Privacy Policy
Polyads
Last updated: 8 July 2026
This Privacy Policy explains how Npcat LLC ("we," "us," or "our") collects, uses, discloses, and protects personal data in connection with Polyads, our competitive advertising-analytics service available at polyads.ai and through the Polyads command-line interface (the "Service"). It also describes the rights and choices available to you.
For the purposes of the EU and UK General Data Protection Regulation ("GDPR"), Npcat LLC is the controller of the personal data described below, except where we act as an independent controller or, in limited cases, as a processor, as explained in Section 9 and in our Data Processing Agreement.
Contact: Npcat LLC, 30 N Gould St Ste R, Sheridan, WY 82801, United States Email: support@polyads.ai
Npcat LLC operates the Polyads service from the European Union. EEA and UK individuals may contact us about their personal data at support@polyads.ai.
1. Scope
This Policy applies to personal data we process about: (a) visitors to our website; (b) account holders and their team members who use the Service; and (c) individuals whose personal data may appear within the publicly available advertising content that the Service analyzes ("advertising data subjects" – see Section 5). The Service is a business tool intended for users who are at least 18 years old and acting for business purposes (see Section 15).
2. A note on how Polyads works
Polyads analyzes advertising that advertisers have made publicly available through advertising-transparency resources such as the Meta Ad Library. It stores those creatives, extracts creative attributes, and computes analytics, including a "Creative Score." We describe below both the limited personal data we hold about our users and the third-party advertising content we ingest, which can incidentally contain personal data of people other than our users.
3. Personal data we collect
3.1 Data about account holders and users
| Category | What it includes | Source |
|---|---|---|
| Account and identity | A unique account identifier and your email address (authentication itself, including any password or single-sign-on credentials, is handled by our identity provider and is not stored by us); workspace name; role; onboarding preferences (such as your stated goal, chosen agent, and operating system) | You / your identity provider |
| Workspace and membership | Workspaces you belong to, team-member records, roles, and invitations | You |
| Access tokens | Command-line and session tokens used to authenticate the CLI and agent access (stored by us in hashed form on our servers; a newly issued CLI token is held briefly in plain text on our servers until your CLI retrieves it, then removed); records of the agent type, operating system, and device name associated with a connection | You / your device |
| Usage and activity | Records of your interactions with the Service, including commands run through the CLI (which may include the command inputs and responses), which analyses and content you load, model-usage and cost telemetry, which insights you have viewed, and application logs (account identifier, email, endpoint, timing, and similar diagnostic data) | Automatically |
| Approximate location | A coarse "city, region, country" label derived from your IP address when you connect an agent, shown to confirm the connection request (we store only the coarse label, not the full IP) | Automatically |
| Product analytics | Page views and interactions within the application (such as pages viewed, referring page, page title, viewport size, and elements clicked), collected through analytics tooling (see Section 6) | Automatically |
| Research work-product | Content you and your connected agent create in the Service – for example, agent sessions, hypotheses and hypothesis tests, notes and supporting evidence, insights, and the tags and tag taxonomy you apply to advertising creatives (this is analysis about competitors' ads and includes the author's account identifier) | You / your agent |
| Communications | The content of messages you send to us (for example, support requests to support@polyads.ai) | You |
| Payment and billing | Your subscription plan, trial and subscription status, and billing identifiers (such as customer and subscription references) needed to operate paid subscriptions and the free trial; card details are entered directly with our payment processor and are not stored by us | You / our payment processor |
Payment card details are processed directly by our third-party payment processor (Stripe) under its own terms and privacy notice; we do not receive or store full card numbers. We use the billing identifiers it returns to manage your paid subscription and free trial, to recognise your subscription status, and to provide the Service. We will describe any material change to how we process payment data before it takes effect.
3.2 Data on your own device
The Polyads CLI stores an access token and basic account identifiers locally on your own machine so that the CLI can authenticate. This data resides on your device, under your control, and is not part of our systems.
3.3 Advertising content we ingest
To provide the Service, we collect and store publicly available advertising content about the advertiser pages you choose to track, including advertiser page names and profile images, ad copy and creative text, calls to action, landing-page references, advertising-library references, and the associated images and videos. This content, and the attributes we extract from it, can incidentally contain personal data of individuals other than our users (for example, faces, names, testimonials, or creator content). Section 5 explains how we handle it.
4. How and why we use personal data, and our legal bases
Where GDPR applies, we rely on the following legal bases.
| Purpose | Personal data used | Legal basis (GDPR) |
|---|---|---|
| Provide, operate, and secure the Service; authenticate users and agents; maintain accounts, workspaces, and your research work-product | Account, membership, access-token, usage, and research work-product data | Performance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) in operating and securing the Service |
| Analyze publicly available advertising content and compute the Creative Score and other analytics | Advertising content (Section 3.3) | Legitimate interests (Art. 6(1)(f)) – see Section 5 |
| Understand and improve how the Service is used (product analytics and diagnostics) | Usage and product-analytics data | Legitimate interests (Art. 6(1)(f)) in improving the Service |
| Respond to your requests and provide support | Communications data | Legitimate interests (Art. 6(1)(f)); performance of a contract |
| Comply with law and enforce our terms; establish, exercise, or defend legal claims | As relevant | Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) |
| Send you service or, where applicable, marketing communications | Contact data | Legitimate interests (Art. 6(1)(f)); consent (Art. 6(1)(a)) where required |
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms; you may object as described in Section 12. The Creative Score and related analytics involve statistical scoring of advertisements, not automated decisions that produce legal or similarly significant effects on individuals; we do not carry out such automated decision-making about individuals.
5. Advertising data and people featured in ads (GDPR Article 14)
Because the Service analyzes advertising that advertisers have made public, the content we ingest can contain personal data of people who are neither our users nor our customers – for example, brand representatives, content creators, and individuals depicted or named in ads. This Section is our transparency notice to those individuals under Article 14 of the GDPR.
- Source of the data. We obtain this content from publicly accessible sources, principally the Meta Ad Library, including through third-party data providers, together with the associated creative files. This is content that advertisers themselves made public through advertising-transparency resources.
- Categories of data. Advertiser and page identifiers; advertising creatives (images and video); ad copy and related text; and attributes we extract from the creatives. This can include a person's image, name, or words where these appear in the advertisement itself.
- Categories of data subjects. Advertisers and their representatives; content creators and people appearing in user-generated or endorsement content; and other individuals depicted or named in advertisements.
- Purpose and legal basis. We process this content for competitive advertising research and analytics (including computing the Creative Score) on advertising that advertisers deliberately published. Our legal basis is our and our customers' legitimate interests (Art. 6(1)(f)). We have carried out a legitimate-interests assessment (balancing test). In summary: the data was published publicly by the advertiser in a transparency library that exists for public scrutiny; we analyze creative attributes and do not build profiles of, identify, enrich, contact, or make decisions about the individuals; we apply data minimization, store data securely, and provide the objection and erasure routes below. We have concluded that our legitimate interests are not overridden by the rights and freedoms of the individuals in the ordinary case.
- Notifying individuals. Because we hold no contact details for the large and continuously changing set of individuals who may appear in this content, notifying each of them individually would involve disproportionate effort. In line with Article 14(5)(b) of the GDPR, we therefore provide this information publicly through this Policy instead of contacting each individual.
- Retention. We retain this content for as long as it is relevant to the Service and as described in Section 11.
- Your rights. If you are featured in advertising content we hold, you may object to our processing and request erasure or restriction by emailing support@polyads.ai (see Section 12). This is the same channel as our rightsholder-complaint and takedown process.
6. Cookies, similar technologies, and analytics
We do not display a cookie banner. Instead, we explain here what we use.
- Strictly necessary and functional. We use cookies and similar technologies that are strictly necessary to operate and secure the Service, and to remember your interface preferences – for example, to keep you signed in, secure your session, and remember settings such as the state of the navigation sidebar. Because these are essential to provide the Service you have requested, they do not require consent under applicable law.
- Product analytics. We use PostHog as our product-analytics provider to record page views and interactions within the application (such as pages viewed, referring page, page title, viewport size, and elements clicked), so we can understand and improve how the Service is used. PostHog processes this data in the European Union (EU) as our service provider, and analytics requests are routed through our own domain. This includes anonymous usage before you create an account, which is later associated with your account when you sign in. We do not use advertising, cross-context behavioral, or cross-site tracking cookies, we do not share this data with any advertising network, and we do not sell or share your personal information.
- Website personalization. We use a first-party cookie ("pv_profile," lasting up to about one year) to remember which version of our landing page to show you. This cookie is not strictly necessary; it is not used for advertising or cross-site tracking.
- Your choices. You can block or delete cookies through your browser settings, though the Service may not function properly without the strictly necessary ones. If you are in the EEA or UK and wish to object to non-essential cookies or product analytics, contact us at support@polyads.ai.
7. How we share personal data
We do not sell your personal data. Personal data is accessed within our organization, and shared with third parties, only as follows:
- Service providers (processors and subprocessors). With vendors that process personal data on our behalf to provide the Service. Where they process personal data on our behalf, we will put in place data-processing terms with them as required by applicable law. See Section 8.
- Our own personnel. Authorized Npcat LLC personnel may access your account data, and may act within your account (an "act as user" capability), where reasonably necessary to operate, secure, support, troubleshoot, or investigate abuse of the Service. This access is limited to authorized personnel.
- Advertising content. Publicly available advertising content is displayed within the Service to the account that chose to track the relevant advertiser, for that account's internal business research.
- Legal and safety. Where necessary to comply with law, respond to lawful requests, enforce our terms, or protect the rights, safety, and property of Npcat LLC, our users, or others.
- Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
8. Service providers and subprocessors
We rely on the following categories of service providers. We can provide more specific information about a given provider on request, and business customers can obtain our current subprocessor list under our Data Processing Agreement.
| Category of provider | Purpose | Personal data involved | Region |
|---|---|---|---|
| Cloud hosting and storage | Hosting the Service and storing data | All application data at rest, including advertising content | European Union (Germany) |
| Authentication provider | Sign-in and session management | Account identifier and email; session and authentication data | United States |
| Product-analytics provider (PostHog) | Product usage analytics (page views and in-app interactions) | Account identifier, product-analytics events, and device/browser metadata | European Union |
| Advertising-data provider | Sourcing publicly available advertising content from advertising-transparency resources | Advertiser and page identifiers we look up; returns public advertising content | United States |
| AI / machine-learning provider | Extracting attributes from advertising creatives | Advertising creative media (which may incidentally contain personal data); no account-holder data | United States / global |
| IP-geolocation provider | Deriving a coarse location label when you connect an agent | IP address (we store only the coarse label) | Global |
| Software-distribution (package registry) | Distributing CLI software updates | Request metadata (IP address, user agent) | United States / global |
9. Our role (controller / processor)
For most personal data – account and team-member data, authentication, usage and product analytics, the ingested advertising content, and the Creative Score and derived analytics – Npcat LLC determines the purposes and means of processing and is therefore a controller (and, for the advertising content about third parties, an independent controller). In the limited situation where a business customer provides personal data to us to be processed only on its documented instructions, we act as that customer's processor; that processing is governed by our Data Processing Agreement, available to business customers.
10. International data transfers
Our infrastructure and primary data storage, including our databases and object storage, are located in the European Union (Germany). Some of our service providers are located in the United States or operate globally, so providing the Service can involve transferring personal data outside the EEA and the UK. Where we do so, we rely, where required, on a lawful transfer mechanism:
- For transfers to a provider certified under the EU-US Data Privacy Framework (and its UK Extension and Swiss counterpart), we rely on that framework's adequacy. Our machine-learning provider participates in the Data Privacy Framework.
- For transfers to other US providers, we will put in place, before relying on them for such transfers, the European Commission's Standard Contractual Clauses and, for UK data, the UK International Data Transfer Addendum / IDTA, together with additional safeguards as appropriate.
You may contact us at support@polyads.ai for more information about the safeguards we use.
11. Retention
We keep personal data only for as long as we need it for the purposes described in this Policy:
- Account and product data (including ingested advertising content and derived analytics) is retained while your account is active and as needed to provide the Service, after which it is deleted or anonymized on request or through our operational processes.
- Application logs are retained for a limited period and then purged.
- The short-lived analysis cache used to compute analytics is automatically evicted (approximately seven days).
We currently manage deletion and retention operationally rather than through an automated self-service mechanism. If we hold personal data we no longer need, we delete or anonymize it. Some data may be retained longer where required to comply with law or to establish, exercise, or defend legal claims.
12. Your rights
Depending on where you are located, you may have some or all of the following rights.
12.1 EEA and UK (GDPR)
You have the right to: access your personal data; rectify inaccurate data; request erasure; restrict or object to processing (including processing based on legitimate interests, and direct marketing); request data portability; and, where processing is based on consent, withdraw that consent at any time without affecting prior processing. You also have the right to lodge a complaint with your local supervisory authority – in the UK, the Information Commissioner's Office (ICO); in the EEA, your national data-protection authority.
12.2 How to exercise your rights
Email support@polyads.ai. We currently handle these requests manually and will respond within the timeframes required by law (generally one month under the GDPR, and 45 days under applicable US state laws, each extendable where permitted). We may need to verify your identity before acting. There is no charge unless a request is manifestly unfounded or excessive.
13. Your US state privacy rights
Depending on your state of residence (for example, California, Virginia, Colorado, Connecticut, Texas, Utah, and other states with comprehensive privacy laws), you may have rights to:
- Know / access the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients;
- Delete personal information we have collected from you;
- Correct inaccurate personal information;
- Data portability;
- Opt out of the "sale" or "sharing" of personal information and of targeted advertising and certain profiling; and
- Be free from discrimination for exercising your rights.
We do not "sell" or "share" personal information as those terms are defined under the California Consumer Privacy Act (as amended by the CPRA) or comparable state laws, and we do not use personal information for cross-context behavioral advertising. We collect the categories of personal information described in Sections 3 and 5, from the sources and for the purposes described there, and we retain them as described in Section 11. We collect little or no "sensitive personal information," and we do not use any such information for purposes that would trigger a "right to limit."
To exercise these rights, email support@polyads.ai. You may use an authorized agent; we may require the agent to provide proof of authorization and may require you to verify your identity. We will not discriminate against you for exercising your rights, and you may appeal a decision by contacting us at the same address.
14. Security
We use technical and organizational measures designed to protect personal data, including authentication and access controls, hashing of access tokens stored on our servers (with the exception that a newly issued CLI token is held briefly in plain text until your CLI retrieves it, then removed), permission checks, rate limiting, restricted network access, and separate storage for logs. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
15. Children
The Service is intended for business users and is not directed to individuals under 18. We do not knowingly collect personal data from children. If we learn that we have collected personal data from a child, we will delete it. If you believe a child has provided us personal data, contact support@polyads.ai.
16. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will provide notice (for example, by email or through the Service) and update the "Last updated" date above. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.
17. Contact
For any question about this Policy or our processing of personal data, or to exercise your rights, contact:
Npcat LLC 30 N Gould St Ste R, Sheridan, WY 82801, United States Email: support@polyads.ai