Your data runs your marketing. It doesn't run ours.
We store your connected-account data, strategy docs and drafts to do the work you approve. We never use any of it to train models. It lives on managed cloud infrastructure, and only your seats and our on-call engineers under audit can see it.
Data handling
Strategy docs and drafts are yours: export or delete them at any time from Settings. We never train models on your content, prompts, drafts or analytics — not ours, not a vendor's.
On cancellation, everything is exportable; deletion completes within 30 days of your request.
Where data lives
Application infrastructure runs on AWS (container images built and deployed via ECR and EC2). // OWNER: B-7 — confirm and publish the AWS region here; not readable from the repo (AWS_REGION is a deployment secret). Backups are encrypted. Model inference calls send only the minimum context needed for each task, under vendor terms that exclude training.
Access & control
Approve-everything is the default mode. Spend caps are yours alone to raise. Every agent action — drafted, approved, published, paused — is written to an audit log your seats can read and export.
Compliance
Built to the Indian Digital Personal Data Protection Act and GDPR from day one. // OWNER: B-7 — SOC 2 Type I status removed pending verification; add back only once true, with the report linked.
Connected accounts
| Integration | Scope requested | Why |
|---|---|---|
| Google Ads | adwords | Paid Ads agent creates and steers campaigns inside caps |
| Google Search Console | webmasters.readonly | SEO and AI Visibility agents read queries and indexation |
| GA4 | analytics.readonly | Analytics agent reads traffic and conversions |
| Meta Ads | ads_read, ads_management, business_management | Paid Ads agent creates and steers campaigns inside caps |
| LinkedIn Ads | r_ads, r_ads_reporting, rw_ads | Paid Ads agent reads and steers LinkedIn ad spend |
| X Ads | ads.read, offline.access | Paid Ads agent reads X ad performance |
| Webflow / WordPress | site API token | SEO agent applies approved on-page fixes and publishes them |
Sub-processors
| Vendor | Purpose | Region |
|---|---|---|
| AWS | Application hosting (ECR + EC2) | // OWNER: B-7 — region not in repo |
| Supabase | Database, auth, file storage | // OWNER: B-7 — confirm region |
| OpenAI, Anthropic, Google (Gemini), Perplexity | Model inference (no training, per vendor API terms) | US / global |
| Resend | Transactional email | US |
| Inngest | Background job orchestration | US |
Report a vulnerability
Email security@heynoor.ai. We acknowledge within 2 business days and share a fix timeline within 10.