Privacy Policy

Last updated: 2026-05-13

1. What we collect

  • From Meta login: your Meta user ID, name, email, profile picture URL
  • The Meta access token you authorize (used to access your ad accounts)
  • From onboarding: company name, role, intended use
  • Your conversations (user messages + Claude responses + tool call results)
  • Optimization actions you approve / reject (agent_actions table)
  • Cookie: a signed session cookie for authentication

2. Why we collect it

Sole purpose: deliver AI-driven ads optimization analysis and recommendations. We do not use your data for marketing, do not sell to third parties, do not train models on it.

3. Third-party processors

  • Anthropic (Claude API): processes your conversations to produce analysis. Anthropic does not retain data for training; see Anthropic Privacy Policy.
  • Meta (Graph API): provides your ad account data. Your authorized token is used to read and modify ads (per your approvals).
  • Neon (PostgreSQL host): database hosting (currently Singapore region).
  • Vercel: application hosting.

4. Encryption & storage

Meta access tokens are encrypted with AES-256-GCM before storage; the key is held only in app environment variables, not in the database. Conversations and action logs are stored unencrypted at the application level (the database itself uses TLS in transit and at-rest encryption provided by Neon).

5. Your rights

  • Disconnect Meta any time on the Account page — revokes our access to your Meta account
  • Request account + data deletion: email wayne@mdigi.net; we process within 7 days
  • Request a copy of the data we hold about you (same contact)

6. Data retention

All data retained while your account is active. Upon deletion request, fully purged within 30 days (including database records and backup rotation).

7. Cookies

We use exactly one essential cookie (session) holding a signed user ID, for authentication state. No tracking cookies, no third-party ad cookies.

8. Changes to this policy

Updates are posted here; material changes are notified via your registered email. Continued use constitutes acceptance.

9. Contact

For privacy questions: wayne@mdigi.net