Privacy Notice
Last updated: June 2026
This Privacy Notice describes how Affiliate Mechanic ("we", "us"), operating from Burnet County, Texas, USA, collects, uses, and shares personal data in connection with the CoSbotApp service.
1. Controller
Affiliate Mechanic is the data controller for personal data processed through CoSbotApp. Contact us at support@affiliateprogrampro.com.
2. What we collect
- Account data: name, email, login credentials.
- Usage data: features used, API calls, timestamps, error logs.
- Device & technical data: IP address, browser type, device identifiers.
- Support communications: messages you send us.
- Content you submit: data you upload or input to use the Service, including prompts and chat content.
Payment data is collected directly by our Merchant of Record, Paddle, and is not stored by us.
3. Why we use it
- To create and manage your account (contract performance).
- To provide and improve the Service (contract performance / legitimate interests).
- To prevent fraud, abuse, and security incidents (legitimate interests / legal obligation).
- To respond to support requests (contract performance).
- To send service notifications and (with consent) marketing communications.
- To comply with legal and tax obligations.
4. Who we share with
- Service providers / subprocessors: hosting, database, AI model providers, analytics, email delivery, and customer support tooling.
- Paddle — our Merchant of Record — for sale of the product, subscription management, payments, tax compliance, and invoicing.
- Professional advisers (legal, accounting) where necessary.
- Authorities where required by law or to protect our rights.
We don't sell your personal data.
5. International transfers
We are based in Burnet County, Texas, USA. Some of our subprocessors may process data in other countries. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses).
6. Retention
We keep personal data for as long as your account is active and for a reasonable period after to meet legal, accounting, or dispute-resolution needs. After that we delete or anonymise it.
7. Your rights
Depending on your location, you may have rights to:
- access the personal data we hold about you;
- correct inaccurate data;
- request deletion;
- restrict or object to processing;
- request data portability;
- withdraw consent (where processing is based on consent);
- lodge a complaint with your local data protection authority.
To exercise these rights, email support@affiliateprogrampro.com. We'll respond within a reasonable timeframe (and within one month for GDPR requests).
8. Security
We use appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, and regular review of our security practices.
9. Cookies
We use strictly necessary cookies for authentication and core functionality, and may use analytics cookies to understand how the Service is used. You can manage cookies through your browser settings.
10. Google user data (Gmail, Calendar, Docs)
CoSbotApp lets you optionally connect your Google account so your AI agent can act on your behalf in Gmail, Google Calendar, and Google Docs. Connecting is entirely optional and you can disconnect at any time from the Integrations page in the app, or by revoking access at myaccount.google.com/permissions.
What we access (OAuth scopes requested):
- Gmail —
gmail.readonly(read messages so the agent can search and summarize your inbox at your request) andgmail.compose(create drafts for you to review; we do not send mail automatically). - Google Calendar —
calendar.events(read your events and create/update events you ask the agent to schedule). - Google Docs —
documentsanddrive.file(create and edit Docs the app itself creates; we do not access other files in your Drive). - Profile —
userinfo.emailso we can show which Google account is connected.
How we use this data: solely to provide the user-facing features you invoke (search your email, draft a reply, list/create calendar events, create or update a document). Processing happens in-session in response to your prompts.
Limited Use disclosure. CoSbotApp's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not:
- use Google user data for serving advertising, including targeted, personalized, retargeted, or interest-based ads;
- sell, rent, or otherwise transfer Google user data to data brokers, information resellers, or any third party for advertising or independent use;
- use or transfer Google user data to train, fine-tune, or improve generalized or non-personalized AI/ML models. Data sent to AI providers is used only to produce the immediate response you requested and is not retained for model training;
- allow humans to read your Google user data, except (a) with your explicit consent, (b) to comply with applicable law, (c) for security investigations or to investigate abuse, or (d) when the data has been aggregated and anonymized.
Sharing. Google user data is shared only with the infrastructure subprocessors strictly required to operate the feature you invoked (our hosting/database provider and the AI model provider that generates the response). We do not share Google user data with any other third parties.
Storage & retention. We store the minimum needed to operate the integration: your Google OAuth tokens (access and refresh tokens, encrypted at rest), the connected account email, and the granted scopes. Message bodies, calendar entries, and document contents fetched from Google APIs are processed in memory to fulfill your request and are not persisted to our database. Chat transcripts you choose to save in CoSbotApp may contain content you asked the agent to summarize or compose; you can delete those at any time.
Deletion. Disconnecting an integration in CoSbotApp deletes the stored OAuth tokens for that provider immediately. Deleting your CoSbotApp account removes all associated Google connection records. You can also revoke CoSbotApp's access directly at myaccount.google.com/permissions.
11. Changes
We may update this Notice from time to time. We'll post the new version here and update the "Last updated" date.