Privacy Policy
Last updated: September 18, 2026
This Privacy Policy explains how Aideo collects, uses, stores, shares, and deletes data when you use our AI creative workspace, connected YouTube, TikTok, Facebook, and Instagram features, and the Aideo browser extension that Aideo's Douyin, Xiaohongshu (RedNote), and WeChat Channels features require.
1. Information We Collect
- Account data, including email address, phone number (for phone-based sign-up), username, password hash, verification status, and login metadata.
- Brand profile data, including company name, industry, brand description, tone, and optional logo preferences.
- User-provided creative inputs, including prompts, briefs, captions, uploaded brand assets, and reference images.
- Generated media and history, including prompt summaries, generated images, generated videos, job status, and publishing history.
- Connected account data from Google/YouTube, TikTok, and Meta, including OAuth tokens, account identifiers, channel/page/account names, scopes, connection status, and dashboard metrics.
- Data from Douyin, Xiaohongshu (RedNote), and WeChat Channels collected by the Aideo browser extension, once you install it and connect it to your Aideo account, as described in Section 6.
- Billing data, including wallet balances, wallet transaction history (grants, charges, refunds, adjustments), pricing shown for generations, and subscription status. We never store card numbers or full payment credentials; payment processing, when introduced, is handled by a dedicated payment provider.
- Support messages you exchange with the Aideo team through the in-app inbox.
- Technical data needed for security and operations, such as request metadata, error logs, and usage records.
- Privacy-safe product usage events that record which features and workflow steps you reach (for example, opening the studio, confirming a plan, or a generation succeeding or failing) so we can understand and improve the product. These events are limited to a fixed set of step names and simple counts; they never include your prompts, briefs, captions, generated media, file contents, or credentials.
2. How We Use Information
We use information to:
- create and secure your account;
- generate AI-assisted creative briefs, images, copy, and videos;
- store your generation history and product workspace state;
- connect social destinations and publish only content you approve;
- show YouTube, Instagram, and Facebook dashboard metrics where you have granted permission;
- through the Aideo browser extension, show your Douyin, Xiaohongshu (RedNote), and WeChat Channels statistics and publish videos you approve to those platforms;
- send verification, password reset, and service emails;
- measure aggregate product usage and funnel drop-off to improve the product;
- detect abuse, debug errors, protect the service, and comply with law.
3. Google and YouTube API Data
Aideo accesses the following raw Google user data, only after you connect your YouTube channel and only for user-facing features that you initiate: your channel identifier and channel name, metadata about your channel's videos (such as video IDs, titles, and publishing status), YouTube Analytics metrics for your channel (such as views and watch time), and the OAuth tokens needed to keep the connection active. OAuth tokens are encrypted before storage. We do not create aggregated or anonymized datasets from Google user data.
We use this data to show your connected channel, its videos, and its performance metrics in your dashboard, and to upload videos you explicitly approve to your channel. Google user data is processed and stored only by the hosting and database infrastructure providers that operate our service. It is never sold or shared with any other third party, never transferred to advertising platforms or data brokers, never used for retargeting, and never sent to the AI providers described in Section 7 or used to train AI/ML models.
Google user data is retained and deleted as described in Sections 9 and 10. When you disconnect YouTube inside Aideo, we delete the stored OAuth tokens; you can also revoke Aideo's access at any time from your Google Account permissions page.
Aideo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4. Meta, Facebook, and Instagram Data
Aideo uses Meta Graph API data only for user-facing Facebook and Instagram features that you initiate, such as identifying manageable Facebook Pages or Instagram Professional Accounts, showing eligible destinations, displaying account metrics, and publishing approved post assets and captions. OAuth tokens are encrypted before storage. We do not sell Meta user data or use it to train foundation models.
5. TikTok Data
Aideo uses TikTok data only for user-facing features that you initiate, including connecting your TikTok account, displaying the connected creator name, and exporting a generated video you explicitly approve to your TikTok inbox. You complete editing and publishing inside TikTok. TikTok OAuth tokens are encrypted before storage. We do not sell TikTok user data or use it to train foundation models.
6. Aideo Browser Extension (Douyin, Xiaohongshu/RedNote, and WeChat Channels)
Douyin, Xiaohongshu (including its overseas site RedNote), and WeChat Channels do not offer publishing or analytics APIs to third parties, so Aideo's features for them require the Aideo browser extension (“Aideo 助手”). It works inside your own browser, using the creator-centre sessions you are already signed in to. It runs only on aideo.it.com, creator.douyin.com, creator.xiaohongshu.com, creator.rednote.com, your public profile pages on www.xiaohongshu.com and www.rednote.com, and channels.weixin.qq.com. It does not read any other site you visit.
What it never collects. The extension never reads or transmits your passwords, cookies, or login sessions for these platforms. Aideo's servers cannot sign in to your platform accounts; everything the extension does happens in your browser, under your own session.
What it sends to Aideo, only after you install it and connect it to your Aideo account:
- Account identity: the platform's own identifier for the account you are signed in to (read from the value the platform stores in your browser) and the account's display name. We use the identifier to keep two accounts on one platform apart, and to confirm before publishing that your browser is signed in to the account you chose.
- Account statistics shown in the creator centre, such as follower, following, like, and view totals.
- For each post listed there: its identifier, title, cover image address, link, publish time, and view, like, comment, share, and save counts.
- When you publish: whether the post was submitted or failed and, if something failed, a short diagnostic such as the page path and the platform's on-screen message.
When it acts. While your browser is open, the extension reads the statistics above about once a day, and once more right after you publish, by opening the creator-centre pages in background tabs and closing them when done. It publishes only when you press Publish in Aideo: it downloads the video you chose from Aideo, uploads it to the platform through your own session, fills in the caption and the publish settings you selected in Aideo (such as the content declaration, visibility, and scheduled time), and presses the platform's publish button.
What stays in your browser. The extension keeps a connection token for your Aideo account and a note of which regional creator centre each of your accounts uses. For each connected browser, our servers keep only a label derived from its user agent (for example, “Chrome on macOS”), the extension version, when it was last seen, and a one-way hash of its token.
How it is used. Data collected by the extension is used only to show your statistics in Aideo, to publish content you approve, and to check the target account before publishing. It is stored and deleted with the rest of your Aideo account data (Sections 9 and 10). It is not sold, not used for advertising, credit, or lending decisions, and not sent to the AI providers described in Section 7. The use of information collected through the extension complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.
Your controls. You can disconnect a browser at any time from Settings in Aideo, which revokes its token and stops the extension from syncing or publishing. Removing the extension from your browser deletes the data it keeps there. Deleting your Aideo account deletes the statistics, account records, and publishing history the extension collected.
7. AI Providers and Subprocessors
To provide generation features, Aideo may send relevant prompts, briefs, uploaded references, and brand context to AI providers and infrastructure providers. We limit this sharing to what is needed to provide the requested feature and operate the service.
Phone verification codes are delivered through Alibaba Cloud's SMS service, which processes your phone number on our behalf solely to deliver the message. Verification codes are stored by Aideo only as salted one-way hashes and expire within minutes. When bot protection is enabled, sign-up and verification requests are additionally checked through Alibaba Cloud's CAPTCHA service. We log phone numbers only in masked form.
8. Storage and Security
We use reasonable technical and organizational safeguards, including HTTPS in production, password hashing, encrypted OAuth token storage, role-based admin controls, and access-limited storage for media assets. No internet service can be guaranteed to be perfectly secure.
9. Retention
We retain account data, brand profiles, generated assets, connection records, metrics, and publishing history while your account is active or as needed to provide the service, comply with law, resolve disputes, prevent abuse, or maintain security. You can delete your account from Settings.
Wallet transaction records are financial records: after account deletion they are retained in anonymized form (no longer linked to your identity) where bookkeeping and tax law requires, and are excluded from the deletion described below for that reason.
10. Deletion and Revocation
You may delete your Aideo account in product settings. You may also revoke Google access from your Google Account permissions page, revoke TikTok access from TikTok security settings, and revoke Meta access from Facebook Business Integrations or Meta account settings. You can disconnect the Aideo browser extension from Settings in Aideo and remove it from your browser at any time. See Data Deletion Instructions for details.
11. Children
Aideo is not intended for children under 13 and should not be used by anyone who is not old enough to consent to online services in their jurisdiction.
12. Changes to This Policy
We may update this Privacy Policy as the product, law, or platform requirements change. If we materially change how we use Google, Meta, or other user data, we will provide notice or request renewed consent where appropriate.
13. Contact
Privacy questions can be sent to support@aideo.it.com.