Privacy Policy

    Last updated: August 13, 2026

    1. Introduction

    Adsidian ("we", "our", or "us") operates an AI-powered advertising management platform at adsidian.ai and associated subdomains, including the Prism server-side tracking service. This Privacy Policy explains how we collect, use, and protect personal information — both when you use our platform and when we process data on behalf of our customers.

    2. Our Two Roles

    We process personal data in two distinct capacities:

    • As a controller / business for data about our own users: your account, billing, and usage of the platform.
    • As a processor / service provider for data our customers (advertising agencies and their clients) entrust to us: CRM contacts synced from their systems, and website-visitor event data collected by Prism on their websites. For that data, our customer is the controller and this processing is governed by our Data Processing Agreement. Requests about data collected on a customer's website should be directed to that website's operator; we support our customers in fulfilling them.

    3. Information We Collect

    • Account information: Name, email address, and password when you create an account.
    • Agency and client data: Business names, campaign details, and advertising data you enter into the platform.
    • Ad platform integration data: Ad account IDs, access tokens, and campaign performance data retrieved from the Meta, Google Ads, and LinkedIn APIs on your behalf.
    • CRM data (on behalf of customers): Contact records (names, email addresses, phone numbers, appointments, conversation summaries) synced from CRM systems such as GoHighLevel that our customers connect.
    • Prism tracking data (on behalf of customers): Website event data collected first-party on our customers' websites — page views and conversion events, pseudonymous visitor identifiers (cookie IDs, ad click IDs), IP address and browser user-agent, and SHA-256-hashed contact identifiers (such as hashed email or phone) where the visitor provides them. Raw email addresses and phone numbers are hashed in the visitor's browser before transmission.
    • AI assistant data: Prompts, conversation history, and voice-dictation audio (transcribed in real time; audio is not stored) when you use the built-in assistant.
    • Usage data: Log data, IP addresses, browser type, and pages visited to operate and improve the service.
    • Payment information: Billing details processed securely by our payment provider (Stripe). We do not store card numbers.

    4. How We Use Information

    • To provide, operate, and improve the Adsidian platform.
    • To manage advertising campaigns via the Meta, Google Ads, and LinkedIn APIs on your behalf.
    • To measure ad performance and deliver conversion events to ad platforms (Meta Conversions API, Google Ads, LinkedIn Conversions API) on behalf of our customers, subject to the consent controls described in Section 6.
    • To generate AI-powered campaign strategies, creatives, and recommendations.
    • To process billing and send service-related communications.
    • To comply with legal obligations.

    Data retrieved from ad platform APIs (Meta, Google Ads, LinkedIn) is used solely to provide campaign management, measurement, and reporting for the ad accounts our customers connect. It is never used to build or enrich user profiles, generate leads, enhance CRM records, or create audience lists outside the connected platform's own tools, and it is never sold or transferred to third parties. In particular, our LinkedIn integration accesses advertising data only (ad accounts, campaigns, creatives, and performance metrics) — not LinkedIn member profile data — and is operated in accordance with the LinkedIn Marketing API Terms.

    5. Legal Bases (GDPR)

    Where the GDPR applies and we act as controller, we rely on: contract performance (operating your account and the services you request), legitimate interests (service security, product improvement, business communications), consent (where required, e.g. non-essential cookies), and legal obligation (tax and accounting records). Where we act as processor, our customer determines the legal basis and we process only on their documented instructions.

    6. Prism Tracking, Consent, and Ad Platforms

    Prism collects website events server-side, first-party, on our customers' websites. Before any event is shared with an ad platform, Prism evaluates the visitor's consent signal (from the website's consent manager or an IAB TCF-compatible CMP): an explicit denial always suppresses sharing with ad platforms. Where a visitor has opted out of personalized advertising, we forward restricted-processing signals (Meta Limited Data Use; Google Consent Mode). Identifiers such as email and phone are SHA-256 hashed before they leave the visitor's browser. Visitor IP addresses can be truncated at the website operator's election. Cookies set by Prism: a first-party visitor identifier (up to 1 year) and ad click-ID cookies (90 days).

    7. Data Sharing and Subprocessors

    We do not sell personal information, and we do not share our users' personal information for cross-context behavioral advertising. Conversion events processed on behalf of our customers are delivered to the ad platforms those customers have connected (Meta, Google, LinkedIn), acting on their instructions. We share data with the following categories of service providers, each bound by contract:

    • Infrastructure: Supabase (database & authentication), Cloudflare (hosting, CDN, and Prism edge network), Fly.io (API hosting).
    • Payments: Stripe.
    • AI providers: Anthropic and OpenRouter (assistant & strategy generation), Groq / OpenAI (voice transcription), Google, Runway, Higgsfield, and fal.ai (creative generation).
    • Ad platforms & CRM: Meta, Google, LinkedIn, and GoHighLevel — when you connect them.
    • Email delivery: Resend (lead notifications configured by customers).
    • Legal requirements: When required by law or to protect our rights.

    A current subprocessor list is maintained at docs.adsidian.ai. Data may be processed in the United States; where we transfer personal data from the EEA, UK, or Switzerland, we rely on our providers' Standard Contractual Clauses and/or Data Privacy Framework participation.

    8. Data Retention

    • Account data: for as long as your account is active, then deleted on request or per our offboarding schedule.
    • Ad platform integration data: OAuth access and refresh tokens are deleted when you disconnect the integration or close your account; synced campaign and performance data is deleted per our offboarding schedule or on request.
    • Prism raw event data: 13 months by default (configurable per customer); aggregate statistics are retained thereafter in de-identified form.
    • CRM-synced records: mirrored while live in the connected CRM; records no longer present at the source are purged within 180 days (configurable).
    • Webhook processing logs: 90 days.
    • AI assistant conversations: 12 months by default (configurable per customer).
    • Detailed audit logs: 30 days.

    9. Security

    We use industry-standard security measures including encryption in transit (HTTPS/TLS) and at rest, row-level tenant isolation, signed webhook verification, and secret masking in our interface. No method of transmission or storage is 100% secure; we will notify affected customers of any personal data breach as required by applicable law.

    10. Your Rights (GDPR / UK GDPR)

    If you are in the EEA, UK, or Switzerland, you have the right to access, rectify, erase, restrict, or object to processing of your personal data, the right to data portability, and the right to lodge a complaint with your supervisory authority. To exercise these rights, contact us at the address in Section 13 — we respond within one month. If your data was collected on one of our customers' websites, we will refer your request to that customer and assist them in fulfilling it.

    11. Your Rights (California / CCPA-CPRA)

    California residents have the right to know what personal information we collect, to delete it, to correct it, and to opt out of "sale" or "sharing" of personal information. We do not sell personal information and do not share our users' personal information for cross-context behavioral advertising; where we deliver conversion data to ad platforms we do so as a service provider acting on our customers' instructions. You will not be discriminated against for exercising your rights. Submit requests to the contact in Section 13 — we verify and respond within 45 days.

    12. Cookies

    On adsidian.ai we use essential cookies for authentication and session management, and our own first-party Prism analytics (no third-party advertising cookies), which you can decline via the cookie notice. Cookies set by Prism on our customers' websites are described in Section 6 and in the customer's own privacy notice.

    13. Contact

    For privacy questions or to exercise your rights, contact: [email protected]

    14. Changes to This Policy

    We may update this Privacy Policy from time to time. We will notify you of significant changes by email or via an in-app notice. Continued use of Adsidian after changes constitutes acceptance of the updated policy.