AI92 is live - our global soft launch is on: the full platform is open worldwide for the first 30 days.
LEGAL

Privacy Policy

Last updated: April 2026

AI92 is represented by KOLOXO WEST AFRICA LTD.
Registered address: 58–60, Medife House, Broad Street, Central Business District, Marina, Lagos State, Nigeria
Office address: Plot 274 Ajose Adeogun Street, Victoria Island, Lagos, Lagos 101241, Nigeria.

Introduction

Applies to: All Customers

This Privacy Policy explains how KOLOXO WEST AFRICA LTD ("we," "us," or "our") collects, uses, discloses, and protects your personal information when you use our website, platform, and services.

We are committed to protecting your privacy and handling your data in an open and transparent manner. This policy applies to all users of our services, including website visitors, prospects, and platform customers.

By using our services, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our services.

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.

Information We Collect

Applies to: All Customers

We collect different types of personal information depending on how you interact with our services:

Website Visitors: When you visit our website, we automatically collect certain information about your device, including information about your web browser, IP address, time zone, and some of the cookies installed on your device. We also collect information about individual web pages or products that you view, what websites or search terms referred you to the site, and how you interact with the site.

Prospects and Marketing Contacts: If you provide your professional email address or contact information through our website forms, newsletter subscriptions, or marketing materials, we collect your name, email address, company name, job title, and any other information you voluntarily provide.

Platform Customers: When you sign up for our platform, we collect additional information including your full name, business address, billing address, country of residence or business establishment, payment information (processed through third-party payment processors), and tax identification numbers (VAT ID, GST number, or other applicable tax IDs) as required for tax compliance in your jurisdiction.

Customer Data: Our platform is designed to help businesses with customer acquisition, retention, and revenue optimization. When you use our services, you may input or our systems may collect:

- Contact information of your prospects and customers

- Marketing campaign data and performance metrics

- Business analytics and engagement data

- Sales and revenue data for True CAC (Customer Acquisition Cost) calculation

- Cloud service consumption data when using our Cloud Services module

Usage Data: We automatically collect information about how you access and use our platform, including access times, pages viewed, features used, your IP address, browser type, device information, and referring website addresses.

Cookies and Tracking Technologies: We use cookies, web beacons, and similar tracking technologies to collect information about your browsing activities. For more information, see our "Third-Party Tracking and Cookies" section.

Communication Data: We collect data from correspondence you send to us, including emails, support tickets, chat messages, and feedback forms.

Social Media Platform Data: When you authorize AI92 to connect with your accounts on supported social media platforms (Facebook, Instagram, Threads, LinkedIn, TikTok, Pinterest, Snapchat, Reddit, YouTube, and Google Ads), we receive information from those platforms through their official APIs. The specific data varies by platform and by the permissions (scopes) you grant, but may include: your platform user ID, display name, profile picture, email address on file, the list of pages, accounts, channels, or ad accounts you manage, the posts, videos, pins, or other content you have created or scheduled through AI92, engagement metrics (impressions, clicks, reactions, comments, watch time), audience demographics (when expressly granted), and ad performance data. AI92 only requests the scopes strictly required to deliver the feature you activate, and you can revoke access at any time from within each platform's settings. See the 'Social Media Platform Integrations' section below for platform-by-platform detail.

Tax and Compliance Data: As a global business operating in multiple jurisdictions, we collect and process tax-related information including VAT/GST registration numbers, tax residency information, and billing country data to determine, calculate, collect, and remit applicable transaction taxes.

LTD (Long-Term Data) Analytics: Our platform uses LTD analytics to maintain a Single Source of Truth (SSOT) for business metrics. This includes historical performance data, campaign effectiveness over time, and longitudinal customer behavior patterns.

Cloud Infrastructure Data: When using our Cloud Services module, we collect data about your cloud resource consumption, configuration settings, performance metrics, and billing data across multiple cloud providers through our Multi-Cloud Hub-and-Spoke architecture.

Payment Data: While we do not directly store credit card numbers or bank account details, we collect transaction identifiers, payment status, billing amounts, and payment method types (e.g., credit card brand) to maintain accurate billing records and calculate taxes.

We collect this information through various means including directly from you, automatically through your use of our services, and from third-party sources such as payment processors, tax authorities, and public business databases.

API Services - What We Process

Applies to: API Services

When you use the AI92 API Services, in addition to the categories of Information We Collect described above, AI92 processes the following API-specific data categories.

API request logs. Each API request you make is logged with the following fields: timestamp, request id, trace id, endpoint path, HTTP method, status code, response time, credits consumed, your account id, the originating IP address, and the user-agent string. We retain this log for ninety (90) days for the public log surface visible in your dashboard, and for thirteen (13) months for the internal audit trail used for forensic review and fraud detection.

Webhook delivery logs. When you register webhooks, we log every delivery attempt with the following fields: timestamp, your endpoint URL (the host name is logged in full; query parameters are scrubbed before storage), event type, attempt number, the HTTP status code received from your endpoint, response body (truncated to 200 bytes for diagnostic purposes), and total round-trip latency. We retain webhook delivery logs for ninety (90) days.

OAuth application metadata. When you register an OAuth application, we store the client id, a hash of the client secret (the cleartext secret is never stored after issuance), the application name, description, redirect URIs, requested scopes, and identifying information about the registering account.

OAuth token grants. When an end user grants your OAuth application access to their AI92 account, we record the token id, the granting user id (we do not record the user's content), the granted scopes, the granted-at timestamp, the last-used-at timestamp, and the application's client id.

Audit log. Every administrative action on your account - such as a manual balance adjustment by AI92 support, an account suspension, or an OAuth application suspension - is recorded in an append-only audit log with the action, the actor (AI92 employee identity), the timestamp, the reason, and the diff of values before and after the action. We retain the audit log for seven (7) years per AI92's SOC 2 control framework.

Credit ledger. Every credit purchase, consumption event, subscription grant, refund, and adjustment is recorded in the credit ledger with the timestamp, type, amount, your account id, the related Stripe transaction reference (if any), and the resulting balance. We retain the credit ledger indefinitely as required by tax-record obligations.

Identification of natural persons in API payloads. Where API request payloads contain personal data of natural persons (for example, the e-mail address of a contact you are seeking to enrich, or the location id of a Google Business Profile you manage), that data is processed strictly to deliver the requested service. We do not link such data to your account beyond the request log, and we do not use it to build profiles of those natural persons. Where applicable, the relationship between you and those natural persons is governed by the AI92 Data Processing Addendum.

How We Use Your Information

Applies to: All Customers

We use the information we collect for various purposes, including:

Service Delivery: To provide, maintain, and improve our platform services; to process transactions and manage billing; to calculate, collect, and remit applicable transaction taxes based on your billing country and tax jurisdiction; and to provide customer support and respond to your inquiries.

LTD Analytics and SSOT: Our Long-Term Data (LTD) system maintains a comprehensive Single Source of Truth (SSOT) for your business metrics. We use this data to provide accurate historical reporting, track long-term campaign performance, calculate lifetime customer value, and identify trends and patterns that inform business decisions.

True CAC Calculation: We process sales, marketing, and customer data to calculate True Customer Acquisition Cost (True CAC), which includes all costs associated with acquiring a customer over time. This calculation helps you understand the actual cost-effectiveness of your marketing and sales efforts.

Account Management: To manage your account, authenticate your identity, communicate with you about your account and services, and notify you about changes to our terms or policies.

Marketing and Communications: To send you marketing communications about products, services, and promotions that may interest you (you can opt out at any time); to conduct surveys and market research; and to personalize your experience and deliver targeted content.

Analytics and Improvement: To understand how our services are used; to develop new features and functionality; to conduct research and analysis to improve our services; and to optimize user experience and platform performance.

Security and Fraud Prevention: To detect, prevent, and respond to fraud, unauthorized access, and other illegal activities; to enforce our terms of service and protect our rights; and to comply with legal obligations and respond to lawful requests.

Tax Compliance: We use billing country, business address, and tax identification information to determine which taxes apply to your transactions (VAT, GST, sales tax, or other transaction taxes), calculate the correct tax amounts based on jurisdiction-specific rates and rules, collect taxes as part of your invoices, and remit collected taxes to the appropriate tax authorities.

Financial Record-Keeping: We maintain detailed transaction records, including billing information, payment data, and tax documentation, to comply with accounting standards, prepare for audits, and meet statutory record retention requirements in various jurisdictions.

Multi-Cloud Operations: We use infrastructure and performance data from our Multi-Cloud Hub-and-Spoke architecture (18 endpoints globally) to optimize service delivery, ensure data residency compliance, monitor system health and security, and provide redundancy and disaster recovery capabilities.

Compliance and Legal: To comply with applicable laws, regulations, and legal processes; to enforce our agreements and policies; to protect the rights, property, and safety of our company, users, and the public; and to respond to requests from government authorities and law enforcement.

Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email and/or prominent notice on our website of any change in ownership or uses of your personal information.

Customer Retention Analytics: We analyze usage patterns, engagement metrics, and platform adoption to help you optimize customer retention strategies, identify at-risk customers, and improve customer lifetime value.

Cloud Cost Optimization: When you use our Cloud Services module, we analyze your cloud resource consumption and spending patterns across multiple providers to identify cost-saving opportunities and optimize resource allocation.

We do not sell your personal data to third parties. We may share anonymized or aggregated data that cannot be used to identify you for research, analytics, or marketing purposes.

Information Sharing and Disclosure

Applies to: All Customers

We may share your personal information in the following circumstances:

Service Providers: We share data with third-party vendors who perform services on our behalf, including payment processors (Stripe, PayPal), cloud infrastructure providers (AWS, Google Cloud, Azure), email service providers, analytics providers (Google Analytics), customer support tools, and tax calculation and compliance services. These service providers are contractually obligated to use your data only for the purposes we specify and to protect your data.

AI and Machine Learning Sub-processors: We use the following named third-party artificial-intelligence sub-processors to power specific Platform features. Each sub-processor receives only the minimum input required to deliver the feature and operates under a contractual Data Processing Agreement that prohibits the use of Customer Data to train, fine-tune, or otherwise improve the sub-processor's general-purpose models. (i) Google Cloud - Vertex AI - used to draft and refine marketing content, produce analytical summaries from your campaign data, translate platform content into the languages we support, and automatically classify news and content items. Operates under Google's Cloud Data Processing and Security Terms and the Vertex AI Generative AI Service Terms, which prohibit Google from using your data to train its foundation models. (ii) Perigon, Inc. (United States) - used to retrieve and enrich third-party news articles surfaced inside our Reputation module. We send Perigon only search parameters (such as a brand keyword); no personally identifiable Customer Data is sent. (iii) xAI Corp. (United States) - used to discover public trends and viral content topics that inform our market-intelligence features. We send xAI only a category or search keyword; no personally identifiable Customer Data is sent. We will update this list whenever we add or remove an AI sub-processor; the current version is always available on this page. If you would like to receive prior written notice of any change to this list, please contact [email protected].

Social Media Platforms (as data processors on your behalf): When you schedule or publish content, retrieve analytics, or manage ad campaigns through AI92, we transmit that content and related metadata to the relevant social media platform's official API (Meta Graph API, LinkedIn Marketing API, TikTok for Business API, Pinterest API, Snap Marketing API, Reddit API, YouTube Data API v3, Google Ads API). The platform then stores and processes that data under its own terms and privacy policy. AI92 acts only as a conduit between you and those platforms for the content and actions you explicitly authorize.

Business Transfers: If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have.

Legal Requirements: We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., court orders, subpoenas, tax authorities, or law enforcement agencies).

Tax Authorities: We share billing information, transaction amounts, and tax collection data with relevant tax authorities in jurisdictions where we are required to collect and remit taxes. This includes VAT/GST registration information, transaction records, and periodic tax filings.

Protection of Rights: We may disclose information to enforce our rights, protect our property or safety, protect the rights, property, or safety of others, investigate fraud, or respond to government requests.

With Your Consent: We may share your information for any other purpose with your explicit consent.

Cost Attribution and Aggregation

Applies to: API Services

AI92 operates an internal cost-aggregation system (the AI92 Cost Aggregator) which tracks the underlying vendor cost of each API request you make. The Cost Aggregator processes the following data fields per request: the operation name (for example, 'seo.audit'), your account id, an integer count of credits consumed, a numeric vendor cost in United States dollars, a trace id, and an optional categorical 'extra' field naming the vendor (such as Vertex AI, xAI, DataForSEO, SerpAPI, Hunter, or Twilio) and the model or product tier used (such as 'imagen-3.0-generate' or 'gemini-2.5-flash').

The content of your requests is never shared with the Cost Aggregator. The Aggregator processes only the metadata described above. AI92 uses this aggregated cost data for financial reporting, unit-economics analysis, capacity planning, and to make pricing decisions. We may share aggregated, anonymised cost data with potential investors under standard confidentiality terms, with auditors under non-disclosure obligations, and with the vendors whose costs we aggregate for the purpose of benchmarking against published rates.

AI92 does not sell cost data. AI92 does not share cost data that identifies individual customers with third parties for marketing purposes.

Social Media Platform Integrations

Applies to: Platform Services

AI92 integrates with third-party social media and advertising platforms through their official APIs. These integrations are optional and only take effect after you explicitly authorize each platform through an OAuth consent screen. This section explains, for each supported platform, what data we access, how we use it, and how you can revoke access.

General principles applicable to all platforms:

- We request only the minimum permissions (scopes) required to deliver the feature you activated.

- OAuth access tokens are stored encrypted at rest in Google Cloud Secret Manager within our ai92-shared GCP project, and are never logged, shared, or exposed to third parties.

- We do not sell, rent, or trade data obtained from any social media platform.

- We do not use data obtained from any social media platform to build advertising audiences outside of the platform where the data originated.

- Mandatory human approval gate: no content is ever published automatically. Every piece of content generated by AI92's creative engine is placed in the brand owner's own My Activity approval queue inside the AI92 dashboard, and is published to a connected platform only after the brand owner reviews it and explicitly approves it. You can revoke any platform connection at any moment, and you stay in control of every post before it goes live.

- You can revoke AI92's access to any connected platform at any time. Revocation takes effect immediately and we delete the associated tokens within 24 hours.

- If you delete your AI92 account, we revoke and delete all platform tokens and related cached data within 30 days, subject only to retention required by law (e.g., billing records).

YouTube (Google Data API v3):

AI92's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In addition, AI92 accesses YouTube API Services, and by connecting your YouTube account you also agree to the YouTube Terms of Service and acknowledge the Google Privacy Policy.

- Scopes requested: `youtube.readonly` (read channel and video metadata), `youtube` (manage uploads and playlists), `youtube.upload` (publish videos on your behalf), `youtube.force-ssl` (secure channel management), `yt-analytics.readonly` (read channel analytics for reporting).

- Data received: channel ID, channel title, channel description, video IDs, titles, descriptions, upload status, thumbnails, aggregated analytics (views, watch time, subscriber delta, demographic breakdowns when available), comment identifiers on content you own.

- How it is used: to display your channel inside AI92, schedule and upload videos, show performance reporting, and enable AI-driven recommendations for optimization. YouTube data is never used to target ads, never sold, and never shared with any party other than Google itself as the API provider.

- How it is stored: channel metadata and analytics snapshots are stored in our managed database and object-storage tiers for the duration of your subscription. OAuth tokens are stored encrypted in GCP Secret Manager (ai92-shared project).

- Limited Use commitment: AI92 complies with the YouTube API Services Limited Use requirements. We do not transfer YouTube data to third parties, we do not use YouTube data for serving ads, we do not allow humans to read YouTube data except (i) with your explicit consent, (ii) as necessary for security purposes, (iii) to comply with applicable law, or (iv) where the data is aggregated and used for internal operations.

- How to revoke: visit https://myaccount.google.com/permissions and remove AI92 from the list of connected apps. You may also request deletion of all stored YouTube data by emailing [email protected] from the address associated with your AI92 account.

Google Ads:

- Scopes requested: Google Ads API read/write on the customer accounts you authorize (linked via your Google Ads Manager Account).

- Data received: campaign, ad group, ad, keyword and asset structures; performance metrics (impressions, clicks, conversions, cost); audience and budget configuration; account hierarchy under your MCC.

- How it is used: to display, create, pause, and optimize ad campaigns inside AI92's Promote module and to compute True CAC across channels. No data is shared with other Google Ads advertisers.

- How to revoke: visit https://myaccount.google.com/permissions and remove AI92. You can also request MCC unlink through Google Ads support.

Meta - Facebook, Instagram, Threads:

By connecting your Facebook or Instagram accounts, you also agree to the Meta Platform Terms and the Meta Privacy Policy. For Threads, the Threads Supplemental Privacy Policy additionally applies.

- Scopes requested (Facebook + Instagram App #1): `public_profile`, `email`, `pages_show_list`, `pages_read_engagement`, `pages_manage_posts`, `pages_manage_metadata`, `instagram_business_basic`, `instagram_business_content_publish`, `instagram_business_manage_comments`, `instagram_business_manage_insights`, `business_management`.

- Scopes requested (Threads App #2): `threads_basic`, `threads_content_publish`, `threads_manage_replies`, `threads_read_replies`, `threads_manage_insights`.

- Data received: name and profile photo of the connecting user; list of Facebook Pages and Instagram Business accounts managed; post content, media, captions, and publishing status; engagement metrics (reach, impressions, reactions, comments, shares); Threads posts and reply metadata.

- How it is used: to publish and schedule posts on your Pages and Instagram/Threads accounts, to display engagement analytics inside AI92, and to enable AI-assisted content suggestions.

- Data deletion: you can request deletion of all data received from Meta by (i) emailing [email protected] from the address linked to your AI92 account; (ii) using the Meta App Data Deletion flow which Meta forwards to AI92; or (iii) having Meta invoke AI92's Data Deletion Callback directly at `https://module-a.ai92.ai/api/v1/social-connect/meta/data-deletion` (used for Facebook, Instagram, and Threads connections). AI92 responds synchronously with a confirmation code and a status URL and completes deletion within thirty (30) days. For Threads specifically, deletion obligations additionally follow the Threads Supplemental Privacy Policy.

- How to revoke: visit https://www.facebook.com/settings?tab=applications for Facebook/Instagram and https://www.threads.net/settings/account for Threads.

LinkedIn:

By connecting your LinkedIn account you also agree to the LinkedIn API Terms of Use and the LinkedIn Privacy Policy.

- Scopes requested: `openid`, `profile`, `email`, `w_member_social` (post on your behalf), `w_organization_social` (post on Company Pages you admin), `r_organization_admin` (read metadata for the Company Pages you admin), `rw_organization_admin` (manage the Company Pages you admin). The legacy `r_organization_social` scope, deprecated by LinkedIn in 2024, is not used.

- Data received: member ID, name, headline, profile photo URL, email, list of Company Pages you administer, posts and their engagement metrics, organizational analytics.

- How it is used: to publish content and schedule posts, retrieve engagement analytics, and help you manage your Company Page.

- How to revoke: visit https://www.linkedin.com/mypreferences/d/data-sharing-and-permitted-services.

TikTok:

By connecting your TikTok account you also agree to the TikTok for Developers Terms of Service and the TikTok Privacy Policy.

- Scopes requested (Phase 1): `user.info.basic` (identity), `video.upload` (send AI-generated videos as drafts to your TikTok inbox so you can review, edit, and publish them from the TikTok app yourself). Direct publishing via `video.publish` is deferred to a future release and is not requested during Phase 1. For TikTok for Business accounts, additional scopes (`business.get`, `business.creative.manage`) will be requested only if and when you connect a Business account; they are not part of the Phase 1 consumer submission.

- Data received: open ID, username, display name, avatar URL, uploaded video metadata and performance counters.

- How it is used: to publish videos, schedule uploads, and show performance analytics inside AI92.

- How to revoke: visit https://www.tiktok.com/setting/connected_apps.

Pinterest:

By connecting your Pinterest account you also agree to the Pinterest API Terms and the Pinterest Privacy Policy.

- Scopes requested (Phase 1): `user_accounts:read`, `boards:read`, `pins:read`, `pins:write` (optional `boards:write` if you choose AI92 to create a dedicated destination board). Pinterest Ads scopes (`ads:read`, `ads:write`) are deferred to a future release and are not requested during Phase 1.

- Data received: account ID, profile, list of boards and pins, pin engagement metrics, ad campaign structures and metrics (if you authorize ads scopes).

- How it is used: to create and schedule pins, manage boards, and show analytics inside AI92.

- How to revoke: visit https://www.pinterest.com/settings/apps/.

- Attribution: AI92 uses the Pinterest API but is not endorsed, sponsored by, or affiliated with Pinterest, Inc. Pinterest and the Pinterest logo are trademarks of Pinterest, Inc.

Snapchat (Snap Kit / Marketing API):

By connecting your Snapchat account you also agree to the Snap Developer Terms and the Snap Privacy Policy.

- Scopes requested (Snap Kit Login Kit - Phase 1): `https://auth.snapchat.com/oauth2/api/user.display_name` (to show your Snapchat display name on your AI92 connection card), `https://auth.snapchat.com/oauth2/api/user.bitmoji.avatar` (to render your Bitmoji on the card), `https://auth.snapchat.com/oauth2/api/user.external_id` (to uniquely identify your Snapchat account across sessions). Creative Kit: no OAuth scope is required - Creative Kit uses a deep-link / attachment flow in which AI92 passes an AI-generated image or short video plus an optional caption to the Snapchat camera, and you, inside the Snapchat app, decide whether to publish. Snap Marketing API: not requested during Phase 1.

- Data received: external ID, display name, Bitmoji avatar URL (when granted), ad account structures and performance data.

- How it is used: to authenticate you, to publish or schedule content via Creative Kit, and to manage ad campaigns via Marketing API.

- How to revoke: visit https://accounts.snapchat.com/accounts/manage-apps.

Reddit:

By connecting your Reddit account you also agree to the Reddit Data API Terms and the Reddit Privacy Policy.

- Scopes requested (Phase 1): `identity`, `submit`, `read`. If a future feature requires editing your own submissions, reading your comment history, or setting flair, we will request `edit`, `history`, and/or `flair` separately at that time with explicit consent.

- Data received: username, karma, moderated subreddits, submission and comment metadata you have created or for which you request analytics.

- How it is used: to publish posts and comments on your behalf and to compile engagement analytics.

- How to revoke: visit https://www.reddit.com/prefs/apps and remove AI92.

X (Twitter) - not available in Phase 1:

AI92 intends to offer X integration in a future release. This section will be updated when the integration becomes available and before any user data from X is collected.

Information Protection and Security

Applies to: All Customers

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. Our security measures include:

Multi-Cloud Hub-and-Spoke Architecture: We operate a geographically distributed infrastructure with 18 endpoints worldwide across multiple cloud providers (AWS, Google Cloud, Azure). This architecture provides redundancy, disaster recovery capabilities, and reduced latency through regional data processing.

Encryption: We use industry-standard encryption for data in transit (TLS/SSL) and at-scale encryption for sensitive data at rest. All connections to our platform are encrypted using HTTPS.

Access Controls: We implement strict access controls and authentication mechanisms, including multi-factor authentication for privileged accounts, role-based access control (RBAC), and regular access reviews.

ODB and LTD Architecture: Our platform uses a dual-layer data architecture: Operational Database (ODB) for real-time operations and Long-Term Data (LTD) storage for historical analytics. The LTD layer provides additional security through data segregation and immutability of historical records.

Security Monitoring: We continuously monitor our systems for security threats, conduct regular vulnerability assessments and penetration testing, maintain incident response procedures, and employ automated threat detection systems.

Employee Training: Our employees receive regular security awareness training, are bound by confidentiality obligations, and access personal data only on a need-to-know basis.

Vendor Security: We assess the security practices of our third-party service providers and require them to implement appropriate security measures through contractual obligations.

LTD Log Server: We maintain specialized LTD Log Servers at key geographic locations (AFRAD-D HUB in Nigeria for African operations, EROSC-E N Node in the Netherlands for European operations) that provide audit trails and compliance monitoring for data access and processing activities.

Regular Audits: We conduct regular internal audits of our data processing activities and security controls, and we maintain documentation of our processing activities as required by data protection regulations.

Despite our security measures, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security. If you have reason to believe that your interaction with us is no longer secure, please contact us immediately at [email protected].

Third-Party Tracking and Cookies

Applies to: All Customers

We use cookies and similar tracking technologies to collect and track information about your use of our services. Cookies are small data files stored on your device that help us improve our services and your experience.

Types of Cookies We Use:

- Essential Cookies: Required for basic site functionality, authentication, and security. These cookies are necessary for the platform to work and cannot be disabled.

- Analytics Cookies: Help us understand how visitors use our website and platform, including page views, traffic sources, and user behavior patterns. We use Google Analytics for this purpose.

- Marketing Cookies: Used to deliver relevant advertisements and track campaign effectiveness. These cookies remember your visit and may be used to show you targeted ads on other websites.

Third-Party Services: We use the following third-party services that may collect information about you:

- Google Analytics: Tracks website and platform usage patterns. You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.

- Payment Processors: Stripe and PayPal process payment information and may set their own cookies. Please refer to their privacy policies for details.

- AI and Machine Learning Tools: The Platform uses artificial-intelligence and machine-learning features to provide insights and recommendations. Some of these features run on our own infrastructure; others are powered by named third-party AI sub-processors. The full list of AI sub-processors, what each one is used for, and the contractual safeguards in place is provided above in the section "Information Sharing and Disclosure - AI and Machine Learning Sub-processors". We do not authorise any third-party AI sub-processor to use your data to train, fine-tune, or otherwise improve its general-purpose models.

You can control cookie preferences through your browser settings. However, disabling cookies may limit your ability to use certain features of our services.

International Data Transfers

Applies to: All Customers

We operate globally and may transfer your personal information to countries outside your country of residence, including countries that may not provide the same level of data protection as your home country.

Multi-Cloud Architecture: Our Multi-Cloud Hub-and-Spoke architecture operates across multiple regions globally, with endpoints in North America, Europe, Asia-Pacific, Africa, and other regions. Data may be processed in any of these regions to provide optimal performance and service delivery.

Standard Contractual Clauses: When we transfer data from the European Economic Area (EEA) or United Kingdom to countries outside these regions, we use Standard Contractual Clauses (SCCs) approved by the European Commission or other appropriate safeguards to ensure your data is protected.

Data Residency Options: For customers in regulated industries or jurisdictions with specific data residency requirements, we offer data residency options that allow you to specify where your data is primarily stored and processed.

Data Residency: Our approach to data residency and to jurisdictions with data-localization laws is as follows:

- No China or Russia routing: AI92 does not operate infrastructure in, or route customer personal data through, China- or Russia-based cloud providers.

- Residency on request: Where a customer is subject to specific data-residency obligations, we assess and, where feasible, accommodate them under the Data Processing Addendum before onboarding, and reflect any such arrangement in our sub-processor register.

LTD Log Server Locations: Our LTD Log Servers are strategically positioned to provide audit and compliance capabilities:

- AFRAD-D HUB: Located in Nigeria, serves as the primary audit and data residency compliance node for African operations.

- EROSC-E N Node: Located in the Netherlands, serves as the European regional audit and compliance hub.

Cross-Border Tax Compliance: Due to our global operations and multi-jurisdictional tax obligations, certain billing and tax data may be transferred internationally to comply with tax reporting and remittance requirements in various countries.

By using our services, you acknowledge and agree to the transfer of your information to our facilities and to the third-party service providers with whom we share it as described in this policy.

Data Retention

Applies to: All Customers

We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

Operational Data (OTM - Operational Time Mode): Real-time operational data in our ODB layer is retained for the shortest period necessary to provide our services, typically ranging from a few months to two years depending on the data type and your subscription level.

Long-Term Data (LTD): Our LTD system maintains historical data for analytics purposes, including campaign performance history, True CAC calculations, and longitudinal customer behavior patterns. This data is retained indefinitely or until you request deletion, as it forms the Single Source of Truth (SSOT) for your business metrics.

Billing and Tax Records: We retain billing information, transaction records, and tax documentation for periods required by law in various jurisdictions, typically ranging from 5 to 10 years depending on the jurisdiction. This includes invoices, payment records, tax collection documentation, and VAT/GST filing records.

Account Information: We retain your account information for as long as your account is active. After account closure, we retain certain information to comply with legal obligations, resolve disputes, enforce our agreements, and maintain business records.

Marketing Data: If you have opted in to marketing communications, we retain your contact information until you unsubscribe or request deletion.

Logs and Security Data: Server logs, access logs, and security monitoring data are typically retained for 12-24 months for security and troubleshooting purposes.

When you request deletion of your data, we will delete or anonymize your personal information within 30 days, except where we are required to retain it for legal or compliance purposes. Some data may persist in backup systems for up to 90 days after deletion.

Your Privacy Rights

Applies to: All Customers

Depending on your location, you may have certain rights regarding your personal information. These rights may include:

Access: You have the right to request access to the personal information we hold about you. You can request a copy of your data by contacting [email protected].

Rectification: You have the right to request correction of inaccurate or incomplete personal information. You can update most of your account information directly through your account settings.

Deletion (Right to be Forgotten): You have the right to request deletion of your personal information, subject to certain legal exceptions (such as retention requirements for billing, tax, and audit purposes).

Data Portability: You have the right to receive your personal information in a structured, commonly used, and machine-readable format and to transmit that data to another controller. We can provide your data in JSON or CSV format upon request.

Objection: You have the right to object to the processing of your personal information for certain purposes, including marketing. You can opt out of marketing emails by clicking the unsubscribe link in any marketing email or by contacting us.

Restriction: You have the right to request restriction of processing your personal information in certain circumstances, such as while we verify the accuracy of the data or assess your objection to processing.

Withdraw Consent: Where we process your data based on consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

Revocation of Social Media Platform Access: If you have connected one or more social media platforms to AI92, you can revoke access at any time either from within AI92 (Settings → Connected Accounts → Disconnect) or directly from the platform's app settings page (links provided in the 'Social Media Platform Integrations' section). Revocation invalidates the OAuth token immediately; AI92 deletes the token and any cached platform data within thirty (30) days.

Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority if you believe we have violated your data protection rights. In the UK, this is the Information Commissioner's Office (ICO). In EU countries, you can contact your national data protection authority.

Automated Decision-Making: You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you. Our platform uses AI and machine learning for analytics and insights, but significant decisions are always subject to human review. We do not authorise any third-party AI vendor to use Customer Data to train, fine-tune, or otherwise improve its general-purpose models. If you would like to exercise your right to object to a specific AI processing activity, contact [email protected] with the subject line "AI Processing Objection"; we will respond within thirty (30) days.

California Privacy Rights (CCPA): If you are a California resident, you have additional rights under the California Consumer Privacy Act, including the right to know what personal information is collected, the right to delete personal information, and the right to opt-out of the sale of personal information (note: we do not sell personal information).

GDPR Rights: If you are located in the European Economic Area or United Kingdom, you have rights under the General Data Protection Regulation (GDPR), including all the rights listed above.

To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days (or within the time period required by applicable law). We may need to verify your identity before processing your request.

Please note that exercising certain rights may limit your ability to use some features of our platform. For example, deleting your account will result in loss of access to the platform and all associated data, including LTD analytics and historical reporting.

AI Disclosures

Applies to: All Customers

This section is a plain-language summary of how artificial intelligence is used inside the AI92 Platform and how that use affects your data. It is provided in addition to, not in place of, the more detailed text elsewhere in this Privacy Policy.

1. What AI is used for. We use AI to draft ad copy and response suggestions, summarise campaign analytics, classify and translate content, and surface relevant news. AI is a feature of the Platform; it is not used to make consequential decisions about you.

2. Which AI vendors process your data. Our current third-party AI sub-processors are Google Cloud Vertex AI, Perigon (United States), and xAI (United States). The full list and what each is used for is in the "Information Sharing and Disclosure" section above.

3. What we do NOT allow. We contractually prohibit our AI sub-processors from using Customer Data to train, fine-tune, or otherwise improve their general-purpose models. We do not sell Customer Data to AI vendors. We do not allow AI vendors to combine data they receive from us with data they hold from other sources to build a profile of any individual.

4. What you can do. You can ask us at any time which AI sub-processors are currently used, what data has been sent to them on your behalf, and (where applicable) request that we stop using a specific AI feature on your account. Send a request to [email protected] with the subject line "AI Disclosures Request".

5. Generated Output. AI-generated content (for example, drafted ad copy) is provided as a starting point. Because of the nature of AI models, the same or similar output may be produced for other customers. You should review AI-generated content before publishing it, and you remain responsible for any content you choose to publish.

6. When this section was last updated. April 2026.

Data Processing Addendum

Applies to: API Services

If you use the API Services to process personal data of natural persons - your own customers, your customers' customers, individuals identified in lists you submit, individuals receiving e-mails or messages you have generated using the API, and similar categories - the relationship between you and AI92 with respect to that personal data is governed by the AI92 Data Processing Addendum (the DPA) published at ai92.ai/data-processing-addendum. The DPA forms an integral part of these Terms of Service and is incorporated by reference into this Privacy Policy.

If you are an Enterprise customer with a Master Services Agreement (MSA), the DPA terms may be modified by your MSA. In case of conflict, the MSA controls.

Contact Us

Applies to: All Customers

If you have any questions or concerns about this Privacy Policy or our data practices, please contact us: