Legal
Privacy Policy
Last updated: July 16, 2026
1. Overview
This Privacy Policy explains how Croxa (“Croxa,” “we,” “us,” or “our”) collects, uses, stores, and shares personal information when you visit our websites, create an account, or use our AI Marketing Operating System (the “Service”). We designed Croxa for organizations that need predictable, brand-safe automation — and we apply the same discipline to privacy.
By using the Service, you acknowledge this Policy. If you are using Croxa on behalf of a company, you represent that you have authority to accept this Policy for that company.
2. Information We Collect
2.1 Account and organization data
We collect information you provide during signup and workspace setup, including name, email address, password credentials (stored as irreversible hashes), organization name, billing contacts, and role assignments within a tenant.
2.2 Brand memory and marketing assets
To generate on-brand campaigns, you may upload logos, product images, brand colors, tone preferences, industry details, campaign objectives, and related creative references. These materials are processed as customer content within your organization boundary.
2.3 Usage and device data
We automatically collect technical logs such as IP address, browser type, approximate location derived from IP, device identifiers, referring URLs, pages viewed, feature usage events, and diagnostic error reports needed to keep the Service reliable.
2.4 Integrations
If you connect social platforms (for example Facebook, Instagram, LinkedIn, or X), we receive OAuth tokens and account metadata required to publish or schedule content. Tokens are encrypted at rest and used only to perform actions you authorize.
3. How We Use Information
- Provide, operate, secure, and improve the Croxa Service.
- Authenticate users and enforce role-based access within tenants.
- Generate, store, and deliver campaign assets based on your brand configuration.
- Process subscriptions, credit usage, invoices, and customer support requests.
- Detect abuse, prevent fraud, and investigate security incidents.
- Communicate product updates, operational notices, and optional marketing messages.
- Comply with legal obligations and enforce our Terms of Service.
4. AI Data Usage
Croxa routes certain requests through an AI Provider Gateway to text, vision, and image models selected by platform configuration. Customer prompts, brand rules, layout schemas, and uploaded references may be transmitted to those providers solely to produce the requested output.
We do not sell customer content. Where commercially available, we configure providers to disable training on customer data and to process requests under enterprise/API terms. Because model providers may change over time, the active model identifiers can be updated by Croxa administrators without changing the principles in this section.
You should avoid uploading sensitive personal data that is not necessary for campaign generation (for example government IDs, health records, or precise geolocation of private individuals). If such data is submitted, it will be handled as customer content under this Policy and our data processing commitments.
5. Generated Content & Copyright
Subject to your compliance with our Terms and applicable third-party model licenses, you retain ownership of your pre-existing brand assets. As between you and Croxa, you own the campaign outputs generated for your organization, including copy and images produced by the Service, except for underlying model weights, platform software, and Master Style Library rules that remain Croxa intellectual property.
You are responsible for ensuring generated content does not infringe third-party rights, violate platform policies, or misrepresent regulated claims. Croxa provides tooling and guardrails; it does not guarantee that every output is free from similarity to other works or suitable for every regulated industry.
7. Retention & Security
We retain account and workspace data for as long as your organization maintains an active subscription and for a reasonable period afterward to comply with legal, accounting, or security requirements. Layout schemas may be archived (not immediately deleted) to support historical reuse features described in the product.
We implement administrative, technical, and organizational safeguards including encrypted transport, access controls, password hashing, least-privilege internal access, and monitoring. No method of transmission or storage is perfectly secure; we continuously improve controls as the threat landscape evolves.
8. Your Rights
Depending on your location, you may have rights to access, correct, delete, or export personal information; object to or restrict certain processing; and withdraw consent where processing is consent-based. Organization owners can manage most workspace data directly in-product. For additional requests, contact privacy@omnisync.ai. We may need to verify your identity before fulfilling a request.
9. International Transfers
Croxa may process data in countries other than where you are located. When we transfer personal information internationally, we use appropriate safeguards such as standard contractual clauses or equivalent mechanisms recognized under applicable law.
10. Children
Croxa is a business service and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will take appropriate steps to delete it.
11. Changes
We may update this Privacy Policy to reflect product, legal, or operational changes. We will revise the “Last updated” date and, when changes are material, provide additional notice through the Service or by email.
12. Contact
Questions about this Policy or Croxa privacy practices can be sent to privacy@omnisync.ai. For general support, contact support@omnisync.ai.