DataMind Privacy Policy
Last updated: July 20, 2026
This Privacy Policy describes how Affect Group Inc. ("Affect Group", "we", "us", or "our"), the operator of the DataMind platform, collects, uses, processes, stores, discloses, and protects information when you use:
- our website located at datamind.affectgroup.com and any related DataMind websites, pages, or forms displaying this Privacy Policy (collectively, the "Site"); and
- the DataMind analytics and optimization platform — an AI-assisted service for auditing, analyzing, and generating optimization recommendations for digital advertising accounts (such as Google Ads), together with all related tools, reports, integrations, APIs, and materials (collectively with the Site, the "Services").
Please read this Privacy Policy carefully. By accessing or using the Services, you acknowledge that you have read and understood it. If you do not agree with our practices, please do not use the Services. Capitalized terms not defined here have the meaning given in our Terms of Service, which also govern your use of the Services.
1. Scope, Definitions, and Our Role
This Privacy Policy applies to:
- "Customers" — individuals or businesses that create a DataMind account and use the Services, including on a free or trial basis;
- "Site Visitors" — anyone who visits the Site without an account;
- "Platform Data" — data we access from third-party advertising and analytics platforms (such as Google Ads, Google Analytics 4, Meta Ads, or TikTok Ads) via their official APIs, with the Customer's explicit authorization.
Our role. For account, billing, and usage information, Affect Group acts as a data controller. For Platform Data that a Customer connects to the Services, the Customer is the controller (or is authorized by the account owner to act on their behalf), and Affect Group acts as a data processor — we process that data solely to provide the Services to the Customer, per the Customer's instructions.
This Privacy Policy does not apply to data collected directly by third-party platforms (such as Google, Meta, or TikTok), which is governed by their respective privacy policies.
2. Information We Collect
2.1 Account Information
When you create a DataMind account or communicate with us, we collect:
- your name, email address, and password credentials (passwords are stored in hashed form; we never see or store them in plain text);
- your company or workspace name and any profile details you choose to provide;
- the contents of messages, forms, or support requests you submit to us.
2.2 Advertising Platform Data (via API Access)
When you connect an advertising or analytics account, you authorize DataMind through the platform's official authorization flow (e.g., Google OAuth). With that explicit authorization, we may access and process:
- campaign, ad group / ad set, ad, keyword, and asset metadata and settings;
- performance metrics (e.g., impressions, clicks, cost, CPC, CPM, conversions, conversion value, ROAS, impression share, quality signals);
- search terms and audience/segment reporting made available by the platform;
- account identifiers, currency, time zone, and configuration data;
- for Google authorization, your basic Google profile information (name, email address) used solely to identify the connected account;
- OAuth access and refresh tokens, which we store securely and use only to retrieve the data described above.
We do not collect:
- personal profiles of the individuals who see or interact with your ads (e.g., their names, emails, phone numbers);
- messages, comments, or private communications from any platform;
- payment credentials of your advertising accounts;
- sensitive personal data as defined by applicable laws.
Platform Data is business and advertising performance data. Note that some platform reports (for example, search terms) may incidentally contain text typed by end users; we process such data only as part of the reports the platform provides and only to deliver the Services to you.
Scope of permissions vs. our actual use. Some advertising platforms grant only a single, combined permission level covering both reading and writing. The Google Ads API, for example, offers no read-only permission, so Google's consent screen states that the application may "see, edit, create, and delete" your Google Ads accounts and data, regardless of what the application actually does. DataMind uses this access exclusively to read data: we issue only read queries and never create, modify, pause, or delete anything in your advertising accounts. Every change to your accounts is made by you. Where a platform does offer a read-only permission, we request only that permission (for example, we use the read-only scope for Google Analytics). If you wish to enforce this limitation technically, you may authorize the connection using a platform user account that itself holds read-only access, since our access can never exceed the permissions of the user who authorized it.
2.3 Business Information You Provide
To improve the relevance of audits and recommendations, you may provide business context — such as your business description, goals, target economics (e.g., target CPA or ROAS), budgets, geographies, and constraints (a "Brief"). We process this information solely to generate analyses and recommendations for you.
2.4 Payment and Billing Information
Paid subscriptions are processed by our payment processor, Stripe. Your full payment card details are collected and processed by Stripe directly and are never stored on our servers. We receive and store limited billing information: your subscription plan, billing status, invoices, transaction identifiers, and the last digits / brand of your card as provided by Stripe. Stripe's processing is governed by its own privacy policy.
2.5 Usage and Technical Data
We automatically collect:
- usage events within the Services (e.g., data fetches, audits run, reports generated, features used) — including to measure activity against the limits of your subscription plan and to calculate billing;
- log data (timestamps, API request metadata, error logs);
- device and browser metadata, operating system, and language settings;
- IP address (for security, abuse prevention, and approximate region);
- crash and diagnostic information.
2.6 Cookies and Similar Technologies
We use cookies and similar technologies that are necessary to operate the Services (authentication, session management, security) and to understand aggregate usage of the Site. We do not use third-party advertising or cross-site tracking cookies. Most browsers let you block or delete cookies; if you block essential cookies, parts of the Services may not function.
Some data you enter (such as Brief drafts) may be stored locally in your browser (e.g., IndexedDB / local storage) to preserve your work between sessions. You can clear this at any time via your browser settings.
3. How We Use Information
We use the information described above to:
- Provide the Services — fetch and analyze your Platform Data, compute metrics, run audits, and generate reports and optimization recommendations;
- Operate your account — authentication, workspace management, and customer support;
- Billing and plan enforcement — calculate usage against your plan's limits (e.g., number of connected accounts, data fetches, audits), process subscriptions, prevent abuse of free and trial tiers;
- Communicate with you — service notifications, security alerts, responses to inquiries, and (subject to your preferences) product updates and marketing emails, from which you can opt out at any time;
- Maintain safety and security — detect, prevent, and investigate fraud, abuse, unauthorized access, and violations of our Terms of Service;
- Improve the Services — debug, develop, and improve features, using aggregated or de-identified data wherever feasible;
- Comply with law — meet legal obligations and respond to lawful requests from authorities.
We do not:
- sell or rent your personal information or your Platform Data;
- use your Platform Data for advertising targeting, behavioral profiling of individuals, or any purpose unrelated to providing the Services to you;
- share your data with any third party except as described in Section 6.
4. AI-Assisted Processing
DataMind uses large language models (LLMs) to formulate analyses and recommendations. It is important that you understand how this works:
- What the AI does. Quantitative computations (metrics, statistics, threshold checks) are performed by our own deterministic code. LLMs are used to formulate findings and recommendations in natural language based on those computed results and, where relevant, portions of your Platform Data and Brief.
- AI service providers. For this purpose, we transmit relevant data to enterprise AI providers acting as our sub-processors — currently Anthropic and OpenAI — via their commercial APIs. Under the applicable API terms, these providers do not use data submitted via their APIs to train their models.
- No model training on your data. We do not use your Platform Data, your Brief, or any Google user data to develop, improve, or train generalized artificial intelligence or machine learning models.
- Nature of AI outputs. Analyses and recommendations produced by the Services are automatically generated informational suggestions. They may be incomplete or inaccurate, and they are not professional, financial, or business advice and not a guarantee of any advertising outcome. You are responsible for independently reviewing any recommendation before acting on it. See our Terms of Service for the full disclaimer.
- No automated decision-making with legal effect. The Services do not make automated decisions about individuals that produce legal or similarly significant effects. Any change to your advertising accounts is made by you.
5. Google User Data and Limited Use
DataMind's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, we:
- use Google user data (Google Ads and Google Analytics data, and basic profile information) only to provide and improve the user-facing features of the Services that you have requested;
- do not transfer Google user data to third parties except as necessary to provide those features (e.g., to the sub-processors listed in Section 6), to comply with applicable law, or as part of a merger or acquisition with notice to you;
- do not use Google user data for advertising purposes;
- do not allow humans to read Google user data, except with your explicit permission (e.g., a support request), where necessary for security purposes, to comply with applicable law, or as part of aggregated and anonymized internal operations;
- do not use Google user data to develop, improve, or train generalized AI or machine learning models.
You can revoke DataMind's access to your Google data at any time by disconnecting the integration in the Services or via your Google Account security settings.
6. How We Disclose Information
We disclose information only in the following circumstances:
- Service providers (sub-processors). We use a limited set of vendors that process data on our behalf and under our instructions, strictly to operate the Services. Categories include: cloud hosting and database infrastructure (e.g., Supabase), application hosting, payment processing (Stripe), email delivery, and AI providers (Anthropic, OpenAI) as described in Section 4. All service providers are bound by confidentiality and data protection obligations. A current list of sub-processors is available upon request at hello@affectgroup.com.
- At your direction. For example, when you export a report or ask us to share data with a person you designate.
- Legal compliance. When required by law, regulation, subpoena, court order, or other legal process, or to respond to lawful requests from public authorities.
- Protecting rights and safety. Where necessary to investigate, prevent, or act on suspected fraud, security incidents, violations of our Terms of Service, or threats to the safety of any person, or to establish or defend legal claims.
- Business transfers. If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction; this Privacy Policy will continue to apply, and we will provide notice of any change of controller.
- Aggregated / de-identified data. We may use and disclose aggregated or de-identified information that cannot reasonably identify you or any individual (e.g., anonymous benchmark statistics), for research, analytics, and product development.
We do not sell or share personal information for cross-context behavioral advertising (as those terms are defined under California law) and have not done so in the preceding 12 months.
7. Data Retention and Deletion
- Account information is retained for as long as your account is active and for a reasonable period afterward as needed for legal, accounting, dispute-resolution, and security purposes.
- Platform Data is retained while the relevant integration remains connected, so we can provide historical analyses. When you disconnect an integration, we stop fetching new data and delete or revoke the associated OAuth tokens.
- OAuth tokens are deleted upon disconnection of the integration or deletion of your account.
- Usage and billing records are retained as required for bookkeeping, tax, and legal compliance.
- Deletion. You may request deletion of your account and associated data at any time by contacting hello@affectgroup.com or using the tools available in the Services. Upon a verified request, we will delete or irreversibly anonymize your personal information and Platform Data within a reasonable period, except where retention is required by law. Data held in service-provider backups is purged on those providers' standard backup rotation cycles.
8. Security
We implement appropriate technical and organizational safeguards designed to protect your information, including:
- encrypted data transmission (HTTPS/TLS) and encryption at rest for stored data;
- secure storage of OAuth tokens and credentials;
- role-based access controls; access to Customer data is limited to authorized personnel who need it to perform their duties and who are bound by confidentiality obligations;
- logging, monitoring, and internal access reviews;
- vendor due diligence for all sub-processors.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a data breach affecting your personal information, we will notify affected users and relevant authorities as required by applicable law.
9. International Data Transfers
We are a U.S. company, and our Services are hosted on cloud infrastructure located primarily in the United States. If you access the Services from outside the United States, your information will be transferred to and processed in the United States and other countries where our service providers operate. Where required by applicable law (including the GDPR and UK GDPR), we implement appropriate safeguards for such transfers, such as the European Commission's Standard Contractual Clauses.
10. Your Rights
10.1 All Users
You may access, correct, or update your account information in your account settings, and you may unsubscribe from marketing emails at any time via the link in each email. Transactional emails about your account and billing will still be sent while your account is active.
10.2 European Economic Area, United Kingdom, and Similar Jurisdictions (GDPR)
If you are located in the EEA, UK, or a jurisdiction with similar laws, you have the right to: (i) access the personal data we hold about you; (ii) correct inaccurate data; (iii) request deletion; (iv) receive a portable copy; (v) restrict or object to processing; and (vi) withdraw consent at any time where processing is based on consent, without affecting prior processing. Our legal bases for processing are: performance of a contract (providing the Services), consent (e.g., connecting an advertising integration, marketing emails), legitimate interests (security, fraud prevention, service improvement), and legal obligation. You may lodge a complaint with your local supervisory authority; we would appreciate the chance to address your concerns first at hello@affectgroup.com.
For Platform Data processed on behalf of a Customer, we act as a processor: if you contact us about data controlled by a Customer, we will refer your request to that Customer and support them in responding as required by law.
10.3 California and Other U.S. States
Residents of California and other U.S. states with comprehensive privacy laws have the right to: (i) know what categories of personal information we collect, the sources, purposes, and categories of recipients; (ii) access the specific pieces of personal information we hold; (iii) correct inaccurate information; (iv) delete personal information; and (v) not receive discriminatory treatment for exercising these rights. The categories of personal information we collect and our purposes are described in Sections 2 and 3; recipients are described in Section 6. We do not sell personal information, do not share it for cross-context behavioral advertising, and do not use or disclose sensitive personal information other than to provide the Services. To exercise your rights, contact hello@affectgroup.com; we will verify your identity before responding, and you may use an authorized agent as permitted by law.
11. Children's Privacy
The Services are intended for business use and are not directed to individuals under 18. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us at hello@affectgroup.com and we will promptly delete it.
12. Third-Party Platforms and Links
The Services integrate with third-party platforms (Google LLC, Meta Platforms, Inc., TikTok / ByteDance Ltd., Stripe, Inc., and others) through their official APIs and in compliance with their developer policies, including the Google API Services User Data Policy, Meta Platform Terms and Developer Policies, and TikTok's developer terms. The Site and Services may also contain links to third-party websites. We do not control, and are not responsible for, the privacy practices of third parties; your use of their services is governed by their own policies.
13. Do Not Track
Some browsers transmit "Do Not Track" signals. Because there is no common standard for interpreting these signals, the Services do not currently respond to them. We do not track our users across third-party websites over time.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and post the updated policy on the Site. For material changes, we will provide reasonable advance notice (e.g., by email or an in-product notice) and, where required by applicable law, obtain your consent. Your continued use of the Services after an updated policy takes effect constitutes acceptance of the updated policy.
15. Contact Us
If you have questions about this Privacy Policy or our data practices, or wish to exercise any of your rights, contact us at:
Affect Group Inc.
Email: hello@affectgroup.com
Address: 1401 21st ST, STE R, Sacramento, CA 95811, USA