Legal · Version 2026-08-14
Data Protection & Privacy Policy
Effective date: August 14, 2026. Operated by JW-SYSTEMS-LLC, 131 Continental Drive, Newark, DE, United States, Delaware.
This Policy is designed to allocate risk between you and JW-SYSTEMS-LLC. It is not legal advice. Consult your own counsel for advice specific to your situation.
1. Introduction and binding agreement
This Data Protection & Privacy Policy (the "Policy") is a binding agreement between you ("you", "User", "Customer") and JW-SYSTEMS-LLC, located at 131 Continental Drive, Newark, DE, United States, Delaware ("Company", "we", "us", or "our").
It governs your access to and use of the AI Content Automation Platform website, application, APIs, dashboards, automations, and related services (collectively, the "Platform").
BY CREATING AN ACCOUNT, SIGNING IN, CLICKING ACCEPT, OR USING THE PLATFORM IN ANY WAY, YOU ACKNOWLEDGE THAT YOU HAVE READ THIS ENTIRE POLICY, UNDERSTAND IT, AND AGREE TO BE LEGALLY BOUND BY IT. IF YOU DO NOT AGREE, DO NOT USE THE PLATFORM.
You must scroll through the entire Policy and affirmatively accept it before using protected features of the Platform. A persistent link to this Policy remains available so you can review it at any time.
2. Eligibility and authority
You represent that you are at least 18 years old (or the age of majority in your jurisdiction) and have legal capacity to enter this agreement.
If you use the Platform on behalf of a business, you represent that you have authority to bind that business to this Policy, and that "you" includes that business.
You are solely responsible for ensuring your use of the Platform complies with all laws, regulations, industry rules, platform rules (including social networks), and contractual obligations that apply to you.
3. Roles: who is responsible for what
You are the owner and controller of: (a) your account credentials; (b) API keys, tokens, and secrets you supply; (c) business content, brand data, scripts, media, customer lists, and other materials you upload or generate through the Platform ("Customer Data"); and (d) your use of third-party services connected to the Platform.
We provide software tooling and hosting. We are not your lawyer, compliance officer, security auditor, insurer, or guarantor of third-party services.
You remain solely responsible for content you publish, claims you make in marketing, industry-specific advertising rules (including but not limited to healthcare, dental, HVAC, roofing, financial, or professional services rules), and consequences of automated posting.
4. Data we may collect
To operate, secure, improve, support, market, bill, enforce, and develop the Platform, and for any other lawful business purpose we determine, we may collect, receive, store, process, analyze, and retain information including without limitation:
- Account and identity data (name, email, password hashes managed by our auth provider, profile fields, role/membership).
- Workspace and brand data (business profiles, offers, personas, proof points, guardrails, onboarding answers, strategy settings).
- Content and media (ideas, scripts, prompts, assets, renders, captions, B-roll metadata, publish history).
- Integration configuration (provider settings, encrypted API keys/tokens, non-secret configuration such as model names or account IDs).
- Usage, diagnostics, and telemetry (logs, IP addresses, device/browser metadata, approximate location derived from IP, feature usage, error reports, performance metrics).
- Communications you send us (support requests, emails, feedback).
- Payment, license, or commercial information if applicable to your plan.
- Any other information you voluntarily provide or that is reasonably necessary to provide or protect the Platform.
5. Sources of data
We may obtain information directly from you, automatically from your devices and browsers, from your teammates within a workspace, from cookies or similar technologies, from our infrastructure and security tooling, and from third parties you authorize (for example AI providers, avatar/voice vendors, analytics or social platforms when you connect them).
If you scrape, import, or sync data from websites or third-party accounts, you represent that you have all rights and permissions required to do so.
6. How we may use data
We may use data for any purpose related to operating our business and the Platform, including without limitation:
- Providing, maintaining, personalizing, and improving features and workflows.
- Running AI generation, rendering, publishing, scheduling, analytics, and automation jobs you request.
- Securing accounts, detecting abuse, fraud, spam, or misuse, and enforcing this Policy.
- Customer support, onboarding, training materials, and product communications.
- Business analytics, product research, benchmarking in aggregated or de-identified form, and service quality measurement.
- Marketing our products and services (you may opt out of marketing emails where required by law; transactional/service messages may still be sent).
- Legal compliance, dispute resolution, and protection of rights, property, and safety of the Company, users, and the public.
- Corporate transactions (merger, acquisition, financing, or sale of assets), in which data may be transferred as a business asset subject to appropriate confidentiality.
7. API keys, secrets, and BYOK (bring your own keys)
The Platform is designed so that you supply your own third-party API keys, access tokens, and credentials ("Customer Secrets") for providers such as OpenAI, Anthropic, ElevenLabs, HeyGen, Pexels, Meta, TikTok, YouTube, X, Reddit, LinkedIn, and others.
We implement encryption at rest for Customer Secrets stored in workspace integration settings (for example AES-256-GCM with a server-side encryption key). This is a security measure intended to reduce risk; IT IS NOT A GUARANTEE against unauthorized access, misconfiguration, insider threats, zero-day vulnerabilities, compromised endpoints, phishing, malware on your devices, or failures of third-party systems.
YOU ARE SOLELY RESPONSIBLE FOR: (a) creating, rotating, scoping, and revoking Customer Secrets; (b) monitoring provider dashboards for unusual usage and charges; (c) setting spend limits and alerts with each provider; (d) not sharing secrets with unauthorized persons; and (e) immediately rotating secrets if you suspect compromise.
TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE COMPANY IS NOT LIABLE FOR LEAKED, STOLEN, MISUSED, OR OVERBILLED API KEYS OR TOKENS; UNAUTHORIZED USE OF YOUR PROVIDER ACCOUNTS; OR ANY COSTS, DAMAGES, CONTENT LOSS, OR ACCOUNT BANS ARISING FROM CUSTOMER SECRETS—WHETHER CAUSED BY USER ERROR, TEAM MEMBER ACTIONS, THIRD PARTIES, OR SECURITY INCIDENTS.
Do not submit secrets that you are not authorized to use. Do not paste secrets into non-secret fields, chat logs, tickets, or public repositories.
8. Third-party platforms and subprocessors
The Platform may send Customer Data and Customer Secrets to third-party providers you configure or that are required to run the service (hosting, database, authentication, AI inference, media rendering, social publishing, email, analytics, CDN, logging).
THOSE THIRD PARTIES HAVE THEIR OWN TERMS AND PRIVACY PRACTICES. WE DO NOT CONTROL AND ARE NOT RESPONSIBLE FOR: their collection, use, retention, training, logging, or disclosure of data; their outages; their model outputs; their content moderation; their billing; or their security incidents.
Examples (non-exhaustive): OpenAI, Anthropic, ElevenLabs, HeyGen, Pexels, Meta/Facebook/Instagram, TikTok, YouTube/Google, X (Twitter), Reddit, LinkedIn, Supabase, Vercel, and any other integration you enable.
When you publish to social networks, those networks may collect device data, engagement metrics, IP addresses, and content according to their policies. We are not responsible for how those platforms use data after you authorize posting or analytics access.
AI providers may process prompts and outputs according to their enterprise/API terms. You are responsible for reviewing whether those terms allow your intended use (including whether inputs may be used for model improvement under your provider contract).
9. Generated content, publishing, and compliance risk
AI-generated text, audio, video, captions, and recommendations may be inaccurate, incomplete, biased, infringing, or unlawful. You must review and approve outputs before publishing.
You are solely responsible for intellectual property clearance, publicity rights, music/SFX licensing, trademark issues, defamation, false advertising, and regulated claims.
Automated or scheduled publishing features do not shift legal responsibility to us. If a post causes harm, platform penalties, or legal claims, that risk is yours.
10. Security measures (no warranty of absolute security)
We apply commercially reasonable administrative, technical, and organizational measures appropriate to the nature of the Platform, which may include encryption of Customer Secrets, access controls, TLS in transit where supported, and hosting provider safeguards.
NO METHOD OF TRANSMISSION OR STORAGE IS 100% SECURE. We do not warrant that the Platform will be free of vulnerabilities, unauthorized access, data loss, corruption, or downtime.
You must use strong unique passwords, protect session devices, limit teammate permissions, and enable provider-side security features where available.
11. Security incidents and data leaks — limitation of responsibility
If a security incident, suspected breach, misconfiguration, or data exposure occurs, we may investigate and take steps we consider appropriate. Notification will be provided only as required by applicable law or as we choose in our discretion.
TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE COMPANY DISCLAIMS LIABILITY FOR DATA LEAKS, UNAUTHORIZED DISCLOSURE, LOSS OF CUSTOMER DATA, LOSS OF CUSTOMER SECRETS, ACCOUNT TAKEOVER, RANSOMWARE, SUPPLY-CHAIN ATTACKS, OR ANY CONSEQUENTIAL DAMAGES ARISING FROM SECURITY EVENTS—INCLUDING EVENTS INVOLVING OUR HOSTING PROVIDERS OR YOUR CONNECTED THIRD-PARTY SERVICES.
Your exclusive remedies for dissatisfaction with security or privacy practices are to stop using the Platform and, where required by law, exercise applicable statutory rights.
12. Retention and deletion
We may retain data for as long as your account/workspace exists and for a commercially reasonable period afterward for backups, fraud prevention, dispute resolution, legal compliance, and legitimate business records.
You may request deletion of your account by contacting us. We will process requests as required by law and as operationally feasible. Residual copies may remain in encrypted backups for a limited time. We may retain information when we have a legal obligation or compelling legitimate interest to do so.
Deleting the Platform account does not delete data held by third-party providers under your own accounts; you must manage those deletions directly with each provider.
14. International processing
The Platform may be hosted and processed in the United States and other countries. If you access the Platform from outside the United States, you consent to transfer of your information to the United States and other jurisdictions that may have different data-protection laws than your country of residence.
16. Children
The Platform is not directed to children under 18. We do not knowingly collect personal information from children. If you believe a child provided information, contact us and we will take appropriate steps to delete it.
17. Disclaimer of warranties
THE PLATFORM IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, ACCURACY, OR UNINTERRUPTED/ERROR-FREE OPERATION.
We do not warrant that outputs will meet your requirements or that third-party services will remain available, compatible, or lawful for your use case.
18. Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, IN NO EVENT SHALL JW-SYSTEMS-LLC, ITS MEMBERS, OFFICERS, EMPLOYEES, CONTRACTORS, OR AFFILIATES BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES; LOST PROFITS; LOST REVENUE; LOST DATA; COST OF SUBSTITUTE SERVICES; BUSINESS INTERRUPTION; REPUTATIONAL HARM; OR PROVIDER OVERAGES—REGARDLESS OF THEORY OF LIABILITY AND EVEN IF ADVISED OF THE POSSIBILITY.
TO THE MAXIMUM EXTENT PERMITTED BY LAW, OUR TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THE PLATFORM OR THIS POLICY SHALL NOT EXCEED THE GREATER OF: (A) AMOUNTS YOU PAID TO US FOR THE PLATFORM IN THE THREE (3) MONTHS BEFORE THE CLAIM; OR (B) ONE HUNDRED U.S. DOLLARS (USD $100).
SOME JURISDICTIONS DO NOT ALLOW CERTAIN LIMITATIONS; IN THOSE CASES OUR LIABILITY IS LIMITED TO THE MAXIMUM EXTENT PERMITTED.
19. Indemnification
You agree to defend, indemnify, and hold harmless JW-SYSTEMS-LLC and its members, officers, employees, and agents from and against any claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys' fees) arising out of or related to: your Customer Data; your Customer Secrets; your content and publications; your violation of law or third-party rights; your misuse of the Platform; or your breach of this Policy.
20. Changes to this Policy
We may update this Policy at any time. The version identifier (2026-08-14) and effective date will change when we do. Continued use after the effective date of changes, or re-acceptance when prompted, constitutes acceptance of the updated Policy.
We may require you to re-accept a new version before continuing to use the Platform.
21. Governing law and venue
This Policy is governed by the laws of the State of Delaware, United States, without regard to conflict-of-law principles.
Exclusive venue for disputes shall be the state or federal courts located in Delaware, unless applicable law requires otherwise. You consent to personal jurisdiction there.
You waive any right to participate in a class action to the extent waivable under applicable law.
22. Contact
Questions about this Policy may be sent to JW-SYSTEMS-LLC, 131 Continental Drive, Newark, DE, United States, Delaware.
For account or data requests, include the email associated with your account. We may need to verify your identity before acting on a request.
23. Final acknowledgment
YOU ACKNOWLEDGE THAT YOU HAVE HAD THE OPPORTUNITY TO READ THIS POLICY IN FULL, SEEK INDEPENDENT LEGAL ADVICE, AND THAT YOU ACCEPT ALL RISKS ASSOCIATED WITH PROVIDING CUSTOMER DATA AND CUSTOMER SECRETS TO THE PLATFORM AND TO THIRD-PARTY SERVICES.
YOU EXPRESSLY ACCEPT THAT JW-SYSTEMS-LLC IS NOT RESPONSIBLE FOR DATA COLLECTED OR PROCESSED BY THIRD-PARTY PLATFORMS, FOR LEAKED OR MISUSED API KEYS UNDER YOUR CONTROL OR COMPROMISED THROUGH CIRCUMSTANCES BEYOND OUR REASONABLE CONTROL, OR FOR DAMAGES ARISING FROM YOUR USE OF AUTOMATED CONTENT AND PUBLISHING FEATURES.