Legal
Privacy Policy
Last updated: May 5, 2026
1. Introduction
UpMax AI (“UpMax”, “we”, “us”, or “our”) operates the marketing-agency operating system available at app.upmax.ai, with this marketing site at upmax.ai. This Privacy Policy describes how we collect, use, store, transfer, and protect information when you use the Service or visit our websites.
By using the Service you agree to this policy. If you do not agree, please do not use the Service.
This policy is governed by:
- The Google API Services User Data Policy, including the Limited Use requirements (policy).
- The Meta Platform Terms and Developer Data Use Policy.
- The LinkedIn API Terms of Use.
- The TikTok for Business API Terms and TikTok Developer Terms of Service.
- The X (Twitter) Developer Agreement and Policy.
- The Pinterest Developer Guidelines and Snapchat Marketing API Terms.
- The EU General Data Protection Regulation (GDPR) for users in the European Economic Area, United Kingdom, and Switzerland.
- The California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (CCPA/CPRA) for California residents.
2. Who We Are
UpMax AI provides software that helps digital marketing agencies operate. The Service connects to your marketing accounts, aggregates performance data, and uses AI agents to recommend, execute, and verify marketing work for your clients.
Data controller: UpMax AI is the data controller for personal data we process about our customers (the agency operators who hold accounts with us). For data we process on behalf of our customers’ clients (e.g., when an agency connects a client’s Google Ads account through our platform), UpMax acts as a data processor under GDPR and a service provider under CCPA.
3. Information We Collect
3.1 Account Information
When you create an account we collect:
- Name and email address
- Organization name, role, and team-member emails you invite
- Authentication credentials (passwords are hashed using industry-standard algorithms; never stored in plain text)
- Billing information processed by Stripe (we do not store full card numbers; we receive a tokenized reference)
- Optional profile details (timezone, locale, photo)
3.2 Connected Services Data
When you connect a third-party service through our platform we access only the data needed to provide the Service. We list every connected service and the specific data scopes below.
3.3 Usage Data
- Pages and features you use within the Service
- Actions taken (creating tasks, approving recommendations, configuring agents)
- Device, browser, and operating system metadata
- IP address and approximate geographic location (city level)
- Crash reports and performance metrics (via Sentry)
3.4 Cookies and Similar Technologies
We use a small number of strictly necessary cookies for session management and CSRF protection. We do not use cookies for advertising. See section 12 for details and your choices.
3.5 Information from Other Sources
If you sign up via an OAuth provider (e.g., Google), we receive the basic profile information that provider shares (name, email, avatar). We do not collect additional information from other sources without your consent.
4. Connected Services — What We Access and Why
The list below covers every third-party platform you can currently connect through UpMax. We only access data after you authorize it via the provider’s OAuth flow, and only for the purposes stated.
4.1 Google APIs
UpMax integrates with Google services using the OAuth 2.0 authorization flow. Specifically:
- Google Ads: campaign and ad-group performance, keyword data, conversion metrics, account spend. Used to display reporting, recommend optimizations, and (with your approval) push changes back to your account.
- Google Analytics (GA4): traffic, sessions, pageviews, engagement metrics, conversion events, and revenue data. Used for cross-channel reporting and KPI summaries.
- Google Search Console: search queries, clicks, impressions, click-through rates, and average positions. Used for SEO reporting and recommendations.
- Google Business Profile: business listing details, reviews, ratings, and profile performance. Used for local SEO reporting and review management.
- Google Calendar and Google Meet: calendar event metadata for meeting scheduling features (read-only).
- Google Drive: files in folders you explicitly share with our service account or shared drive. Used for client deliverables, asset library, and AI-assisted document workflows.
Google API Services User Data Policy — Limited Use Disclosure. UpMax AI’s use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google user data only to provide and improve user-facing features visible in the UpMax dashboard.
- We do not transfer Google user data to third parties except as necessary to provide or improve user-facing features, comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users.
- We do not use Google user data for advertising, including retargeting, personalized advertising, or interest-based advertising.
- We do not allow humans to read Google user data unless (a) we have your affirmative consent for specific data, (b) it is necessary for security purposes (e.g., investigating abuse), (c) to comply with applicable law, or (d) the data is aggregated and used for internal operations in compliance with applicable laws.
4.2 Meta Platforms (Facebook and Instagram)
When you connect Meta we access, only with your authorization:
- Pages and Page insights for Facebook Pages you manage
- Instagram Business Account posts, comments, and insights
- Meta Ads campaign and ad-set performance, audience metadata, ad spend
- Meta Business Manager account context to identify the assets you have permission to manage
We use this data only to (a) display reporting in the UpMax dashboard, (b) recommend optimizations, and (c) execute changes you have approved (e.g., publishing a post, pausing an ad). We do not use Meta data to build advertising audiences outside the assets you connected, and we do not sell or rent Meta data to any third party.
If you uninstall the Meta integration, we revoke our access tokens and delete cached Meta data within 30 days.
4.3 LinkedIn
We use the LinkedIn Marketing Developer Platform with your authorization to access:
- LinkedIn Pages and Page analytics for pages you administer
- LinkedIn Ads campaign performance and audience metadata
- Member-level analytics aggregated by LinkedIn (we do not receive individual member identities)
We do not access your personal LinkedIn inbox or connections without explicit consent for a specific feature. LinkedIn data is used exclusively to operate features inside UpMax and is never sold or shared for advertising.
4.4 TikTok for Business
When you connect TikTok we access, only with your authorization:
- TikTok Business Account profile and basic metadata
- Video performance metrics (views, engagement, completion rate)
- TikTok Ads campaign performance and spend
- Audience demographics in aggregated form
We comply with the TikTok for Business API Terms and the TikTok Developer Terms of Service. TikTok data is processed for the sole purpose of operating UpMax features for your account and is not used for advertising outside your own TikTok assets.
4.5 X (formerly Twitter)
When you connect X we access, only with your authorization:
- Tweets, replies, and engagement metrics for accounts you administer
- Follower demographics in aggregate form (where X exposes this)
- X Ads performance metrics for advertiser accounts you connect
X data use complies with the X Developer Agreement and Policy. We do not redistribute X data, do not use it for off-platform advertising, and do not retain raw API responses beyond what is needed to provide the feature.
4.6 Pinterest
When you connect Pinterest we access, only with your authorization:
- Pinterest Business Account profile and boards
- Pin and board performance metrics
- Pinterest Ads campaign data for advertiser accounts you connect
Pinterest data use complies with the Pinterest Developer Guidelines and the Pinterest Ads Terms. We do not use Pinterest data for any advertising outside your own Pinterest assets.
4.7 Snapchat
When you connect Snapchat we access, only with your authorization:
- Snapchat Business Account profile
- Snap Ads campaign performance, spend, and creative metadata
- Audience demographics in aggregated form
Snapchat data use complies with the Snapchat Marketing API Terms. We do not redistribute Snapchat data and do not use it for off-platform advertising.
4.8 GoHighLevel (GHL)
We integrate with GoHighLevel using your API key, scoped to the GHL location(s) you authorize. We access contacts, opportunities, pipelines, calendars, and campaign data to mirror your CRM state inside UpMax.
4.9 ClickUp
We integrate with ClickUp using your API key, scoped to the workspace and lists you authorize. We access tasks, comments, and approval status for project-management synchronization.
4.10 Slack
We integrate with Slack using its OAuth flow. We access channel metadata, post messages on your behalf when you authorize it, and receive interaction events for approval workflows.
4.11 Stripe
Stripe is our payment processor. When you subscribe, you provide payment details directly to Stripe; we receive a tokenized customer reference and subscription metadata only. Stripe processes your payment data under Stripe’s Privacy Policy.
4.12 WhatsApp Business
If you enable the WhatsApp integration we use the Meta-provided WhatsApp Business API to send and receive messages on your authorized number. Message content is processed solely to deliver the feature you configured.
4.13 SendGrid and Resend
We use SendGrid and Resend as email infrastructure to deliver transactional and notification emails. They process email metadata (recipient address, subject, send time) under their own privacy policies.
4.14 n8n
If you connect a self-hosted or n8n Cloud workspace, we register webhook endpoints and exchange task payloads with your n8n instance. We do not access n8n data outside the specific workflows you connect.
4.15 Fireflies (meeting transcripts)
If you connect Fireflies.ai we receive meeting transcripts, summaries, action items, and participant metadata for meetings you have authorized Fireflies to record. We use this data only to surface meeting context inside the UpMax dashboard (e.g., associating a call summary with a client). Fireflies data is encrypted in transit and at rest, scoped to your organization, and deleted within 30 days of disconnect.
4.16 Anthropic and OpenAI (AI inference)
We use Anthropic Claude as our primary large language model and OpenAI for text embeddings. When the Service generates AI output (e.g., a draft email, a recommendation), the relevant context — which may include account names, performance metrics, and your prompt — is sent to the model provider.
Specifically, we commit to the following AI-data limits:
- Anthropic and OpenAI do not train their foundation or frontier models on your data under our enterprise data-processing terms.
- UpMax does not use connected-service data (Google, Meta, LinkedIn, TikTok, X, Pinterest, Snapchat, GHL, etc.) to train, fine-tune, or build generalized models of any kind.
- We do not perform cross-tenant learning. Embeddings, prompts, and outputs are scoped to your organization. We do not aggregate data from one customer to improve recommendations for another customer.
- We comply with the X Developer Agreement §III(A)(k) prohibition on training foundation/frontier models with X API content.
- We comply with the Google API Services User Data Policy Limited Use restrictions on AI use of Google data.
4.17 Observability (Sentry, LangSmith, Langfuse)
We use Sentry for crash reports, and LangSmith and Langfuse for AI-call observability. These services receive request and error metadata under their respective data-processing agreements. They do not receive your account credentials.
5. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Authenticate users and protect against unauthorized access
- Aggregate cross-channel marketing metrics into reporting dashboards
- Generate AI-driven recommendations, content drafts, and approvals
- Send transactional emails (account, billing, security)
- Respond to your support requests
- Detect and prevent fraud, abuse, and security incidents
- Comply with legal obligations
- With your separate consent, send product announcements (you may opt out at any time)
We do not sell your personal information. We do not use connected-service data for advertising, retargeting, or to build advertising audiences outside your own assets.
6. Legal Basis for Processing (GDPR)
Where GDPR applies, we rely on the following legal bases:
- Contract: to provide the Service you signed up for
- Legitimate interest: to secure the Service, analyze usage to improve the product, and prevent fraud
- Consent: for marketing emails and any optional integrations you choose to enable
- Legal obligation: to comply with applicable law
You may withdraw consent at any time without affecting the lawfulness of prior processing.
7. How We Share Information
We share personal data only as needed to operate the Service:
- Subprocessors listed in section 13
- Connected service providers as you authorize them (see section 4)
- Professional advisors (e.g., auditors, lawyers) under strict confidentiality
- Authorities when required by law, subpoena, or court order, or to protect rights, safety, and property
- In a corporate transaction (merger, acquisition, asset sale), with notice and continued protection
We do not sell, rent, or share personal information for cross-context behavioral advertising.
8. Your Privacy Rights
8.1 All users — universal rights
- Disconnect any third-party integration at any time from the Service settings; this revokes our access tokens and deletes related cached data within 30 days
- Data deletion: see Data Deletion to request deletion of your account and associated data
- Data export: request a machine-readable export of your data by emailing [email protected]
- Object to specific processing activities
8.2 EU/EEA, UK, and Swiss users — GDPR rights
You have the right to:
- Access the personal data we hold about you
- Rectify inaccurate or incomplete data
- Erase your data (“right to be forgotten”)
- Restrict processing in certain circumstances
- Object to processing based on legitimate interest
- Portability — receive your data in a machine-readable format
- Lodge a complaint with your supervisory authority
To exercise any of these rights, email [email protected] from the address associated with your account. We will respond within 30 days.
8.3 California residents — CCPA/CPRA rights
You have the right to:
- Know what categories and specific pieces of personal information we have collected, used, disclosed, or sold (we do not sell)
- Delete personal information we have collected from you, subject to permitted exceptions
- Correct inaccurate personal information
- Opt out of the sale or sharing of personal information (we do not sell or share for advertising; this right is provided automatically)
- Limit the use of sensitive personal information
- Non-discrimination for exercising these rights
To exercise any of these rights, email [email protected] or use our Data Deletion form. We will verify your identity by the email associated with your account and respond within 45 days.
California Notice at Collection
The table below summarizes the categories of personal information we collect, why, and how it flows. We do not sell personal information and we do not share personal information for cross-context behavioral advertising.
| Category (Cal. Civ. Code §1798.140) | Specific data | Source | Purpose | Retention | Disclosed to |
|---|---|---|---|---|---|
| Identifiers | Name, email, organization, account ID | Direct from you | Account creation, authentication, support | While account active + 30 days post-deletion | Subprocessors §13 |
| Customer records | Billing contact, role, team membership | Direct from you | Service delivery, billing | Account lifetime; billing 7 years (tax law) | Stripe (billing), subprocessors |
| Commercial information | Subscription tier, usage metrics, integrations enabled | Generated by use | Service delivery, capacity planning, billing | Account lifetime | Stripe, observability subprocessors |
| Internet/network activity | IP address, browser, pages viewed, feature events | Generated by use | Authentication, security, product improvement | 90 days for raw logs; aggregated retained | Sentry, observability subprocessors |
| Geolocation (approximate) | City-level, derived from IP | Generated by use | Security, regional defaults | 90 days | Internal only |
| Inferences | AI-generated recommendations referencing your data | Derived | Provide AI features in the dashboard | Account lifetime | Anthropic, OpenAI (no training) |
| Sensitive PI | Login credentials | Direct from you | Authentication only | While account active | Internal only |
| Connected-service data | Marketing performance, ad spend, CRM contacts you authorize | OAuth-connected platforms (Google, Meta, etc.) | Provide reporting and execution features you requested | 30 days post-disconnect (or shorter where partner terms require — see §9) | Anthropic, OpenAI (per §4.16 limits), connected services for write-back you authorize |
We do not knowingly collect sensitive personal information beyond authentication credentials, and we do not use sensitive PI for any purpose other than the disclosed function (logging you in).
8.4 Authorized agents
You may designate an authorized agent to make a request on your behalf. We will require written authorization from you and may verify your identity directly.
9. Data Retention
We retain personal data only as long as needed for the purposes described:
- Active account data: for as long as your account is active
- Historical metric snapshots: retained for trend analysis and period-over-period comparisons
- Billing records: retained for 7 years to comply with tax and accounting laws
- Server logs: retained 90 days, then deleted or aggregated
- Backups: encrypted backups are retained 35 days and rotated automatically
- Account deletion: upon account deletion, all associated data is permanently removed within 30 days, except where retention is required by law
Connected-service data — platform-specific deletion SLAs
Where a connected platform’s terms require a faster deletion than our default, we honor the shorter timeline:
| Platform | Stored data deletion on disconnect / on-request | Source |
|---|---|---|
| 10 days or less for Stored Marketing Data | LinkedIn Marketing API Terms §4.2 | |
| X (formerly Twitter) | 24 hours to remove or update X Content reflecting deletions, suspensions, or content edits on X | X Developer Agreement §IV (Content Compliance) |
| TikTok | 30 days, faster on user request | TikTok for Business API Terms |
| Meta (Facebook / Instagram) | 30 days, immediate on Data Deletion Callback receipt | Meta Platform Terms |
| 30 days | Pinterest Developer Guidelines | |
| Snapchat | 30 days | Snapchat Marketing API Terms |
| Google APIs | 30 days, immediate on token revocation | Google API Services User Data Policy |
| GoHighLevel | 30 days | GoHighLevel API Terms |
| All other connected services | 30 days | UpMax default policy |
When you disconnect a platform from the Service, we revoke OAuth tokens immediately and queue cached data for deletion under the timeline above. You can verify deletion by reconnecting and observing that historical data must be re-fetched.
10. Security
We protect your data with multiple layers:
- Transport: HTTPS/TLS 1.2+ enforced on all endpoints
- At rest: production database encrypted; OAuth tokens encrypted with Fernet symmetric encryption before storage
- Tenant isolation: PostgreSQL row-level security (RLS) ensures each organization can only access its own data
- Access control: role-based permissions inside the Service; principle of least privilege for engineering access to production
- Hosting: production infrastructure runs on Railway with security headers (CSP, HSTS, X-Frame-Options, X-Content-Type-Options) applied to every response
- Monitoring: Sentry for application errors and Langfuse/LangSmith for AI-call observability
- Incident response: in the event of a personal data breach affecting EU/UK users, we will notify the supervisory authority within 72 hours and affected users without undue delay where the breach is likely to result in high risk
No system is perfectly secure. You are responsible for safeguarding your account credentials.
11. International Data Transfers
UpMax stores production data primarily in United States data centers (Supabase, Railway). If you access the Service from outside the United States, your data will be transferred to and processed in the U.S.
For transfers from the EU/EEA, UK, or Switzerland, we rely on the Standard Contractual Clauses (SCCs) approved by the European Commission and (where applicable) the UK Addendum and Swiss Addendum. Subprocessors are bound by equivalent terms.
12. Cookies
We use a minimum set of cookies:
- Strictly necessary: session and CSRF cookies on
app.upmax.ai - Functional: theme preference, recently-used settings (where applicable)
We do not use third-party advertising cookies, do not use Google Analytics or Meta Pixel on either site, and do not participate in cross-site tracking. The marketing site (upmax.ai) sets no analytics cookies; if we add privacy-respecting analytics later (e.g., Plausible), it will not use cookies.
You can clear cookies via your browser settings. Disabling strictly necessary cookies will impair core functionality.
13. Subprocessors
The following service providers process personal data on our behalf:
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Database hosting, authentication infrastructure | United States |
| Railway | Application hosting, deployment | United States |
| Anthropic | AI inference (Claude) | United States |
| OpenAI | Text embeddings | United States |
| Sentry | Error tracking | United States |
| LangSmith | AI observability | United States |
| Langfuse | AI observability | EU |
| SendGrid | Transactional email | United States |
| Resend | Transactional email | United States |
| Stripe | Payment processing | United States |
| Cloudflare | DNS, edge security | Global |
| Formspree | Marketing-site form delivery | United States |
We require all subprocessors to maintain confidentiality and security commitments at least as protective as those in this policy. We will provide updated notice if we add or change subprocessors.
14. Children’s Privacy
The Service is not directed to children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, please contact [email protected] and we will delete it.
15. Automated Decision-Making
UpMax uses AI to recommend marketing actions (e.g., paused campaigns, suggested copy). For any action that affects a customer’s marketing accounts, a human approval step is required by default. We do not make solely-automated decisions that produce legal or similarly significant effects on you.
16. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the updated policy on this page with a revised “Last updated” date
- For material changes, sending an email to the address on file at least 14 days before the change takes effect
Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
17. Contact Us
For privacy questions or to exercise any of your rights, the fastest path is email:
Email: [email protected] Data deletion form: /data-deletion General contact form: /contact
Data controller: UpMax AI (legal entity: UpMax Automation LLC). For postal correspondence, please first email us so we can confirm the most current registered address.
EU/UK representative: We do not currently maintain an in-EU/UK representative under GDPR Article 27 because we do not target the Service to EU/UK consumers as our primary market. If you are an EU/UK data subject and need to escalate, email us first; for unresolved concerns you have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner’s Office; elsewhere, your member-state authority).
We respond to verified privacy requests within 30 days (GDPR) or 45 days (CCPA), whichever is shorter for your jurisdiction.