Last updated 2026-05-28

Privacy Policy

Who we are

Exposure Agency Pty Ltd, Sydney NSW Australia. Contact gabe@exposure.com.au.

What we collect about you (the signed-in user)

  • Email address — required to sign in.
  • Name + profile picture — pulled from your Google account at sign-in if you use Google OAuth. Stored to render your identity in-app.
  • IP address + user agent — captured for security auditing on every state-changing action (audit log).
  • Activity log — what you did, when, and on which brand (e.g., “triggered pipeline at 14:32”). Immutable.
  • Authentication tokens — Supabase session cookies (HttpOnly, Secure, SameSite=Lax).

What we collect about your ads (if you're a brand)

  • Publicly-available Meta ad metadata + creatives (under your authorised Meta Business Manager access).
  • Performance metrics: spend, ROAS, CTR, CPA, video retention.
  • AI-generated analyses of your ads (hook patterns, scripts, concepts).
  • Persona research mined from public sources (Reddit, Quora, Trustpilot).

We never see your customers’ personally-identifying information through Meta — the scope is ads_read only, no access to customer lists, leads, or audiences.

Why we collect it

  • To provide the agency services you’ve engaged us for.
  • To improve creative recommendations and prevent fraud / unauthorised access.
  • To meet our record-keeping obligations.

Who we share it with

We don’t sell your data. We use these processors:

  • Supabase (US/EU) — database + auth + storage.
  • Vercel (US) — application hosting.
  • Anthropic (US) — Claude API for text reasoning.
  • Google (US) — Gemini API for video analysis; OAuth identity.
  • n8n.cloud (DE) — workflow orchestration.
  • Meta (US/IE) — ad data source under your authorised access.
  • Apify, Firecrawl, Serper, ScrapeCreators — public-web scraping for research.

How long we keep it

  • Audit log: indefinitely (immutable record).
  • Ad performance + AI analyses: as long as the brand is an active client; archived 12 months after offboarding.
  • Account profile: until you ask us to delete it, or 12 months after access is revoked.

Your rights

  • Access a copy of your data — email us.
  • Correct inaccurate data — email us.
  • Request deletion — email us. We’ll honour it within 30 days, except for audit records we’re required to retain.
  • Withdraw your consent / close your account — email us.
  • Lodge a complaint with the Office of the Australian Information Commissioner (oaic.gov.au).

Cookies

Only essential cookies: Supabase session (HttpOnly, Secure, SameSite=Lax) and a small active-brand-selection cookie (SameSite=Lax). No tracking, no advertising cookies.

Security

All traffic over HTTPS with HSTS preload. Row-level security on every database table. Service-role keys server-side only. Custom audit log for every mutating action. Daily backups via Supabase Pro.

Changes

Material changes will be notified by email or in-app banner at least 14 days before they take effect.

Starter privacy policy. Get this reviewed by counsel before external commercial roll-out.