Privacy & data
Four integrations. That is the whole data map.
Most AI content setups are a chain of a dozen SaaS trials, each with its own retention policy and its own breach surface. This one talks to four things, your document never leaves the machine it sits on, and nothing that publishes can edit or delete what went out.
Everything it talks to, in full.
Four integrations, each doing one job, each constrained at the point it is wired in. We name every vendor on the call and hand you their own privacy terms with them.
- 01
One AI model provider
Writing, scripting, structuring and review. A single provider under a single agreement, not a different model for every task.
Cannot delete. Cannot edit anything without your say-so.
- 02
One voice provider
Voiceover generation, and nothing else. It receives the script line it has to speak.
Receives the script, not the source material behind it.
- 03
One publishing layer
Scheduling and publishing to the channels you connect, under your own accounts.
Has no power to edit or delete a published post.
- 04
Your own site
A custom integration we build for your blog and newsletter, and for reading content back off your site.
Runs against your site, on your infrastructure.
That is the complete list. There is no fifteenth tool holding a copy of your brand voice because somebody once started a trial with it.
See what each one does in a runWhat the system will not do.
Constraints are built in at the integration layer, not left as house rules somebody has to remember on a busy week.
-
The model is briefed, not handed the file
The system reads your document locally and sends only the brief it needs to write from. Your full document does not leave the machine it sits on. That is the single biggest difference between this and pasting a report into a chat window.
-
Nothing is deleted, and nothing is changed without you
The integrations are constrained at the point they are wired in. No destructive action is available to the system, and no edit lands without your approval.
-
Published work cannot be quietly altered
The publishing layer can queue and post. It cannot edit or delete what has gone out. Everything is reviewed before it is queued, so the review is the control, not a rollback afterwards.
-
Protected material stays on your side
Unreleased product detail, pricing, internal research and anything else you mark as protected is encrypted and held inside your own system. It is used to make the content and it is not sent anywhere else.
-
The logs stay on your machine
Run logs are written into the same folder you nominated for finished videos and posts, on your own device. They are mostly the scripts the system wrote. Nothing is copied off to us, and you can delete any of it whenever you like.
-
No account passwords are stored, anywhere
The system holds no login details for your channels or your accounts. The only secret it keeps is the API keys it needs to run, in a single encrypted file that you hold the password to. If you give us access to connect a channel during setup, you reset that password yourself once setup is finished.
-
Four integrations is the whole data map
Not fifteen SaaS trials, each with its own retention policy and breach surface. A data map this short is one you can hand to a client without a paragraph of caveats.
-
Your keys or ours
You can hold the provider accounts yourself and we build against them, or we provide ours and run them for you. Either way it stays one provider per job, and we tell you exactly who they are.
Rights, licensing and AI Act disclosure.
The questions a client or a platform reviewer actually asks, answered before they ask.
- Music
- Background music comes from a licensed library we hold the licence for. Nothing is lifted from a track you would have to argue about later.
- Video
- Not produced through third-party AI video generators, so the copyright and the licence in what it makes stay with you.
- Disclosure
- Where AI is used, for writing, scripting, voiceover and review, that use is disclosed at the point of generation rather than labelled afterwards, which is what the EU AI Act transparency rules in force require.
- Footage and inputs
- Licensed, generated and supplied material are tracked separately through the run, so a rights question has an answer rather than a guess.
GroovyMark holds no SOC 2 or ISO 27001 certification, and this page is a description of how the build works rather than legal advice. Have your own counsel read it against your obligations.
Watch it run before you commit.
You do not have to take any of this on trust. There are two ways to see the system working on real material before you spend anything on a build — and four months of measured results from an account we ran both ways, published in full.
-
A live demo, on a real run
We take a document and run it end to end in front of you: script, voiceover, video, thumbnails, descriptions and the scheduled queue. Not slides, not a recording. You see how it is working at each stage, not just the files at the end, and you can ask what happens at any of them while it is on screen.
Book a free demo -
Start on the monthly plan
Have us produce and publish on your own brand as a managed service. You get the output without a build, and if it earns its place you commission your own system later. The monthly plans are published in full.
-
4
Systems live with clients today
-
6
More in build right now
Running software, not a proposal. Whichever route you take, you can build your own system whenever you decide to.
Before you ask
The questions a reviewer asks first.
What data actually leaves our machine?
The brief the system writes from, and the script the voice provider has to speak. Not your source document. The system reads the file locally, works out what the piece needs to say, and sends only that. Anything you mark as protected, unreleased product detail, pricing or internal research, is encrypted and stays inside your own system.
Do you hold our API keys, or do we?
Either, and it is your choice. You can hold the provider accounts yourself and we build against them, or we provide ours and run them for you, which is the simpler option and the simpler one. Your social channels stay in your name in both cases. If you give us access to connect them, you reset your own passwords once setup is finished.
Can the system delete or change something we have already published?
No. The publishing layer can queue and post, and it has no power to edit or delete what has gone out. That is a deliberate constraint at the integration rather than a rule someone has to remember. Every piece is reviewed before it is queued, so the review is the control rather than a rollback afterwards.
How many third parties end up holding our content?
Four integrations in total: one AI model provider, one voice provider, one publishing layer and a custom integration with your own site. That is the complete list. The point is the length of it, because a data map this short is one you can hand to your own client without a paragraph of caveats. We name every vendor on the call and give you their own privacy terms with them.
How long do you keep our content, and where is it kept?
We do not keep it. Run logs and the finished files are written into the folder you nominated on your own machine, and they stay there. They are mostly the scripts the system wrote, and you can delete any of it whenever you want without asking us. There is no copy sitting on our side waiting to be requested back.
Are you SOC 2 or ISO 27001 certified?
No, and we will not imply otherwise. What we can show you is how the build is constructed: which four services it talks to, what each one receives, what each one is prevented from doing, and where your material is held. If a certification is a hard requirement for your procurement process, say so on the first call and we will tell you plainly whether we can meet it.
What happens to our data if we stop working with you?
The system runs on your machines and publishes under channels in your own name, so your content and your channels are already on your side of the line. If we ever stopped trading, every credential you need to keep it running is handed straight to you. The code behind it stays with us the way a studio keeps its working files, which is what lets us guarantee the build while it is in service.
Can we see it working before we commit to anything?
Yes, and we would rather you did. We run a real document end to end in front of you: script, voiceover, video, thumbnails, descriptions and the scheduled queue, including where it stops when something is wrong. If you want to go further before committing to a build, have GroovyMark run the work as a managed service on your own brand first and commission your own system later.
Bring your data questions to the call.
We will name every vendor, show you what leaves your machine and what does not, and run the system in front of you, on a real run rather than slides.
Book a build call