Privacy Policy

Last updated July 26, 2026

Vitalis AI is an autonomous marketing engine. You connect your advertising accounts, and Vitalis AI researches, plans, and builds campaigns for you. No advertising money is ever spent without an explicit human approval click. This page explains exactly what we collect, why, and how to get rid of it.

Our use of artificial intelligence

Vitalis AI is an AI product. The research, strategy, ad copy, images, and video it produces are generated by artificial intelligence, not written or filmed by people. AI can be wrong, and it can produce claims that are inaccurate for your business - which is why every campaign is built paused and shown to you before anything runs. You review and approve what goes live, and you remain responsible for the accuracy of the claims in ads you approve. Performance figures shown in the product are your own reported ad-platform and payment-processor data, not predictions or guarantees.

Your business data and advertising data are sent to our AI providers solely to produce your work. They are not used to train AI models - ours or anyone else’s. Generated images and video are synthetic; where an ad depicts a person, that person is AI-generated and not a real customer or a genuine testimonial unless you supplied that material yourself.

What we collect

  • Your account. Email address and authentication details, so you can sign in.
  • Advertising data. When you connect Meta or Google Ads, we read your ad accounts, campaigns, ad sets, ads, and their performance metrics - spend, impressions, clicks, and conversions. We use this to report your results and to let the agents make grounded decisions. See the platform-specific sections below.
  • Access tokens. The credential that lets us reach your ad account on your behalf.
  • Business information you give us. Your products, pricing, service area, budget, objective, and anything you add to the knowledge base.
  • Creative assets. Images and videos you upload, and the ad creative generated for you.

Data collection at a glance

The short version of everything below - what we collect, why, whether it leaves us, and whether it is tied to your identity.

DataWhyLinked to youShared
Email + loginAccount accessYesAuth provider only
Ad account dataYour reporting + agent decisionsYesAI providers, to do your work
Access tokensReaching your ad account for youYesNever - encrypted, never displayed
Business info you enterGrounding the ads in your real offerYesAI providers, to do your work
Uploads + generated creativeBuilding your adsYesAd platforms you connect
Payment-processor revenueTrue ROAS reportingYesNever
BillingSubscription + usage chargesYesStripe (we never see card numbers)
Website analyticsUnderstanding site trafficNo - aggregateAnalytics provider

We do not sell your data, and we run no advertising trackers inside the product. The signed-in Vitalis AI console contains no third-party analytics or advertising pixels - your campaign data, revenue, and business information are never fed to an ad network. Our public marketing pages may use standard website analytics (such as Google Analytics) and, where a conversion pixel is present (such as the Meta pixel), those providers may set cookies to measure visits and ad performance in aggregate. You can block these with your browser or an ad blocker with no loss of product functionality.

How your access tokens are protected

Access tokens are encrypted at rest with AES-256-GCM before they are written to the database. The encryption key is held only by the application server, never in the database. Tokens are never displayed back to you, never sent to your browser, and never written to logs. Each workspace can only reach its own data, enforced at the database level.

Google user data

If you connect Google Ads, you grant Vitalis AI the https://www.googleapis.com/auth/adwords scope for the Google Ads account you choose. This section describes exactly what we do with it.

  • What we access. Your Google Ads campaigns, ad groups, and their performance metrics (cost, impressions, clicks, conversions, conversion value), and the list of ad accounts your login can reach so you can pick which one to connect.
  • Why we access it. Two purposes only: (1) to show you reporting on your own advertising, and (2) to create campaigns, ad groups, and ads in a paused state that you review and approve. We do not enable any campaign or spend any budget without your explicit approval click.
  • How it’s stored. We store an encrypted refresh token (AES-256-GCM) so we can keep reporting for you without asking you to log in again. Performance data is fetched from Google on demand and shown to you.
  • How to revoke it. Disconnect Google on the Connections page, or remove Vitalis AI at your Google Account permissions. Either one immediately ends our access.

Limited Use.Vitalis AI’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we do not sell Google user data; we do not use it for advertising outside of operating your own campaigns at your direction; we do not transfer it to third parties except as needed to provide the service to you, for security, or to comply with the law; and we do not allow humans to read it except with your consent, for security, to comply with the law, or where the data is aggregated and de-identified. We never use Google user data to train AI models.

Meta user data

If you connect Meta, we access the ad account, Facebook Page, and pixel you select - their performance metrics for reporting, and the ability to create campaigns and ads in a paused state for your approval. The same rules apply: it is used only to operate Vitalis AI for you, is never sold, and is never used to train models. You can revoke access at any time from your Facebook Business Integrations settings.

What we do NOT do

  • We do not sell your data, or share it with data brokers or advertisers.
  • We do not use your business data to train anyone’s general-purpose AI models.
  • We do not post to your accounts or spend your ad budget without your explicit approval.

Service providers we share data with

We use a small number of processors to run the product. Each receives only what it needs to do its job. The full list, with what each one processes and where, is on our sub-processors page.

  • Supabase - database, authentication, and file storage.
  • Anthropic - powers the agents and the assistant. Your campaign and performance context is sent to generate plans and copy. It is not used to train models.
  • Runway, Higgsfield and Google (Veo) - generate ad images and video from the creative briefs. They receive the scene descriptions we write, not your performance data.
  • Meta (and other ad platforms you connect) - we read your performance data and, once you approve, create campaigns in your account.
  • Stripe - subscription billing. Stripe handles your card details directly; we never see or store them.
  • Vercel - application hosting.

Government and legal requests

We may receive requests from law enforcement or other public authorities for user data. Our practice when that happens:

  • We review legality first. We do not disclose data in response to a request unless we are satisfied it is valid, properly scoped, and legally binding on us.
  • We challenge requests we believe are unlawful, overbroad, or improperly issued, and we will seek to narrow or resist them where we have grounds to do so.
  • We disclose the minimum necessary. We provide only the specific data a valid request actually compels - never a broader export for convenience.
  • We document every request - what was asked, who asked, what we concluded about its legality, what we disclosed, and when.
  • We notify affected users where we are legally permitted to do so.

How long we keep it

We keep your data for as long as your account is active. Disconnecting a platform deletes that platform’s access token immediately. Deleting your account removes your data - see Delete your data.

Your rights

  • Disconnect any platform at any time, from the Connections page.
  • Request a copy of the data we hold about you.
  • Request deletion of your account and all associated data.
  • Correct anything inaccurate.

Revoking Vitalis AI from your Facebook Business Integrations settings also immediately cuts off our access to your Meta account.

Contact

Questions, access requests, or deletion requests: support@govitalisai.com.