Privacy Policy

Last updated: 2026-04-30 · Version: 1.0.0

Effective date: 2026-04-30
Version: 1.0.0

This Privacy Policy explains how BCAX LLC ("we", "us", "Contentko") collects, uses, shares, and protects personal data when you use contentko.com and any related Contentko domain (collectively, the "Service"). It supplements our Terms of Service, Cookie Policy, Acceptable Use Policy, AI Content Disclosure Policy, OAuth Disclosures, and DMCA Policy.

1. Who we are

Contentko is operated by BCAX LLC, Wyoming, USA — see Legal Entity below.

2. What we collect

Categories of Personal Data We May Collect

CategoryExamplesSource
Identity & ContactName, email, phone, business name, roleYou, when you sign up or contact us
Account & AuthenticationAccount ID, hashed password, OAuth tokens (Google, TikTok, Meta, where applicable), 2FA secretsYou; identity providers
Billing & TransactionBilling address, last 4 digits of card, Stripe customer ID, invoice historyYou; Stripe (we never store full card numbers)
Usage & TelemetryIP address, browser/device, pages visited, feature interactions, referrerAutomatically, via cookies and server logs
Content You ProvideFiles, messages, prompts, lists, listings, reviews you upload to the serviceYou
CommunicationsSupport tickets, emails to/from us, chat transcriptsYou and us
Cookies & Similar TechFirst-party session cookies, anti-CSRF tokens, optional analytics cookiesYour browser

Categories of Sensitive Data

We do not intentionally collect sensitive personal data (health, biometrics, racial/ethnic origin, political opinions, religious beliefs, sexual orientation, precise geolocation) unless you voluntarily provide it in user-generated content. Where collected, processing is based on your explicit consent (Art. 9(2)(a) GDPR).

Children's Data

Our services are not directed to children under 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact [email protected] and we will delete it.

In addition, when you connect a third-party account, we receive:

3. Why we collect it (legal bases)

PurposeLegal basis (GDPR Art. 6)
Provide the ServiceContract — Art. 6(1)(b)
Authenticate you (OAuth, password, MFA)Contract
Generate AI content on your promptContract
Publish content to TikTok / Meta / Google on your instructionContract
Bill you / process Stripe paymentsContract
Detect prompt-injection, AI abuse, deepfake-attemptsLegitimate interest — Art. 6(1)(f)
Improve, secure, develop the Service using de-identified aggregate dataLegitimate interest
Defend against claims, audits, regulatory inquiriesLegitimate interest + legal obligation
Successor-in-interest transferLegitimate interest
Comply with court orders / regulatory requestsLegal obligation

4. AI data handling

When you submit a prompt:

We do not use your prompts or outputs to train any AI model owned by Contentko, BCAX, or any third party.

5. Multi-platform OAuth

See OAuth Disclosures for the verbatim Google "Limited Use" disclosure, the TikTok Developer Terms compliance statement, and Meta Platform Terms compliance statement.

6. Sub-processors

Sub-processors

We use the following third-party service providers ("sub-processors") to operate the Service. Each sub-processor processes only the personal data needed for its specific purpose, under contractual data-protection commitments at least as protective as the GDPR (Art. 28) Standard Contractual Clauses where required.

Sub-processorFunctionPersonal dataRegionTransfer safeguard
Stripe, Inc.Payment processingBilling & transaction dataUSADPF-certified; SCCs
Mercury / Choice Financial GroupU.S. business bankingIdentity, KYC, transactionUSAMandatory contractual safeguards
Wise Payments LtdInternational transfersIdentity, transactionUK / BelgiumUK adequacy + SCCs
Supabase, Inc. (on AWS)Database, auth, storageAll categoriesUSA (us-east-1)DPF + SCCs
Anthropic, PBCAI processing (Claude)Prompts (no training; content-moderation only)USADPF + SCCs
OpenAI, L.L.C.AI processing (where used)Prompts (no training under API terms)USADPF + SCCs
Google LLC (Workspace, OAuth, Maps)Email, OAuth, geo dataOAuth tokens, Google account emailUSA / EUDPF + SCCs
Meta Platforms, Inc.OAuth (where used)Meta account dataUSADPF + SCCs
TikTok Pte Ltd / ByteDanceDirect-Post & developer APIs (where used)TikTok account dataSingapore / USASCCs
Resend, Inc.Transactional emailEmail addresses, message contentEU (Ireland)EU adequacy
Sinch (CLX Communications AB)Fax & SMSPhone, message contentEU (Sweden)EU adequacy
DocuSeal (self-hosted)E-signatureIdentity & signed documentsEU (Frankfurt VPS — Hostinger)EU hosting
Hostinger International LtdVPS hostingServer logsEU (Lithuania)EU adequacy
Contabo GmbHVPS hosting (browser-worker)Server logsEU (Germany)EU adequacy
Cloudflare, Inc.DNS, CDN, edge proxyIP, request metadataGlobal edgeDPF + SCCs
AdsPower (where used)Anti-detect browser profilesLimited (no PII forwarding)SingaporeSCCs
GitHub, Inc.Source-code hosting (no production user data)LimitedUSADPF + SCCs

We may add or replace sub-processors. Material additions are announced at least 30 days in advance, by updating this page and (where required) emailing account holders. Continued use after the effective date constitutes acceptance.

To object to a new sub-processor, email [email protected] within the notice period. Objection on reasonable data-protection grounds entitles you to terminate the affected service for a pro-rated refund of unused fees.

7. International transfers

Same as Section 5 of the BCA Privacy Policy. We rely on the EU–U.S. Data Privacy Framework, SCCs (2021/914), and your explicit consent under GDPR Art. 49(1)(a) where required.

8. Retention

See Data Retention Policy. Headlines:

9. User-generated content & DMCA

Where you upload content (videos, images, audio) for AI processing or publishing, you remain the owner. We act as a passive host; if your content infringes a third-party copyright, that party may file a DMCA notice under our DMCA Policy.

10. Security

Same as Section 7 of the BCA Privacy Policy. No system is 100% secure; you provide data at your own risk; breach notification per Art. 33 GDPR (72 hours) where applicable.

11. Your rights

Your Rights

If you are in the European Economic Area, United Kingdom, or Switzerland (GDPR / UK-GDPR)

You have the right to:

To exercise any of these rights, email [email protected] with the subject line DSR Request. We may need to verify your identity before responding.

If you are a California resident (CCPA / CPRA)

You have the right to:

We do not knowingly collect personal information from California consumers under 16 years of age.

To exercise these rights, email [email protected] or use the "Do Not Sell or Share My Personal Information" link in the site footer (where applicable).

If you are in another jurisdiction

We extend the substantive rights above to all users where reasonably possible, regardless of residence. Email [email protected] for assistance.

12. Automated decisions

We do not make automated decisions producing legal or similarly significant effects. AI generation is initiated by your prompt and reviewed by you before any external publication.

13. Changes

Material changes are announced 30 days in advance to the email on your account.

14. Contact

Contacting BCA on legal matters

Type of inquirySubject lineAddress
General privacy / data-subject rightsDSR Request[email protected]
Refund requestRefund Request — [Engagement Reference][email protected]
Acceptable-use violation reportAUP Report[email protected]
DMCA takedown noticeDMCA — Takedown[email protected] (designated agent: see DMCA Policy)
DMCA counter-noticeDMCA — Counter-Notice[email protected]
Spam / abuse complaintSpam Complaint[email protected]
Law-enforcement / subpoenaLaw-Enforcement Request[email protected]
Sanctions / OFAC concernSanctions Disclosure[email protected]
Legal service of process(paper, certified mail)BCAX LLC, c/o Registered Agent, 30 N Gould St Ste R, Sheridan WY 82801, USA
Security vulnerabilitySecurity[email protected] (we follow coordinated disclosure; we do not pay bounties)

We acknowledge each request within 5 business days and substantively respond within the timelines required by applicable law (typically 30 days under GDPR, 45 days under CCPA, 14 days for DMCA).

Email is preferred. Mail and fax service of process is accepted but slower; electronic delivery to [email protected] is sufficient legal service of any pre-litigation notice required under these legal pages.

15. Legal Entity

Legal Entity

Contentko is a service operated by:

BCAX LLC
30 N Gould St Ste R
Sheridan, WY 82801
United States of America

Employer Identification Number (EIN): 42-2153191
State of formation: Wyoming, USA

This entity is the data controller and contracting party for all users of contentko.com.

Governing Law & Jurisdiction

These terms are governed by the laws of the State of Wyoming, United States, without regard to its conflict-of-laws principles. The exclusive forum for any dispute shall be the state and federal courts located in Sheridan County, Wyoming, except where applicable consumer-protection law of your country of residence grants you a non-waivable right to a local forum.

Contact

Legal & data-protection inquiries: [email protected]

For data-subject-rights requests (access, deletion, portability, objection), use the same email with subject line DSR Request. We respond within 30 days as required under GDPR Article 12 and within 45 days under California CCPA §1798.130.