Privacy Policy
Effective 7 August 2026 · Beta draft. This policy may be updated before general availability.
1. What we collect
Account data: name, email, password hash, optional two-factor secret. Workspace content: products, claims, brand kits, uploaded images and documents, campaigns and generated creatives. Integration data: when you connect an ad platform, the access token (encrypted at rest), your ad account/page selection, and delivery metrics for ads you publish. Usage and billing: credit ledger entries, job records, and payment records processed by Stripe (we never store card numbers). Diagnostics: error reports and logs used to keep the service reliable.
2. How we use it
To operate the service: your product content is sent to the AI model providers configured for generation (for example large-language-model and image-model APIs) solely to produce your campaign output. We do not sell your data, and we do not use your workspace content to train our own models.
3. Metadata we remove
Images you upload are re-encoded on receipt, which strips embedded metadata such as GPS location and device information before the file is stored or served.
4. Where data lives and how long
Data is stored on our hosting infrastructure and retained while your account is active. Diagnostic logs are retained for a limited operational window. Delivery metrics are retained as append-only history for your reporting.
5. Deleting your data
From within the app you can: delete individual uploaded assets; delete a product (removes its claims, brand kit and images); delete a campaign (removes its generations, videos, editor scenes and generated files); and disconnect a connected ad platform, which removes the stored access token. You can also delete your entire account from Settings, which removes your workspaces and everything in them; if you still need help, use the contact page.
6. Security
Access tokens and provider keys are encrypted at rest; platform administration requires two-factor authentication; media access can be restricted to signed, expiring URLs; and all traffic uses TLS. No system is perfectly secure, so report concerns via the contact page.
7. Third parties
We share data only with the processors needed to run the service: AI model providers (generation), Stripe (payments), the ad platforms you explicitly connect (publishing), and our error-monitoring provider (diagnostics). Each receives only what its function requires.
8. Your rights and contact
You may request access to, correction of, or deletion of your personal data via the contact page. Material changes to this policy will be announced in the app or by email.
This document is a beta draft provided for transparency and is not legal advice. Have your counsel review it before general availability.