Privacy

Data serves your workspace. Not an advertising profile.

MarketingOS 0.3.0 stores the workspace locally. Google credentials for the standard connection stay in the managed connector. A dedicated reviewer deployment is undergoing live validation and is not a customer release. Google review and general customer release remain open. Optional consent-based audience measurement for this public website is handled separately.

01

Locally stored data

Workspace settings, goals, evidence, actions, approvals, receipts and audit are stored in a local database in the user profile.

02

Google API data and user-facing uses

After explicit connection, MarketingOS processes GSC raw property, sitemap and URL Inspection status data for the selected workspace, plus aggregated Search Analytics by query and page with clicks, impressions, CTR and position. From GA4 it processes account, property, data stream and key event metadata plus aggregated reports for landing pages, channels, active and new users, sessions, events and key events, not user-level raw event data. From GTM it processes configuration data for accounts, containers, workspaces, tags, triggers, variables and versions. These data are used only for source diagnostics, SEO and GEO prioritization, visible setup plans, approved execution, receipts and post-change measurement for that workspace.

03

Exactly eight incremental permissions

MarketingOS requests only the group selected by the user: gsc.read with webmasters.readonly, gsc.sitemaps.manage with webmasters, ga4.read with analytics.readonly, ga4.measurement.manage with analytics.edit, gtm.read with tagmanager.readonly, gtm.workspace.edit with tagmanager.edit.containers, gtm.version.create with tagmanager.edit.containerversions, and gtm.version.publish with tagmanager.publish. Previously granted permissions are not requested again. After authorization, the three read groups may run; the five write groups are never autonomous.

04

Managed connector and protection

In the standard path, Google access and refresh tokens stay in the server-side managed connector on the dedicated reviewer infrastructure. They never reach the browser interface, Local Agent, OpenClaw or Hermes agents, the local MarketingOS runtime, or a model. The complete persistent proxy state is protected with AES-256-GCM; its 256-bit master key is readable only by the proxy service identity. Tenant-bound and workspace-bound signed requests, a fixed allowlist of named operations and token filtering in responses limit access.

05

Optional transfer to the model provider

Model transfer is off by default. Only the workspace owner can separately opt in, and the owner can immediately disable new transfers at any time. While that consent remains active, MarketingOS may transfer only the following Google API data and data derived from them for the current or later connected Google Search Console (GSC), Google Analytics 4 (GA4) and Google Tag Manager (GTM) connectors in that workspace: GSC property, sitemap and URL Inspection data and aggregated Search Analytics; GA4 account, property, data stream and key event metadata and aggregated reports, never user-level raw events; GTM account, container, workspace, tag, trigger, variable and version configuration; and the derived workspace artifact types goal metric, plan, evidence including diagnostics, claim, action, execution receipt, observation, outcome and connector only as needed for visible workspace-related MarketingOS analysis, prioritization, recommendations and drafts. Workspace context and goals are non-transferable local control data. The sole recipient is the Controlled OpenClaw model path displayed in Google permissions with its exact provider origin, model ID and descriptor digest; Hermes Direct is not eligible for this transfer. The model provider processes transferred data under its own contract and privacy notice. Google tokens and credentials are not transferred. Every provider request containing Google-derived data requires a fresh one-time authorization immediately before transfer; new and replayed requests fail closed after consent is disabled. If disable wins before that authorization commit, no transfer occurs. A request already one-time authorized and durably committed to immediate provider handoff before disable may still be transmitted and completed while the UI shows draining. Consent lasts until withdrawn and covers only this closed list of data types and purposes. New data types or uses require a new disclosure and consent. MarketingOS cannot delete copies already stored by the model provider; its deletion and retention controls apply to those copies. MarketingOS does not use the data for MarketingOS advertising, sale or general-purpose model training.

06

Contact form enquiries

When the form is submitted, the web server processes the role, optional website, email address and description to deliver the enquiry to francesco@scilipoti.de and answer it. No third-party form provider is used. A temporary, non-reversible hourly hash of the sender address limits automated spam and expires with that window. If direct delivery is unavailable on the webspace, the page opens your email application with the details already entered. Form content is not sent to Analytics.

07

Optional website analytics

This website loads Google Analytics 4 only after your explicit consent. It sends the page path, language, browser and device information, an approximate region and clearly named usage events such as opening the demo, starting the form, opening a screenshot and reading depth. The Founding Partner form's email address, website and free text are not sent to Analytics.

08

Retention

The recipient of this website's analytics data is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. User-level and event data are retained in the Analytics property for two months; standard reports may retain longer aggregated values derived from that data. In the managed connector, OAuth state expires after ten minutes. Google access and refresh tokens remain inside the AES-256-GCM-encrypted server-side proxy state until confirmed provider revocation or local connector deletion. Connection metadata remains until deletion. The proxy does not durably store raw Google API responses. Encrypted operational backups of the reviewer installation expire within seven days. Before local Google-data deletion, MarketingOS shows a digest-bound inventory preview. Confirmed deletion removes raw Google data and goal metrics, plans, evidence, claims, actions, execution receipts, observations and outcomes derived exclusively or partly from it. Payload-free guardian and audit metadata remains for the lifetime of the workspace as an integrity and deletion record: IDs, types, versions, hashes and digests, timestamps, event states and the minimal deletion receipt, but no Google payloads or tokens. Local Google-data deletion does not delete Google-derived content already persisted in OpenClaw transcripts or OpenClaw workspace state. That runtime copy must be deleted separately through the root-authenticated OpenClaw lifecycle deletion or runtime controls; after model consent is disabled or local deletion completes, it remains blocked from all new provider egress. The reviewer alpha has no automatic 400-day deletion for that metadata. Local Google-data deletion is not complete workspace erasure; complete MarketingOS workspace erasure requests go to francesco@scilipoti.de. Later customer-controlled local backups remain under the customer's control.

09

Clear exclusions

MarketingOS does not sell Google user data, use it for advertising, transfer it to unrelated third parties, train general-purpose AI models with it, or access Gmail or Drive. MarketingOS does not manage ads or spend ad budget.

010

Disconnect, provider revocation and local deletion

Disconnect disables the connector and stops future Google API calls, but retains the server-side credential and does not revoke Google consent. Provider revocation disables access first, then asks Google exactly once to revoke access and deletes the credential envelope after a confirmed result; an ambiguous revocation outcome is safely fenced and is not retried blindly. The user can also inspect or remove Google's account permission at https://myaccount.google.com/permissions. Local deletion does not revoke Google consent. After a digest-bound inventory preview, it removes the credential envelope or managed binding, raw Google data, and goal metrics, plans, evidence, claims, actions, execution receipts, observations and outcomes derived exclusively or partly from that data. A sanitized connector shell remains only for later setup; payload-free guardian and audit metadata plus the minimal deletion receipt remain as the integrity and deletion record. Pending OAuth states are invalidated immediately and expire within ten minutes. Local Google-data deletion does not delete Google-derived content already persisted in OpenClaw transcripts or OpenClaw workspace state. That runtime copy must be deleted separately through the root-authenticated OpenClaw lifecycle deletion or runtime controls; after model consent is disabled or local deletion completes, it remains blocked from all new provider egress. Customer-controlled local backups and copies already stored by the model provider remain under the control of their respective operator and are not deleted automatically. Local Google-data deletion is not complete workspace erasure; complete MarketingOS workspace erasure must be requested through the privacy contact. Website Analytics consent can be changed independently through Cookie settings. Deletion and privacy requests go to francesco@scilipoti.de.