials, OAuth tokens, and system secrets are strictly quarantined and never included in prompts submitted to language models.
- Human Oversight: AI-generated outputs are treated as non-final drafts requiring explicit human verification before any external action is possible.
6. Data Security & Architecture
We implement defense-in-depth technical and operational safeguards to protect processed information:
- Encryption in Transit: All HTTP interactions with application endpoints and external platform APIs are enforced via HTTPS using Transport Layer Security (TLS 1.3/1.2).
- Encryption at Rest: Database tables, credential vaults, and sensitive application data are encrypted at rest using AES-256-GCM.
- Single-Use State Tokens: OAuth flows use cryptographically random, single-use, time-bound state parameters bound to the specific user and workspace to eliminate CSRF and replay vectors.
- Publication Air-Gap: Content drafting and approval workflows operate in an isolated pipeline. Approving a draft does not trigger publishing unless an explicit publishing command is initiated.
7. Data Retention & Deletion
We retain information only as long as necessary to provide the services requested:
- Content & Approvals: Stored content records, versions, and audit logs are retained within the active workspace until modified or deleted by the user.
- Integration Credentials: OAuth tokens are retained until the token expires or the user disconnects the channel.
- Purging on Disconnect: Disconnecting a channel immediately resets the integration state and purges encrypted credentials from the database.
8. User Controls & Choices
Users maintain full sovereignty over their content and connected integrations:
- Disconnect Integrations: You may disconnect any connected social platform at any time via the Channels interface. Disconnecting revokes application access and deletes stored tokens.
- Editorial Control: You can edit, revise, create new versions of, or reject any content draft prior to approval.
- Draft Isolation: Selecting "Approve Draft" keeps the content safely stored as approved without publishing it externally.
9. Third-Party Services & Platform Terms
When utilizing integrations or external AI services, data handling is also subject to the terms and privacy practices of those respective third-party providers:
- LinkedIn: Subject to the LinkedIn Developer Agreement, API Terms of Use, and LinkedIn Privacy Policy.
- Google Gemini API: Subject to Google Cloud / Google AI Terms of Service and Privacy Policy.
- Supabase: Subject to Supabase Data Processing Agreements and Privacy Policy for hosting backend database infrastructure.
All connected-platform data is handled in strict compliance with applicable platform developer policies, API limits, and guidelines.
10. Children's Privacy
The SELF MASTERY AI Content Agent is intended solely for adult content creators, business professionals, and educators. We do not knowingly collect, solicit, or process personal data from children under the age of 13 (or under 16 where required by applicable local legislation). If we discover that personal data of a minor has been collected without verifiable parental consent, we will promptly delete such information.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect modifications in application functionality, security architecture, third-party platform API requirements, or legal regulations. Any updates will be posted directly to this public route (/privacy) with an updated "Last Updated" timestamp at the top of the document. Continued use of the application following the posting of revisions constitutes acknowledgment of the updated policy.
12. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or the handling of your data within the SELF MASTERY AI Content Agent, please contact the application owner:
Notice: Never include confidential OAuth client secrets, API keys, or access tokens in correspondence.