Privacy Policy
Last updated: 17 August 2026
This page describes how information is handled for ContentSilo. It is a product-specific draft for the current invited private beta. It is not legal advice and is not a claim of GDPR certification or confirmed legal compliance.
1. Introduction
ContentSilo is currently an invited private-beta software service. This policy explains how information is handled when people use the public website and when invited users use the private beta.
2. Controller and contact
The operator of ContentSilo has not yet published a confirmed legal entity for public launch. The following fields are placeholders and must be completed before a wider release:
- Legal entity / owner name: [Operator legal name — to be completed]
- Business contact address: [Operator postal address — to be completed]
- Privacy contact email: privacy@contentsilo.io (this address may be a placeholder until domain email is configured)
Do not treat the placeholders above as a registered company name, VAT number, or postal address.
3. Information collected
Depending on how the service is used, ContentSilo may process:
- Google / Supabase authentication: email address, name or profile information provided by Google, and a Supabase user identifier.
- Account and workspace data: profile, membership, project settings, and private-beta access status.
- User content: uploaded product images and videos, brand assets, copy, instructions, metadata, and creative settings.
- Generated content: generated backgrounds, image variants, video outputs, and review or approval state.
- Operational data: job status, error logs, usage and credit data, timestamps, and device, browser, or network information where collected for security and reliability.
- Support communications sent to the contact addresses on this site.
- Future social integrations: limited connected-account, page, or channel information, encrypted authorization tokens, and publishing requests or results, only if a user later explicitly connects an account and starts a relevant action. In this private beta, invited users may connect YouTube and Facebook Page when those integrations are configured. Instagram, TikTok, and Threads are not live.
4. Purposes
Information is used to:
- Authenticate and authorize invited users.
- Provide product-creative generation, review, storage, and download.
- Process selected AI-generation requests.
- Secure the service, prevent abuse, troubleshoot, and improve reliability.
- Handle support requests.
- Meet applicable legal obligations.
- Support future social publishing only when a user explicitly requests it. In this private beta, that currently means YouTube and Facebook Page when the user connects an account. Instagram, TikTok, and Threads are not live.
5. Service providers / processors
ContentSilo uses infrastructure and service providers to operate the private beta. Current providers include:
- Supabase: authentication, database, and object storage.
- IONOS: application and worker infrastructure for the private-beta deployment.
- External AI providers: image and video generation services when a user requests generation. The current configured generation path uses fal.ai. Other generation features may use additional configured providers only when those features are requested.
- Google: authentication through Google login.
- Connected platforms: YouTube and Meta/Facebook Page when an invited user chooses to connect an account. TikTok is not enabled in this beta.
6. Sharing
Data is shared only as needed with the infrastructure and service providers listed above, and later with a connected platform if a user requests that integration. ContentSilo does not sell personal data. This policy does not claim that data is never shared with processors needed to run the service.
7. Retention
- Account and project assets remain until deleted by the user or account owner, subject to legal and operational requirements.
- Product cutouts and approved assets may be retained while the related project exists.
- Temporary render files are deleted after processing, with limited operational cleanup and retry retention.
- Rejected or unselected variants may be deleted after a configured retention period.
- If social connections are later enabled, connected social tokens are deleted or revoked after disconnection or a deletion request, where supported.
- Logs are retained for a limited operational and security period.
Exact retention durations are not listed here unless a specific configuration is published.
8. Security
ContentSilo uses private access controls, signed URLs for stored media where applicable, encryption in transit (HTTPS), limited server access, and logging and monitoring practices. No method of transmission or storage is completely secure, and this page does not promise absolute security or guarantee encryption at rest.
9. International transfers
Service providers may process information in locations outside the user’s country. This page does not describe a specific GDPR transfer mechanism.
10. Rights and choices
Where applicable, you may have rights to access, correct, delete, restrict, or object to certain processing, and to request portability of personal data. You may request deletion at privacy@contentsilo.io. Instructions are also available on the Data Deletion page.
11. Children
The service is not intended for children.
12. Changes
This policy can change as the product evolves. The updated date at the top of this page will be revised when the text changes.
13. Contact
Privacy questions: privacy@contentsilo.io. General contact details are on the Contact page.
Before public launch, ContentSilo should obtain legal review of this policy for its legal entity, jurisdictions, data-processing arrangements, and planned platform integrations.