Message GuardMessageOSFree Guide
0 spots left this monthGet Message Guard
Legal

Privacy Policy

Effective: [DATE]  ·  Last updated: [DATE]

1. The short version

Protagonist Communications ("Protagonist," "we," "us") helps product marketers build and maintain differentiated positioning. We do that through consulting engagements, the Ultimate Product Differentiation Guide, Message Guard, and MessageOS.

This policy explains what personal information we collect, why, and what control you have over it. A few things worth knowing up front:

  • We don't sell your personal information, and we don't share it for cross-context behavioral advertising.
  • We don't use your Workspace Content to train AI models, and our AI providers are contractually barred from doing so.
  • MessageOS sends your content to third-party AI providers so it can be scored, rewritten, and generated. Section 6 explains exactly how that works.
  • If you connect MessageOS to an outside AI client (Claude, ChatGPT, Cursor, or anything else via our MCP server or API), that client's privacy practices govern what happens on their side, not ours. See Section 7.

2. Who this policy covers

This policy applies to:

  • [protagonistpmm.com] and any other Protagonist marketing site
  • MessageOS, our positioning and messaging platform at [app.protagonistcomms.co], including its API and MCP server
  • Message Guard message audits and reports
  • The Ultimate Product Differentiation Guide (UPDG) and its Realtime Differentiation Assistant
  • The Differentiate or Die Challenge and other workshops, sprints, and consulting engagements
  • Email, support, sales, and event interactions with our team

It does not apply to third-party sites we link to, or to your own customers' data once you export content out of MessageOS.


3. Two different roles we play

This distinction matters, so we're putting it early instead of burying it.

When we're the controller. For your account information, billing details, marketing subscriptions, support conversations, and product usage data, we decide why and how the data is used. This policy governs it.

When we're the processor. For the content you load into a MessageOS workspace — your Message Playbook, your drafts, your competitors' public messaging, anything your team uploads — you decide why and how it's used. We process it on your instructions to deliver the service. If that content contains personal information about your customers, employees, or prospects, you are the controller and we are your processor.

If you're a business customer subject to GDPR, UK GDPR, or a US state privacy law, our Data Processing Addendum governs that relationship and takes precedence over this policy where the two conflict. Request it at [privacy@protagonistpmm.com].


4. What we collect

4.1 Information you give us

CategoryExamplesWhere it comes from
Account and identityName, work email, password credentials, company name, job title, profile photoYou, at signup or in settings
BillingBilling name and address, plan, subscription status, transaction history, last four digits and card brandYou, via Stripe
Workspace ContentMessage Playbooks, brand system prompts, key messages, product and feature descriptions, drafts you submit for scoring or rewriting, uploaded website copy, social posts, email campaigns, video scripts, ad creative, competitor messaging you supplyYou and your team members
Channel and competitor URLsThe website, blog, LinkedIn, X, and Instagram addresses you enter for your brand and for the competitors you want analyzedYou, in workspace and audit settings
Connected accountsAuthorization tokens for advertising accounts you choose to connect, currently LinkedIn Ads and Meta AdsYou, via each platform's OAuth flow
Client and engagement dataNotes, deliverables, briefs, and materials exchanged during consulting engagements, audits, workshops, and sprintsYou and your team
CommunicationsSupport tickets, sales conversations, survey and form responses, webinar and workshop registrations, newsletter signupsYou
RecordingsVideo, audio, still images, and screen recordings of service delivery sessions where you or your organization have agreed to filmingSessions you attend

We do not store full payment card numbers. Card data goes directly to Stripe, our payment processor, and is handled under Stripe's own privacy policy.

4.2 Information we collect automatically

  • Usage data — pages and features viewed, buttons clicked, workspaces accessed, reports run, scores generated, session length, referring URLs
  • Device and connection data — IP address, browser type and version, operating system, device type, language, approximate location derived from IP (city or region level, not precise geolocation)
  • Log data — API requests, timestamps, error traces, request identifiers
  • MCP and API tool logs — see Section 7, which describes these in full, because they record more than metadata
  • Cookies and similar technologies — see Section 11

4.3 Information from other sources

  • Publicly available competitor and channel content. Message Guard and MessageOS collect the public marketing published at the URLs you give us: website and blog pages, and posts from LinkedIn, X, and Instagram profiles. Web pages are fetched by our own collector service; social posts are retrieved through Apify, a third-party scraping provider. That content occasionally contains personal information, like the name of a founder quoted in a testimonial. We collect it only where it appears in public marketing material, use it only for messaging analysis in your reports, and don't build profiles of the individuals involved.
  • Screenshots of analyzed content. Audits capture and store images of the content being reviewed so your report can show the piece as it actually ran. These are held with the rest of your workspace data.
  • Advertising account data. If you connect LinkedIn Ads or Meta Ads, we receive the campaign and creative data those integrations are scoped to send.
  • Business contact data from partners, referral sources, event lists, and public professional directories, used for B2B outreach.

4.4 What we ask you not to send

MessageOS is built for marketing and positioning content. Please don't upload sensitive categories of personal information — government identifiers, financial account numbers, health or medical records, biometric data, precise geolocation, information about children under 16, or data subject to HIPAA, GLBA, FERPA, or similar sector-specific regimes. Our systems and contracts aren't designed for it, and uploading it violates our Terms of Service.


5. Why we use it

PurposeLegal basis (GDPR/UK GDPR)
Provide, operate, and maintain MessageOS and our other servicesContract
Generate scores, reports, rewrites, and content within your workspaceContract
Authenticate users, manage workspaces and permissionsContract
Process payments, invoicing, and dunningContract
Provide support and respond to your requestsContract / Legitimate interests
Debug, monitor performance, and prevent abuse, fraud, and security incidentsLegitimate interests
Improve our products through aggregated and de-identified usage analysisLegitimate interests
Send transactional and service noticesContract
Send marketing emails, newsletters, and event invitationsConsent or Legitimate interests, depending on your jurisdiction
Use session recordings in case studies and promotional contentConsent, via a separate written release
Comply with legal obligations and enforce our agreementsLegal obligation / Legitimate interests

Aggregated and de-identified data. We may create statistics and benchmarks from usage across accounts — average consistency scores by industry, common differentiation failure patterns, that sort of thing. This data is aggregated so it can't reasonably be linked back to you or any individual, and we may publish or share it. We won't attempt to re-identify it.


6. How MessageOS uses AI

This is the section most people actually want, so here's the detail.

Your content goes to third-party AI providers. When you score a draft, generate content from a Key Message button, request a rewrite, run a Differentiation or Consistency Report, run a Message Guard audit, or use the Realtime Differentiation Assistant, we transmit the relevant content — your draft, your Message Playbook, your brand system prompt, and your product and feature information — to one or more large language model providers acting as our subprocessors. They process it, return a result, and we deliver it to you.

Which model runs is configurable. MessageOS is model-agnostic. Today the platform is configured to use OpenAI by default, and it can be pointed at Anthropic, Azure OpenAI, or Google Gemini. The current provider list is in Section 8.1, and we update it when the configuration changes.

What scoring actually does. Content is evaluated against the seven StoryBrand dimensions — hero, problem, product, plan, call to action, failure, and success. Each piece receives a mark per dimension and a written summary explaining it. Reports aggregate those marks by channel and by competitor.

Your content is not used to train models. Our agreements with these providers prohibit using content submitted through our API for model training or improvement. We do not use your Workspace Content to train, fine-tune, or evaluate any model of our own.

Retention at the provider. Providers may retain submitted content briefly for abuse monitoring under their standard enterprise terms, typically [30] days or less, after which it's deleted. Retention periods are set by the provider and can change.

Humans read your content too.

  • Message Guard audits are read by a person. A StoryBrand Certified Guide reads your content and writes the qualitative markup and recommendations. The per-dimension scores that accompany that markup are produced with AI assistance and reviewed by the Guide.
  • Consulting and workshop work is human. Our team reads and works with what you share.
  • Support and engineering access is restricted. Our team accesses Workspace Content only when you ask us to, or when it's necessary to investigate a specific technical fault or a credible security or abuse concern. Access is limited to the people who need it and is logged.

AI output isn't guaranteed. Scores, rewrites, and generated copy are drafts and analytical estimates. They can be wrong. Review before you publish, and don't treat any output as legal, financial, or professional advice.

No automated decisions with legal effect. MessageOS scores content, not people. Nothing in the platform makes automated decisions that produce legal or similarly significant effects about any individual.


7. API keys, the MCP server, and outside AI clients

MessageOS exposes an API and a Model Context Protocol (MCP) server so you can work with your Message Playbook from inside AI assistants and development tools you already use. Through it, a connected client can list your workspaces, read your playbook, score content, and request rewrites.

What this means for your data:

  • A connection is a credential to your workspace. Clients connect either with a workspace API key or by authorizing through OAuth. Either way, the holder can read your Message Playbook, brand system prompt, key messages, and product features, and submit content for scoring and rewriting, within the scope of that credential. Treat an API key like a password.
  • When you connect an outside client, content flows both ways. Your playbook and key messages leave MessageOS and enter that client's context. Content that client sends for scoring or rewriting enters ours.
  • We don't control the other side. Once your playbook data is in a third-party AI client, that provider's privacy policy, retention practices, and training practices govern it — not this policy. If that client uses conversations for training, your positioning could be included. Check before you connect.
  • You're responsible for who you authorize. Issue keys narrowly, rotate them, and revoke any key or authorized client you no longer need from your workspace settings.
  • We log the content of MCP tool calls, not just the metadata. Every call is recorded with the tool name, the calling user, which API key or OAuth session was used, the workspace referenced, the time, the duration, whether it succeeded, and any error. The log also stores the arguments sent to the tool and the result returned, truncated when large. That means the drafts you submit for scoring and the text returned to you are held in this log. We keep it to investigate faults, abuse, and misuse of credentials, under the retention period in Section 10.

8. Who we share with

We share personal information only in these situations. We do not sell personal information, and we do not share it for cross-context behavioral advertising.

8.1 Subprocessors

We use third-party providers to run the service. Each is bound by contract to protect the data and use it only to provide services to us.

ProviderWhat it doesData involved
OpenAIDefault provider for scoring, rewriting, generation, and reportsWorkspace Content, prompts
Anthropic, Azure OpenAI, Google GeminiAlternative model providers the platform can be configured to useWorkspace Content, prompts
Fly.ioApplication hosting and deliveryAll service data in transit and at rest
ApifyRetrieves public posts from the LinkedIn, X, and Instagram profiles you specifyChannel and competitor URLs, retrieved public content
StripePayments and subscription billingBilling and transaction data
SendGridTransactional email: workspace invitations, password resets, report deliveryName, email, delivery events
PostHogProduct analyticsUsage, device, and log data
[Newsletter platform]Marketing email and newslettersName, email, subscription status
[Support tooling]Support tickets and conversationsContact and support content

Where your data is stored. MessageOS stores workspace data and its search index in the application's own database and vector store, on infrastructure we host. We do not use a third-party database-as-a-service for Workspace Content.

A current subprocessor list is available at [URL]. Business customers under a DPA can subscribe to advance notice of changes.

8.2 Other disclosures

  • Within your organization. Workspace admins can see workspace membership, activity, and content. If your employer provisioned your account, they control it.
  • Professional advisors. Lawyers, accountants, insurers, and auditors, under confidentiality obligations.
  • Legal and safety. When required by law, subpoena, or court order, or where necessary to investigate fraud, enforce our agreements, or protect the rights and safety of any person. Where we're legally permitted, we'll notify you before disclosing your data.
  • Business transfers. In a merger, acquisition, financing, or sale of assets, subject to this policy continuing to apply to the transferred information.
  • With your consent. Anything else — including using your name, likeness, logo, or recorded sessions in promotional content, which we do only under a separate signed release.

9. Recording and promotional use

Workshops, sprints, working sessions, and check-ins are recorded, covering video, audio, still images, screen capture, and chat. Recordings are used to deliver your work and, under the licence in Section 12 of our Terms of Service, in our marketing and educational material. Your Master Services Agreement can override that licence.

  • We tell you before recording starts and the indicator stays on. We don't record covertly.
  • What we won't publish: financial figures, unreleased products or roadmap, personal information about your customers or staff, and anything you designate confidential in the session or flag within [10] business days of it.
  • If you're an individual participating in a session your organization agreed to have filmed, you can ask not to appear on camera. Contact [privacy@protagonistpmm.com] or tell the facilitator before the session.
  • Withdrawing consent stops future use. It can't retroactively pull back material already published and distributed.

10. How long we keep things

DataRetention
Account dataFor the life of the account, then [30] days after closure
Workspace ContentFor the life of the account, unless you delete it sooner; deleted content is purged from active systems within [30] days
Audit screenshots and collected channel contentWith the workspace, and deleted with it
BackupsEncrypted backups retained up to [90] days, then overwritten
Billing and transaction records[7] years, for tax and audit obligations
MCP tool logs, including submitted and returned text[12] months
Other API and security logs[12] months
Marketing contact dataUntil you unsubscribe, then suppression-list only
Support conversations[24] months
Session recordings and promotional footagePer the applicable release

We may keep information longer where a legal hold, dispute, or statutory obligation requires it.

Deletion. You can delete individual content from your workspace at any time. To delete an entire workspace or account, contact [privacy@protagonistpmm.com] and we'll act within [30] days.


11. Cookies and tracking

We use:

  • Strictly necessary cookies — login sessions, security, load balancing. These can't be turned off.
  • Functional cookies — remembering preferences and workspace selection.
  • Analytics cookies — understanding how the product and site are used so we can improve them.

We do not use advertising or cross-site tracking cookies.

You can control cookies through your browser. Blocking necessary cookies will break parts of MessageOS.

Global Privacy Control. We honor GPC signals as an opt-out of sale and sharing where applicable law requires it.


12. Your rights

Everyone. You can ask us to access, correct, delete, or receive a portable copy of your personal information, and you can unsubscribe from marketing at any time using the link in any marketing email. Contact [privacy@protagonistpmm.com]. We'll verify your identity before acting and respond within the time your local law requires.

If you're in the EEA, UK, or Switzerland. You have rights to access, rectification, erasure, restriction, portability, and objection, including objection to processing based on legitimate interests. Where we rely on consent, you can withdraw it at any time without affecting prior processing. You can lodge a complaint with your supervisory authority.

If you're in California. You have the right to know, delete, correct, and to opt out of sale or sharing (we do neither), plus the right to limit use of sensitive personal information (we don't collect it for the purposes that trigger this right). We won't discriminate against you for exercising these rights. Authorized agents may submit requests with proof of authority.

If you're in Colorado, Connecticut, Virginia, Utah, Texas, Oregon, or another US state with a comprehensive privacy law, you have comparable rights, including the right to appeal a denial. To appeal, reply to our decision or write to [privacy@protagonistpmm.com] with "Privacy Appeal" in the subject line.

If your data is in a workspace someone else controls, send your request to that organization. We'll route it to them and support their response.


13. International transfers

Protagonist operates from the United States, and our subprocessors are primarily US-based. If you're outside the US, your information will be transferred to and processed in the US and other countries whose data protection laws may differ from your own.

For transfers out of the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses and the UK Addendum, with supplementary measures where appropriate. Copies are available on request.


14. Security

We use encryption in transit (TLS) and at rest, role-based access controls, least-privilege internal access, audit logging, environment isolation, and regular dependency and vulnerability review. Access to production data is restricted to personnel who need it.

No system is perfectly secure. If we become aware of a breach affecting your personal information, we'll notify you and any required regulator within the timeframes the law sets.

You're responsible for your side: strong unique passwords, enabling multi-factor authentication where available, controlling who you invite to your workspace, and safeguarding API keys.


15. Children

Our services are built for businesses and aren't directed to anyone under 16. We don't knowingly collect personal information from children. If you believe a child has given us information, contact us and we'll delete it.


16. Changes to this policy

We'll update this policy as our products and obligations change. Material changes will be announced by email or in-product notice at least [14] days before they take effect, and the "last updated" date above will always reflect the current version. Continuing to use the services after changes take effect means you accept them.


17. Contact us

Protagonist Communications [Full legal entity name, e.g. Protagonist Communications LLC] [Street address] [City], Utah [ZIP] United States

Privacy questions and rights requests: [privacy@protagonistpmm.com] General: [hello@protagonistpmm.com]

Products

Message Guard MessageOS Ultimate Product Differentiation Guide

Company

About Case Studies Resources FAQ

Follow

PrivacyTermsCookies
Written with — graded before it shipped
© 2026 Protagonist Communications