Privacy Policy

Effective Date: May 2025

1. Overview

This Privacy Policy outlines how getsoma.ai collects, uses, and protects your personal data. By using our platform, you agree to the practices described below.

2. Information We Collect

When you interact with getsoma.ai, your browser may automatically share data like your IP address, browser type, pages visited, time spent on the site, and related activity logs. We also integrate with third-party APIs, including Meta, which may collect and process similar data to improve our service experience. Each third party operates under its own privacy policy.

3. Data Storage & Processing

Your information may be stored and processed in:

  • India
  • The United States

4. Third-Party Platform Integrations

If you connect your getsoma.ai account to platforms like Facebook, Instagram, their privacy policies also apply. We recommend reviewing them to understand how your data is handled when accessed through our platform.

5. Google Drive API Access & Use

Scope used: https://www.googleapis.com/auth/drive.file (per-file access only).

When you connect Google Drive, getsoma.ai lets you import your existing creative assets (e.g., images and videos) for use in ad campaigns. We only access files you explicitly open or select through the app — we cannot see, read, or access any other files in your Drive.

5.1 What we access

  • File metadata: name, ID, mimeType, size, modifiedTime, thumbnail link.
  • File content (download) only for user-selected files to enable ad creation and uploads.

5.2 What we do not do

  • No editing, moving, deleting, or sharing of your Drive files.
  • No background scanning or indexing of your Drive — we can only access files you explicitly select. This is enforced at the scope level by drive.file.
  • No access to any files beyond those you open or select through the app.

5.3 Data handling, retention, and deletion

  • Temporary file copies created for processing are discarded after upload/processing.
  • Minimal metadata and optional thumbnails may be cached to improve UX and are automatically purged within 30 days.
  • You may disconnect Google Drive access at any time via your Google Account settings; upon disconnect, tokens are revoked and associated Drive identifiers and caches are deleted on our side.

5.4 Compliance (Google API Services User Data Policy)

  • We comply with Google's API Services User Data Policy, including Limited Use.
  • We do not use Google Drive data to develop, improve, or train generalized AI/ML models.
  • Human access to user data is restricted and allowed only with explicit consent, to fulfill legal obligations, or for security/debugging purposes strictly as necessary.
  • You can revoke access at any time at myaccount.google.com/permissions.

5.5 YouTube API Access & Use

Scopes used:

  • https://www.googleapis.com/auth/youtube — full YouTube account access, required to upload videos and assign them to user-selected playlists
  • https://www.googleapis.com/auth/youtube.readonly — read channel identity and fetch the user's playlist library for selection
  • https://www.googleapis.com/auth/youtube.upload — upload videos to the user's YouTube channel

When you connect your YouTube account, getsoma.ai allows you to upload video creatives directly to your own YouTube channel from within the platform, streamlining your ad ops workflow.

5.6 What we access

  • Channel name, profile picture, and channel ID — displayed in the UI to confirm which account is connected.
  • User's playlist list — fetched via youtube.readonly to let the user select a target playlist before uploading.
  • Upload capability and playlist assignment — the youtube scope is used exclusively to upload videos and insert them into the user-selected playlist via playlistItems.insert. No other write operations are performed.

5.7 What we do not do

  • We do not modify, delete, or manage any existing videos, playlists, channel settings, comments, or subscriptions.
  • We do not perform any write operations beyond video upload and playlist assignment.
  • We do not upload videos or modify playlists without explicit user action.
  • We do not share YouTube data with third parties or use it for advertising targeting or AI/ML purposes.

5.8 Data handling, retention, and deletion

  • OAuth tokens are stored encrypted (AES-256 at rest, TLS in transit) and retained until you explicitly disconnect your YouTube account, at which point the token is revoked and deleted from our systems.
  • Video files are deleted from our servers immediately upon upload completion or failure — we do not retain your video content.
  • Upload action metadata (timestamp, status, video title) is retained for support and audit purposes.

5.9 Compliance (YouTube API Services Terms of Service)

  • We comply with the YouTube API Services Terms of Service and Google API Services User Data Policy, including Limited Use requirements.
  • We do not use YouTube user data to develop, improve, or train generalized AI/ML models.
  • Human access to user data is restricted and allowed only with explicit consent, to fulfill legal obligations, or for security/debugging purposes strictly as necessary.
  • You can revoke YouTube access at any time at myaccount.google.com/permissions or from within Soma's account settings.

6. How We Use Your Data

We may use your information to:

  • Operate and maintain the platform
  • Inform you of updates or changes
  • Enable features you choose to use
  • Provide customer support
  • Analyze usage patterns to improve the service
  • Detect bugs, technical issues, or abuse
  • Share anonymized insights or trends
  • Produce educational content from aggregate, anonymous data

7. Data Sharing

getsoma.ai does not sell or rent your personal data. We may share aggregated, anonymized usage data with partners or collaborators. If you prefer not to participate, you may opt out by contacting us.

8. Cookies & Tracking

We use cookies to enhance user experience. You may set your browser to block cookies, but doing so might limit some functionalities of the platform.

9. Your Data Rights

You have the right to:

  • Request access to your data
  • Ask for corrections to inaccurate information
  • Delete your data permanently
  • Export your data in a portable format

To exercise any of these rights, please email [email protected]. We'll respond within 30 days. Note: Some data may be retained for legal compliance.

10. Security Measures

We protect your data through:

  • Encryption at rest and in transit
  • Secure SSL/TLS connections
  • Regular security reviews and tests
  • Restricted internal access
  • Mandatory two-factor authentication for internal systems

11. Policy Updates

This policy is effective from May 2025. Future updates will be posted here and will take effect upon publication.

12. Contact Us

If you have questions or concerns, reach out to: [email protected]

Legal Entity Info

Company: Almos Auto Graphics Private Limited

CIN: U34202DL2011PTC228989

Address: C-375, Second Floor Palam Ext. Sector-7 Dwarka, New Delhi 110077