Legal
Privacy Policy
What data we collect, how we use it, how we store and protect it, and the choices you have.
Last updated: August 4, 2026
BlackoutOS (“BlackoutOS”, “we”, “us”) is a private, invite-only executive operating system for commerce operators, available at app.blackoutos.com. This policy applies to the BlackoutOS application and to data we receive from third-party services you choose to connect, including Google APIs.
Data we collect
- Account data — your name, email address, and workspace membership, provided when your workspace admin invites you.
- Connected business data — data imported from services your workspace explicitly connects (for example Shopify, Klaviyo, Meta, Google, Microsoft Clarity), limited to the permissions granted during connection.
- Usage data — standard application logs (page requests, errors) used to operate and secure the service.
Data we receive from Google APIs
Connecting Google is optional. If your workspace chooses to connect it, BlackoutOS requests the following OAuth scopes and receives only the data they cover:
- Google Search Console — read-only
https://www.googleapis.com/auth/webmasters.readonly
Search performance data for the verified site you select: clicks, impressions, click-through rate, average position, queries, and pages. - Google Analytics — read-only
https://www.googleapis.com/auth/analytics.readonly
GA4 reporting data for the property you select: sessions, users, traffic sources, landing pages, events, and conversion metrics. - Google Ads
https://www.googleapis.com/auth/adwords
Campaign performance reports for the account you select: spend, impressions, clicks, and conversions. The Google Ads API publishes only this single scope — there is no read-only equivalent — so it grants broader access than BlackoutOS uses. BlackoutOS issues reporting queries only. It never creates, edits, pauses, or deletes campaigns, budgets, or ads, and never changes account settings.
We request these scopes only when you connect the corresponding service, and we do not request any scope the product does not use.
How we use, store, and share Google user data
- Use — Google data is used solely to provide BlackoutOS features to your workspace: dashboards, metrics, executive briefs, answers, and opportunities. It is never used for advertising, never sold, and never used to train generalized machine-learning models.
- Storage — imported reporting data is stored in our database (hosted on Supabase) scoped to your organization. OAuth tokens are encrypted at rest and are never exposed to other workspaces or third parties.
- Sharing — Google data is visible only to authorized members of your own workspace. We do not transfer it to third parties except subprocessors that host the service (for example our database and hosting providers), as required by law, or as part of a merger or acquisition with equivalent protections.
- Human access — our staff do not read your Google data except with your explicit permission for support, for security investigations, or where required by law.
BlackoutOS’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Retention and deletion
- Disconnecting a Google service from BlackoutOS deletes the stored OAuth tokens for that service. You can also revoke access at any time from your Google Account permissions.
- Imported reporting data is retained while your workspace remains active so historical metrics stay accurate. You may request deletion of your workspace’s imported data at any time by contacting us; we complete deletion requests within 30 days.
- When a workspace is closed, its connected data and tokens are deleted.
Security
All traffic is encrypted in transit (HTTPS). OAuth tokens are encrypted at rest. Data access is scoped per organization with row-level security, and application access is invite-only with role-based permissions.
Your choices
- Connect or disconnect any integration at any time from the app.
- Revoke BlackoutOS’s Google access from your Google Account permissions page.
- Request access to, correction of, or deletion of your data by emailing [email protected].
Changes and contact
We will update this policy when our practices change and revise the date above. Material changes are announced in the app. Questions: [email protected], or see our terms of service.