Privacy Policy

Last updated: June 28, 2026

This Privacy Policy explains how 17145608 Canada Inc. ("ContentBeamer," "we," "us," or "our") collects, uses, discloses, and protects personal information in connection with the ContentBeamer service (the "Service"). We are committed to handling personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), applicable provincial privacy laws, and, where applicable, the EU and UK General Data Protection Regulation (GDPR).

1.Who We Are and How to Contact Us

17145608 Canada Inc. is the organization responsible for personal information processed through the Service.

For any privacy question, request, or complaint, contact:

Privacy Contact: support@contentbeamer.com
Location: Ontario, Canada

2.Information We Collect

  • Account information. When you create an account, we collect your name, email address, and organization name through our authentication provider, Clerk.
  • Site and configuration data. Information about the sites you create, including name, URL, brand assets, audience, tone, and publishing configuration.
  • Content you provide and generate. Keywords, prompts, uploaded files, and the articles, social posts, audio, images, and video produced through the Service.
  • Connected account credentials. When you connect a CMS or a social media platform (including TikTok, X/Twitter, LinkedIn, Facebook, Instagram, Reddit, and YouTube), we collect and store the OAuth access and refresh tokens necessary to publish on your behalf, together with associated account identifiers. These tokens are encrypted at rest.
  • AI provider API keys. If you supply your own provider keys, we store them in encrypted form.
  • Billing information. Payments are processed by Stripe. We receive limited billing details but do not collect or store full payment card numbers.
  • Usage and technical data. Information about how you use the Service, including pages visited, features used, log data, and device/browser information.
  • Cookies. See Section 9.

3.How We Use Information

We use personal information to:

  • provide, operate, and maintain the Service;
  • generate content through the AI providers you authorize;
  • publish content to the CMS and social platforms you connect, on your behalf;
  • authenticate users and secure accounts;
  • process payments and manage subscriptions;
  • enforce usage limits and our Terms;
  • monitor, debug, and improve the Service;
  • communicate with you about your account, security, and service changes;
  • comply with legal obligations and protect our rights.

We do not sell your personal information.

We do not use your content to train our own AI models. Content is sent to third-party AI providers only to fulfill your requests; those providers' use of data is governed by their own terms (see Section 5).

4.Legal Bases for Processing (GDPR)

Where the GDPR applies, we process personal information on the following bases:performance of a contract (to provide the Service you sign up for);legitimate interests (to secure, maintain, and improve the Service, balanced against your rights);consent (for analytics cookies and any optional communications); andlegal obligation (to comply with applicable law). You may withdraw consent at any time where processing is based on consent.

5.How We Share Information

Service providers and sub-processors. We use the following third parties to operate the Service. Each processes data only as needed to provide its function:

  • Clerk — authentication and account management
  • Stripe — billing and payment processing
  • Vercel — application hosting and analytics
  • Neon — database (Postgres)
  • Cloudflare R2 — file and media storage
  • Upstash — caching, rate limiting, and job queues
  • Railway — video rendering
  • OpenAI, Anthropic, Google, Groq, Mistral — AI content generation
  • ElevenLabs — audio generation
  • HeyGen — avatar video generation
  • Resend — transactional email

Connected platforms you authorize. When you connect and use an integration, we transmit your content and the necessary authorization data to that platform at your direction. These platforms are independent controllers of the data they receive.

Legal and protective disclosures. We may disclose information if required by law, subpoena, or other legal process, or where we believe disclosure is reasonably necessary to protect our rights, your safety, or the safety of others.

Business transfers. If we are involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction, subject to this Policy.

6.International Data Transfers

We are based in Canada, and our service providers may process and store data in Canada, the United States, the European Union, and other countries. Where we transfer personal information across borders, we take steps to ensure it remains protected in accordance with applicable law, including, where required, the use of appropriate safeguards such as Standard Contractual Clauses.

7.Data Retention

We retain personal information for as long as your account is active and as needed to provide the Service. After account closure, we delete or anonymize personal information within 90 days, except where we must retain certain data to comply with legal, tax, accounting, or security obligations, resolve disputes, or enforce our agreements. Connected-platform tokens are deleted when you disconnect the integration or close your account. Encrypted backups are purged on a 30-day rotation cycle.

8.Your Rights and Choices

Depending on your jurisdiction, you may have the right to access, correct, delete, restrict, or port your personal information, and to withdraw consent.

You can exercise several of these directly in the Service:

  • Delete your account and associated data from Settings → Delete Account.
  • Disconnect any integration at any time from site settings.
  • Request a data export or any other privacy request by emailing support@contentbeamer.com.

We will respond to verified requests within the timeframe required by applicable law. If you are in Canada and are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada. If you are in the EU/UK, you may lodge a complaint with your local supervisory authority.

9.Cookies and Analytics

  • Functional/essential — required for authentication, session management, and security. These cannot be disabled without affecting the Service.
  • Analytics — to understand usage and improve the Service. These are used only with your consent where consent is required.

You can control non-essential cookies through your browser settings or any consent mechanism we provide.

10.Security

We implement technical and organizational measures designed to protect personal information, including AES-256-GCM encryption of all stored credentials with per-credential initialization vectors, storage of decryption keys separately from the database, tenant isolation, encryption in transit, and access controls. Credentials are never returned in API responses and are decrypted only in memory at the moment they are used.

In the event of a data breach, we will notify affected individuals and applicable regulators as required by law.

11.Children's Privacy

The Service is not directed to children, and we do not knowingly collect personal information from anyone under the age of 16. If you believe a child has provided us personal information, contact us and we will delete it.

12.Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version with a new "Last updated" date and, for material changes, provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance.

13.Contact

17145608 Canada Inc.
Ontario, Canada
support@contentbeamer.com