Privacy Policy
Last updated: November 18, 2025
Effective date: November 18, 2025
Company: CoStudio Pte. Ltd.
Product: MyCoCreator (https://mycocreator.ai)
Table of Contents
1. Introduction
CoStudio Pte. Ltd. ("CoStudio", "we", "our", "us") provides MyCoCreator — an AI-powered creator assistant for YouTube creators, agencies, MCNs, and brands.
This Privacy Policy explains how we collect, use, disclose, and protect your information when you use MyCoCreator, our website, API integrations, and any related products or services (collectively, the "Services").
We adhere to:
- Singapore Personal Data Protection Act (PDPA)
- YouTube API Services User Data Policy (including Limited Use)
- OpenAI API policies
- Industry best practices for SaaS data security
By using MyCoCreator, you agree to the practices described in this Privacy Policy.
2. Data We Collect
We only collect the minimum data required to operate, personalise, and improve MyCoCreator.
2.1Information You Provide
- Account Information: name, email, password (hashed), profile image (optional).
- YouTube Channel Handle or URL (required for personalization).
- YouTube OAuth Permissions (if you choose to connect):
- Analytics read-only scopes
- Channel metadata
- Public video information
- Messages & Prompts entered into MyCoCreator chat.
- Uploaded documents or media (optional).
- Billing Information (processed securely by Stripe; we do not store card numbers).
2.2Automatically Collected Information
- Device information, browser type, IP address, timestamps.
- Usage data: page views, requests made to agents, model usage volume, feature usage.
- Crash logs and diagnostics (via Sentry or equivalent).
2.3Data From Third-Party Integrations
Depending on your usage, MyCoCreator may fetch:
From YouTube API (if you connect):
- Channel metadata
- Video metadata
- Analytics metrics (views, watch time, impressions, CTR, retention, subs gained/lost)
- Transcripts (if publicly available)
From OpenAI API (for processing prompts):
- Prompts and data sent for completion
- Model responses
We never share your YouTube OAuth data with OpenAI unless you explicitly instruct an agent to process that data (e.g., "analyze my last 10 videos").
3. How We Use Your Data
We use your data only to operate MyCoCreator and provide personalized, actionable insights. Specifically:
3.1Provide AI-powered creator insights
- Generate analytics summaries
- Provide competitor analysis / niche research
- Produce recommendations, scripts, titles, and trends
- Execute strategic workflows across agents
3.2Operate and improve the Services
- Personalize dashboards and suggestions
- Detect usage anomalies
- Improve model routing, agent quality, and feature performance
- Ensure compliance with YouTube's Limited Use provisions
3.3Security, Compliance & Anti-abuse
- Prevent spam, misuse, or unsafe activity
- Monitor usage for anomaly detection
- Enforce YouTube, OpenAI, and PDPA compliance
3.4Communication
- Send onboarding messages, product updates
- Billing or subscription notices
- Security alerts
You can opt out of non-essential emails at any time.
4. Data Sharing & Disclosure
4.1With third-party processors (strictly necessary)
We share data only with vendors who help us operate our product:
- Google Cloud Platform (GCP) — hosting and storage
- OpenAI — to generate AI responses
- Stripe — billing
- Sentry / Log services — error tracking
- Email providers (e.g., Postmark, SendGrid)
All vendors comply with PDPA and hold industry-standard certifications (SOC 2, ISO 27001, etc.).
4.2YouTube Limited Use Compliance
For users connecting YouTube:
- We adhere to YouTube's Limited Use policy.
This means:
- We do not sell your YouTube data.
- We do not transfer YouTube data to third parties except to provide or improve user-facing features.
- We do not use YouTube data for ads or marketing targeting.
- We do not store or access the data beyond what is necessary for the MyCoCreator experience.
- We never use YouTube data to build profiles about you outside the app.
4.3No human training review unless opted-in
- We do not use your data for LLM training.
- We do not allow OpenAI employees to review your data unless you explicitly opt in for "Model Improvement."
4.4Enterprise Partners / MCNs
For MCNs, agencies, brands, or enterprise clients:
- Data from each creator account remains siloed and accessible only to permitted users.
- MCNs may choose to view connected creator analytics only with explicit creator permission.
- We do not share cross-channel analytics without consent.
4.5Legal Requirements
We may disclose data if required to:
- Comply with applicable laws or lawful requests
- Enforce our Terms of Service
- Detect or prevent security threats, fraud, or abuse
We do not accept broad or unnecessary data requests.
5. Data Retention
We keep your data only as long as necessary:
- Account data: retained until account deletion.
- YouTube OAuth tokens: deleted immediately on disconnection.
- Chat messages: stored to provide history unless you manually delete them.
- Analytics data: cached for performance but purged regularly (typically 90 days).
- Billing records: kept as required by Singapore tax law (5 years).
You may request deletion at any time.
6. Your Rights
As a user, you have the right to:
- Access your data
- Request correction
- Withdraw consent for YouTube or other integrations
- Request deletion
- Export your data
- File a complaint with the PDPC (Singapore)
To exercise these rights, email: privacy@costud.io
7. Data Security
We implement strong safeguards:
- Data encryption at rest and in transit
- Role-based internal access controls
- Tokenized API credentials
- GCP regional isolation
- Automated backups
- Continuous monitoring and audit logs
No system is 100% secure, but we follow industry standards for creator analytics SaaS products.
8. International Data Transfers
We may process data in Singapore, the United States, or any region where our cloud providers operate.
All transfers comply with PDPA cross-border data rules and contractual safeguards.
9. Children's Privacy
MyCoCreator is not intended for children under 13 (or applicable local minimum age).
We do not knowingly collect data from minors.
10. Changes to This Privacy Policy
We may update this Privacy Policy as our product evolves.
We will notify users of material updates via email or in-app notification.
11. Contact Us
For privacy questions or requests:
CoStudio Pte. Ltd.
Singapore
Email: privacy@costud.io