Privacy policy
Madder is in early access. This page says in plain words what we collect, what our agents can touch in your ad accounts, and how to get it all deleted. If something here is unclear, write to hello@madder.ai and a person will answer.
Last updated
The short version
- Early access is open to businesses in the United States for now. To join, you give us your email and your site. The next page has two optional questions.
- You connect your own ad account through the platform’s own sign-in: Meta today, Google and TikTok when they launch. You choose what to grant, and you can take it back any day.
- We never see or hold your card. The ad platform bills you directly.
- AI model providers process the text of your site and your ads to do the work: Anthropic for the agents’ work, and OpenAI for checking each chat message for misuse and naming chats. Each provider handles it under its own terms.
- We don’t sell your data, and we don’t use it to show you ads.
- The site uses only essential storage and doesn’t count visits. If we ever add counting, it runs only if you say yes.
- Email hello@madder.ai for a copy of your data or to have it deleted.
Who we are
Madder (madder.ai) makes AI agents that plan, make, launch and watch ads for small businesses, in the business owner’s own ad account. Madder decides what data it collects and why, so we are responsible for it (the “controller” under the GDPR, the “business” under California law).
How to reach us: write to hello@madder.ai. Madder is run by its founder as an individual; there is no company behind it yet. When one is formed, its name and address will appear here. Early access is open only to businesses in the United States for now; before we offer Madder in the EU or the UK, we will name our representatives there on this page.
This policy covers this website, the early-access sign-up, and the Madder app.
What we collect on this site
You can read this site without giving us anything. When you ask for early access, we collect only what you type:
- Your email, so the founder can write back about your access.
- Your site address, so we can read what you sell before you start.
- Optional answers on the early-access page: where you run ads today and roughly what you spend a month. You can skip them. If you answer, we use them to decide who gets in first.
- What you want to promote, if you tell us on the early-access page (a short note, up to 280 characters).
With each request we also record the time and which Madder page you sent it from.
These go into one waitlist file on our server that only the operator can read. They don’t go to any mailing-list or advertising service.
To stop repeated automated sign-ups, the server looks at your IP address for a minute. It keeps only a scrambled (hashed) form of it in memory, not on disk. Our web server also keeps standard access logs (IP address, browser, page, time) to keep the site running and spot abuse.
What we collect when you use Madder
- Your account: your email, and the one-time sign-in codes we email you. We don’t use passwords.
- Your business: the public pages of your site the agents read, including the photos on them, which the Creative uses to make your ads, and what you tell the agents in the chat.
- The work: plans, ads, the photos and text used in them, and every approval you give or decline.
- Your ad accounts: what you grant when you connect them (see the next section).
We don’t ask for your date of birth, your ID or any sensitive personal information, and please don’t send us any in the chat.
Your ad accounts
You connect an ad platform by signing in on that platform’s own page (OAuth) and choosing what to grant. Madder gets only what you allow there, and never your platform password.
Meta is live today. Google Ads and TikTok are rolling out; when they arrive, the same rules apply to them.
- Meta (Facebook and Instagram): the ad accounts you pick, your business portfolios (Meta requires this to manage ads; we only use it to find your ad accounts) and the Page your ads run from. Meta’s Page permission would let us read its posts; we don’t.
- Google Ads: access to the Google Ads accounts your Google login can reach (Google grants it that way), and your Google account ID, to tell connections apart. The agents work only in the one you choose in Madder.
- TikTok: the TikTok ad accounts you authorize.
With that access, the agents:
- Read campaigns, ads, spend and results, so they can report and suggest fixes.
- Write, only with your tap. Nothing launches and your daily budget never goes up until you approve it in Madder. Today every change, including a pause or a budget move, waits for your tap. Pausing an expensive ad and moving money between campaigns inside your approved budget is being built; we will update this page before it starts.
- Never touch your card. The platform bills you directly. We never see, store or charge it.
- Never read your messages. No inbox, no DMs, no customer conversations.
Your customers’ details. Today the agents see how many leads your ad forms bring and what each cost, not who sent them. When lead retrieval ships, we will read your lead-form answers (your customers’ names and contact details) only to show them to you, acting for you as your processor, and we will update this page before it starts.
Opening an ad account for you is not available yet. Today you open your own account on the platform. When the agents can open one for you, we will send the platform your business name, address, time zone and currency, the account will be opened in your name and billed to your card, and it will be yours from the first day. We will update this page before that starts.
We keep the access keys the platform gives us encrypted, and use them only to do what you asked. Data we get from Google APIs is used and transferred in line with the Google API Services User Data Policy, including its Limited Use requirements: we don’t use it for advertising to you, we don’t sell it, we don’t use it to train AI models, and people read it only with your permission, for security, or when the law requires.
To disconnect, use Disconnect in Madder or remove Madder in the platform’s own settings. Madder can no longer act in that account; ads already running keep running on the platform until you pause them there. Disconnecting does not delete what we already hold. To delete what we got from a platform (including through Facebook Login), email hello@madder.ai; removing Madder in Facebook’s settings also sends us a deletion request. That request reaches us as a line in our server log; we check for them, a person follows up on each one, and we delete the data within 30 days of it. Email is the quicker way.
How the AI agents use your data
Madder’s agents run on large language models from outside providers. To write a plan, make an ad or answer a question, we send them the text they need: your site’s text, your ad text, your results, and your messages to the agents. Anthropic’s models do the agents’ work. A smaller OpenAI model checks each chat message you send for misuse before the agents see it, and gives each chat its short name, so your chat messages reach OpenAI too. We don’t send your card (we don’t have it) or your platform passwords (we don’t have those either).
The text goes to these providers through a model gateway, OpenRouter, and each of them handles it under its own terms and privacy policy. We don’t use your data to train models of our own.
The agents suggest; you decide. Today every change in your ad account waits for your tap, so no decision with money or legal effect on you is made by software alone.
Why we use it
We use your data only to run Madder for you and to keep it safe. Under the GDPR, these are our legal reasons:
| What we do | Legal reason |
|---|---|
| Answer your early-access request (your email and site) | You asked us to (steps before a contract) |
| Decide who gets in first, from the optional answers | Our legitimate interest in letting people in a few at a time. The answers are optional: skip them and you keep your place. |
| Run Madder: read your site, make and launch ads, report results | Our contract with you |
| Keep the site and the app secure, stop abuse | Our legitimate interest in a safe service |
| Count visits to the site (not done today) | Your consent, only if you say yes |
| Keep records the law requires | Legal obligation |
Where your data is processed
Our servers and database are in the EU (Finland). Sign-in, email and AI model providers may process data in the United States and other countries, so your data crosses borders whether you are in the US or in Europe. When data leaves the EU, the UK or Switzerland, we rely on the Standard Contractual Clauses (with the UK Addendum) or the EU-US Data Privacy Framework where the provider is certified.
How long we keep it
- Waitlist details: until you get access or 12 months pass, then we remove them by hand; sooner if you ask.
- Your Madder account, including plans, ads and the agents’ notes: while your account is open. After you ask us to delete it, within 30 days.
- Data from your ad accounts: while they are connected. After you disconnect, email us (or remove Madder in Facebook’s settings, which logs a request that a person follows up), and a person deletes it within 30 days of the request. Your ads and their history stay in your ad account, which is yours.
- Server logs and backups: nightly database backups are kept for 14 days. We also take a copy of the database before each software update and keep the copies from the last 10 updates, so a deleted item can stay in one of those copies until 10 more updates have gone out. Web server logs are kept for about 14 days. The app’s own logs are kept by size rather than by age, so they can reach further back; we are setting them to 14 days as well.
- Your cookie choice: in your browser until you change or clear it.
Your rights
Wherever you live, you can ask us to:
- give you a copy of your data, in a common format you can take elsewhere;
- correct it;
- delete it;
- stop or limit using it for something, or object to how we use it;
- withdraw a consent you gave, such as to counting visits, at any time.
How: email hello@madder.ai from the address you signed up with, so we know it’s you. It costs nothing. We answer within 30 days (45 days where California law allows), usually much sooner.
If you are in the EU or the UK
You have these rights under the GDPR and the UK GDPR, and you can complain to your local data protection authority. We’d rather hear from you first, so we can fix it.
If you are in California or another US state with a privacy law
You have the right to know what we collect and why, to delete it, to correct it, and to opt out of its sale or sharing for targeted ads. We don’t sell or share personal information, so there is nothing to opt out of. We won’t treat you differently for using any of these rights. Someone you authorize can ask on your behalf.
In the words of California law, in the last 12 months we collected: identifiers (email, IP address), commercial information (your ad accounts’ campaigns, spend and results) and internet activity (server logs). We got them from you, from the ad platforms you connect, and from your public site, and used them only for the purposes in “Why we use it”. We collected no sensitive personal information. We honor Global Privacy Control; since we don’t sell or share, it changes nothing, and we treat it as “Essential only”.
How we protect it
Everything travels over HTTPS. Access keys from ad platforms are stored encrypted, the waitlist file is readable only by the operator, and each part of the app can read only the data it needs. No system is perfectly safe; if a breach affects your data, we tell you and the authorities as the law requires.
Children
Madder is for businesses and their owners. It is not meant for anyone under 18, and we don’t knowingly collect data from children. If you think a child sent us something, email hello@madder.ai and we delete it.
Changes to this policy
When we change what we collect or how we use it, we update this page and the date at the top. If a change affects data you’ve already given us, we email you before it takes effect.
Contact
Anything about your data, or anything else: hello@madder.ai. A person reads every email.