Effective date: September 15, 2026.
Scope and operator
Sweet Pea Baby LLC, operating as SweetPea Universe, uses SweetPea OS as an internal tool to prepare and review its own business content. This notice covers that tool's text assistance, live voice features and optional LinkedIn Page connection. It does not replace the separate privacy notice for orders placed on the SweetPea Universe store.
The current app runs locally on the operator's computer. Live AI features send information to OpenAI for processing. If enabled and authorized, the LinkedIn connection sends an approved post to the business's LinkedIn Page.
Information used by the app
When you submit a brief, the app processes the text you enter, the AI team member you select and instructions needed to answer. Authorized reference text may be included with the request.
When you start live voice and allow microphone access, your audio is sent to OpenAI so it can respond. The app displays conversation text as it receives transcription events. The inspected app does not create local audio recordings or save voice transcripts to a server file.
The dashboard keeps local activity records that include a short excerpt of a successful brief, the selected team member, time, processing details and review indicators. Error records can include error text. The normal launcher also saves operational and request logs on the computer. Browser storage keeps approval-card information, including generated headings and review reasons. These fields can contain information from your brief.
AI processing and its limits
OpenAI processes live briefs, authorized reference text and voice input to generate responses. API data is not used to train OpenAI models by default unless the account opts in. The text service requests that responses not be stored for later API retrieval. This does not eliminate other provider retention. Under default settings, abuse-monitoring logs can retain content for up to 30 days, with longer retention for applicable legal or protective purposes. Provider processing can involve transfers outside your location. The operator's account settings have not been verified for additional retention controls. See OpenAI's API data documentation.
AI output can be inaccurate. A draft or AI review is not an independent verification of the underlying facts. The operator reviews the content and decides whether it may be used or published.
Optional LinkedIn connection
The connection is limited to SweetPea's own company Page and text posts. Before connecting, the app presents its privacy notice, app terms and data-use explanation, then asks for consent. LinkedIn handles the sign-in and permission grant. During connection, the app receives authorization credentials. Before publication, it verifies the selected Page and your administrative permissions. Page and permission responses are processed temporarily rather than saved as a profile collection.
LinkedIn's permission names may cover more actions than this first version performs. The connection is intended to check Page identity and administrative access, then create an expressly approved text post. It does not offer personal-profile posting, comments, advertising or analytics collection.
The AI drafting and review steps use text supplied by the operator. Data returned by LinkedIn is kept out of those AI requests. During publication, the connection sends the approved text and destination to LinkedIn. It records the result and any returned post identifier to show the outcome and help prevent a repeated submission. An expired authorization or a detected invalid grant prevents further publication until restored. The app does not continuously check LinkedIn for revocation while idle.
AI assistance supports drafting and review. Human approval applies to the exact text and Page. Changes require renewed review and approval. Approval alone does not publish a post; the operator must use a separate publish action. This connection creates public LinkedIn Page posts and provides no private-audience option. Successfully published content is subject to LinkedIn's Privacy Policy.
Local storage and retention
Dashboard audit records, saved operational logs and browser approval cards have no scheduled expiration. They remain until removed from the computer or browser. Removing a browser approval card does not remove the server's audit record. Displayed conversation text may remain on the open page, and later responses can replace it. Closing or reloading the page, or changing the selected team member, clears it.
The LinkedIn connection uses a separate local encrypted store protected by the Windows user account. It holds connection settings and credentials, consent information, saved drafts, AI reviews, approvals and submission records. Its owner sign-in uses a session cookie that expires after 30 minutes. The encryption does not protect against other programs with access as the same Windows user and does not extend to the dashboard's existing audit files or browser cards.
Saved drafts and their reviews and approvals are removed after 30 days without a workflow update. Returned LinkedIn post identifiers are removed after 24 hours from submission. Cleanup runs at startup, on status access and periodically while the connection service runs. If the service is closed, cleanup waits until it next starts. Content fingerprints, outcome labels and submission dates remain as duplicate-post guards until all connection data is deleted.
Locally exported documents and any backups are separate copies. Deleting app data does not automatically delete those copies, information retained by a provider or a post already published on LinkedIn.
Your controls and contact
Use Stop voice to end the app's microphone stream. This does not itself clear text already displayed in the page. You can also withdraw microphone permission in your browser.
You can remove the app's LinkedIn access through LinkedIn's account settings. Withdrawal stops future access but does not, by itself, erase information already stored on the computer. The app's Disconnect control disables the connection, AI review and publishing. It removes tokens, the client secret, stored LinkedIn post identifiers and approvals. It retains owner-supplied drafts, AI reviews, setup and consent information and duplicate-post guards.
Delete all connection data logically erases that local connection store and ends owner sessions. It does not revoke the permission grant at LinkedIn or remove published posts, separately supplied certificate files, dashboard logs, browser approval cards, exports or backups. Removing the LinkedIn grant and removing local data are separate actions. If a privacy request concerns those other copies, they must be handled separately.
For questions about this app's information handling or help removing locally stored records, contact hello@sweetpeauniverse.com. Do not send API keys or authorization tokens by email.
Material changes to the connection's data use will be explained before renewed consent is requested.
