← Ensemind

Privacy Policy

Effective date: July 20, 2026 · Ensemind (ensemind.com)

Ensemind ("Ensemind", "we", "us") provides an AI-assisted advertising management platform at ensemind.com (the "Service"). This policy explains what data we collect, why, who we share it with, and the choices you have. It applies to visitors of our website and to customers and their invited users.

1. Data we collect

Account data

Name, email address, hashed password (we never store plaintext passwords), optional passkey (WebAuthn) public keys, role and workspace membership, and session records.

Business & workspace data you provide

Company details, goals and budgets, business context you teach the AI, uploaded planning documents, and preferences you confirm. This data belongs to you.

Connected advertising-platform data

When you connect an ad account (e.g., Meta, Google Ads, TikTok, Microsoft Advertising, LinkedIn, Amazon Ads), we access it only with the credentials and permissions you grant — campaign structures, performance metrics, audiences metadata, creatives metadata, and account settings. Access tokens and API credentials are encrypted at rest (AES-256-GCM). We access these platforms solely to provide the Service to you: importing your reporting data and executing the specific actions you or your workspace approve.

Analytics & business-intelligence sources you connect

Aggregated metrics from sources you configure (e.g., Google Analytics, Search Console, BigQuery, spreadsheets). We store bounded aggregates, not your raw datasets.

Usage & log data

Standard server logs (IP address, browser type, timestamps), audit trails of actions taken in your workspace, and error diagnostics. We use an essential session cookie for sign-in, and a first-party cookie that remembers your cookie choice.

Analytics cookies

We use Google Analytics to understand which pages and features are useful. It sets cookies on your device, and it runs only where you have allowed it: in the EEA, the UK and Switzerland nothing analytics-related loads until you accept, and we honour Global Privacy Control as a refusal everywhere in the world. Your IP address is anonymised, we never send Google your name or email, and Google's advertising signals (ad personalisation and ad user data) stay denied. We run no advertising or remarketing tags. You can change or withdraw your choice at any time from the Cookie preferences link in the site footer.

Payment data

Payments are processed by Stripe. Your full card details never touch our servers; we store only subscription status, plan, and invoice metadata.

2. How we use data

Legal bases where GDPR or similar laws apply: performance of our contract with you; our legitimate interests in securing and improving the Service; consent where required (e.g., connecting a platform is always your explicit action); and compliance with legal obligations.

3. What we never do

4. Who we share data with (subprocessors)

We share data only with service providers that help us operate, each bound by contractual confidentiality and used only for the stated purpose:

We may disclose data if required by law, or in connection with a merger or acquisition (in which case this policy continues to apply until amended with notice).

5. Data retention

We retain workspace data while your account is active. Audit logs are retained for accountability of executed advertising actions. Aggregated, de-identified statistics may be retained for service improvement. Backups roll off on our provider's standard schedule.

6. Data deletion (your rights)

You can request deletion of your account and workspace data at any time — including data obtained from connected platforms such as Meta or Google — in either of these ways:

Where applicable law grants them (e.g., GDPR, CCPA), you also have rights of access, correction, portability, restriction, and objection — exercised via the same email. You may lodge a complaint with your local supervisory authority.

7. Security

TLS in transit; platform credentials and tokens encrypted at rest (AES-256-GCM); passwords hashed with scrypt; optional passkey (WebAuthn) second factor; signed, revocable sessions; deny-by-default authorization; per-workspace isolation; and a durable, hash-chained audit trail for executed advertising actions. No method of transmission or storage is 100% secure, but we treat security as a first-class product feature.

8. International transfers

Our infrastructure providers operate globally (primarily the United States and Europe). Where required, transfers rely on appropriate safeguards such as standard contractual clauses maintained by our subprocessors.

9. Children

The Service is for businesses and is not directed to anyone under 18. We do not knowingly collect data from children.

10. Changes

We may update this policy as the Service evolves. Material changes will be announced in-product or by email, with the effective date above updated. Continued use after the effective date constitutes acceptance.

Questions? Contact us at founder@ensemind.com. · Privacy Policy · Terms of Service