Privacy Policy
Risos is an evidence-first community-intelligence service. This page describes the product behavior implemented in this build; it does not claim source permissions or analytics capabilities that have not been activated.
YouTube API Services
When the YouTube source is activated, Risos uses the official YouTube Data API v3 to retrieve relevant public video context, public comments, and public replies. Risos does not scrape youtube.com, use unofficial mirrors, or download/archive YouTube audiovisual content.
Raw YouTube API text and metadata are maintained in a source-aware rolling cache. The system targets refresh around day 27 and must refresh or remove raw data by the applicable 30-day deadline. If a comment or video is deleted or unavailable, Risos removes raw text and any raw vector state and keeps only policy-safe tombstone/audit metadata.
Before Google accepts any additional analytics or derived-metrics scope, raw YouTube comments are display-only evidence: they are not sent through Risos raw-evidence OpenAI/Anthropic synthesis routes, do not create raw embeddings, and do not become durable analytical Research Memory. If Google later approves specific analytics, Risos enables only the accepted capabilities and preserves source provenance.
Risos minimizes commenter data and does not need persistent individual commenter profiles or protected-characteristic inference for its Voice-of-Customer research use case.
Threads API Services
When an organization connects Threads, Risos uses the official Meta Threads API and organization-authorized OAuth. The implemented integration supports public keyword search and best-effort conversation/reply expansion only within the capabilities Meta authorizes. Risos does not scrape Threads or use unofficial mirrors.
Threads access is centrally policy-gated. Before Meta approval for ordinary production access, the source remains tester-only. A database guard prevents the adapter from being switched to production while the Threads policy approval status is still pending.
Threads organization isolation
Threads evidence acquired through an organization connection is stored with that organization's scope and namespaced source identifiers. It is not exposed to another organization and is not reused across organizations. Retrieval without matching organization context does not return organization-owned Threads evidence.
Threads retention and deletion
Disconnecting Threads removes the organization's stored Threads credentials and Threads-acquired evidence, and removes Threads-derived research memory that depends on that connection. Account and source deletion controls remain separate so users can disconnect a source without deleting the entire Risos account.
Security
Threads access tokens are designed to be stored server-side using authenticated encryption. OAuth state is one-time, time-bounded, organization-bound, and user-bound. Source credentials are not exposed to the browser, API responses, MCP responses, or evidence records.
Other source data
Other community and knowledge sources are handled under their own source policies, licenses, connection boundaries, and retention rules. Source identity and limitations remain attached to evidence and intelligence products.
Contact and choices
Workspace account export and deletion controls are available through Risos account governance. Platform-specific source deletion and termination rules are propagated where required.
Manage source connections · Data deletion instructions
Google Privacy Policy applies to Google services used by the YouTube API.