- Introduction
- Definitions
- Information We Collect
- How We Use Information
- Artificial Intelligence & Machine Learning
- Google API Services User Data Policy
- Data Storage and Security
- Data Retention
- Sub-Processors
- Your Privacy Rights
- California Residents (CCPA/CPRA)
- EU and UK Residents
- Children
- Acceptance Records
- Cookies
- Changes to This Policy
- Contact
1. Introduction
This Privacy Policy describes how myAgency ("we," "us," "our") collects, uses, stores, discloses, and protects information when you use the website at meetmyagency.com and the related Google Ads automation platform (the "Service"). It applies to all users of the Service, including customers, affiliates, and prospective users who interact with our marketing pages. This Policy is incorporated into our Terms of Service by reference.
If you have questions about anything in this Policy, contact support@meetmyagency.com.
2. Definitions
The following definitions are used consistently with our Terms of Service, Section 13:
- Customer Data means data you submit to the Service, plus data we receive from your connected Google Ads accounts through OAuth — including campaign, ad group, keyword, search term, ad creative, conversion, and performance data. You own all Customer Data; we process it only to operate the Service for you.
- Service Data means metadata, telemetry, and feedback signals generated by your use of the Service — which recommendations you approve, reject, dismiss, or roll back; configuration choices; navigation patterns; feature usage; error logs; and performance metrics.
- Aggregated Data means data that has been aggregated across multiple customers and de-identified such that it cannot reasonably be linked, directly or indirectly, to you, your business, or any individual.
- Personal Information means information that identifies, relates to, or could reasonably be linked with a particular individual.
3. Information We Collect
We collect the following categories of information:
- Account information. Email address, name, password (stored as a bcrypt hash — we cannot read it), and (if you sign in with Google) your Google account profile picture and unique Google user ID.
- Google Ads data. When you connect a Google Ads account, we access campaign data, ad group structure, keywords, search term reports, ad creative, conversion data, bid information, and related performance metrics through the Google Ads API. We store this data only to provide the Service to you.
- OAuth refresh tokens. The refresh token issued by Google when you authorize access, encrypted at rest using Fernet symmetric authenticated encryption. We never see your Google account password.
- Service Data. Telemetry about your use of the Service: actions taken in the dashboard (approve, reject, roll back, etc.), feature usage, configuration choices, performance metrics, and error logs. See Section 5 for how this is used.
- Billing information. If you subscribe, we store your Stripe customer ID, subscription status, and the last four digits and expiry of your card on file. We never store full credit-card numbers or bank-account details — those live exclusively in Stripe.
- Affiliate information. If you participate in the Affiliate Program: your referral activity (link clicks, signups, conversions), commission and payout history, and milestone progress. Payout processing is handled by Stripe Connect Express; the information you provide to Stripe during Connect onboarding (bank-account details, identity verification documents) is governed by Stripe's Privacy Policy.
- Security data. IP addresses, browser user-agent, and approximate geolocation derived from IP, recorded with login attempts, password changes, OAuth events, and other security-significant events.
- Acceptance records. When you accept our Terms of Service or this Privacy Policy, we record the timestamp, IP address, browser user-agent, and the version of the document accepted. See Section 14.
- Communications. If you email support or use the contact form, we retain the content of those messages.
We do not knowingly collect any other categories of Personal Information.
4. How We Use Information
We use the information we collect to:
- Provide and operate the Service — fetch your Google Ads data, generate recommendations, apply approved changes, render the dashboard, send cycle and digest emails.
- Authenticate you and protect your account against unauthorized access.
- Process subscription payments and affiliate payouts via Stripe.
- Maintain audit logs of recommendations, approvals, and account changes.
- Detect and prevent fraud, abuse, and policy violations — including referral fraud (IP-matching and behavioral analysis) and account abuse.
- Improve the Service and our machine-learning models (see Section 5).
- Communicate with you about the Service — transactional notifications, billing receipts, security alerts, and (only if you have not opted out) the weekly performance digest.
- Comply with legal obligations, respond to lawful requests, and protect our rights and the rights of others.
We do not use your information for cross-context behavioral advertising, do not sell your information, and do not share your information with data brokers.
5. Artificial Intelligence & Machine Learning
The Service uses two different kinds of automated intelligence, and we describe them separately because they treat your data differently.
5.1 Our own machine-learning models
Most of the Service runs on conventional machine-learning models that we build and run on our own servers: our V2 confidence calibration system, our n-gram waste-detection engine, our search-term discovery engine, and our bid curve engine. These are statistical models such as isotonic-regression calibrators, logistic-regression quality classifiers, and robust regression curves. They are not generative AI and they do not produce free-form text.
Service Data and feedback signals. When you approve, reject, or roll back a recommendation, that signal becomes part of Service Data. We use Service Data to operate, maintain, secure, monitor, improve, and develop the Service, including to train, evaluate, and deploy the machine-learning models used in the Service.
5.2 Third-party generative AI
Two features of the Service send data to Anthropic PBC, the provider of the Claude family of large language models, and use the model's response to make a better decision. This happens at the moment the feature runs. Anthropic is listed as a sub-processor in Section 9.
- Website context extraction. When we crawl your advertised website (see Section 3), we send the text of those public pages to Anthropic to work out what services you actually offer, the vocabulary your industry uses, and which industry you are in. We use the result so the engine does not treat a service you genuinely sell as irrelevant.
- Non-English search term review. Our waste-detection engine sometimes flags a search term it does not recognize. Before we act on that, if the term looks non-English we send the flagged phrase, the Google Ads search queries that produced it, and a list of your business's own keywords to Anthropic, and ask whether the phrase is actually relevant to your business. This exists to protect you: it stops the engine from blocking a legitimate customer searching for your service in Spanish, Portuguese, or French. The answer can only ever spare a keyword from being blocked, never cause one to be blocked.
What this means for your data. We want to be precise about the boundary here:
- We send data to the model to get an answer back. We do not send it so that anyone can train on it.
- Anthropic is contractually prohibited from training its models on the data we send. Under Anthropic's Commercial Terms of Service, the content we submit is our confidential information, and Anthropic may not train models on it.
- We do not train generative-AI foundation models or large language models on Customer Data, and we will not do so without your separate written consent.
- No human at Anthropic or at myAgency reviews this data as part of the feature. It is an automated request and an automated response.
- We cache the result of the non-English review so we do not re-send the same phrase repeatedly. The cache holds the phrase and the verdict, and is deleted when your account is deleted.
- Both features fail safe. If the model is unavailable or returns something we cannot use, the engine falls back to its ordinary behavior rather than guessing.
- You can opt out. Email support@meetmyagency.com and we will disable both features on your account. The engine will keep working; it will just be less good at recognizing your services and at sparing non-English searches.
Section 6 explains how this is consistent with the commitments we make to Google about data received from the Google Ads API.
5.3 Aggregated Data
We may use Aggregated Data for any lawful purpose, including benchmarking, analytics, research, marketing materials, industry reports, and model training. We will not attempt to re-identify Aggregated Data, and we contractually require any third party that receives Aggregated Data from us to be similarly bound. This commitment is intended to satisfy the de-identification standards in California Civil Code §1798.140 and similar state-law provisions, so that Aggregated Data falls outside the scope of those laws.
5.4 Recommendations are not automated decisions about consumers
Recommendations generated by the Service relate to your management of advertising campaigns. They are not "significant decisions" about consumers within the meaning of California CPRA Automated Decision-making Technology regulations, and they are not automated decisions producing legal or similarly significant effects on natural persons under Article 22 of the GDPR.
Recommendations are also probabilistic. They can be wrong. Where you have enabled automatic application for an automation type, the Service will apply a change to your Google Ads account without asking you first, subject to the confidence thresholds described in your dashboard. You can review every change in the activity log, roll most of them back, and switch any automation to approve-and-deny at any time in Settings.
6. Google API Services User Data Policy
myAgency's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only access Google user data necessary to provide and improve user-facing features of the Service.
- We do not sell Google user data.
- We do not use Google user data for advertising or for retargeting.
- We do not allow humans to read Google user data except (a) with your explicit consent, (b) as necessary for security purposes, (c) to comply with applicable law, or (d) where the data has been aggregated and anonymized for internal operations consistent with the User Data Policy.
When a person at myAgency can see your account
We want to be straight about the exception above rather than leave it abstract. Our support tooling lets an administrator open your dashboard as you, so we can reproduce a problem you have reported or investigate a fault. This is how we debug, and it falls within the exception for security and troubleshooting purposes.
- Access is limited to administrators. It is read-only by default, and switching a session to one that can make changes is a separate, deliberate step.
- Every time such a session starts, ends, or is escalated, we write a security event recording who did it and when. Those records are retained for 90 days as described in Section 8.
- We use it to operate and support the Service. We do not use it to browse your data for any other purpose.
How this applies to our use of AI
Section 5.2 describes two features that send data to Anthropic, our AI sub-processor. One of them, the non-English search term review, sends Google Ads search queries, which are data received from a Google API. We treat that transfer as governed by the commitments above, and we hold it inside them:
- The transfer happens only to provide a feature you can see and use in the Service, and only for accounts where the feature is active. It is not a bulk export.
- Anthropic acts as our service provider on our instructions. It may not use the data for its own purposes and, under its Commercial Terms of Service, may not train its models on it.
- The data is not sold, and is never used for advertising or retargeting.
- No human reads it. The request and the response are automated.
- By accepting our Terms of Service, which incorporate this Policy, you consent to this processing. You may withdraw that consent for your account at any time by emailing support@meetmyagency.com, and we will disable the feature without otherwise affecting your Service.
If Google notifies us that this processing is inconsistent with any policy applicable to our API access, we will disable it rather than continue.
You can review and revoke myAgency's access to your Google account at any time at myaccount.google.com/permissions.
7. Data Storage and Security
Your data is stored on access-controlled servers operated by DigitalOcean in the United States. We use industry-standard administrative, technical, and physical safeguards to protect it, including:
- TLS 1.2+ encryption for all data in transit.
- Fernet symmetric authenticated encryption (AES-128-CBC + HMAC-SHA256) for OAuth refresh tokens at rest.
- Bcrypt password hashing.
- HTTP-only, Secure, SameSite=Lax cookies for authentication; JWT-based session tokens with version-based revocation.
- PostgreSQL instance not exposed to the public internet — accessible only from the application server.
- Rate limiting and CSRF protection at the application layer.
We comply with the New York Stop Hacks and Improve Electronic Data Security Act (SHIELD Act, N.Y. Gen. Bus. Law §899-bb), including maintaining a designated security coordinator, conducting risk assessments, contractually obligating vendors to maintain appropriate safeguards, training employees on security practices, and adhering to a written breach-notification procedure that targets disclosure within 30 days of discovery.
No system is perfectly secure. We disclaim any warranty of absolute security in our Terms of Service, Section 17. If we become aware of a breach affecting your Personal Information, we will notify you as required by applicable law.
8. Data Retention
We retain different categories of data for different periods, generally aligned with the purposes for which we collected the data:
- Customer Data and account information: retained for the duration of your account. On account deletion or termination, deleted within 30 days, with residual copies cleared from backup systems within 90 days, except where retention is required by law.
- Recommendations: expired recommendations are automatically purged after 7 days. Applied and failed recommendations are purged after 30 days. Recommendations you rejected or rolled back are kept for as long as your account is open, because they are how the engine remembers not to suggest the same thing to you again. They are deleted when your account is deleted.
- Search term data from the Google Ads API: 30 days, then automatically deleted. Thirty days is the minimum retention Google's Required Minimum Functionality policy expects of a tool like ours.
- Action log (the audit trail of changes applied to your Google Ads account): 90 days, then automatically deleted. We keep this longer than other operational data so there is a durable record of what the Service did on your behalf.
- Security event logs (login attempts, IP addresses, geolocation): 90 days, then automatically deleted.
- AI review cache (Section 5.2): the flagged phrase and the model's verdict, kept while your account is open so we do not re-send the same phrase, and deleted with your account.
- Billing records: retained for a period consistent with tax and accounting obligations (generally 7 years), independent of account status.
- Acceptance records for Terms of Service and Privacy Policy: retained for at least three (3) years following the conclusion of the account relationship, per our commitment in Terms of Service, Section 22.
- Affiliate records: referral activity, commission, and payout history are retained for the duration of the Affiliate's account and a reasonable period after termination for tax and legal compliance.
- Aggregated Data: retained indefinitely as it is no longer linked to any individual or account.
You may request deletion at any time — see Section 10.
9. Sub-Processors
We use the following service providers ("sub-processors") to operate the Service. Each is engaged under a data processing agreement that contractually obligates them to maintain appropriate safeguards and to process Personal Information only as needed to provide their service.
| Sub-processor | Purpose | Data category | Location |
|---|---|---|---|
| DigitalOcean | Cloud hosting, PostgreSQL database, object storage for backups | All data at rest | United States |
| Stripe | Subscription payment processing, customer-balance credits, Affiliate Program Connect payouts | Billing identifiers, payment-method metadata; for Affiliates, identity verification | United States |
| Google (Google Ads API) | Source of Customer Data; destination for approved campaign mutations | OAuth tokens, account identifiers | United States / Global |
| Anthropic PBC | Generative AI for the two features described in Section 5.2: website context extraction and non-English search term review | Text of your public website pages; flagged search terms and the Google Ads search queries behind them; your business keyword vocabulary. Contractually may not be used to train Anthropic's models. | United States |
| Google (Analytics 4 / Tag Manager) | Anonymous traffic analytics on our public marketing pages only. Not present on the signed-in application. | Pseudonymous usage and device data from marketing pages | United States / Global |
| Resend | Transactional and digest email delivery | Email address, message content | United States |
| MaxMind (GeoLite2) | IP-to-approximate-location lookup for security event logging | IP addresses (processed locally, not transmitted) | Local database; no live data sent |
We will notify you by email at the address associated with your account, or by posting an updated version of this Policy, before adding or replacing a sub-processor that materially affects how Personal Information is processed. We will not add sub-processors that do not satisfy our security and privacy standards.
10. Your Privacy Rights
Regardless of where you live, you may:
- Access: request a copy of the Personal Information we hold about you.
- Correct: request correction of inaccurate Personal Information.
- Delete: request deletion of your account and associated Personal Information. You can also delete your own account at any time from Settings → Delete Account.
- Port: request a copy of your data in a structured, commonly-used, machine-readable format.
- Object or restrict: object to or ask us to restrict certain processing.
- Revoke Google API access: at any time, at myaccount.google.com/permissions.
To exercise any of these rights, email support@meetmyagency.com from the address associated with your account. We will respond within 45 days. We may request additional information to verify your identity before fulfilling a request, in order to protect against unauthorized disclosure.
We will not discriminate against you for exercising any of these rights.
11. California Residents (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), gives you the following specific rights:
- Right to know. Request disclosure of the categories of Personal Information we collected, the sources, the purposes, and the categories of third parties with whom we shared it.
- Right to access. Request a copy of the specific pieces of Personal Information we hold about you.
- Right to delete. Request that we delete the Personal Information we collected from you, subject to applicable exceptions.
- Right to correct. Request that we correct inaccurate Personal Information.
- Right to limit use of sensitive personal information. We do not use sensitive personal information for any purpose other than what is necessary to provide the Service.
- Right to opt out of sale or sharing. We do not sell Personal Information and we do not share Personal Information for cross-context behavioral advertising. No opt-out is necessary because there is nothing to opt out of.
- Right of non-discrimination. We will not deny service, charge different prices, or provide a different quality of service because you exercised any of these rights.
Categories of Personal Information collected (last 12 months)
Identifiers (name, email, IP address, Google user ID); commercial information (subscription status, billing identifiers, transaction history); internet/network activity (usage of the Service, dashboard navigation, recommendation approval/rejection); geolocation (approximate, from IP); inferences drawn from the above (recommendation-quality and confidence-calibration scores).
We do not collect biometric information, precise geolocation, race or ethnicity, religious beliefs, philosophical beliefs, union membership, sexual orientation, gender identity, health or genetic information, or any other category of sensitive personal information.
How to submit a request
Email support@meetmyagency.com with subject line "CCPA REQUEST". We will respond within 45 days. You may also designate an authorized agent to make a request on your behalf — the agent must provide written authorization, and we may still contact you to verify identity.
If you believe we have not adequately responded to your request, you may contact the California Attorney General at oag.ca.gov.
12. EU and UK Residents
The Service is offered only to United States-based businesses and U.S. residents. We do not target users in the European Economic Area, the United Kingdom, or Switzerland, and our Terms of Service, Section 3 require you to represent that you are not located in those regions. If you nonetheless access the Service from one of those regions, you do so at your own initiative and we make no representations regarding compliance with GDPR, UK GDPR, the EU-U.S. Data Privacy Framework, or other regional data-protection laws. If you believe you have submitted Personal Information to us as an EU, UK, or Swiss resident, email support@meetmyagency.com and we will delete it.
13. Children
The Service is not directed to, and we do not knowingly collect Personal Information from, children under 18. If you believe a child has submitted Personal Information to us, email support@meetmyagency.com and we will delete it.
14. Acceptance Records
We retain a record of each user's acceptance of the Terms of Service and this Privacy Policy, including the version accepted, the timestamp of acceptance, and the IP address and browser user-agent from which acceptance was made. We use these records to demonstrate that you agreed to the version of our policies in effect at the relevant time — including the binding arbitration clause in Terms of Service, Section 19. These records are retained for at least three (3) years after the conclusion of your account relationship.
15. Cookies
Cookies set by the application
These are set on app.meetmyagency.com and are strictly necessary to operate the Service:
| Name | Purpose | Duration | Attributes |
|---|---|---|---|
access_token | Authentication. Keeps you logged in. | 24 hours | HttpOnly, Secure, SameSite=Lax |
oauth_state | CSRF protection during Google OAuth sign-in | 5 minutes | HttpOnly, Secure, SameSite=Lax |
oauth_scopes | Records which permissions were requested, so the sign-in can be completed correctly | 5 minutes | HttpOnly, Secure, SameSite=Lax |
affiliate_intent | Identifies the affiliate signup flow during OAuth | 5 minutes | HttpOnly, Secure, SameSite=Lax |
audit_intent | Identifies the free audit flow during OAuth | 5 minutes | HttpOnly, Secure, SameSite=Lax |
consent_retry | Prevents an infinite loop when Google needs to ask for your consent a second time | 5 minutes | HttpOnly, Secure, SameSite=Lax |
mya_attribution | Remembers which link or campaign brought you to us, so signups are attributed correctly. First-touch only; never overwritten. | 30 days | Secure, SameSite=Lax. Readable by our own scripts. |
We do not use tracking, analytics, or advertising cookies on the signed-in application.
Cookies and analytics on our marketing pages
Our public marketing pages at meetmyagency.com load Google Tag Manager and Google Analytics 4. These set their own cookies, typically named _ga and _ga_<container>, which Google uses to distinguish one visitor from another and to measure traffic. We use this only for aggregate traffic analytics. We do not use it to build advertising audiences, we do not use it for retargeting, and it is not connected to your myAgency account or to any Google Ads data.
The same marketing pages store a first-touch attribution record in your browser's local storage under the key mya_attribution. It holds the campaign parameters from the URL you arrived on. It is written once and not overwritten.
You can block or delete these at any time in your browser settings, or opt out of Google Analytics with Google's opt-out add-on. Blocking them does not affect the Service.
Global Privacy Control. We do not sell or share Personal Information as those terms are defined under state privacy law, so there is no sale or sharing for a GPC signal to opt you out of. We honor GPC signals as an opt-out request in any case.
16. Changes to This Policy
We may update this Privacy Policy from time to time. If we make a change that materially affects how we collect, use, or share your Personal Information, we will provide at least thirty (30) days' advance notice by email to your account address and by posting an updated version on this page. Non-material changes (clarifications, typographical fixes, formatting) are effective on posting. The "Last Updated" date at the top of this page reflects the most recent change.
17. Contact
If you have questions about this Privacy Policy, or to exercise any of the rights described above, contact us at support@meetmyagency.com. For California-specific requests, use subject line "CCPA REQUEST".
myAgency operates from New York, United States.
Connect Google Ads