Privacy Policy
Effective and last updated: July 31, 2026
CMO AI is a multi-tenant marketing intelligence and workflow service. This policy explains what information we process, why we process it, and the choices available to users.
Information we process
- Account information: email address, password hash, verification state, workspace membership, role, and security-session metadata.
- Workspace configuration: goals, constraints, brand voice, offers, geographic focus, budgets, risk tolerance, and success metrics supplied by authorized users.
- Connected platform data: only after authorization. Depending on the connection, this can include Google Ads account and campaign data, Google Analytics 4 properties and reports, Search Console sites and performance, Google Business Profile accounts, locations, and performance, and supported social-ad resources.
- Operational records: recommendations, evidence, approvals, rejections, requested changes, agent activity, experiments, results, and audit events.
How information is used
We use information to authenticate users, isolate workspaces, discover authorized resources, analyze marketing performance, generate cited recommendations and briefs, operate approval workflows, maintain audit history, secure the service, and provide support. CMO AI does not sell personal information or connected Google user data.
Google API data
CMO AI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google data is used only to provide and improve the user-facing marketing intelligence and workflow features the user requests. It is not used for advertising profiles, sold, or transferred to data brokers.
AI processing and epistemic integrity
Authorized workspace data may be sent to the model provider configured by the workspace or service operator to perform requested analysis. Agents are required to distinguish sourced observations from judgments, disclose uncertainty, avoid invented metrics, and retain evidence references. Model output can still be incomplete or wrong and must be reviewed by a human.
Security and tenancy
Workspace data is tenant-scoped. Passwords are hashed, sessions use secure server controls, provider tokens are encrypted at rest, and provider credentials are never placed in frontend code. Permissions and approval gates are enforced by the server. No method of storage or transmission is completely risk-free.
Retention, revocation, and deletion
We retain data while a workspace is active and as needed for security, audit, legal, and backup obligations. Users can disconnect a provider in CMO AI and revoke access in the provider's account settings. Workspace owners may request export or deletion. Requests are fulfilled subject to legal, fraud-prevention, security, and backup-retention requirements.
Sharing
We share information only with service providers needed to operate CMO AI, with platform APIs the user directs us to connect, when required by law, or in a business transfer subject to appropriate safeguards. Access inside a workspace follows owner, approver/member, and viewer roles.
Contact
For privacy, access, correction, export, or deletion requests, contact joeyharnist@yahoo.com. Include “CMO AI privacy” in the subject and the email address associated with your account.