news SSD storage with increased flexibility. View Promotions

MyLightHost Virtual Assistant

An owner-operated application for managing MyLightHost's authorized business accounts through official provider APIs. Its Google Analytics integration reads aggregate website performance and property settings, with separately authorized controlled property-setting changes. The Search Console connection is restricted to MyLightHost performance, indexing and sitemap information and individually approved sitemap-management operations. The YouTube connection being activated uses YouTube API Services to identify the MyLightHost channel and verify a separately approved private, empty playlist creation and cleanup. The proposed LinkedIn connection identifies and verifies authority over the MyLightHost Company Page, then supports separately authorized Page-post work where approved by LinkedIn. This is not a public customer sign-up service.

The operator is Rakibur Rahman, operating MyLightHost. These app-specific documents apply to the Virtual Assistant's Google connections and the separately authorized LinkedIn, X, Google Ads, Meta Ads and Facebook Page connections described below, not to hosting purchases, payment processing, customer support conversations, or other separately operated integrations.

Virtual Assistant Privacy Policy

Version 1.9 — effective 9 September 2026. This notice describes the owner-operated Google Analytics, Search Console, YouTube, proposed LinkedIn, X, Google Ads, Meta Ads, Facebook Page and Instagram connections. Privacy contact: rokib91@gmail.com (Rakibur Rahman, MyLightHost).

1. Who may connect and what we access

Only the MyLightHost account owner and expressly authorized operators may use this application. Connections are bound to the owner's configured Google identity, MyLightHost Analytics property the Search Console domain property sc-domain:mylighthost.com, and the MyLightHost YouTube channel. It is not offered to children or to unrelated Google account holders.

  • openid supplies a stable Google account identifier used to check the authorized identity. These connections do not request the Google email or profile scope.
  • https://www.googleapis.com/auth/analytics.readonly permits reading Analytics account/property identifiers, configuration metadata, and aggregate reports such as traffic counts and dates.
  • A separate management grant requests https://www.googleapis.com/auth/analytics.edit with openid. Although Google's permission is broader, the implemented change workflow is restricted to a named property display-name update; it does not permit arbitrary Analytics changes.
  • A separate Search Console grant requests https://www.googleapis.com/auth/webmasters with openid. It supports bounded search-performance, URL-indexing and sitemap reads and individually approved sitemap submissions. A connection verification may add an exact temporary sitemap registration and remove only that registration after independent readback. Existing sitemap registrations are not removed as a test; broader Search Console account or ownership changes are not exposed.
  • A separate YouTube grant requests https://www.googleapis.com/auth/youtube.force-ssl with openid. The implemented workflow reads the owned channel identifier and verifies one newly created private, empty playlist, then removes only that verified test playlist. It does not expose uploads, public posts, comment actions, existing video or playlist changes, audience data collection, or media downloads.

The app processes authorization grants, account/property identifiers, property names and settings, report dimensions and aggregate metrics, MyLightHost page and sitemap URLs, search/indexing status, YouTube channel and test-playlist identifiers, playlist title, privacy and empty-content status, modification evidence, and operation results. It does not request Gmail, Drive, Google Ads, Analytics user-management permissions, or visitor-level browsing profiles through these connections. Provider consent screens show the permissions actually requested.

2. Why data is used

Data is used to confirm the correct account, property and channel, show MyLightHost website performance, prepare owner-requested analysis, and check and verify specifically approved configuration changes. YouTube processing is currently limited to connection verification; unrelated playlist metadata is not retained. Separate reporting and management grants limit which worker can perform each operation. A permission grant alone does not authorize a write.

3. Storage and protection

Google credentials are held in the workstation's encrypted, access-controlled operating-system credential store and are consumed internally by purpose-specific workers. Credential values are excluded from application reports, approval documents, AI prompts, and audit output. Google API traffic uses HTTPS. Account identity hashes, resource identifiers, approved plans, minimal execution evidence, and selected aggregate reports may be retained in operator-controlled project storage on the workstation and MyLightHost operational servers. These records are not promised to be anonymous.

4. Sharing, AI assistance, and human access

Google processes API requests to provide the connected features. For owner-requested analysis and task preparation, the operator may send selected aggregate metrics, non-secret configuration metadata, and sanitized operation results to OpenAI through the operator's AI-assistant service. Access tokens, refresh tokens, client secrets, and unrelated customer content must not be sent. Such AI processing is optional to a particular analysis task and remains subject to that service's applicable data controls; this notice does not claim that an unverified zero-retention or no-training setting is enabled.

The owner may request work without AI processing by contacting the operator before that work. Any new AI use involving additional data requires prior disclosure and consent. The application does not use Google data to build or train a general-purpose AI model. Operator access is limited to the authorized task. Additional human review of specific non-aggregate Google data requires the user's affirmative agreement, except where necessary for security, applicable law, or permitted aggregate internal operations.

MyLightHost Virtual Assistant's use and transfer of Google API data follows the Google API Services User Data Policy, including its Limited Use requirements. We do not sell Google data, send it to data brokers or advertising platforms, use it to target advertisements, or use it for credit or lending decisions. Transfers are limited to consented app features, security, legal obligations, or a business transfer with explicit prior consent. These restrictions also cover derived and aggregate Google data.

5. Retention and deletion

Credentials are retained while the connection is required and authorized. Bounded provider responses are processed during the operation; selected report results and configuration evidence may remain in project records. Approval and execution records are retained as needed to prevent duplicate writes, verify authorized work, and investigate incidents. Retention is currently operator-managed: there is no automatic fixed-day purge or self-service data-deletion button.

You may request access, correction, export, or deletion of retained app data at rokib91@gmail.com. Identify the application and account or property concerned, but never send a password or token. The operator verifies the requester, identifies relevant credentials, reports, audit records and backup copies, and confirms what was removed or must be retained, with the reason and applicable retention criteria. Stopping access does not automatically erase earlier reports, AI-service records, or backup copies; their deletion must be addressed separately. No specific completion period or automatic deletion is represented by this notice.

YouTube-specific limits. Stored YouTube API metadata is deleted or refreshed within 30 calendar days. Requests to delete stored YouTube user data, or an expressed intent to end this app's access, are handled as soon as possible and within 7 calendar days. Following revocation through Google's permissions page, affected stored API data is deleted as soon as possible and within 30 calendar days. These limits override the general retention language above. Rakibur Rahman manages these deadlines, including retained connection-test metadata and relevant report or processor copies; an automatic purge is not claimed. API-data-free execution tombstones may remain solely to prevent duplicate writes. Deleting this app's records does not delete existing content stored by YouTube.

6. Withdrawing Google access

You control authorization through Google Account — third-party connections. Select the MyLightHost application and use Google's removal control to withdraw access. This can affect other Google grants associated with the same project. Contact the operator to retire the connection and remove no-longer-needed stored credentials and retained app data. The app cannot guarantee uninterrupted access if Google or the account owner expires, restricts, or revokes a grant.

For YouTube, you may also revoke access at Google security permissions. The application uses YouTube API Services; Google's handling is described in the Google Privacy Policy. Existing content on YouTube is managed in YouTube or through an expressly authorized supported API action.

7. Changes and questions

New providers, scopes, data categories, recipients, or purposes require an updated disclosure and any necessary consent before use. Material changes will carry a new effective date and be communicated to affected authorized users before changed processing begins. Contact Rakibur Rahman at rokib91@gmail.com with app privacy questions. This notice does not limit rights provided by applicable law.

8. LinkedIn connection-specific disclosure

Scope and timing. MyLightHost Marketing Control Plane is being registered for the owner's MyLightHost Company Page, organization 3837007. Initial requested permissions are r_organization_admin and r_organization_social, for account/Page identity, administrator authority, and owner-requested Page-post reads. Later w_organization_social access is subject to LinkedIn approval, member consent and an individually approved post operation. Relevant information includes application-specific member and Page identifiers, administrator role/state, and the identifiers, text and publication state of the owner's selected Page posts. Access occurs during authorized operations; no recurring LinkedIn collection or automatic publication is enabled by this registration.

Excluded access and sharing. This phase does not collect personal messages, connection lists, member feeds, follower profiles, lead forms, comments or reactions, or manage advertisements. LinkedIn API content, member data and organization-profile data are not sent to external AI services or combined with other customer datasets. The owner may separately supply their own proposed post text for drafting. LinkedIn processes requests to provide its service; only authorized operators may access the connector's bounded operational results. No LinkedIn data is sold or used for ad targeting.

Storage and deletion. Once activated, the separate connector must keep credentials inside the approved encrypted OS credential boundary, excluded from chat, logs and reports. API content is processed in memory. Application-specific member identifiers and authorization tokens may be retained for the authorized connection; other API data is retained only where LinkedIn's applicable terms expressly permit it, separated by provider and only while needed. No bulk profile database is created. LinkedIn-specific deletion rules override the general retention wording above: the operator immediately deletes stored LinkedIn data and credentials on a verified deletion request, account closure, cessation of use or applicable LinkedIn termination request, except where a legal obligation requires retention. Deletion does not remove posts already published on LinkedIn.

Consent and ending access. Review these disclosures before LinkedIn consent. You can withdraw the application's access in your LinkedIn account settings and request retirement or deletion at rokib91@gmail.com. Identify the MyLightHost LinkedIn application, but do not send credentials. The operator confirms the affected records and completion. A new purpose, permission or data recipient requires disclosure and the necessary consent before activation. Registration, policy publication and product approval are not proof of a working read/write connection. LinkedIn's own handling is described in its Privacy Policy.

9. X connection-specific disclosure

Owner and permissions. The separate X connector is bound to @mylighthost and the existing MyLightHost application. It requests tweet.read, users.read, tweet.write, list.read, list.write and offline.access. These allow account/post reads, posting, List management and renewable access within X's rules. The initial implemented operations are exact owner identification and one approved private, empty List creation, independent readback, and deletion of only that verified new List. Post publication remains subject to a supported, separately approved operation; requesting its scope does not activate automatic publishing. No direct messages, email, follower synchronization, media downloads, advertising or payment changes are exposed.

Data, storage and use. The connector processes the owner's X user ID and username, access and refresh grants, and the temporary List's ID, name, description, ownership, private visibility and empty status. Credentials and the one-use operation journal remain in the encrypted operating-system credential store, consumed internally by a protected purpose-specific worker. Credential values never enter chat, reports, command arguments or AI prompts. Bounded non-secret identity, approved plan and verification results may be retained in operator-controlled project records and used with the owner's AI assistant to complete this requested setup. Raw X responses, posts, private content and unrelated users' information are not sent to external AI services. X data is not used for model training, sale or advertising targeting. There is no recurring content collection enabled by this connection test.

Retention and control. Renewable grants remain only while the owner authorizes and needs the connection; revocation, provider restrictions or expiry can end access. X processes requests under its own Privacy Policy. The owner can withdraw this app at X connected apps and request deletion at rokib91@gmail.com. The operator stops access, retires the affected credentials and removes no-longer-needed X data from operational records and applicable processor or backup copies, subject to legal obligations and X's applicable deletion requirements. Retention and deletion are operator-managed; no automatic purge or perpetual authorization is promised. Keep only API-data-free consumption tombstones where needed to prevent replay. Deleting local records does not itself delete content on X.

10. Google Ads connection-specific disclosure

Owner, scope and purpose. The Google Ads connector is for MyLightHost advertiser account 154-647-0879, using developer manager 918-018-3792 and the owner's existing MyLightHost Google Desktop application. It requests https://www.googleapis.com/auth/adwords and openid for authorized Ads read/write access and exact owner identity. Initial activation verifies the enabled production advertiser and one individually approved, temporary unassigned label: creation, independent readback, removal of only that new label, and absence verification. The label is not attached to any advertisement. This phase does not create or edit campaigns, advertisements, budgets, bidding, billing, payments, users, account links or audiences, or upload conversions. Later reporting or advertising operations require supported operations, specific authorization and updated disclosure where applicable.

Data and sharing. The protected connector processes the owner identity, OAuth grants, developer credential, advertiser ID, currency, time zone and account status, and the temporary label's identifier, name, description, color and verification state. Credential values and raw provider responses remain outside AI prompts, chat and operational logs. Only bounded non-secret account configuration, approved plans and verification results may reach the owner's AI assistant for this requested setup. No customer records, audience lists, visitor-level data or unrelated account content are collected in this phase. Google data is not sold, brokered, used for model training or used for ad targeting. No recurring collection is enabled by connection verification.

Storage, retention and ending access. The developer credential, renewable grant and one-use operation journal remain in the encrypted operating-system credential store, in an Ads-specific slot. A protected purpose-specific worker may internally consume the existing Google Desktop application credential without replacing other Google grants. Bounded account and verification metadata may be retained in operator-controlled task records while needed for the authorized work. The operator handles retention and deletion requests, including affected credentials, operational reports, relevant processor records and backups, subject to legal obligations and applicable Google requirements. No automated purge or permanent authorization is promised. On withdrawal or the end of authorized use, stop Ads access and retire no-longer-needed Ads credentials and data; preserve only API-data-free anti-replay records where needed. Removing app data does not delete advertisements or account data at Google. Contact rokib91@gmail.com without sending credentials. Google's handling is described in its Privacy Policy; the owner controls access in Google Account connections. Revocation may affect other grants for the same Google application and is never used as an automated connection test.

11. Meta Ads connection-specific disclosure

Owner, purpose and scope. This owner-operated connection uses the existing MyLightHost Message Manager app, 1716891766273198, and a separate Ads-only login configuration for the owner-selected ad account ending 19368. It requests ads_read and ads_management. Initial activation verifies the consenting identity, app and account permissions, status, currency and time zone, then tests one specifically approved temporary unassigned ad label: create, independently read, confirm it has no campaign, ad set, advertisement or creative associations, remove only that newly created label, and independently verify absence. No campaign delivery, advertisement, budget, billing, payment, audience, customer data, conversion upload, account transfer or restriction appeal is enabled. Other existing app permissions are not revoked, and WhatsApp and its Android connection remain outside this worker.

Data, storage and sharing. Authorization grants and the existing app credential are consumed only inside a protected, purpose-specific app3 worker. The Ads grant and one-use journal are encrypted on that server and are separate from other integrations. Credential values and raw Meta responses must not enter the laptop, chat, AI prompts, command arguments or logs. The connector processes only bounded app-scoped identity, effective Ads permissions and expiry, exact account configuration, and test-label identifiers, name, association counts and verification results. Minimal non-secret account configuration, approved plans and outcomes may be retained in operator-controlled task records and shared with the owner's AI assistant to perform this requested setup. Unrelated account content is not exported. No Meta data is sold, used for general model training or used for audience targeting; no recurring data collection is activated by this test.

Retention, withdrawal and deletion. Access is retained only while authorized and needed; token expiry, provider restrictions, owner actions or app changes may interrupt it. The operator handles verified deletion requests by stopping affected access and retiring no-longer-needed Ads credentials and data from operational storage, relevant processor records and backups, subject to applicable legal and Meta requirements. Keep only API-data-free execution tombstones where needed to prevent duplicate writes. No automated purge or permanent authorization is promised. Contact rokib91@gmail.com without sending credentials. Meta processes requests under its Privacy Policy. The owner can manage connections through Facebook's app and business-integration settings; removing a shared app can affect sibling integrations, so automated shared-app revocation is not a test or cleanup step. Deleting this app's records does not delete existing advertisements or Meta account data.

12. Facebook Page connection-specific disclosure

Owner, purpose and permissions. The owner authorizes the same MyLightHost Message Manager app, 1716891766273198, to manage MyLightHost Page 432464263537716. The fixed Page connector checks existing pages_show_list, pages_read_engagement and pages_manage_posts permissions and the owner's current Page content-creation task. It can reuse the already-consented owner User grant inside app3 to obtain a token for this exact managed Page through Meta's supported API. It does not restart or replay an old failed authorization, revoke the shared app, or inspect or change WhatsApp or Android.

Data and isolation. Only the trusted Page worker may internally consume the saved owner grant; its source store is mounted read-only and remains unchanged. The selected Page token stays in process memory and is not exported to the laptop, AI prompts, chat, arguments or logs. Unselected Page credentials and raw provider responses are not retained. The Page worker has a separate encrypted one-use operation journal. Bounded app/owner/Page identifiers, Page name, effective permissions and task validation, expiry metadata, and approved test-post identifiers and verification outcomes may be retained in operator records and shared with the owner's AI assistant for this requested work. No customer conversations, private messages, visitor comments, bulk feed content or media are collected; no Meta data is used for model training, sale or audience targeting.

Safe write and ending access. Initial write verification is one individually approved unpublished text draft: create with published=false, independently verify exact Page authorship, text and unpublished state, remove only that newly created draft after a fresh read, then independently verify absence and continuing Page access. No existing post, cover, profile, role, subscription, advertisement or comment is changed. Each later real publishing operation needs its own supported implementation and exact approval. No scheduled collection or publication is enabled here. Retention and verified deletion requests are operator-managed across affected journals, task records and processor/backup copies; retire no-longer-needed data when authority ends, preserving only API-data-free anti-replay records as needed. Stopping Page access must not revoke or alter a shared grant needed by another approved connection. Token validity and separate data-access expiry remain live checks, not a promise of permanent access. Meta's Privacy Policy and Platform Terms apply; use the privacy contact above without sending credentials.

13. Instagram connection-specific disclosure

Owner and permissions. This owner-operated connection is restricted to @mylighthost, professional account 17841409334357801 linked to Facebook Page 432464263537716, through existing Meta app 1716891766273198 and separate User login configuration 4135309426770837. Consent requests instagram_basic, instagram_content_publish, instagram_manage_comments, pages_show_list, pages_read_engagement and the existing ads_read business-role dependency. No Ads operation is exposed. The worker verifies the exact owner, app, effective permissions, account and Page binding before use. Existing permissions, grants and other integrations are preserved; WhatsApp and Android are excluded.

Data, storage and sharing. The Instagram grant and one-use journal are separately encrypted on app3. Only the protected purpose-specific systemd consumer may use the existing app secret internally. Credentials remain outside the laptop, chat, prompts, arguments and logs. Bounded owner/profile/Page identifiers, permission and lifetime metadata, owned-media IDs, authorship and comment-enabled status, and the exact approved test comment and verification outcomes may be processed and retained in operator-controlled records and shared with the owner's AI assistant for this requested setup. No raw provider responses, media downloads, captions, customer comment content or private messages are exported or retained. No Instagram data is sold, used for general model training or used for audience targeting.

Initial write and limits. Connection verification may create one separately approved temporary public comment on exact owned commentable media, independently read its exact content and ownership, remove only that verified new comment after a fresh check, and independently verify absence. The comment may be briefly visible and any notifications cannot be recalled. The publishing permission does not by itself activate media publishing. No existing content, other comments, messages, advertisements, billing, roles, webhooks or sibling connection changes are exposed. No recurring collection or publication is enabled. Later real work requires its own supported operation and specific approval.

Retention and withdrawal. Access remains only while authorized and needed and may expire or be restricted or revoked. The operator handles verified deletion requests across the isolated grant and journal, relevant task records, processor copies and backups under applicable Meta and legal requirements. Stop access when authority ends and retire no-longer-needed data; preserve only API-data-free consumption tombstones where needed to prevent replay. No automatic purge or permanent access is promised. Contact the privacy address above without sending credentials. Meta's Privacy Policy and Platform Terms apply. Shared-app revocation can affect other connections and is never an automated test or cleanup action; deleting local records does not delete other Instagram content.

13. Owner-authorized marketing operations

Version 1.9; effective 9 September 2026. The owner has approved Phase 2 organic marketing for MyLightHost. This section supersedes the earlier connection-test-only descriptions solely for implemented and verified operations described here; it does not activate an unavailable provider feature. It does not change hosting contracts, prices, billing, account ownership, security, or any other integration. WhatsApp and its Android system are entirely excluded.

Standing authorization and exact accounts. Routine original educational articles and service-related content may be drafted, scheduled, published and measured without a separate human prompt only when the versioned application policy passes. Targets are blog.mylighthost.com (existing WordPress admin, user 2); Facebook Page 432464263537716; LinkedIn organization 3837007; X @mylighthost (1885785296); Instagram 17841409334357801; and YouTube channel UC_A0b5IxS_-4ouFj6SzENSw. Rolling publication limits are WordPress 1 per 7 days and 4 per 30 days; Facebook 2 per 7 days and 8 per 30 days; LinkedIn, X and Instagram each 1 per 7 days and 4 per 30 days; YouTube 1 per 14 days and 2 per 30 days. Separate platform rollout and provider requirements must pass before activation. Business Profile publication awaits an approved exact location binding.

Content and execution limits. Only original or appropriately licensed content, checked destination links and independently verified service claims qualify. Prices, discounts, guarantees, testimonials, unsupported commercial claims, private messages, customer replies, moderation, branding changes, tracking changes, purchases and advertising delivery are outside this standing authorization. Exceptions appear in the protected dashboard for the owner. Every write retains an exact immutable content/account plan, explicit standing-policy or owner-one-shot authorization, fresh state checks, a single-use consumption record, one dispatch and independent read-back. Uncertain results require read-only reconciliation, not repeat dispatch. Global and platform pause controls block new writes, but cannot recall an in-flight call or a notification already sent.

WordPress and measurement data. The separate WordPress worker consumes the existing Application Password only inside its encrypted OS credential boundary. It processes the owner's reviewed article, exact post identifier, draft/public status, modification evidence and permalink for creation and publication verification through WordPress REST APIs; no direct database credentials, account changes or unrelated private posts are exposed. Recurring Google reporting is restricted to GA4 property 399318212 and Search Console sc-domain:mylighthost.com, using already-consented reporting grants and fixed aggregate queries. The dashboard stores selected aggregate traffic and search counts, reporting windows, freshness, content/task state, reviewed own-business copy, exact execution evidence and owner-confirmed aggregate leads, sales and costs. Missing observations and targets are identified as unavailable; revenue is not called profit without the necessary costs. No customer names, email addresses, raw order records or visitor-level profiles are collected for this dashboard.

Version 1.10; effective 9 September 2026. Owner-authorized aggregate advertising reports. The verified growth reporting extension may read Google Ads advertiser 1546470879 through manager 9180183792 and Meta Ads account 275253824919368 using existing separate grants. Fixed account-level reports cover the last 28 complete account-timezone days and the previous 28 days: impressions, clicks, spend, currency, reporting dates and verification evidence. Only these filtered aggregates may enter the protected dashboard and the owner's requested AI assistance. Raw responses, audience records, customer records, search terms, individual conversions and credentials are not exported. Missing conversions, revenue and profit remain unknown; spend is not profit. The existing laptop scheduler may run one bounded report daily in Asia/Dhaka scheduling time. This supersedes earlier connection-only and no-recurring-collection descriptions solely for these implemented verified reports. Existing provider consent, retention, deletion, withdrawal and permitted-use restrictions remain unchanged. No model training, sale or ad-targeting use is permitted. Reporting does not activate ads. Any separately requested live advertising test requires an explicit budget, bounded duration, exact campaign review, spending controls and verification; there is no unlimited spending, automatic top-up or billing-change authority.

Version 1.11; effective 10 September 2026. Individually requested business branding. On the owner's specific instruction, supported operations may update the cover or profile image of the exact MyLightHost business accounts listed above. This is an owner-one-shot exception, not recurring branding authority under the organic posting policy. The protected Facebook worker may use the already-consented pages_manage_metadata permission and Page management task alongside existing Page permissions. The protected YouTube worker may use the existing youtube.force-ssl grant for a channel-banner upload and the exact branding update, preserving other channel settings. No new OAuth scope, grant replacement or shared-app revocation is implied. Public brand images, current owned-account image references and branding settings may be processed inside purpose-specific consumers solely to preview, preserve and independently verify the requested change. Only fixed account/image identifiers, approved artwork, image fingerprints, exact-action plans and sanitized verification outcomes reach the dashboard and the owner's assistant; raw provider settings, credentials and signed media links do not. LinkedIn API content remains excluded from external AI processing. Each change requires an exact image and target, fresh pre-state, one-use authorization, consumption before dispatch and independent read-back. Unsupported operations may use the official signed-in provider editor; an uncertain API write must be reconciled before any retry or fallback. Global, platform and branding pause controls block new dispatches but cannot recall an in-flight request. Existing retention, deletion and withdrawal limits remain; YouTube data is refreshed or removed within 30 days, and its existing 7-day deletion-request limit applies. This exception does not enable posts, customer messages, advertising spend, billing, security, ownership or WhatsApp changes.

Calendar-month advertising budget monitoring

The owner-authorized assistant may read current-calendar-month account-level advertising totals for MyLightHost Google Ads advertiser 1546470879 and Meta Ads account 275253824919368. The fixed report uses Asia/Dhaka calendar boundaries and includes the current day where the provider supports it. Only the bound account, reporting dates, currency, aggregate impressions, clicks, reported media cost and verification metadata reach the private dashboard and the owner's assistant. Existing 28-day comparison reporting remains available.

Reported costs can be delayed or adjusted. They are not final settlement, proof of available funds or an all-in spending cap. Missing taxes, fees, currency conversion and outstanding exposure remain unknown. The existing protected grants are reused without exporting credentials or accessing customer records, audiences, search terms, individual conversions or payment details. No model training, sale or ad-targeting use is permitted.

Read-only monthly monitoring may run at most once daily and on a separately recorded, bounded recovery or pre-execution check. It does not itself authorize campaign launches, billing changes, top-ups or auto-recharge. Provider execution requires its own approved exact plan, all-in financial limit, independent stop and read-back safeguards. Existing provider-specific retention, deletion and withdrawal requirements continue to apply; WhatsApp and its Android/support systems remain excluded.

Bounded advertising pilot operations

The owner-authorized MyLightHost assistant may prepare, validate and create one initially paused domain campaign in Google Ads account 1546470879 and one initially paused promotion of MyLightHost's existing Facebook domain-guide post in Meta Ads account 275253824919368. Google media is limited to USD 3 over three calendar days with a non-shared campaign-total budget. Meta media is limited to BDT 250 over one day with a lifetime budget, subject to provider eligibility. Both remain within the existing combined test allowance and owner-entered monthly limit, including applicable taxes, conversion and fees. Missing cost bounds do not become zero or permission to spend.

Protected workers process the owner's proposed creative, exact owned campaign identifiers, budget/end and review settings, and bounded inventory and aggregate performance needed to prevent duplicate operations and excess exposure. Raw API responses and credentials stay within their existing protected consumers. Only reviewed plans, identifiers, aggregate financial/performance evidence and bounded execution records reach the private dashboard and assistant. No customer-list uploads, remarketing audiences, private messages, raw visitor records, payment identifiers or new recipients are added. Existing provider retention, deletion and withdrawal limits remain unchanged.

Activation requires exact single-use authorization, reconciled financial limits, provider-enforced total/lifetime caps and ends, and independent stop/read-back verification. Unknown writes are reconciled without retrying publication. Pausing or withdrawing authority blocks new launches and requests stops only for the assistant's journaled pilot. Laptop-hosted controls cannot immediately issue a Google API stop while offline; its verified native cap/end remains the offline spending bound. A separately restricted app3 worker may stop the exact Meta pilot. This does not enable recurring paid campaign creation, account security or billing changes, purchases, top-ups, automatic recharge, or WhatsApp/Android operations.

Separation, storage and scheduling. Research and drafting are separated from publishing credentials and execution authorization. Selected permitted aggregates, original drafts and sanitized results may support the owner's requested AI assistance under the existing Google data-use restrictions; LinkedIn API content remains excluded from external AI processing. Raw provider responses and credentials are not exported to the dashboard, chat, logs or drafting processes. Provider-specific retention, deletion, consent and revocation requirements above remain unchanged and override general language. The local owner-protected dashboard and bounded daily, weekly and monthly jobs use Asia/Dhaka time and require the laptop to be available. Operational failures, stale data and recovery actions are recorded. No paid subscriptions, ad spend or automatic top-ups are authorized. This notice records operating rules, not a guarantee of provider access, publication, sales or profit.

Virtual Assistant Terms of Use

Version 1.9 — effective 9 September 2026. These terms cover the MyLightHost Virtual Assistant operated by Rakibur Rahman for authorized MyLightHost business-account work. They do not replace the separate terms governing hosting orders, domains, billing, refunds, or service availability.

The dated Phase 2 marketing operations section defines standing authorization for eligible organic work, exact accounts, posting limits, exceptions and pause controls. It supersedes the historical connection-test-only limits only for implemented, verified operations within that section. Other provider-specific restrictions remain in force.

  1. Authorized use. Connect only accounts you own or are expressly permitted to manage. Use the app for MyLightHost's disclosed business tasks and follow each connected provider's rules. Do not attempt to bypass account permissions, security controls, or another person's privacy.
  2. Read access and changes. OAuth permissions establish technical access, not unlimited action approval. Read operations are limited to the configured account and supported features. A write must have an exact-target, immutable plan, approved parameters, fresh state checks, a one-use approval, and provider read-back. An uncertain write result must be reconciled read-only rather than blindly repeated.
  3. Current availability. Analytics connection-level authentication, reads and a controlled property-write test are verified. Search Console connection-level authentication, reads and a reversible sitemap-write test are verified. YouTube activation and its private-playlist verification are in progress. Other proposed provider connections are not represented as complete by these documents. Publication of a policy does not establish a working API capability.
  4. YouTube. By using the YouTube connection, you agree to be bound by the YouTube Terms of Service. The connection verification creates a private, empty playlist only under an exact approved plan and removes only that new playlist after readback. It does not change existing content visibility or authorize a public post.
  5. LinkedIn. The same owner-only authorization and exact one-use write controls apply to MyLightHost Company Page work. API access remains subject to LinkedIn's API Terms of Use, applicable Marketing Developer Terms, approved products and member consent. No public test post or advertising spend is authorized by these terms alone. LinkedIn activation is pending; endorsement and uninterrupted access are not promised.
  6. X. The owner authorizes the exact private, empty List connection test and its verified cleanup separately from this notice. Every write remains bound to a one-use plan and fresh owner state; uncertain results are reconciled read-only, never automatically repeated. Access remains subject to X\'s applicable developer agreement, policies and account permissions. This notice does not authorize public test posts, recurring charges, or arbitrary changes to existing content.
  7. Google Ads. Access is subject to the Google Ads API Terms and Conditions, developer policies, account permissions and OAuth consent. The initial write test is one explicitly approved unassigned label and its verified cleanup. Every mutation requires its own immutable exact-target plan, one-use approval and independent readback; an uncertain result is reconciled read-only, never blindly repeated. API registration or token approval alone does not prove a working connection or authorize campaign launches, spending or other account changes. Access may expire, be restricted or be revoked.
  8. Facebook Page. The owner authorizes existing-grant reuse only inside the protected app3 Page worker, exact Page access verification and a one-use unpublished draft creation/readback/removal test. Existing grants, quarantined authorizations and other integrations remain preserved. Unknown writes are reconciled read-only, never replayed. Provider consent, account roles and the connection-specific privacy limits remain mandatory; broader publishing or community management requires a separately supported and approved operation.
  9. Meta Ads. Use is subject to Meta Platform Terms, Developer Policies, applicable advertising rules, account eligibility and provider consent. Initial writes are limited to the exact approved unassigned-label test and cleanup, with fresh state, a one-use plan, single dispatch and independent readback. An uncertain outcome is reconciled read-only, never automatically replayed. This notice does not authorize campaign delivery, spending, changes to existing ads, transfer of assets or evasion of restrictions. Setup and token issuance alone do not establish a completed read/write connection.
  10. Instagram. Each write requires an immutable exact-target plan, fresh owner and media checks, digest-bound one-use approval, one dispatch and independent readback. Uncertain outcomes are reconciled read-only, never replayed or reset. The separately approved temporary public-comment test includes exact new-comment cleanup, but notifications cannot be recalled. Provider consent, roles, Meta Platform Terms and the connection-specific privacy limits apply; this notice alone does not authorize general publication.
  11. Review and limitations. Reports and AI-assisted recommendations can be incomplete or mistaken. The operator must review material changes before execution. Provider limits, permissions, outages, and account decisions can interrupt service. The app does not guarantee search rankings, advertising results, uninterrupted access, or Google endorsement.
  12. Privacy and ending use. The Virtual Assistant Privacy Policy explains data handling, AI assistance, retention, withdrawal, and deletion requests. Stop using the app and contact the operator to retire access when it is no longer authorized.
  13. Updates and contact. Material changes to these terms will be dated and communicated before they apply to affected users. Questions and requests: rokib91@gmail.com. Nothing here excludes rights or duties that cannot lawfully be excluded.

About the Virtual Assistant · Separate hosting and cookie information

Cookie Basics

Cookies are small text files stored on your browser. MyLightHost uses them to keep you signed in, remember language or currency preferences, and show localized routes. Essential cookies operate automatically; optional cookies are controlled by your consent.

Optional cookies are not required to use the public site. You can accept or decline them below and change that choice later in this browser.

Types of Cookies We Use

Manage Preferences

Use the buttons below to update cookie consent. Choices apply to the current browser for one year. Essential cookies remain active.

Current status: Not set

Privacy & Data Protection

We process personal data needed to provide hosting, billing, support, fraud prevention, and account security, subject to applicable law and the services you use.

  • Payment information is handled by the payment method and provider selected during checkout.
  • Support conversations are retained as needed to resolve requests, maintain account history, and protect the service.
  • Optional analytics or marketing technologies are controlled by your cookie preference where applicable.
  • Data access, correction, export, or deletion requests can be submitted through a verified support ticket.

Data Retention

Retention periods balance legal obligations with operational requirements. After the window closes, information is securely deleted or anonymized.

Third-Party Providers

We use service providers only where they are needed to deliver hosting, payments, email, protection, and monitoring. The providers presented during checkout may vary by country and payment method.

  • Payment details are handled by the payment provider selected at checkout.
  • Network, CDN, and DDoS providers may process connection metadata needed to protect the service.
  • Transactional email providers deliver account, invoice, and support notifications.
  • Infrastructure monitoring providers process operational telemetry rather than customer content where practical.

Security Measures

Security is embedded in every layer of MyLightHost. We invest in technology, people, and processes to keep workloads safe.

  • Layered network filtering, malware controls, vulnerability management, and encrypted transport.
  • Role-based administrative access and restricted handling of production credentials.
  • Monitoring, alerting, backups, and documented incident-response procedures.
  • Security controls are reviewed as infrastructure and threats change.

Legal Terms

The terms shown during checkout and in the client portal govern each service. Important points to review before ordering include:

  1. The acceptable-use rules for spam, abusive content, and malicious activity.
  2. The backup coverage and restoration options included with the selected plan.
  3. The renewal, cancellation, refund, and notice terms shown for that service.
  4. Any availability target or service credit expressly included in the order terms.

Policy Updates

We may update this page when legal requirements, service providers, or MyLightHost products change.

Material changes will include an effective date and, where appropriate, a notification in the client area or by email.

Contact Compliance

Need a signed Data Processing Agreement, help with a privacy request, or clarification on cookies? Our compliance desk is ready to assist.