RoyalOS Privacy Policy
Privacy and connected-service data
Effective and last updated: August 28, 2026
RoyalOS is operated by Triple-Hay Concept LLC, a North Carolina company (“RoyalOS,” “we,” “us,” or “our”). This policy explains how we collect, access, use, store, disclose, protect, retain, and delete information when people use RoyalOS websites, organization workspaces, AI-assisted features, applications, support, and connected services.
1. Scope and roles
This policy applies to RoyalOS-controlled services. A customer organization generally controls the business content and personal information its authorized users submit, while RoyalOS processes that information to provide the service. Customers are responsible for notices, permissions, and lawful instructions for data they control. Third-party services have separate privacy practices.
2. Information we collect
We may collect account and contact details; authentication and organization membership; organization and Brand settings; roles and permissions; subscription, billing, and transaction records; device, browser, IP, diagnostic, security, and usage events; support and feedback communications; missions, approvals, schedules, conversations, prompts, AI output, Knowledge, Memory, files, media, records, and other content users provide.
When an authorized user connects a provider, we may receive provider account identifiers, OAuth scopes and tokens, connection status, and the provider data required for the selected feature. We do not ask users to give RoyalOS their Google password.
3. Google data we access
Google products are connected separately and only when the user chooses the feature. Depending on the connection and scopes shown on Google’s consent screen, RoyalOS may access:
- YouTube: authorized channel identity, channel and video metadata, statistics, and publishing activity through
youtube.readonlyfor diagnostics. This scope does not upload, edit, or delete YouTube content. - Gmail: mailbox identity and messages needed for inbox review or response preparation through read-only access, and sending only when the separately granted
gmail.sendscope and RoyalOS approval controls permit it. - Google Drive: files the user creates, opens, or selects for RoyalOS workflows through
drive.file. - Google Calendar: calendars and events needed for user-requested scheduling through the Calendar scope displayed at authorization.
- Basic identity: OpenID, email address, and profile information used to identify the connecting account.
The scopes actually requested at authorization control access. RoyalOS must not use a broader capability merely because it appears in this policy. New Google data types or materially different uses require updated disclosure, any required verification, and user consent before use.
4. Why and how we use information
We use information to authenticate users; provide and personalize authorized workspace features; retrieve user-requested connected data; produce diagnostics, drafts, research, analytics, records, and AI-assisted work; execute approved actions; maintain tenant and Brand boundaries; provide support; process subscriptions; measure reliability; prevent fraud and abuse; investigate security incidents; meet legal obligations; and improve RoyalOS using appropriately controlled operational information.
RoyalOS does not sell Google user data, use it for targeted advertising, transfer it to data brokers, or use it to train generalized or public AI models. Google data is processed by AI only when necessary to deliver the user-requested feature and subject to the same tenant and permission boundaries.
5. Legal bases and choices
Where applicable law requires a legal basis, processing may be necessary to perform a contract, follow the user’s consent or instructions, comply with law, or pursue legitimate interests such as security, service reliability, and fraud prevention that are not overridden by individual rights. Users may decline optional connections, revoke consent where applicable, or disconnect a provider, although dependent features may stop working.
6. Disclosure and service providers
We may disclose information to infrastructure, hosting, database, storage, security, payment, communications, support, analytics, and AI service providers only as needed to operate an authorized feature and under appropriate confidentiality, security, and data-use restrictions. We may disclose information at a customer’s direction, in a business transaction subject to appropriate protections, or when reasonably necessary to comply with law, enforce rights, prevent fraud or abuse, or protect users and the public. We do not permit another RoyalOS customer to access an organization’s connected data.
7. Google API Limited Use
RoyalOS’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Human access to Google user data is prohibited except with the user’s affirmative agreement for support, when necessary for security or abuse investigation, to comply with applicable law, or where otherwise permitted by that policy; access is limited to authorized personnel with a need to know.
8. Security and tenant isolation
RoyalOS uses safeguards designed for the sensitivity of the information, including HTTPS/TLS in transit; server-side authentication and authorization; least-privilege access; organization and Brand scoping; database access controls and Row Level Security where supported; audit records; monitoring; and AES-256-GCM encryption of stored OAuth tokens and provider credentials. Encryption keys remain server-side. No internet service can guarantee absolute security.
Public users are not given direct access to RoyalOS private LAN ports, Ollama, Open WebUI, containers, internal dispatchers, or server credentials.
9. Retention, YouTube refresh, and deletion
We retain information only as long as needed for the disclosed feature, account administration, security, auditability, legal obligations, dispute resolution, and legitimate business records. Retention varies by data type. OAuth tokens are removed or disabled when the applicable connection is deleted, subject to limited security or legal records.
Stored YouTube API data must be refreshed or deleted within the periods required by YouTube Developer Policies, generally no longer than 30 days without refresh or continuing authorization. A request to delete stored YouTube API data will be completed as soon as possible and within seven calendar days. Deleting data from RoyalOS does not delete the original data from YouTube.
To request access, correction, export, restriction, objection, account closure, or deletion—including deletion of connected Google or YouTube data—email support@choiceroyals.com from the account email and identify the organization and requested data. We may verify identity and authority. We will respond within the time required by applicable law; YouTube deletion follows the shorter period above. Limited backups, security events, billing records, or legal records may remain until their applicable retention period expires.
10. Revoking connected access
Authorized users can disconnect supported services in RoyalOS. Google access can also be revoked at Google Account third-party connections. After disconnection or revocation, RoyalOS stops making new requests with that authorization. Revocation alone may not delete previously stored diagnostics or records; use the deletion request above when deletion is desired.
11. Individual privacy rights
Depending on location, a person may have rights to know, access, correct, delete, obtain a copy of, restrict, or object to processing and to appeal certain decisions. Authorized organization administrators may need to handle requests involving customer-controlled workspace content. RoyalOS will not discriminate against a person for exercising applicable privacy rights.
12. Cookies and service communications
RoyalOS may use essential cookies or similar storage for authentication, security, tenant selection, preferences, and service operation. Optional analytics or marketing technologies, if introduced, must use appropriate notice and choice. We may send transactional messages about authentication, security, billing, support, or service changes; marketing messages include legally required choices.
13. Children
RoyalOS is a business service and is not directed to children under 13. We do not knowingly collect personal information directly from children under 13. If such information was submitted without appropriate authorization, contact us for deletion. Organizations using RoyalOS with information about minors are responsible for lawful authority and appropriate safeguards.
14. International processing
RoyalOS and its providers may process information in the United States and other countries where privacy laws may differ. Where required, we use appropriate contractual or legal transfer safeguards.
15. Security incidents
We investigate suspected incidents, take reasonable containment and remediation steps, preserve evidence, and notify affected parties or authorities when required by applicable law or contract. Report a suspected incident promptly using the contact below.
16. Changes
We may update this policy as features, providers, law, or security practices change. We will change the date above and provide additional notice or obtain consent when required. Materially new uses of Google user data will not begin before required notice and consent.
17. Contact
Triple-Hay Concept LLC, North Carolina, United States. Privacy, security, and data requests: support@choiceroyals.com.