Privacy policy

Madder is in early access. This page says in plain words what we collect, what our agents can touch in your ad accounts, and how to get it all deleted. If something here is unclear, write to hello@madder.ai and a person will answer.

Last updated

The short version

Who we are

Madder (madder.ai) makes AI agents that plan, make, launch and watch ads for small businesses, in the business owner’s own ad account. Madder decides what data it collects and why, so we are responsible for it (the “controller” under the GDPR, the “business” under California law).

How to reach us: write to hello@madder.ai. Madder is run by its founder as an individual; there is no company behind it yet. When one is formed, its name and address will appear here. Early access is open only to businesses in the United States for now; before we offer Madder in the EU or the UK, we will name our representatives there on this page.

This policy covers this website, the early-access sign-up, and the Madder app.

What we collect on this site

You can read this site without giving us anything. When you ask for early access, we collect only what you type:

With each request we also record the time and which Madder page you sent it from.

These go into one waitlist file on our server that only the operator can read. They don’t go to any mailing-list or advertising service.

To stop repeated automated sign-ups, the server looks at your IP address for a minute. It keeps only a scrambled (hashed) form of it in memory, not on disk. Our web server also keeps standard access logs (IP address, browser, page, time) to keep the site running and spot abuse.

What we collect when you use Madder

We don’t ask for your date of birth, your ID or any sensitive personal information, and please don’t send us any in the chat.

Your ad accounts

You connect an ad platform by signing in on that platform’s own page (OAuth) and choosing what to grant. Madder gets only what you allow there, and never your platform password.

Meta is live today. Google Ads and TikTok are rolling out; when they arrive, the same rules apply to them.

With that access, the agents:

Your customers’ details. Today the agents see how many leads your ad forms bring and what each cost, not who sent them. When lead retrieval ships, we will read your lead-form answers (your customers’ names and contact details) only to show them to you, acting for you as your processor, and we will update this page before it starts.

Opening an ad account for you is not available yet. Today you open your own account on the platform. When the agents can open one for you, we will send the platform your business name, address, time zone and currency, the account will be opened in your name and billed to your card, and it will be yours from the first day. We will update this page before that starts.

We keep the access keys the platform gives us encrypted, and use them only to do what you asked. Data we get from Google APIs is used and transferred in line with the Google API Services User Data Policy, including its Limited Use requirements: we don’t use it for advertising to you, we don’t sell it, we don’t use it to train AI models, and people read it only with your permission, for security, or when the law requires.

To disconnect, use Disconnect in Madder or remove Madder in the platform’s own settings. Madder can no longer act in that account; ads already running keep running on the platform until you pause them there. Disconnecting does not delete what we already hold. To delete what we got from a platform (including through Facebook Login), email hello@madder.ai; removing Madder in Facebook’s settings also sends us a deletion request. That request reaches us as a line in our server log; we check for them, a person follows up on each one, and we delete the data within 30 days of it. Email is the quicker way.

How the AI agents use your data

Madder’s agents run on large language models from outside providers. To write a plan, make an ad or answer a question, we send them the text they need: your site’s text, your ad text, your results, and your messages to the agents. Anthropic’s models do the agents’ work. A smaller OpenAI model checks each chat message you send for misuse before the agents see it, and gives each chat its short name, so your chat messages reach OpenAI too. We don’t send your card (we don’t have it) or your platform passwords (we don’t have those either).

The text goes to these providers through a model gateway, OpenRouter, and each of them handles it under its own terms and privacy policy. We don’t use your data to train models of our own.

The agents suggest; you decide. Today every change in your ad account waits for your tap, so no decision with money or legal effect on you is made by software alone.

Why we use it

We use your data only to run Madder for you and to keep it safe. Under the GDPR, these are our legal reasons:

What we doLegal reason
Answer your early-access request (your email and site)You asked us to (steps before a contract)
Decide who gets in first, from the optional answersOur legitimate interest in letting people in a few at a time. The answers are optional: skip them and you keep your place.
Run Madder: read your site, make and launch ads, report resultsOur contract with you
Keep the site and the app secure, stop abuseOur legitimate interest in a safe service
Count visits to the site (not done today)Your consent, only if you say yes
Keep records the law requiresLegal obligation

Cookies and browser storage

By default the site and the app use only what they need to work: no tracking cookies, and none of it follows you across other sites.

NameWhat it does, and for how long
madder-consentEssential. Remembers your cookie choice so we don’t ask twice. Kept in your browser’s storage until you change it here or clear it. An older copy under madder.consent is moved to this name once.
madder.earlyEssential. Keeps the email you just sent, in this tab only, so the next page can pick it up. Gone when you close the tab.
madder.sessionEssential, in the Madder app only. Your sign-in (the access and refresh tokens), kept in your browser’s local storage, not a cookie, until you sign out.
madder.prefs, madder.setup.list, madder.agent, madder.draft, madder.draft.dismissedEssential, in the Madder app only. A local copy of your settings, your setup checklist, where you put the agents’ panel and the draft you are on, so pages open fast and you pick up where you left off. Kept in local storage until you sign out or clear it.
madder.waitlist, madder.quiz, madder.quizAnswers, madder.invite, madder.accessEssential, on the early-access, sign-in and welcome pages. Carry what you just typed or the invite you opened from one page to the next, in this tab only. Gone when you close the tab.

Counting visits is optional, and off today. The site runs no measurement at all right now, and the cookie card on the site says so. If we add it, it will count visits to learn which pages help, never for advertising, and only for people who chose “Allow counting visits” in the cookie card or below. If you choose “Essential only”, or never choose, it stays off. Closing the cookie card without choosing (for example with Escape) counts as “Essential only”. A browser that sends a Global Privacy Control or Do Not Track signal is treated as “Essential only”.

Who we share it with

We don’t sell your personal information, and we don’t share it for advertising. A few companies process data for us, only to run Madder and under their terms for business customers, which limit what they may do with it (for the AI providers, see the note in the table):

ServiceWhat they handle
HostingOur servers and database: your account, the waitlist file and server logs.
Sign-in and emailYour email address, to send sign-in codes and messages about your access.
AI model providersThe text the agents need for a task, sent through the OpenRouter model gateway to the model that does it. For the agents’ work that is Anthropic first, and other hosts of the same models (such as AWS, Azure or Google) only when it is down. For checking each chat message for misuse and naming chats it is OpenAI, or another host of the same model (such as Azure). The setting that limits them to providers that don’t keep the text is being turned on and is not on for every request yet (see “How the AI agents use your data”).
Ad platformsMeta, Google and TikTok, only the ones you connect. They already hold your ad account; we send them the campaigns you approve.

Our fonts are served from madder.ai itself, so reading this site sends nothing to a font service. We may also disclose data if the law requires it, or to a buyer if Madder is ever sold, under this same policy. For the current list of company names, email hello@madder.ai.

Where your data is processed

Our servers and database are in the EU (Finland). Sign-in, email and AI model providers may process data in the United States and other countries, so your data crosses borders whether you are in the US or in Europe. When data leaves the EU, the UK or Switzerland, we rely on the Standard Contractual Clauses (with the UK Addendum) or the EU-US Data Privacy Framework where the provider is certified.

How long we keep it

Your rights

Wherever you live, you can ask us to:

How: email hello@madder.ai from the address you signed up with, so we know it’s you. It costs nothing. We answer within 30 days (45 days where California law allows), usually much sooner.

If you are in the EU or the UK

You have these rights under the GDPR and the UK GDPR, and you can complain to your local data protection authority. We’d rather hear from you first, so we can fix it.

If you are in California or another US state with a privacy law

You have the right to know what we collect and why, to delete it, to correct it, and to opt out of its sale or sharing for targeted ads. We don’t sell or share personal information, so there is nothing to opt out of. We won’t treat you differently for using any of these rights. Someone you authorize can ask on your behalf.

In the words of California law, in the last 12 months we collected: identifiers (email, IP address), commercial information (your ad accounts’ campaigns, spend and results) and internet activity (server logs). We got them from you, from the ad platforms you connect, and from your public site, and used them only for the purposes in “Why we use it”. We collected no sensitive personal information. We honor Global Privacy Control; since we don’t sell or share, it changes nothing, and we treat it as “Essential only”.

How we protect it

Everything travels over HTTPS. Access keys from ad platforms are stored encrypted, the waitlist file is readable only by the operator, and each part of the app can read only the data it needs. No system is perfectly safe; if a breach affects your data, we tell you and the authorities as the law requires.

Children

Madder is for businesses and their owners. It is not meant for anyone under 18, and we don’t knowingly collect data from children. If you think a child sent us something, email hello@madder.ai and we delete it.

Changes to this policy

When we change what we collect or how we use it, we update this page and the date at the top. If a change affects data you’ve already given us, we email you before it takes effect.

Contact

Anything about your data, or anything else: hello@madder.ai. A person reads every email.