Privacy Policy
Version v4-draft · Australian English · Australian Privacy Principles
1. Collection notice
[Placeholder — solicitor to supply: what personal information we collect, why we collect it, and how it is used, consistent with the Australian Privacy Principles.]
2. Data categories
[Placeholder — solicitor to supply: account details, billing details, and read-only advertising performance metrics drawn from connected ad accounts.]
3. Sub-processors
[Placeholder — solicitor to supply: we rely on the following sub-processors — Supabase (database & authentication), Stripe (payments), Resend (transactional email), and Anthropic (AI assistance).]
4. Australian data residency
[Placeholder — solicitor to supply: where personal information is stored and processed, and the position on Australian data residency and any overseas disclosure.]
5. Deletion-request contact
[Placeholder — solicitor to supply: how to request access, correction, or deletion of your personal information. Deletion requests may also be lodged via our data-deletion endpoint.]
6. Security & complaints
[Placeholder — solicitor to supply.]
7. Use of data to improve & train the system
[Placeholder — solicitor to supply. Intended position (conservative): we use account and ad-performance data to operate and continually improve AdPilot, including training and evaluating our models. Any such training or evaluation uses de-identified and/or aggregated data only; we do not use identifiable personal information — including lead data — to train our models. We treat lead identifiers (including the one-way hash we store) as personal information under this policy and the Australian Privacy Principles, not as de-identification, unless a documented re-identification-risk assessment establishes otherwise. Your data is never shared with or exposed to another customer (strict tenant isolation). You may opt out of de-identified model-improvement use at any time without losing core functionality. See the erasure process above.]