Ensemind ("Ensemind", "we", "us") provides an AI-assisted advertising management platform at ensemind.com (the "Service"). This policy explains what data we collect, why, who we share it with, and the choices you have. It applies to visitors of our website and to customers and their invited users.
Name, email address, hashed password (we never store plaintext passwords), optional passkey (WebAuthn) public keys, role and workspace membership, and session records.
Company details, goals and budgets, business context you teach the AI, uploaded planning documents, and preferences you confirm. This data belongs to you.
When you connect an ad account (e.g., Meta, Google Ads, TikTok, Microsoft Advertising, LinkedIn, Amazon Ads), we access it only with the credentials and permissions you grant — campaign structures, performance metrics, audiences metadata, creatives metadata, and account settings. Access tokens and API credentials are encrypted at rest (AES-256-GCM). We access these platforms solely to provide the Service to you: importing your reporting data and executing the specific actions you or your workspace approve.
Aggregated metrics from sources you configure (e.g., Google Analytics, Search Console, BigQuery, spreadsheets). We store bounded aggregates, not your raw datasets.
Standard server logs (IP address, browser type, timestamps), audit trails of actions taken in your workspace, and error diagnostics. We use an essential session cookie for sign-in, and a first-party cookie that remembers your cookie choice.
We use Google Analytics to understand which pages and features are useful. It sets cookies on your device, and it runs only where you have allowed it: in the EEA, the UK and Switzerland nothing analytics-related loads until you accept, and we honour Global Privacy Control as a refusal everywhere in the world. Your IP address is anonymised, we never send Google your name or email, and Google's advertising signals (ad personalisation and ad user data) stay denied. We run no advertising or remarketing tags. You can change or withdraw your choice at any time from the Cookie preferences link in the site footer.
Payments are processed by Stripe. Your full card details never touch our servers; we store only subscription status, plan, and invoice metadata.
Legal bases where GDPR or similar laws apply: performance of our contract with you; our legitimate interests in securing and improving the Service; consent where required (e.g., connecting a platform is always your explicit action); and compliance with legal obligations.
We share data only with service providers that help us operate, each bound by contractual confidentiality and used only for the stated purpose:
We may disclose data if required by law, or in connection with a merger or acquisition (in which case this policy continues to apply until amended with notice).
We retain workspace data while your account is active. Audit logs are retained for accountability of executed advertising actions. Aggregated, de-identified statistics may be retained for service improvement. Backups roll off on our provider's standard schedule.
You can request deletion of your account and workspace data at any time — including data obtained from connected platforms such as Meta or Google — in either of these ways:
Where applicable law grants them (e.g., GDPR, CCPA), you also have rights of access, correction, portability, restriction, and objection — exercised via the same email. You may lodge a complaint with your local supervisory authority.
TLS in transit; platform credentials and tokens encrypted at rest (AES-256-GCM); passwords hashed with scrypt; optional passkey (WebAuthn) second factor; signed, revocable sessions; deny-by-default authorization; per-workspace isolation; and a durable, hash-chained audit trail for executed advertising actions. No method of transmission or storage is 100% secure, but we treat security as a first-class product feature.
Our infrastructure providers operate globally (primarily the United States and Europe). Where required, transfers rely on appropriate safeguards such as standard contractual clauses maintained by our subprocessors.
The Service is for businesses and is not directed to anyone under 18. We do not knowingly collect data from children.
We may update this policy as the Service evolves. Material changes will be announced in-product or by email, with the effective date above updated. Continued use after the effective date constitutes acceptance.