Privacy Policy
Dimarkass is an AI digital marketing assistant. It advises on selling online, manages advertising campaigns on your behalf after you approve each change, and reports on your organic and paid performance. This policy explains what data it handles and why. Effective 2 September 2026.
Who is responsible
Dimarkass is operated by Nicolás Méndez as the data controller. For any privacy question, or to exercise the rights listed below, write to nicolas.mendez.gonzalez@gmail.com.
What we collect
Account data
When you sign up with Google or with an email address and password, we receive your email address and, for Google sign-in, your name and profile picture. Authentication is handled by Supabase Auth; we never see or store your Google password, and email/password credentials are stored only as salted hashes by Supabase.
Business profile
What you tell the assistant about your business during onboarding or on the Profile page: business name, website URL, industry, target market, products and marketing goals. You choose what to provide; the assistant gives weaker advice without it, but the app works.
Platform credentials
To read your analytics and manage your campaigns, you connect your own Google Ads, Google Search Console, Google Analytics 4, Meta Ads and Shopify accounts. The resulting API keys, access tokens and refresh tokens are encrypted in our application before they reach the database, using a key held only by the server. The database stores ciphertext only. You can disconnect any platform at any time from the Profile page, which deletes the stored credential.
Content you create
- Conversations— your messages and the assistant's replies, so you can return to a chat later.
- Uploaded documents — files you add to your private knowledge base, and the text chunks derived from them.
- Campaign assets — product photos taken from a page you point us at, images you upload by hand, and the ad creatives the assistant generates from them.
- Audit trail — every tool the assistant ran, its arguments, its result and whether you approved it. This is a safety record: it is how you and we can reconstruct what was changed in an ad account and on whose approval.
Platform data we read on your behalf
Campaign, ad set, ad, spend and performance figures from Google Ads and Meta Ads; search queries, clicks and impressions from Search Console; sessions, conversions and traffic sources from Google Analytics 4; and order totals from Shopify where connected. These are cached so your dashboard loads without re-querying every platform, and so we can alert you when a metric moves sharply.
What we do with it
- Run the assistant and answer your questions.
- Show your dashboard, trends and alerts, and send the reminder email digest if you enable it.
- Prepare advertising changes for your approval, and execute the ones you approve.
- Keep the audit trail and enforce spending guardrails you configure.
- Diagnose failures and keep the service working.
We do not sell your data, we do not share it with advertising networks for their own purposes, and we do not use your content to train our own models.
Legal bases (GDPR)
- Contract — providing the service you signed up for: your account, conversations, connected platforms and campaign actions.
- Legitimate interest — security, abuse prevention, the audit trail, and diagnosing failures.
- Consent — optional extras you switch on, such as reminder emails. Withdraw it any time in your profile.
Google user data
Dimarkass requests access to Google Ads, Search Console and Google Analytics on your explicit authorisation, and only to the scopes it needs: reading your advertising and analytics data, and — if you enable it — making the configuration or campaign changes you approve.
Dimarkass's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide and improve the features you see in the app, is never sold, is never used for advertising, and is never read by a human except with your explicit permission, for security purposes, or where required by law.
Meta platform data
Where you connect a Meta ad account and Facebook Page, Dimarkass reads campaign structure and performance data and — only after you approve a specific change — creates or edits campaigns, ad sets, ads and creatives. Meta platform data is used solely to deliver those features to you, is not transferred to third parties beyond the processors named below, and is deleted when you disconnect the platform or delete your account.
Processors we use
These providers process data on our instructions so the service can function:
- Supabase — authentication, database and file storage for your account, conversations, credentials and campaign assets.
- Google Cloud Run — hosting for the backend.
- Vercel — hosting for the web frontend.
- OpenRouter— routes your prompts to the language and image models that generate the assistant's answers and ad creatives. Your message text, the retrieved knowledge-base passages and the platform figures under discussion are sent to the model serving your request.
- Langfuse — tracing, so a failed or poor answer can be diagnosed. Traces can include prompt and answer text.
- Tavily — web search, when the assistant researches a market or competitor. Search queries are sent; your account data is not.
- Gmail SMTP — delivery of the reminder email digest, if you enable it.
Some of these providers operate outside the European Economic Area. Where that is the case, transfers rely on the safeguards those providers offer, such as the European Commission's Standard Contractual Clauses.
What deliberately never leaves
- Search embeddings for your documents are computed on our own server. Your uploaded files are not sent to an external embedding service.
- Our application logs carry metadata only — request identifiers, user identifiers, timings, error codes. They never contain chat text, prompts, knowledge-base passages, ad copy or uploaded documents. This is enforced by an automated test, not only by policy.
- No personal data is placed into a generated image. The name and contact details on your account are stripped out of the brief before any creative is drawn.
Security
Traffic is encrypted in transit. Platform credentials are encrypted at the application layer before storage. Database access is constrained by row-level security, so a query can only reach rows belonging to the signed-in user. Advertising changes cannot be executed by the assistant on its own: every write is presented to you as an approval card first, and budget limits are enforced in code.
No system is perfect. If you believe your account has been compromised, write to nicolas.mendez.gonzalez@gmail.com.
How long we keep it
Account data, conversations, documents, campaign assets and cached metrics are kept while your account exists. The audit trail is kept for the life of the account, because its purpose is to explain past changes to your ad accounts. Everything is deleted when you delete your account.
Deleting your data
You can delete your account and all associated data yourself from the Profile page, or ask us to do it. Full instructions and what exactly gets removed are on the Data Deletion page.
Your rights
If you are in the EEA or the UK you have the right to access, rectification, erasure, restriction, portability and objection regarding your personal data. Write to nicolas.mendez.gonzalez@gmail.com and we will respond within one month. You may also complain to your national data protection authority; in Spain this is the Agencia Española de Protección de Datos (AEPD).
Cookies and local storage
Dimarkass stores your authentication session and interface preferences (theme, language) in your browser. There are no advertising cookies and no cross-site tracking. Clearing your browser storage signs you out.
Children
The service is for business use and is not intended for anyone under 18. We do not knowingly collect data from children.
Changes to this policy
If this policy changes materially, the date at the top changes and, for anything that affects how your data is used, we notify you by email before it takes effect.