DataMind Privacy Policy

Last updated: July 20, 2026

This Privacy Policy describes how Affect Group Inc. ("Affect Group", "we", "us", or "our"), the operator of the DataMind platform, collects, uses, processes, stores, discloses, and protects information when you use:

Please read this Privacy Policy carefully. By accessing or using the Services, you acknowledge that you have read and understood it. If you do not agree with our practices, please do not use the Services. Capitalized terms not defined here have the meaning given in our Terms of Service, which also govern your use of the Services.


1. Scope, Definitions, and Our Role

This Privacy Policy applies to:

Our role. For account, billing, and usage information, Affect Group acts as a data controller. For Platform Data that a Customer connects to the Services, the Customer is the controller (or is authorized by the account owner to act on their behalf), and Affect Group acts as a data processor — we process that data solely to provide the Services to the Customer, per the Customer's instructions.

This Privacy Policy does not apply to data collected directly by third-party platforms (such as Google, Meta, or TikTok), which is governed by their respective privacy policies.

2. Information We Collect

2.1 Account Information

When you create a DataMind account or communicate with us, we collect:

2.2 Advertising Platform Data (via API Access)

When you connect an advertising or analytics account, you authorize DataMind through the platform's official authorization flow (e.g., Google OAuth). With that explicit authorization, we may access and process:

We do not collect:

Platform Data is business and advertising performance data. Note that some platform reports (for example, search terms) may incidentally contain text typed by end users; we process such data only as part of the reports the platform provides and only to deliver the Services to you.

Scope of permissions vs. our actual use. Some advertising platforms grant only a single, combined permission level covering both reading and writing. The Google Ads API, for example, offers no read-only permission, so Google's consent screen states that the application may "see, edit, create, and delete" your Google Ads accounts and data, regardless of what the application actually does. DataMind uses this access exclusively to read data: we issue only read queries and never create, modify, pause, or delete anything in your advertising accounts. Every change to your accounts is made by you. Where a platform does offer a read-only permission, we request only that permission (for example, we use the read-only scope for Google Analytics). If you wish to enforce this limitation technically, you may authorize the connection using a platform user account that itself holds read-only access, since our access can never exceed the permissions of the user who authorized it.

2.3 Business Information You Provide

To improve the relevance of audits and recommendations, you may provide business context — such as your business description, goals, target economics (e.g., target CPA or ROAS), budgets, geographies, and constraints (a "Brief"). We process this information solely to generate analyses and recommendations for you.

2.4 Payment and Billing Information

Paid subscriptions are processed by our payment processor, Stripe. Your full payment card details are collected and processed by Stripe directly and are never stored on our servers. We receive and store limited billing information: your subscription plan, billing status, invoices, transaction identifiers, and the last digits / brand of your card as provided by Stripe. Stripe's processing is governed by its own privacy policy.

2.5 Usage and Technical Data

We automatically collect:

2.6 Cookies and Similar Technologies

We use cookies and similar technologies that are necessary to operate the Services (authentication, session management, security) and to understand aggregate usage of the Site. We do not use third-party advertising or cross-site tracking cookies. Most browsers let you block or delete cookies; if you block essential cookies, parts of the Services may not function.

Some data you enter (such as Brief drafts) may be stored locally in your browser (e.g., IndexedDB / local storage) to preserve your work between sessions. You can clear this at any time via your browser settings.

3. How We Use Information

We use the information described above to:

We do not:

4. AI-Assisted Processing

DataMind uses large language models (LLMs) to formulate analyses and recommendations. It is important that you understand how this works:

5. Google User Data and Limited Use

DataMind's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular, we:

You can revoke DataMind's access to your Google data at any time by disconnecting the integration in the Services or via your Google Account security settings.

6. How We Disclose Information

We disclose information only in the following circumstances:

We do not sell or share personal information for cross-context behavioral advertising (as those terms are defined under California law) and have not done so in the preceding 12 months.

7. Data Retention and Deletion

8. Security

We implement appropriate technical and organizational safeguards designed to protect your information, including:

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a data breach affecting your personal information, we will notify affected users and relevant authorities as required by applicable law.

9. International Data Transfers

We are a U.S. company, and our Services are hosted on cloud infrastructure located primarily in the United States. If you access the Services from outside the United States, your information will be transferred to and processed in the United States and other countries where our service providers operate. Where required by applicable law (including the GDPR and UK GDPR), we implement appropriate safeguards for such transfers, such as the European Commission's Standard Contractual Clauses.

10. Your Rights

10.1 All Users

You may access, correct, or update your account information in your account settings, and you may unsubscribe from marketing emails at any time via the link in each email. Transactional emails about your account and billing will still be sent while your account is active.

10.2 European Economic Area, United Kingdom, and Similar Jurisdictions (GDPR)

If you are located in the EEA, UK, or a jurisdiction with similar laws, you have the right to: (i) access the personal data we hold about you; (ii) correct inaccurate data; (iii) request deletion; (iv) receive a portable copy; (v) restrict or object to processing; and (vi) withdraw consent at any time where processing is based on consent, without affecting prior processing. Our legal bases for processing are: performance of a contract (providing the Services), consent (e.g., connecting an advertising integration, marketing emails), legitimate interests (security, fraud prevention, service improvement), and legal obligation. You may lodge a complaint with your local supervisory authority; we would appreciate the chance to address your concerns first at hello@affectgroup.com.

For Platform Data processed on behalf of a Customer, we act as a processor: if you contact us about data controlled by a Customer, we will refer your request to that Customer and support them in responding as required by law.

10.3 California and Other U.S. States

Residents of California and other U.S. states with comprehensive privacy laws have the right to: (i) know what categories of personal information we collect, the sources, purposes, and categories of recipients; (ii) access the specific pieces of personal information we hold; (iii) correct inaccurate information; (iv) delete personal information; and (v) not receive discriminatory treatment for exercising these rights. The categories of personal information we collect and our purposes are described in Sections 2 and 3; recipients are described in Section 6. We do not sell personal information, do not share it for cross-context behavioral advertising, and do not use or disclose sensitive personal information other than to provide the Services. To exercise your rights, contact hello@affectgroup.com; we will verify your identity before responding, and you may use an authorized agent as permitted by law.

11. Children's Privacy

The Services are intended for business use and are not directed to individuals under 18. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us at hello@affectgroup.com and we will promptly delete it.

12. Third-Party Platforms and Links

The Services integrate with third-party platforms (Google LLC, Meta Platforms, Inc., TikTok / ByteDance Ltd., Stripe, Inc., and others) through their official APIs and in compliance with their developer policies, including the Google API Services User Data Policy, Meta Platform Terms and Developer Policies, and TikTok's developer terms. The Site and Services may also contain links to third-party websites. We do not control, and are not responsible for, the privacy practices of third parties; your use of their services is governed by their own policies.

13. Do Not Track

Some browsers transmit "Do Not Track" signals. Because there is no common standard for interpreting these signals, the Services do not currently respond to them. We do not track our users across third-party websites over time.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and post the updated policy on the Site. For material changes, we will provide reasonable advance notice (e.g., by email or an in-product notice) and, where required by applicable law, obtain your consent. Your continued use of the Services after an updated policy takes effect constitutes acceptance of the updated policy.

15. Contact Us

If you have questions about this Privacy Policy or our data practices, or wish to exercise any of your rights, contact us at:

Affect Group Inc. Email: hello@affectgroup.com Address: 1401 21st ST, STE R, Sacramento, CA 95811, USA