Security & Privacy

Your data runs your marketing. It doesn't run ours.

We store your connected-account data, strategy docs and drafts to do the work you approve. We never use any of it to train models. It lives on managed cloud infrastructure, and only your seats and our on-call engineers under audit can see it.

Data handling

Strategy docs and drafts are yours: export or delete them at any time from Settings. We never train models on your content, prompts, drafts or analytics — not ours, not a vendor's.

On cancellation, everything is exportable; deletion completes within 30 days of your request.

Where data lives

Application infrastructure runs on AWS (container images built and deployed via ECR and EC2). // OWNER: B-7 — confirm and publish the AWS region here; not readable from the repo (AWS_REGION is a deployment secret). Backups are encrypted. Model inference calls send only the minimum context needed for each task, under vendor terms that exclude training.

Access & control

Approve-everything is the default mode. Spend caps are yours alone to raise. Every agent action — drafted, approved, published, paused — is written to an audit log your seats can read and export.

Audit log · example
09:12ContentDraftedBlog: 'Why AI answers matter' → queue
09:40PriyaApprovedBlog: 'Why AI answers matter'
09:41ContentPublishedwebflow · /blog/ai-answers
11:03Paid AdsAdjusted bidQ4 retargeting · within ₹40,000 cap

Compliance

DPDP Act 2023GDPR

Built to the Indian Digital Personal Data Protection Act and GDPR from day one. // OWNER: B-7 — SOC 2 Type I status removed pending verification; add back only once true, with the report linked.

Connected accounts

IntegrationScope requestedWhy
Google AdsadwordsPaid Ads agent creates and steers campaigns inside caps
Google Search Consolewebmasters.readonlySEO and AI Visibility agents read queries and indexation
GA4analytics.readonlyAnalytics agent reads traffic and conversions
Meta Adsads_read, ads_management, business_managementPaid Ads agent creates and steers campaigns inside caps
LinkedIn Adsr_ads, r_ads_reporting, rw_adsPaid Ads agent reads and steers LinkedIn ad spend
X Adsads.read, offline.accessPaid Ads agent reads X ad performance
Webflow / WordPresssite API tokenSEO agent applies approved on-page fixes and publishes them

Sub-processors

VendorPurposeRegion
AWSApplication hosting (ECR + EC2)// OWNER: B-7 — region not in repo
SupabaseDatabase, auth, file storage// OWNER: B-7 — confirm region
OpenAI, Anthropic, Google (Gemini), PerplexityModel inference (no training, per vendor API terms)US / global
ResendTransactional emailUS
InngestBackground job orchestrationUS

Report a vulnerability

Email security@heynoor.ai. We acknowledge within 2 business days and share a fix timeline within 10.

Enter your website. Meet your marketing team.

Free · no credit card · first plan in ~2 minutes