This Privacy Policy explains what information Havadis collects, how we use it, and the choices you have. We aim for plain-language transparency over dense legalese. If something here is unclear, write to us.
Data we collect
Account data you provide through Google sign-in (name, email, profile image). Workspace content you create inside Havadis — topics, brand profiles, generated posts, personas, analysis results. Operational data such as log events, API usage, and error traces needed to run the service. We do not buy personal data from third parties.
How we use your data
To authenticate you, provision your workspace, run the content and analysis pipelines you request, enforce plan limits and credits, answer support requests, and improve reliability and quality. We do not sell your data, and we do not use your workspace content to train foundation models.
AI processing of your content
When you run an analysis or a content job, we send the relevant inputs to our large-language-model providers (Google Gemini and Eachlabs) to generate outputs. These providers are bound by their own data-processing terms and, for our API tier, do not use request data to train their models. Model outputs are stored in your workspace; you can delete them at any time.
Third parties
We rely on: Google (authentication), LLM providers (content generation), a managed database and object storage for persistence, and observability providers for logs and metrics. Each receives only the minimum data needed to perform its function. How we handle data received from Google APIs and from Meta platforms specifically is covered in the Google user data and Meta platform data sections below.
Google user data
When you sign in with Google we receive your basic profile (name, email address, profile image). If you choose to connect Google Search Console or Google Analytics to a brand, we access — with read-only scopes — your site's search performance data (queries, clicks, impressions, positions) and aggregated analytics metrics. We use this data for one purpose: showing you how your own content performs and surfacing search opportunities inside Havadis. We do not sell Google user data, do not use it for advertising, do not use it to train AI or machine-learning models, and do not share, transfer, or disclose it to third parties except to the infrastructure providers that host Havadis (listed above) or where the law requires it. If you start a content job from a search query you selected, only that query text enters the normal content pipeline. You can disconnect Google Search Console or Google Analytics at any time from Settings — we delete the stored tokens immediately — and you can also revoke Havadis's access from your Google Account permissions page. Havadis's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Meta platform data
If you choose to connect Facebook (Meta Ads) or Instagram to a brand, we receive data from Meta only within the scopes you grant. For a Meta Ads connection that is: the connected Facebook user's name and id, the list of ad accounts they can reach, the campaigns, ad sets and ads in the account you select together with their performance metrics (spend, impressions, clicks, CTR, conversions), and the name of the Facebook Page you pick when creating a creative. We use this data for one purpose: showing you how your own ads perform and writing better ad copy. When we generate new ad copy we pass your account's recent ad copy to our language-model provider as input so we do not repeat something you already ran; those providers do not use request data to train their models. We do not sell Meta platform data, do not use it for ad targeting, identity enrichment or surveillance, and do not share it with third parties other than the infrastructure providers that host Havadis (listed above) or where the law requires it. Every ad Havadis creates is created PAUSED; we never create campaigns, ad sets or budgets, never modify your existing ads, and never set an ad live — publishing is your decision in Ads Manager. You can disconnect at any time from Settings and we delete the stored tokens immediately; you can also revoke access from the Business Integrations page of your Facebook account.
How we protect your data
All traffic between your browser, our servers, and third-party APIs is encrypted in transit with TLS. Data is stored on managed database and object-storage services that encrypt it at rest. OAuth access and refresh tokens for connected accounts — including Google — are additionally encrypted at the application level before they are written to the database, are never sent to the browser, and are deleted when you disconnect the account. We request the narrowest scopes that make each feature work (read-only wherever possible), and access to production data is limited to the small set of operators who run the service.
Data retention
Workspace content is retained while your account is active. When you delete a resource it is removed from the live database and purged from backups within the backup rotation window. If you close your account, we delete or anonymize your data within 30 days, except where we are required to retain records for legal or billing reasons.
API and developer surface
When you create an API key for your account, we keep a record of the calls made with it: the operation invoked, the key's identity (only its public prefix, never the secret), the outcome, the duration, and the IP address the call came from. We store the IP address so we can detect abuse of a leaked key and protect your account. These records delete themselves after 7 days for MCP server calls and 30 days for REST API calls. We also count each key's daily credit spend; those counters are deleted within 7 days. If your key is detected in a public code repository (GitHub secret scanning partnership), it is automatically suspended to protect your account, and the event is logged.
Your rights
You can access, correct, export, or delete your workspace content from inside the product. For requests that cannot be completed in-app — including deletion of your account — contact us and we will respond within a reasonable time. If you are in the EU or UK, the GDPR gives you additional rights that we honor.
Deleting your data
You can delete your account and the data we hold about you at any time. You can remove most content directly in the app, and disconnect linked accounts — Facebook (Meta Ads), Instagram, Threads, LinkedIn, Google Search Console, Google Analytics — from Connected accounts in Settings to revoke their access and delete their stored tokens. To request full deletion of your account and all associated data — including content you generated, ad and performance data pulled from connected accounts, account details, and access tokens — email [email protected] and we will process the request within a reasonable time and confirm once it is complete.
Contact
Privacy questions, data-subject requests, and complaints: contact the team via the email address associated with your account or the support channel shown in your workspace.
