Privacy

Privacy Policy

Last updated 2026-09-28 · v0 · early access

This policy explains what Admiry.ai, a Barton Alto Holdings, LLC company (“Admiry”, “we”) collects, why, who sees it, how long we keep it, and how you delete it. It is written to be read, not skimmed: every section names the actual data and the actual service behind it.

Admiry is in early access. This is version v0 of the policy. Counsel will review it before Admiry leaves early access; when it changes, the date above changes and business owners with an account are told by e-mail. Nothing here is a substitute for the agreements you accept inside the product, which say in more detail what Admiry may do in your Google Ads account.

1. Who this covers

Admiry runs three things, and this one policy covers all of them:

  • The website at admiry.ai and www.admiry.ai, including the early-access application forms.
  • The Admiry marketing agent for local and service businesses at agent.admiry.ai, and the same agent reached through an AI assistant such as Meta Muse, Claude or ChatGPT (a “connector”).
  • The advertising platform for performance advertisers at ads.admiry.ai, and the ad delivery system behind it.

Admiry is operated from the United States and its servers are in the United States. If you use Admiry from elsewhere, your data is processed in the United States.

2. The website

Reading admiry.ai collects nothing about you. The site sets no cookies, runs no analytics and loads no third-party scripts or fonts; our web server keeps ordinary access logs (IP address, page, time, browser) only as long as security and running the site need them.

If you fill in an early-access form, what you type (your name, e-mail address, company, website and the answers to the form) is sent to us as an e-mail through Resend, our e-mail provider, and read by the founders. We use it to reply to you and to decide whom to onboard. It is not added to any marketing list.

3. The Admiry marketing agent

The agent plans and runs marketing for your business. To do that it keeps a record of your business, a record of you as its owner, and a record of everything it did on your behalf.

What you tell it

  • Your description of the business and your answers in the consultation (what you do, where, whom you want to reach, your offer, what a customer is worth to you, your monthly limit).
  • Your public website, if you give its address: Admiry reads up to 20 pages of it, keeps the text it needs to describe your services, and never reads pages behind a sign-in.
  • Your listing on Google Maps: to confirm which business you mean, Admiry looks up the name and address you gave in Google’s Places service and keeps only the matching name, address and place identifier.

From these it writes a “business knowledge” record and a marketing plan. Both are yours to read and correct at any time, on the plan page or by asking your assistant.

You, the owner

  • Google sign-in. You sign in with Google. Admiry asks Google for your e-mail address and your Google account identifier only (the “openid email” scopes): no profile, no contacts, no access to Gmail, Drive or any other Google service. Admiry keeps the e-mail address and identifier to know which businesses are yours.
  • Cookies. The agent sets only the cookies it needs to work, and none for advertising or analytics: a session cookie after you sign in (30 days), a short-lived cookie that binds a sign-in to the browser that started it, and, on the homepage, a visitor cookie that holds the draft you are working on (24 hours while anonymous, 30 days once you have signed in and claimed it). All are HttpOnly and sent only over HTTPS.
  • Access keys and grants. Keys you paste into an assistant and OAuth grants you give an assistant are stored hashed; Admiry keeps their label, when they were made and last used, and which business they open. You can see and revoke every one on your connect page.
  • IP address. Kept with sign-in attempts and API calls for rate limiting and abuse prevention.

Google Ads

If you link your own Google Ads account, Admiry keeps your Customer ID, the state of the link, and, once linked, the campaign, performance and cost data it needs to run and report on your ads. It changes ads only within the limit you set and only after you approve a plan. It never changes your billing, payment method or who has access to the account.

If you choose the prepaid option, Admiry opens a Google Ads account for your business inside its own manager account, and keeps that account’s number and its performance and cost data. Details are in the Prepayment Addendum you accept on the connect page.

Payments

Prepaid balances are paid by card on Stripe’s checkout page. Admiry never sees or stores your card number; it keeps the amount, the date, Stripe’s identifiers for the payment, and your balance and statement. Stripe’s own privacy policy applies to the payment page.

The audit log

Every action taken for your business, by you, by your assistant or by Admiry’s own scheduled jobs, is written to an audit log with who did it and when. You and your assistant can read it at any time. It exists so that you can always see what happened to your money.

Leads

When Admiry tracks calls, form submissions and bookings for your business (a feature not yet on in early access), the contact details of those leads are kept for 24 months and then purged, while counts are kept. You can delete any lead sooner or shorten that window for your business.

4. Your AI assistant

When you use Admiry through Meta Muse, Claude, ChatGPT or another assistant, the conversation happens inside that assistant, under its own terms and privacy policy, not ours. Admiry receives only what the assistant sends to its tools: your answers, your instructions and the business it is acting for. Admiry sends back the data the tool returns and a short sentence for the assistant to relay to you.

An assistant acts with the access you gave it. A key or grant that can only read cannot change anything; anything that spends money still needs your approval on the plan page or by an approval code. You can revoke an assistant’s access at any time on the connect page, and Admiry stops honouring it immediately.

5. How Admiry uses AI

The agent uses a large language model to turn your description and website into a business record, to read free-text answers in the consultation, and to draft plans and ad text. The model is Meta’s Model API. Under the tier Admiry uses, Meta may use the prompts and completions to improve its models. What reaches the model is the description of your business, the text of your public website, your consultation answers and the plan being drafted. Your e-mail address, sign-in details, access keys, Google Ads credentials and payment details are never part of a prompt.

Text an AI writes for you (ads, pages, plans) is shown to you for approval before it is used anywhere public, and you are responsible for what you approve.

6. The advertising platform

Advertisers on ads.admiry.ai have accounts that Admiry creates for them. For each account Admiry keeps a username, a hashed password, an API key, server-side session records, the campaigns, creatives, targeting lists and apps the advertiser sets up, and a record of payments received and spend. Uploaded creative assets are stored under their content hash. Measurement partners (MMPs) the advertiser connects send Admiry install and in-app event data for that advertiser’s campaigns.

7. Ad delivery data

To buy ad space for advertisers, Admiry receives bid requests from ad exchanges, in real time, for people it has no relationship with. This is the one place Admiry processes personal data about people who are not its customers, so it is described in full.

What a bid request contains

  • the device’s IP address and, from it, an approximate location (country, region, city);
  • the device’s advertising identifier (IDFA or GAID) when the platform and the person allow it, or a signal that the person has limited ad tracking;
  • device make, model, operating system and browser (the user agent);
  • the app or site and the ad placement, and the exchange’s own identifiers;
  • privacy signals sent with the request: COPPA, GDPR, the US privacy string, GPP, and the device’s limit-ad-tracking and do-not-track flags.

What Admiry does with it

  • decide whether and how much to bid, and which ad to show;
  • cap how often one device sees an advertiser’s ads;
  • detect fraud and invalid traffic;
  • measure results (impressions, clicks, installs and in-app events reported by measurement partners);
  • train the models that predict whether an ad is relevant.

Admiry honours the privacy signals it receives: a request flagged under COPPA is treated as a child’s and never profiled; requests with a GDPR flag, a US privacy opt-out, a GPP section or a limit-ad-tracking or do-not-track flag are served without an identity profile. Admiry does not sell this data, does not build profiles of named people, and does not combine it with the data in sections 2 to 6.

Your choices on your device

You can reset or turn off your advertising identifier in your phone’s settings (iOS: Settings, Privacy & Security, Tracking; Android: Settings, Privacy, Ads). Admiry respects those settings on the next request it sees from your device. You can also write to the address in section 13 with your advertising identifier and ask that Admiry delete the records that carry it.

8. Who sees your data

Admiry does not sell personal data. It shares data only with the services it needs to run:

  • Google: sign-in, the Places lookup, and the Google Ads API for the accounts you link or Admiry opens for you.
  • Meta: the Model API described in section 5; and Meta Muse, when it is the assistant you choose.
  • Stripe: card payments for prepaid balances.
  • Resend: e-mail we send you and the application forms on the website.
  • Hosting: Akamai (Linode) servers, Google Cloud and Amazon Web Services storage, all in the United States.
  • Ad exchanges and measurement partners: the bid responses and event data that ad delivery requires (section 7).

Each of them processes data under its own terms and only for the purpose Admiry engages it for. Admiry will also disclose data when the law requires it, or to protect Admiry, its customers or the public from fraud or harm, and it will tell you when it is allowed to.

9. How long we keep it

Retention periods by kind of data
DataKept for
Application e-mails from the websiteUntil we have replied and decided; then deleted
A business you started on the homepage but never claimed14 days, then deleted
An anonymous consultation on the homepage24 hours
A claimed consultation that was never finished7 days
Sign-in sessions30 days, or until you sign out
Keys and OAuth grantsUntil you revoke them; OAuth access tokens 1 hour, refresh tokens 30 days
Your business record, plan and audit logWhile your business is active, and 30 days after you delete it
Payment recordsAs long as the law requires for accounting, normally 7 years
Lead contact details24 months, then purged; counts kept
Bid and event logs (ad delivery)30 days in full; summarised records up to 180 days
Model training sets built from those logs90 days
Server access logsOnly as long as security and operations need them

10. Your choices and deletion

You can, at any time and without asking us:

  • read and correct your business record and plan on the plan page, or through your assistant;
  • revoke any key or assistant on the connect page;
  • unlink your Google Ads account from inside Google Ads (Admin, then Access and security);
  • sign out, which ends the session on that browser.

To delete your account and everything Admiry holds about your business, e-mail privacy@admiry.ai from the address you signed in with. Admiry stops any running ads, refunds an unspent prepaid balance to the card that paid it, and deletes the business record, plan, keys, grants and audit log within 30 days. It keeps only what accounting law requires (the payment records) and the summarised ad delivery records that carry no identifier of yours.

You can also ask for a copy of your data at the same address. Admiry answers within 30 days. If you are in a place whose law gives you further rights (for example California residents under the CCPA, or residents of the European Economic Area or the United Kingdom), you may exercise them the same way, and Admiry will not treat you differently for doing so.

11. Security

Everything travels over HTTPS. Passwords, keys, sessions and tokens are stored as hashes, never in the clear. Access keys expire, OAuth tokens rotate, and a stolen refresh token used twice revokes the whole grant. Anything that spends money needs an approval you give outside the assistant. Servers are in access-controlled environments and databases are backed up. No system is perfectly secure; if a breach affects your data, Admiry will tell you by e-mail without undue delay.

12. Children

Admiry’s products are for businesses and are not directed to anyone under 18. Admiry does not knowingly collect data from children; a bid request flagged as a child’s under COPPA is never profiled. If you believe a child has given Admiry personal data, write to the address below and it will be deleted.

13. Changes and contact

When this policy changes, the date at the top changes, and business owners and advertisers with an account are told by e-mail before a change that affects them takes effect. Earlier versions are available on request.

Questions, requests and complaints: privacy@admiry.ai.
Admiry.ai, a Barton Alto Holdings, LLC company, United States.