Privacy Policy
CO8 is a business tool for planning, generating and publishing advertising creative. This policy explains what we collect, why, how long we keep it, and how to get it deleted.
Effective 11 August 2026 · CO8
1. Who this covers
CO8 is used by businesses. Accounts are created for named people inside a company workspace, and the data in a workspace belongs to that company. We do not offer consumer accounts and we do not knowingly collect data from anyone under 18.
2. What we collect
- Account data. Name, email address, hashed password, company and brand membership, and the settings you choose. Used to sign you in and scope what you can see.
- Content you create. Brand profiles, products, campaigns, prompts, generated images and copy, and the assets you upload. Stored so your workspace persists between sessions.
- Connected platform data. Tokens and data returned by advertising and social platforms you choose to connect. Detailed in section 3.
- Operational logs. Request metadata, error traces, and job records. Used to keep the service running and to investigate faults. Not used to build advertising profiles of you.
3. Meta platform data
Connecting a Meta account is optional and always initiated by you. When you connect one, we request only the permissions the corresponding feature needs:
ads_read,ads_management,business_management— to read your ad accounts, campaigns, creatives and performance metrics, and to manage the campaigns you ask us to manage.pages_show_list,pages_read_engagement,read_insights— to list the Pages you administer and read their engagement and insights.pages_manage_posts,instagram_basic,instagram_content_publish,instagram_manage_insights— to publish the posts you schedule and report back how they performed.
We also read the Meta Ad Library, which is public data Meta publishes about ads that are running. That research needs no permission from you and involves no personal data.
Meta data is used only to provide the features you asked for. We do not sell it, we do not use it for advertising to you, we do not use it to train machine learning models, and we do not merge one customer's Meta data into another customer's workspace. Access tokens are stored encrypted and are used only on your behalf.
Disconnecting a Meta account from your workspace settings revokes our access and deletes the stored token immediately. You can also revoke access at any time from your Facebook settings under Business Integrations, which takes effect at once and without notice to us.
Removing the app on Facebook triggers our data deletion callback automatically: we delete the stored tokens and platform connections and hand Facebook a confirmation code you can use to verify it on our data deletion page. No email or support request is needed.
4. AI processing
Generating creative sends your prompt and the relevant brand context to third-party AI providers. Those providers process it to return a result and are contractually restricted to that purpose. Do not put information into a prompt that you would not want processed by a third party.
5. Sharing
We share data with infrastructure and AI providers strictly to run the service — hosting, storage, databases, email delivery, and the model providers above. We do not sell personal data and we do not share it for anyone else's advertising. We disclose data to authorities only where legally required.
6. Retention and deletion
Workspace data is kept while your account is active. Delete individual items at any time from inside the app. To delete an entire account and everything in it, email [email protected] from the address on the account. We action deletion within 30 days, after which the data is gone from live systems; backups age out on their own schedule.
Deleting your account also deletes any stored Meta tokens and the platform data we hold for it.
7. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to some processing. Email [email protected] and we will respond within 30 days.
8. Security
Traffic is encrypted in transit. Credentials are hashed and platform tokens are stored encrypted. Access is scoped per company and per brand, so one workspace cannot read another. No system is perfectly secure; if a breach affects your data we will notify you as required by law.
9. Changes
If we change this policy we update the effective date above, and for material changes we notify account holders by email before the change takes effect.