AIMOSAI Marketing OS
РусскийEnglish
Back to sign in

Contents

  1. General provisions
  2. What data we process
  3. What we do not collect and will never ask for
  4. Why we process data
  5. Who receives data
  6. Where data is stored and cross-border transfer
  7. Threads data
  8. Instagram data
  9. How we protect data
  10. What you can do
  11. Your rights
  12. Cookies
  13. Age
  14. Changes to this Policy
  15. Contacts
Terms of UseData deletion

Effective 8 October 2026

Privacy Policy

How AI Marketing OS (AIMOS) collects, uses and protects your data, and what you can do to keep it safe.

1. General provisions

This Policy sets out how personal data of users of AI Marketing OS (AIMOS) (the "Service") is processed. The owner and operator of the personal data is ИП ANTECH, IIN 901121350491, address: г. Астана, проспект Қабанбай батыр, 43В, 1111 (the "Operator", "we").

This Policy follows the Law of the Republic of Kazakhstan No. 94-V of 21 May 2013 "On Personal Data and Their Protection" and the Law of the Republic of Kazakhstan No. 418-V of 24 November 2015 "On Informatization".

By registering with the Service you confirm that you have read this Policy and consent to the collection and processing of your personal data on the terms described here, including its cross-border transfer (section 6). If you do not agree, do not register or use the Service.

2. What data we process

We process only what the Service needs to work:

  • Account data: your name (how to address you) and email address.
  • Password. We do not store the password itself, only its irreversible hash (scrypt). Nobody, including us, can recover or view your password.
  • When you sign in with Google: name, email address, profile picture and the technical ID of your Google account. We never receive your Google password.
  • Session data: sign-in date, IP address and browser or device type, so that you can see in "Profile" where you are signed in and end a session you do not recognise.
  • Data about your products and content: product names, descriptions, post texts, images, publishing schedule, reasons for approval and rejection.
  • Data of connected social networks (Threads, Instagram), if you connected them: account ID, the access token issued by the network itself, posts published through the Service and their statistics (views, likes, replies, reposts and similar). The access token is stored encrypted. Threads is described in detail in section 7, Instagram in section 8.
  • Technical logs: time and result of operations, without passwords, access tokens or email codes.

3. What we do not collect and will never ask for

  • Bank card, bank account or banking app data. The Service does not accept or process payments (see the Terms of Use, section 6) and has no access to your banking data.
  • Passwords to your social networks. Threads and Instagram are connected only through the official Meta window, where you press "Allow" yourself. You enter your social network password only on the Meta website, never with us.
  • Codes from SMS, push notifications and banking apps.

We will never ask you for a sign-in code, an email code, a password or card details by phone, messenger, social network or email. Anyone asking for this on our behalf is a fraudster. Do not share anything and contact us.

4. Why we process data

  • To create and maintain your account, let you sign in and restore access.
  • To provide the Service: prepare texts and images, keep the publishing plan, publish the materials you approved and show their statistics.
  • To keep you safe: protect against password guessing, detect suspicious sign-ins, show you active sessions.
  • To send service emails: sign-in codes, email confirmation, password reset. We do not send marketing emails without your separate consent.
  • To comply with the laws of the Republic of Kazakhstan.

5. Who receives data

We do not sell your data or share it for third-party advertising. To run the Service we use third-party providers that process data on our behalf and only to the extent needed for their function:

  • Railway: hosting of the application and the database.
  • Cloudflare: image storage.
  • Anthropic: text generation. Product information and the content needed for generation are sent to the model.
  • Replicate: image generation from a description.
  • Resend: sending service emails.
  • Google: signing in with a Google account, if you choose it.
  • Meta (Threads, Instagram): publishing and retrieving statistics, if you connected these networks and granted permission in the Meta window.

Data may be disclosed to public authorities only in the cases and manner provided by the laws of the Republic of Kazakhstan.

6. Where data is stored and cross-border transfer

The servers of the providers listed in section 5 may be located outside the Republic of Kazakhstan. Under Article 16 of Law No. 94-V, cross-border transfer of personal data takes place with your consent, which you give when registering.

Retention depends on the purpose of processing: account and product data is kept while the account exists. After the account is deleted, the data is removed from the live database immediately; it may remain in backups for a limited time until the backups are overwritten.

7. Threads data

If you connected your Threads account to a product through the Meta window, the Service receives and processes the following data of that account:

  • Threads account ID, username, display name and profile picture: to show you which account is connected;
  • the access token issued by Meta: to publish the posts you approved, and a reply with a link under them, on behalf of that account;
  • statistics of posts published through the Service (views, likes, replies, reposts, quotes) and the follower count of the account: to show you the results and suggest what works better.

The Service requests only four permissions from Meta: threads_basic, threads_content_publish, threads_manage_replies and threads_manage_insights. The Service does not read other people’s posts, replies by other people or private messages, publishes nothing without your approval and does not delete your posts.

Where it is stored: in the Service database at the hosting provider Railway; the profile picture is stored there too. The access token is stored encrypted (AES-256-GCM); the encryption key is kept separately from the database and never appears in logs.

We do not sell Threads data and do not use it for advertising. It is shared only with Meta (when publishing and retrieving statistics) and with the providers listed in section 5, to the extent of their function: the texts of your published posts and their view counts are sent to Anthropic together with the request for new posts, as examples of what readers liked. Under Anthropic’s terms, data sent through its API is not used to train its models.

How long it is kept: while the Threads account is connected to the product. When you disconnect it (with the button in "Profile" or in the Threads settings), the access token, username, name and picture are deleted immediately. Statistics of posts already published and the follower count remain in the product history until you delete the product or the account, or request data deletion through Meta: then they are deleted immediately.

How to delete your data and disconnect Threads is described at https://www.aimos.kz/data-deletion.

8. Instagram data

If you connected your professional Instagram account (creator or business) to a product through the Instagram login window, the Service receives and processes the following data of that account:

  • Instagram account ID, username, display name, account type and profile picture: to show you which account is connected and to check that it is a professional account;
  • the access token issued by Meta: to publish the videos you approved on behalf of that account;
  • statistics of videos published through the Service (views, reach, likes, comments, shares, saves, average watch time, share of viewers who skipped in the first seconds): to show you the results and suggest what works better.

Video publishing and its statistics are enabled in the Service as these features become available; until then the Service uses only the profile data and the access token.

The Service requests only three permissions from Meta: instagram_business_basic, instagram_business_content_publish and instagram_business_manage_insights. The Service does not read other people’s posts, comments or private messages, publishes nothing without your approval and does not delete your posts.

Where it is stored: in the Service database at the hosting provider Railway; the profile picture is stored there too. The access token is stored encrypted (AES-256-GCM); the encryption key is kept separately from the database and never appears in logs.

We do not sell Instagram data and do not use it for advertising. It is shared only with Meta (when publishing and retrieving statistics) and with the providers listed in section 5, to the extent of their function.

How long it is kept: while the Instagram account is connected to the product. When you disconnect it (with the button in "Profile" or in the Instagram settings), the access token, username, name and picture are deleted immediately. Statistics of videos already published remain in the product history until you delete the product or the account, or request data deletion through Meta: then they are deleted immediately.

How to delete your data and disconnect Instagram is described at https://www.aimos.kz/data-deletion.

9. How we protect data

Security is built into the Service at the code level:

  • All connections to the Service use HTTPS only, and browsers are instructed never to open the Service without encryption (HSTS).
  • Passwords are stored only as an irreversible hash (scrypt).
  • Social network access tokens are stored encrypted (AES-256-GCM); the encryption key is kept separately from the database.
  • The session is kept in a protected cookie that page scripts cannot read. Other websites cannot send requests on your behalf: such requests are rejected.
  • Sign-in attempts are limited so that a password cannot be guessed by brute force.
  • Each user’s data is isolated: you see and change only your own products. Automated tests check this on every code change.
  • The Service cannot be embedded in another website to trick you into clicking a button.
  • "Profile" shows where you are signed in, and any session can be ended. When you change the password, other devices are signed out automatically.
  • Nothing is published to your social networks without your approval in the Service.

No system is absolutely secure. If we learn of an incident affecting your data, we will inform you and take the measures required by law.

10. What you can do

  • Use a separate strong password for the Service, longer than 12 characters, that you do not use anywhere else. The strength meter in the Service will show how good it is.
  • Add a second sign-in method (password and Google) so as not to lose access.
  • Check the website address before entering your password. Fraudsters make copies of sign-in pages.
  • Never share codes from emails, SMS and banking apps, passwords or card details. Neither we, nor social networks, nor banks ask for them.
  • Protect your banking data: do not keep it in notes or chats, and enable sign-in protection in banking apps.
  • Regularly check the list of sessions in "Profile" and end any you do not recognise.
  • If you suspect someone else has gained access to your account, change the password and contact us.

11. Your rights

Under Law No. 94-V you have the right to:

  • know what data of yours we process and get access to it;
  • request changes and additions to the data (name and password are changed in "Profile");
  • withdraw consent to processing and delete the account ("Profile" → "Delete account");
  • disconnect a social network from the Service, including in the settings of the network itself;
  • appeal the Operator’s actions to the authorised personal data protection body or to court.

Send personal data requests by phone at +7 705 607 4701 or by email at nukenovayan14@gmail.com.

12. Cookies

The Service uses only necessary cookies: for the sign-in session and to remember your display settings (for example, the selected planning period). There are no advertising or third-party analytics cookies.

13. Age

The Service is intended for persons aged 18 or over. If you are under 18, do not register with the Service.

14. Changes to this Policy

We may update this Policy, for example when adding new features or providers. The new version applies from the date shown at the top of the page. We will announce material changes in the Service or by email.

15. Contacts

Operator: ИП ANTECH, IIN 901121350491, address: г. Астана, проспект Қабанбай батыр, 43В, 1111. Contact us by phone at +7 705 607 4701 or by email at nukenovayan14@gmail.com.

Privacy PolicyTerms of UseData deletionSupport

ИП ANTECH · IIN 901121350491 · г. Астана, проспект Қабанбай батыр, 43В, 1111 · +7 705 607 4701 · nukenovayan14@gmail.com

2026 ANTECH. All rights reserved.