PRIVACY

Privacy Policy

What Sensory OS collects, why we collect it, and how to have it deleted.

Last updated: September 3, 2026

This Privacy Policy explains how Sensory Creative (“we”, “us”, “our”) collects, uses, and protects information when you use Sensory OS (the “Service”) at os.sensory-creative.com. Sensory OS is a business-to-business platform used by marketing agencies to onboard clients, run intake questionnaires and booking funnels, and report on advertising performance.

Information we collect

  • Account information — name, email address, and organization details you provide when creating an account.
  • Content you submit — questionnaire responses, project details, files, contracts, and links uploaded through the Service.
  • Lead information — the contact details and answers that people submit through funnels and forms you publish with the Service.
  • Usage data — basic technical information (browser, device, IP-derived signals) used to operate and secure the Service.
  • Connected platform data — data we retrieve, with your explicit authorization, from third-party accounts you connect. Each platform is described below.

Meta (Facebook and Instagram) data

With your explicit consent, the Service connects to your Meta Business account so an agency can report on and manage the advertising it runs for its clients. We request only the permissions the features you use require, and we do not sell Meta data or transfer it to data brokers. Our use of Meta data complies with the Meta Platform Terms and Developer Policies.

Permissions we request, and why

PermissionWhat it is used for
ads_readRead campaigns, ad sets, ads and their performance statistics so they can be shown in your reporting dashboard.
ads_managementPublish an ad creative you have approved into your own ad account as a paused campaign for your review. Everything we create is created paused and stays paused; we do not start, re-budget or delete campaigns — only you can, in Ads Manager.
business_managementList the ad accounts your Business Manager controls so each can be mapped to the right client project.
pages_show_listList the Facebook Pages you manage, so ads can be matched to the Page that published them.
pages_read_engagementRead the Page posts and video creatives behind your ads, so the creative shown in a report is the creative that actually ran.
pages_read_user_contentRead public comments left on your own ads and Page posts, so they can be reviewed in one list instead of ad by ad.
public_profileIdentify the person who authorized the connection, so the account shows who connected it and who to ask before disconnecting.

What we receive from Meta and store

  • Connection identity — the app-scoped user ID and display name of the person who authorized the connection, the permissions they granted, and an encrypted access token. The token is encrypted at the application layer and is never exposed to the browser.
  • Advertising data — ad account, campaign, ad set and ad names and settings, budgets, and performance statistics including impressions, reach, clicks, spend, conversions and derived cost-per-result figures.
  • Creative data — ad creative text, images, video references and video metadata for the ads in those accounts.
  • Public comments — the text, timestamp, like count and public display name attached to comments left on your own ads and Page posts. We do not collect commenters’ profile photos, email addresses, phone numbers or friend lists, and we do not build profiles of commenters.

How we use it

Solely to provide the Service to the agency that connected the account: to display advertising reports, to join ad spend to the leads and appointments a funnel captured so cost per result can be calculated, to apply pause and budget changes you make in the interface, and to show ad comments for review. We do not use Meta data for advertising, for training machine-learning models, or for any purpose unrelated to the connected account.

Retention and deletion

Meta data is retained only while the connection is active. Disconnect Meta from within Sensory OS and the stored access token and connection identity are deleted; you may also revoke access at any time from your Facebook Business Integrations settings. To have Meta-derived data erased, follow the data deletion instructions.

Google user data

The Service can connect to Google services with your explicit consent. We request the narrowest scopes needed for each feature, store only what is necessary to keep the connection working, and never sell Google user data. You can disconnect at any time from within Sensory OS or from your Google Account permissions; on disconnect we delete the stored tokens.

Google Drive (questionnaire file uploads)

With your consent, the Service connects to your Google Drive using the drive.file scope. This scope grants access only to files and folders the Service itself creates on your behalf — we cannot see, read, or manage any other file in your Drive.

Google Calendar (appointment scheduling)

With your consent, the Service reads availability and writes appointments for the calendars you select, so bookings made through a funnel appear on the right calendar. We store only the identifiers and event references needed to keep those bookings in sync.

Sensory OS’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How we use information

  • To operate, maintain and secure the Service.
  • To deliver the features you have enabled — onboarding, questionnaires, scheduling, contracts, lead routing and advertising reporting.
  • To route data to the destinations you configure, such as your CRM or a webhook you supply.
  • To respond to support requests and to meet legal obligations.

We do not sell personal information, and we do not use the content you submit or the platform data you connect to train machine-learning models.

Sharing

We share information only with the service providers that run the Service on our behalf — hosting, database, email delivery, error monitoring and payment processing — each bound to process it only on our instructions; with the destinations you explicitly configure; and where required by law.

AI processing of library media (optional)

If your workspace turns on AI naming for its media library, a few downscaled still frames of each clip or image — and, when the clip is small enough and contains speech, its audio — are sent to a model provider to generate a file name, tags from your own vocabulary and a short description. Frames and descriptions are processed by OpenAI (or another OpenAI-compatible provider configured for the deployment); speech is transcribed by Groq. Both process the data only to return the result and do not use it to train models. The feature is off by default, is enabled per workspace and per folder, and every AI-proposed name can be reverted to the original.

Requests from public authorities

Government agencies, law enforcement and other public authorities occasionally ask companies to hand over personal information. We apply the following practices to every such request, whether it concerns data you gave us directly or data we received from Meta or Google.

  • We review whether the request is lawful. No request is actioned simply because it arrives on official letterhead. We check that it is properly issued, that the authority has jurisdiction over us, and that it covers the data it asks for.
  • We disclose the minimum necessary. Where a request is valid, we produce only the specific records it compels, scoped as narrowly as its terms allow. We do not volunteer adjacent data because it happens to sit in the same table.
  • We challenge requests we believe are unlawful. If a request is overbroad, improperly issued, or seeks data we consider it has no right to, we object to the issuing authority and, where warranted, seek to have it narrowed or set aside before producing anything.
  • We document every request. We keep a record of each request, what we produced or refused, the legal reasoning behind that decision, and who was involved in making it.
  • We tell you where we are allowed to. If a request covers your data, we notify you unless we are legally prohibited from doing so, so that you have the opportunity to respond yourself.

Security

Data is stored on infrastructure protected by encryption in transit. Third-party access tokens are additionally encrypted at the application layer, held in tables reachable only by server-side code, and never sent to the browser. Access within a customer organization is controlled by roles and per-project scoping.

Your rights

You may request access to, correction of, or deletion of your personal information. See the data deletion instructions for how to make a deletion request, including a request scoped to data we received from Meta or Google.

Children

The Service is a business tool and is not directed to children under 13. We do not knowingly collect information from children.

Changes to this policy

We may update this policy from time to time. The date above reflects the most recent revision, and material changes will be communicated through the Service.

Contact

Questions about this policy, or about data we hold? Email admin@sensory-creative.com.