Chorix Social Command

Privacy

Notice version: SC-PRIVACY-2026.09.26 · Status: Issued 2026-09-26 — in force · Effective: 2026-09-26

This page is a plain-words summary of the Chorix Social Command Privacy and Local-Operation Notice — Application Schedule, an application schedule to the CHORIX Privacy and Local-Operation Notice. It covers the Chorix Social Command software you run on your PC and, under "Buying on this website", SPEKTX's site where you buy it. It is a product of SPEKTX LLC, a New Jersey limited liability company (SPEKTX). The full Notice controls; section numbers below point to it.

The software is local — this is the important part Notice §3

Chorix Social Command runs on your own Windows PC. Your campaigns, drafts, approvals, decision records, media and connection keys are kept on your PC, in a folder you can see. Apart from the subscription renewal call described below, there is no server of ours for the software to contact, and no other account with us. SPEKTX does not receive standing access to your project content because you bought or ran the software — the renewal call carries only your licence file, never your project content, and goes only to SPEKTX's site at chorixstudiosc.com.

The desk (the screen you work in) is served only to your own PC unless you turn on the home-network door for a phone or tablet.

What SPEKTX receives Notice §4

Subscription renewal [BUILT; ADDRESS SET; NOT YET TESTED AGAINST THE LIVE SITE]. Social Command is a subscription. The software renews its own signed licence file by sending it to SPEKTX's site, at chorixstudiosc.com/api/renew-license, an address built into the software; it makes the call only while a valid licence file is in place. What it sends is the signed licence file (your licensee name, organization, licence id, order reference, edition, agreement version and hash, and your paid-through date), and nothing else; when: the software checks at launch and every hour while it runs, and calls only when a call is due — once a day while your subscription is paid and the last call went through, and once an hour during the grace period, after it has lapsed, or after a call that did not go through — and when you press "Renew now" on the licence screen; if the site does not answer or refuses, the licence file you have is kept as it was; how long we keep it: renewal-check logs, 90 days; the signed licence file and order record, for the life of your subscription and, after it ends, for as long as tax and accounting law requires (see below). This call never carries your project content.

Everything else: nothing. Apart from that renewal call, the software sends SPEKTX nothing. It has no analytics, no telemetry, no crash reports, and no other update check. [NV-1, NV-9]

If you write to admin@chorixstudiosc.com, we receive what you send. Buying on SPEKTX's site, chorixstudiosc.com, is covered below, under "Buying on this website".

What the software keeps on your PC Notice §5

WhatDetails
Your workCampaign briefs, drafts, approvals and rulings, the record of decisions (the Ledger), your conversations with the campaign manager (M), threads, and generated or imported media.
Connection secretsDeveloper-app IDs and secrets you enter, sign-in tokens issued when you connect a platform, API keys you add, Pushover keys, and keys the software creates for itself.
Mail items (only if you turn the mailbox lane on)Sender, subject and Gmail's short preview for each message the search selects. Not the message body.
Platform readingsComments, replies and account statistics from platforms you connected.
A local identityA local account made on your PC from your Windows user name (<user name>@personal.local) and a bridge ID that includes your PC's name.
Run logsA text log of each launch.
Voice and phone (only if you enrol)A voice fingerprint in your browser's local storage; a phone credential in that phone's browser storage.

Who receives data, and when Notice §6

Nothing is sent to any provider just because the software starts. Data goes out only when you connect or invoke one of the services below. Two things run without a fresh action from you once set up: the daily wake (on by default once the campaign manager is set up; you can turn it off) and the scheduler tick that reads comments and statistics from platforms you already connected. Each provider handles data under its own terms; SPEKTX does not control that. [NV-4]

ServiceWhat goes to itWhen
Your AI sign-in or key: Anthropic (Claude), OpenAI (Codex), Google (Gemini) — §6.2The turn's instructions, what you typed, the thread record, the brief and board items the turn uses, and anything the seat reads or runs. Sent by the command-line program: Claude and Codex as you signed them in; Gemini with the Gemini API key you pasted on its door, which the software keeps encrypted on your PC and hands to the gemini program for each turn, and which that program sends to Google. An Operations Director seat that is not cast on a command-line program (its default) is answered instead by Google's Gemini API directly, with the Gemini API key you add for new images and video, not the door's key: each of its turns sends its instructions and the thread record to Google, and without that key it is not sent.Whenever an AI turn runs, including the daily wake.
Your own API keys: Anthropic, OpenAI, Google — §6.3Prompts and your text, straight to that provider with your key. Generation prompts (with your palette and type names) if you add a generation key.Only after you add a key, and only for the seat or request that uses it.
Social platforms you connect: Meta (Facebook, Instagram), X, TikTok, LinkedIn, Google (YouTube) — §6.4To publish, only for pieces you approved — Meta: post text and media (Instagram's media is fetched by the platform from your own public address); X: post text and media; TikTok: post text and a video fetched from your own public address; LinkedIn: post text and media; YouTube: the video with its title, description and audience settings. To read, once connected, using the token from your own sign-in to each platform — Meta: comments and account insights; X: recent replies and account stats; TikTok: account stats; LinkedIn: follower counts; YouTube: comments and channel stats.Only for platforms you connect; publishing only for approved pieces; reads on an hourly tick or immediately if you press a manual refresh.
Gmail (off by default) — §6.5A read-only search you control; the software asks Gmail for header lines and its short preview, not the body, and keeps the sender, subject and preview on your PC.Only if you switch the mailbox lane on and your Google connection holds the read-only Gmail permission.
Pushover (optional phone alerts) — §6.6Alert text (for example the first 300 characters of M's reply). If the phone door is on, the alert can include a link to your Podium; the link no longer carries a Podium key — a paired phone's own device cookie signs it in, and the link carries only a non-secret item reference.Only after you enter Pushover keys and turn alerts on.
Cloudflare or ngrok (optional public address) — §6.7Internet traffic for that address passes through them; the software accepts only a short list of paths.Only if you set a tunnel mode, and only while the software runs.
Netlify DNS — §6.8Your Netlify token, domain and a text record.Only when you press the DNS button.
Helper-program files (Operations Director only) — §6.9Normally nothing: the browser helper ships inside the software at one exact pinned version. Only if that copy is missing does the software fetch that same exact version once, from the public npm registry — never the newest version.When the Operations Director seat runs on Claude and starts its browser; the fetch, if it happens at all, is a rare fallback.
Web feeds you add — §6.10Your PC's internet address and the name Chorix-Social-Scout/1.0 are visible to the feed's site.Only for feeds you configure.

Other paths: your browser's voice dictation is handled by your browser and its vendor; the AI programs keep their own history on your PC (Google's documentation says the Gemini command line keeps its sessions under ~/.gemini/tmp/ for 30 days by default). [NV-6] As shipped, AI seats run at the full-permission tier: they can run commands and change files with your Windows permissions and reach the network, and what a seat reads can become part of what goes to its AI company. You can narrow a seat to a lower tier (§6.12).

Your choices Notice §7

Where it is kept Notice §8

In %LOCALAPPDATA%\ChorixSocialCommand (the launcher prints the exact folder): settings and secrets, the database, logs, media, the seats' working folders, and the Operations Director's browser profile. Some copies live elsewhere: standing instructions in the Windows temp folder, the AI programs' own histories, ~/.gemini/settings.json (which the software sets to use your key if you use the Gemini door), and, if you install the background service, a Windows Scheduled Task. If the database cannot open, the old copy is moved aside, not deleted.

How long it is kept Notice §9

Nothing expires by itself; data stays on your PC until you remove it. The Ledger, publishing receipts and campaign authorizations are kept on purpose and the database refuses to change or delete them. A retention floor (default 3,650 days, adjustable from 1 to 36,500) is a minimum, not a deletion timer. Run logs are added one per launch and are never trimmed. What SPEKTX itself keeps: apart from the subscription renewal call above, SPEKTX holds none of this, so it applies no retention period to it. For the renewal call: renewal-check logs, 90 days; the signed licence file and order record, for the life of your subscription and then as long as tax and accounting law requires, up to 7 years; payment card data, never held by us — our payment processor (Stripe) handles it directly; deletion honoured except where the law requires the order or tax record to be kept. Acceptance and consent records (the signed clickwrap and the recurring-charge consent) are kept the same way — for the life of your subscription and then as long as tax and accounting law requires, up to 7 years, and in any case for at least as long as the law governing that consent requires.

Export and delete Notice §10

Your records are stored on your own PC and belong to you; SPEKTX has no access to them.

Export and backup. A command-line export and import tool is included, but it is not yet a button in the software. The export seals your database, your keys, your media and your licence file into one encrypted .scbackup file, protected by a passphrase of at least 12 characters; SPEKTX holds no copy of the passphrase, so a lost one cannot be recovered. It runs while the software is stopped. The import restores that file into an empty folder and refuses a wrong passphrase. Before an update that changes your database's format, the software also copies the database automatically into the backups folder in your data folder and keeps the newest 3 copies; those copies are not encrypted and do not include your keys. You can also download a per-campaign audit pack (a signed JSON or PDF summary of one campaign's approvals, receipts and Ledger lines), which is evidence of what was approved, not a copy of your data.

Deleting your data. There is no delete-everything button in the software. Deleting a thread or campaign only hides it. Removing the background service removes only the Scheduled Task. The uninstaller, UNINSTALL.cmd, asks you to type UNINSTALL, offers the export first, and then deletes the %LOCALAPPDATA%\ChorixSocialCommand folder; it leaves the temp-folder copy, the AI programs' histories and the program folder. To remove everything by hand, stop the software and delete the %LOCALAPPDATA%\ChorixSocialCommand folder, the temp-folder copy and the AI programs' histories. Either way, you must revoke platform access in each platform's settings.

Cookies and browser storage Notice §11

The desk sets two cookies on your own PC, chorix_session and chorix_workspace (HttpOnly, SameSite=Strict), only to keep you signed in. The software contains no advertising or analytics cookies or scripts. It uses your browser's local storage for the voice fingerprint and phone credential. [NV-18]

Security Notice §12

No sale of personal information Notice §13

SPEKTX does not sell personal information or share it for cross-context behavioral advertising. Apart from the renewal call above, the software sends SPEKTX nothing, and shares data with no one except as above, at your direction.

License verification and renewal Notice §14

The software checks its licence file locally; no clock is read for that check itself. Renewing the file is the separate, periodic call to SPEKTX described above — it carries only the licence file, never your project content, and runs at most once a day while your subscription is paid, and at most once an hour during the grace period, after it has lapsed, or after a call that did not go through. The renewal code is built in, and so is its address, on SPEKTX's site at chorixstudiosc.com; if the site does not answer, the licence file you have is kept as it was. [NV-19]

Children Notice §15

Chorix Social Command is a professional business tool and is not directed at children under 16. It has no age check, and because it sends SPEKTX nothing beyond the renewal call above, we do not knowingly collect information from anyone.

Buying on this website Notice §4.3

This part covers SPEKTX's site for Chorix Social Command, chorixstudiosc.com, where you subscribe, sign the licence and download the software. The site keeps only what it needs to take your subscription, record that you accepted the agreement, issue and renew your licence file, let you download the software, and email you your licence key when you ask for it.

This website does not load Google Analytics, advertising tags or a connection to the Social Command application. Checkout opens Stripe for payment: Stripe handles the card, and SPEKTX never receives card details. Stripe, SPEKTX's payment processor, emails you receipts, payment reminders and renewal notices at the address you give at checkout.

Who handles it for SPEKTX: Stripe takes payment, as above; Supabase holds the order, licence and acceptance records, and the private storage the software download comes from; Netlify hosts the site and runs its functions, and so receives each request to the site, including your IP address. Where it is handled: Supabase keeps the records in the United States, in Amazon Web Services' us-west-2 region (Oregon); Netlify runs the site's functions in the United States, in Amazon Web Services' us-east-2 region (Ohio), and serves the site's pages from its servers around the world; Stripe processes payment data in the United States and may pass it to its own affiliates and service providers in other countries. Each of the three handles this data under its data processing terms, which form part of its terms of service with SPEKTX. If you ask for your licence key by email, an email delivery service sends that email for SPEKTX; SPEKTX will name it here, with its data processing terms and where it handles the data, before that feature is switched on. It receives your purchase email, the licence key, the download page's address and the message.

How long: renewal-check logs, 90 days; order, licence and acceptance records, for the life of your subscription and, after it ends, for as long as tax and accounting law requires, up to 7 years, and in any case as long as the law requires a consent record to be kept. An order that is never paid is deleted, with the email address it holds, after 30 days. The records kept to limit licence-key email requests are deleted after 24 hours.

Your requests: write to admin@chorixstudiosc.com to see, correct or delete what the site holds about you. We delete it except where the law requires an order, tax or consent record to be kept. SPEKTX does not sell this information or share it for cross-context behavioral advertising.

Changes Notice §17

We will post changes at https://chorixstudiosc.com/privacy.html and include the current Notice with each new download. The software has no automatic notice-push, so a change reaches you when you download a new version or visit that page. The version and effective date at the top show which one you have.

Contact Notice §18

SPEKTX LLC — admin@chorixstudiosc.com c/o Northwest Registered Agent LLC, 971 US Highway 202N, Ste N, Branchburg, New Jersey 08876

This page summarizes the Chorix Social Command Privacy and Local-Operation Notice — Application Schedule, which sits beside the CHORIX Privacy and Local-Operation Notice in the CHORIX Customer License Package. If this page and the Notice differ, the Notice controls.