Privacy Policy
What data contentos collects, why it is collected, which providers it is sent to, how long it is kept, and how to request access to it or its deletion.
Updated 2026-09-27 · contentos · גרסה בעברית
1.Who controls the data
This document describes what personal data is collected when you use contentos, why it is collected, who it is shared with and how long it is kept. It is written in accordance with the Israeli Protection of Privacy Law, 5741-1981 and the regulations made under it.
The controller of the database, and the contact for any privacy enquiry:
- Service operated by:
- MOMENTUM
- Business details and contact:
- momentumdigital.co.il
- Email:
- support@contentos.co.il
2.What data is collected
Information you provide. Email address, name (optional) and password. The password is stored as a one-way hash (bcrypt); the password itself cannot be recovered from it.
Workspace settings. Page name, topic, tone, image style, schedule, and any words you asked us to avoid.
Social network permissions. The page identifier, the page name and the access token received from Facebook or Instagram. Access tokens are stored encrypted in the database.
Facebook page details.When you connect a Facebook page, its public business details as they appear on the page: category or categories, “about” text and description, website, location and address, and opening hours. They are used to suit the content generated for that page to the business. A detail the page has not filled in is not stored.
Content and performance data. The posts and images generated for you, and the reach and engagement figures retrieved from the platforms for posts that were published.
Signup source. utm parameters, the referring domain and the first landing page, as stored in a cookie on your first visit. There is no device identifier and no cross-site tracking.
Marketing page usage. On the public pages only, and never inside the system once you are signed in, Google Analytics records the pages viewed, the source of the visit, device and browser type, approximate geographic region and a truncated IP address. It is used in aggregate, to know which pages work. We do not link it to your account.
Technical data.Operational server logs containing IP address, browser type and request time, together with the system’s error logs.
What we do not collect: credit card details. Those are given directly to the payment processor and never pass through our servers at any stage.
3.Why the data is collected
- To provide the service itself: to generate content, schedule it and publish it to the pages you connected.
- To manage the account, the plan and the monthly quota.
- To provide support and to handle faults you reported.
- To keep the system secure and to detect abuse.
- To understand which marketing content brings signups, at source level only and without personal identification.
- To meet legal obligations, including accounting and reporting duties.
We do not sell personal data, and we do not use it to train models of our own.
4.Basis for processing
Processing is necessary to perform the contract between us, for the legitimate interest of keeping the system secure and improving it, and to comply with legal obligations. Providing the data is voluntary, but the service cannot be supplied without it. You are not required to provide data that is not needed to operate the account.
5.Who the data is shared with
Data is not passed to third parties except to the providers required to operate the service, and only for the purpose it was given for:
- Google(text and image generation models): the channel’s content instructions and the selected topic are sent. For a connected Facebook page, the text model is also sent the page’s name, business type, description and city, from the page details in clause 2, as context for writing. Opening hours, the website and the street address are not sent. No account details and no access tokens are sent.
- Meta (Facebook and Instagram): the post, the image and the page access token, for the purpose of publishing, of reading the page details described in clause 2, and of retrieving performance data.
- Google Fonts(site typefaces): your browser loads the site’s fonts from Google’s servers, and your IP address is disclosed to them in the process. No cookie is involved and no tracking.
- Google Analytics (measuring traffic on the marketing pages): the page viewed, the source of the visit, device type and your IP address, which it truncates before storage. It runs on the public pages only: it is not loaded at all inside the system once you are signed in, so the names of the pages you connected, your post content and your performance data never reach it. We do not enable personalised advertising in it and do not share the data with advertising networks.
- Google Workspace (the mailbox that receives your enquiries): messages you email us, and everything written in them, are held in a mailbox hosted on this service. A request sent through the cancellation form is recorded in our database and does not pass through it.
- SerpAPI(trend and news discovery): search terms derived from the channel’s topic. No personal data.
- PayMe (card processing): payment details are given by you directly to the processor on its own page. We receive confirmation that a payment was made, not the card details.
- Hetzner (server hosting): the system and the database are hosted on this infrastructure.
- Telegram (operational alerts): messages to the system operators about faults and runs. These contain channel names and status, not personal data about your own end users.
In addition, data may be disclosed if we are required to do so by court order or by law, or in order to defend our rights in legal proceedings.
6.Transfer of data outside Israel
Some of the providers listed above operate outside Israel, including in European Union countries and in the United States. This means data is also stored or processed outside the country. Engagement with these providers is on the basis of their terms of service and the protection mechanisms they offer.
7.Data security
Traffic to the site is encrypted with TLS. Passwords are stored as one-way hashes. Social network access tokens, which are the most sensitive data we hold, are stored encrypted in the database rather than in plain text. Access to the servers is restricted and monitored.
No system is entirely immune. In the event of a security incident affecting your data we will notify you and the authorities as required by law.
8.How long data is kept
- Account data and content: for as long as the account is active, and for 90 days after the engagement ends.
- Page access tokens: deleted when the page is removed from the system. Revoking the permission from the Facebook or Instagram side invalidates the token immediately, whether or not we remove it.
- Facebook page details: kept while the page is connected, updated when it is reconnected, and deleted when the page is disconnected in contentos, when the page or the account is deleted, or on request.
- Signup source cookie: 90 days from the first visit.
- Google Analytics data: up to 14 months, per the retention setting on the account. The aggregate reports themselves are kept indefinitely.
- Server logs and error logs: kept for diagnostic and security purposes. There is currently no automatic deletion of these; they are deleted when no longer needed or on request.
- Accounting records: seven years, as required by tax law.
9.Your rights
Under the Protection of Privacy Law you are entitled to review the data held about you, to request its correction if it is not correct, complete or accurate, and to request its deletion.
Requests of any of these kinds should be made through the contact details in clause 1, and will be answered within 30 days. We may ask you to verify your identity before disclosing data, so that we do not disclose it to someone who is not you. If a deletion request conflicts with a legal retention obligation, we will delete what we can and explain what remains and why.
Step-by-step instructions for deleting your data, including the data received from Facebook and Instagram, are on the data deletion page.
11.Changes to this policy
This policy may be updated, mainly if a provider is added to or replaced in the list in clause 5. The updated text will be published on this page with a new update date, and a material change will be notified by email to active customers. See also the Terms of Service.