← Back to home
Privacy Policy
Last updated: April 4, 2026
OSOK Life LLC ("we," "us," "our") operates the OSOK Life platform. This Privacy Policy describes what information we collect, how we use it, how we protect it, and your rights regarding your data.
1. Information We Collect
When you use OSOK Life, we collect:
- Account information: Your name and email address, provided through Clerk (our authentication provider). We do not store your password — Clerk handles all credential management.
- Platform tokens: OAuth access tokens for social media platforms you choose to connect (YouTube, TikTok, X/Twitter, Facebook, Instagram, Bluesky). These are encrypted with AES-256-GCM before storage and are used solely to post content on your behalf.
- Usage events: We log actions you take on the platform (e.g., "used content generator," "connected YouTube"). These logs track the type of action, not the content of what you typed, uploaded, or generated.
- Veteran verification status: A simple yes/no flag indicating whether ID.me has verified your veteran or active duty status. We do not receive or store your military records, service history, DD-214, or identification documents.
- Bug reports and feedback: Information you voluntarily submit through the bug report or feedback tools.
2. Information We Do NOT Collect
- We do not store your passwords (handled by Clerk, a SOC 2 compliant provider)
- We do not store your social media passwords (OAuth tokens only)
- We do not store the content of your AI conversations on the free tier
- We do not access your private messages, followers, friends lists, or analytics on connected platforms
- We do not store your military records, ID documents, or government-issued identification
- We do not store credit card numbers (handled by Stripe)
- We do not sell, rent, or share your personal information with third parties for marketing purposes
- We do not use your data for advertising or ad targeting
- We do not track you across other websites
3. How We Use Your Information
Your information is used to:
- Authenticate your account and maintain your session
- Connect to and post content on your social media platforms
- Provide AI-powered guidance and assistance
- Verify veteran status for free-tier access
- Store your preferences and settings
- Monitor platform health and fix bugs
- Improve the Service based on aggregated, anonymized usage patterns
4. Data Storage and Security
- Encryption: All platform tokens are encrypted with AES-256-GCM before being written to the database. The encryption key is stored in secure environment variables, not in source code.
- Per-user isolation: Each user's data is stored separately keyed by their unique user ID. Users cannot access other users' data.
- Authentication security: Admin access uses timing-safe comparison to prevent timing attacks. OAuth flows use PKCE S256 challenge method and cryptographic state parameters to prevent CSRF and replay attacks.
- Infrastructure: The Service runs on Railway with encrypted connections (HTTPS/TLS). The database uses SQLite with WAL mode and busy timeout for safe concurrent access.
5. Third-Party Services
The Service integrates with the following third-party services. When you use these integrations, their respective privacy policies also apply:
- Clerk — Authentication and account management
- Anthropic (Claude) — AI-powered features and guidance
- ID.me — Veteran and military status verification
- YouTube / Google — Video publishing (when connected)
- Meta (Facebook / Instagram) — Content publishing (when connected)
- TikTok — Video publishing (when connected)
- X / Twitter — Content publishing (when connected)
- Bluesky — Content publishing (when connected)
- Stripe — Payment processing (when applicable)
We only request the minimum permissions needed to provide each feature. We do not request or use permissions beyond what is necessary.
6. OTC and Shopping Features
The Smart Shopper tool provides general shopping guidance using AI. OSOK Life is not affiliated with any insurance company, pharmacy, or benefit card provider (including but not limited to CVS, Walgreens, Humana, UnitedHealthcare, Aetna, or any other entity). Coverage and eligibility information is general guidance only. We do not access, store, or process your insurance information, benefit card numbers, or health plan details.
7. Data Deletion
You have the right to delete your data:
- Platform disconnection: Disconnect any platform at any time from the control panel. This immediately deletes the associated encrypted tokens from our database.
- Local data: Use the "Clear my data" button on the dashboard to remove all locally stored data from your browser.
- Full account deletion: To delete your account and all associated data entirely, contact us via the Feedback button in the app. We will delete all your data within 30 days of the request.
8. Cookies and Local Storage
The Service uses:
- Cookies: Authentication session cookies managed by Clerk. No tracking or advertising cookies.
- localStorage: Your preferences, settings, and UI state are stored locally on your device. This data never leaves your browser unless you explicitly submit it.
9. Children's Privacy
The Service is not intended for users under the age of 13. We do not knowingly collect information from children under 13. If we become aware that we have collected personal information from a child under 13, we will delete it promptly.
10. California Privacy Rights
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to request deletion, and the right to opt out of the sale of personal information. We do not sell personal information.
11. Changes to This Policy
We may update this Privacy Policy at any time. Material changes will be communicated through the Service. Continued use of the Service after changes constitutes acceptance of the updated policy.
12. Contact
For privacy-related questions, data deletion requests, or concerns, reach out via the Feedback button in the app or contact OSOK Life LLC at the address on file with the California Secretary of State.