Privacy Policy

Last Updated and Effective Date: 24 May 2025

Article 1: Introduction & Scope

This Privacy Policy details the data processing practices of Oolook Ltd. ("Oolook," "we," "us," or "our"). It applies to all information collected through your use of the Oolook website, platform, associated mobile applications, mini-tools, and APIs (collectively, the "Services"). This policy governs your rights and our obligations regarding your Personal Data, including specific disclosures on how we handle Google user data accessed via OAuth.

By accessing or using our Services, you signify that you have read, understood, and agree to our collection, storage, use, and disclosure of your personal information as described in this Privacy Policy and our Terms of Service. This policy is prominently linked and accessible from our application's homepage and within the user interface.

Article 2: Definitions

  • Personal Data: Any information that relates to an identified or identifiable individual, including name, email address, and profile information.
  • Google User Data: Any data accessed from a user's Google Account via OAuth authentication, such as profile information or data from connected services like YouTube.
  • Usage Data: Information collected automatically through the operation of the Services, such as IP addresses, browser type, and actions taken within the platform.
  • User Content: Any data, text, images, videos, or other materials that you upload, submit, or generate through the Services, including AI prompts and outputs.
  • Subprocessor: A third-party data processor engaged by Oolook who has or potentially will have access to or process Service Data to help provide our Services.

Article 3: Data We Collect and How We Collect It

3.1. Data Provided Directly by You

  • Identity and Contact Data: We collect your first name, last name, email address, and company name when you register for an account, request a demo, or contact support.
  • Financial Data: Our third-party payment processors (e.g., Stripe) collect payment and billing information when you subscribe to a paid Service. Oolook does not directly store or have access to your full credit card information.
  • User Content: We process any User Content you provide to the Services to enable the core functionality of the platform, such as generating AI content, scheduling posts, or analyzing performance.

3.2. Data from Third-Party Services (e.g., Google)

  • When you choose to connect a third-party service like a Google Account to Oolook, we collect data from that service as authorized by you. This is exclusively used to provide and improve the user-facing features of our Services. See Article 4 for detailed information on Google User Data.

3.3. Data Collected Automatically

  • Log and Device Data: We automatically log information about your device, such as IP address, operating system, browser type, and pages visited, to ensure the security and proper functioning of our Services.
  • Cookie Data: We use cookies and similar technologies to operate our Services, gather usage data to improve your experience, and for performance analytics.

Article 4: Information from Google Services (OAuth)

Oolook allows you to connect your Google Account to our platform to enable specific features, such as scheduling videos to YouTube or logging in with Google. Our handling of this data is governed by strict policies to protect your privacy.

4.1. What Google User Data We Access

We only request access to the minimum scopes necessary to provide our Services. Depending on the features you use, this may include:

  • Basic Profile Information: Your name, email address, and profile picture to create and secure your Oolook account.
  • YouTube Channel Data: With your explicit permission, we may access your YouTube channel data to allow you to schedule video publications, manage comments, and view analytics directly within the Oolook platform. This access is granted on your behalf and can be revoked by you at any time.

4.2. How We Use Your Google User Data

Our use of Google User Data is strictly limited to providing or improving user-facing features that are prominent in Oolook's user interface. This includes:

  • Account Authentication: Using your Google identity to log you into your Oolook account securely.
  • Social Media Management: Allowing you to manage your connected YouTube channel, such as publishing content you have created and scheduled within Oolook.
  • Analytics Reporting: Displaying performance metrics from your connected YouTube channel within your Oolook analytics dashboard.

4.3. Limited Use Disclosure

Oolook's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4.4. Prohibited Uses of Google User Data

We explicitly state that we **do not** and **will not** use any Google User Data for the following prohibited purposes:

  • We do not sell Google User Data to any third parties, data brokers, or information resellers.
  • We do not use Google User Data for serving advertisements, including personalized, re-targeted, or interest-based advertising.
  • We do not use Google User Data for determining credit-worthiness or for any lending purposes.
  • We do not transfer Google User Data to other apps or services for reasons other than providing or improving our user-facing features.
  • We do not use any of your User Content or data accessed from connected Google services to train our general-purpose AI models.

Article 5: Use of Your Information

Your data is used to:

  1. Provide, maintain, and secure the Services.
  2. Process transactions and manage your subscription.
  3. Provide features you connect via third-party services (e.g., posting to a YouTube channel you have authorized).
  4. Communicate with you regarding your account and provide customer support.
  5. Analyze usage patterns to improve the user experience and service functionality.
  6. Prevent fraudulent activity and ensure compliance with our terms.

Article 6: AI Model Training

To improve our artificial intelligence models, we may use anonymized or aggregated User Content. However, we will **never** use personally identifiable information, sensitive information, or any data accessed from your connected Google services for training our general-purpose AI models.

Article 7: Data Sharing and Disclosure

We do not sell your Personal Data. We only share it with trusted Subprocessors for the sole purpose of providing and improving our Services. We will not transfer Google User Data to third parties for any reasons other than those outlined in Article 4. Categories of Subprocessors include:

  • Cloud & Hosting Providers: We use subprocessors like Amazon Web Services (AWS) and Vercel for secure data storage and hosting.
  • Payment Processors: To securely process your payments (e.g., Stripe).
  • Analytics Providers: To understand how our Services are used (e.g., Google Analytics).
  • Legal Authorities: If required by law, subpoena, or other legal process, and only to the extent required.

Article 8: Data Security and Protection

We implement robust technical and organizational security measures designed to protect your data from unauthorized access, disclosure, or destruction. These mechanisms include:

  • Encryption: All data, including sensitive Google User Data, is encrypted in transit using TLS 1.2+ and at rest using AES-256 encryption.
  • Access Controls: We enforce strict access controls and the principle of least privilege, ensuring that only authorized personnel with a legitimate business need can access your data.
  • Regular Audits: We conduct regular security assessments and penetration tests to identify and remediate potential vulnerabilities.

Article 9: Data Retention and Deletion

We retain your Personal Data for as long as your account is active or as needed to provide you with the Services. If you choose to delete your account, we will delete your Personal Data and any associated Google User Data from our production systems within 30 days, unless a longer retention period is required to comply with our legal obligations, resolve disputes, or enforce our agreements. You may request the deletion of your data at any time by contacting our Data Protection Officer.

Article 10: Your Rights and Choices

You have rights over your Personal Data. Subject to any exemptions provided by law, you have the right to:

  • Access, update, or delete the information we have on you through your account settings or by contacting us.
  • Object to or request that we restrict the processing of your Personal Data.
  • Request a copy of your data in a portable format (data portability).
  • Revoke Oolook's access to your Google Account at any time via your Google Account security settings page.

Article 11: International Data Transfers

Your information may be transferred to, and maintained on, computers located outside of your state, province, or country. We rely on legal mechanisms such as Standard Contractual Clauses (SCCs) to ensure that your data receives an adequate level of protection in the jurisdictions in which we process it.

Article 12: Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please contact our Data Protection Officer at privacy@oolook.in.