Legal
Privacy Policy
Last updated: 4 August 2026
1. Who we are
This Privacy Policy describes how Infotex Media Private Limited (“Infotex”, “we”, “us”) collects, uses, stores, and shares information when you use Origin OS (the “Service”), including Mission Control, Studio, Growth Intelligence, Integration Center, Poola TV admin tools, and related modules.
Contact: privacy@infotex.media · Support: support@infotex.media
Legal entity: Infotex Media Private Limited (India).
2. Scope
This Policy applies to authenticated users of Origin OS (employees, contractors, studio members, and authorized clients) and to visitors of our sign-in and legal pages. Separate consumer products (for example the public Poola TV viewer experience on poola.tv) may publish additional notices where required.
3. Information we collect
Account & identity. Name, email address, authentication credentials (hashed/managed via our auth provider), role and studio membership, profile photo if provided, and device/session identifiers used to keep your login secure.
Workspace content. Projects, scripts, assets, generation prompts and outputs, comments, reviews, reports, ad project settings (goals, budgets, YouTube links, headlines), and similar content you create or upload in the Service.
Integration & connection data. When you connect third-party services (for example Google Ads, YouTube, Google Drive, Cloudflare, AI providers), we store connection metadata, account labels, OAuth tokens (encrypted), API credentials you place in Secrets Vault (encrypted at rest), and technical logs needed to operate those integrations.
Usage & diagnostics. Feature usage, generation usage and spend metrics, approximate IP address, browser/device type, timestamps, error logs, and security events.
Communications. Support messages and transactional emails (invites, stage notifications, reports).
4. How we use information
- Provide, secure, and improve Origin OS and its modules.
- Authenticate users, enforce roles, and prevent unauthorized access.
- Run integrations you enable — including Google Ads campaign management/reporting, YouTube metadata, cloud storage, AI generation, and email delivery — only as needed to perform the requested action.
- Measure usage, billing/quotas, reliability, and product analytics.
- Comply with law, respond to lawful requests, and protect Infotex and users.
We do not sell personal information. We do not use Google user data obtained via Google APIs for advertising to end users outside the Service, or for purposes unrelated to providing Origin OS features you requested.
5. Google APIs & Limited Use
Origin OS’ use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
When you connect Google Ads / YouTube / related Google services, we access only the scopes you authorize (for example Ads management/reporting and YouTube read scopes as configured). Access tokens and refresh tokens are stored encrypted and used to call Google APIs on your behalf. You can disconnect Google accounts in Integration Center; you may also revoke access in your Google Account permissions.
Google Ads campaigns, policies, billing, and ad content remain subject to Google Ads policies and your Google Ads account terms. Origin OS does not override Google’s review, disapproval, or suspension decisions.
6. Third-party processors
We use subprocessors to host and operate the Service. Depending on configuration, these may include:
- Supabase — authentication and database (Privacy).
- Cloudflare — R2 object storage and related infrastructure (Privacy).
- Google — OAuth, Google Ads API, YouTube APIs (Privacy).
- AI generation providers (for example Runware, Fal, OpenAI) — process prompts/media you submit to generate content under their terms.
- Resend (or similar) — transactional email delivery.
- Hosting / observability providers used to run and monitor the application.
These providers process data under their own policies and our instructions. Where you bring your own API keys, those providers may associate usage with your provider account.
7. Secrets Vault & credentials
Platform Secrets Vault encrypts API keys and similar credentials at rest. Access is restricted to authorized server processes and privileged administrators. You are responsible for the accuracy of credentials you store and for rotating them if compromised.
8. Retention
We retain account and workspace data while your organization uses the Service and for a reasonable period afterward for backups, audits, dispute resolution, and legal compliance. Integration tokens are retained until you disconnect or an admin deletes them. Logs are retained for security and operations on a rolling basis.
9. Security
We use industry-standard measures including TLS in transit, encrypted storage for sensitive secrets, role-based access control, and session controls. No method of transmission or storage is 100% secure; please use strong unique passwords and report suspected incidents to security@infotex.media.
10. Your choices & rights
Depending on your location and role, you may request access, correction, deletion, or export of personal data we hold about you, subject to legal and operational limits (including employer-controlled workspace data). Contact privacy@infotex.media. Workspace owners/admins may manage user access inside Origin OS.
11. International transfers
Infotex is based in India. Data may be processed in India and in other countries where our processors operate. Where required, we use appropriate safeguards for cross-border transfers.
12. Children
Origin OS is a business tool and is not directed to children under 16. We do not knowingly collect personal information from children.
13. Changes
We may update this Policy from time to time. Material changes will be reflected by updating the “Last updated” date on this page. Continued use of the Service after changes constitutes acceptance of the updated Policy where permitted by law.
