Privacy

Privacy Policy

Last updated 2026-09-29 · v0 · early access

This policy explains what Admiry.ai, a Barton Alto Holdings, LLC company (“Admiry”, “we”) collects, why, who sees it, how long we keep it, and how you delete it. It is written to be read, not skimmed: every section names the actual data and the actual service behind it.

Admiry is in early access. This is version v0 of the policy. Counsel will review it before Admiry leaves early access; when it changes, the date above changes and business owners with an account are told by e-mail. Nothing here is a substitute for the agreements you accept inside the product, which say in more detail what Admiry may do in your Google Ads account.

1. Who this covers

Admiry runs three things, and this one policy covers all of them:

  • The website: the pages about Admiry at admiry.ai (the Programmatic and Local pages and these policies), including the early-access application forms. www.admiry.ai only redirects to admiry.ai.
  • The Admiry marketing agent for local and service businesses: the conversation on the admiry.ai front page and its sign-in, plan and settings pages, its connection point for AI assistants at agent.admiry.ai, and the same agent reached through an AI assistant such as Meta Muse, Claude or ChatGPT (a “connector”).
  • The advertising platform for performance advertisers at ads.admiry.ai, and the ad delivery system behind it.

Admiry is operated from the United States and its servers are in the United States. If you use Admiry from elsewhere, your data is processed in the United States.

2. The website

Reading the website’s pages collects nothing about you. They set no cookies, run no analytics and load no third-party scripts or fonts; our web server keeps ordinary access logs (IP address, page, time, browser) only as long as security and running the site need them. The conversation on the admiry.ai front page is the agent, not the website: the cookies it sets once you start talking or sign in are described in section 3.

If you fill in an early-access form, what you type (your name, e-mail address, company, website and the answers to the form) is sent to us as an e-mail through Resend, our e-mail provider, and read by the founders. We use it to reply to you and to decide whom to onboard. It is not added to any marketing list.

3. The Admiry marketing agent

The agent plans and runs marketing for your business. To do that it keeps a record of your business, a record of you as its owner, and a record of everything it did on your behalf.

What you tell it

  • Your description of the business and your answers in the consultation (what you do, where, whom you want to reach, your offer, what a customer is worth to you, your monthly limit).
  • Your public website, if you give its address: Admiry reads up to 20 pages of it, keeps the text it needs to describe your services, and never reads pages behind a sign-in.
  • Your listing on Google Maps: to confirm which business you mean, Admiry looks up the name and address you gave in Google’s Places service and keeps only the matching name, address and place identifier.

From these it writes a “business knowledge” record and a marketing plan. Both are yours to read and correct at any time, on the plan page or by asking your assistant.

You, the owner

  • Google sign-in. You sign in with Google. Admiry asks Google for your e-mail address and your Google account identifier only (the “openid email” scopes): no profile, no contacts, no access to Gmail, Drive or any other Google service. Admiry keeps the e-mail address and identifier to know which businesses are yours.
  • Cookies. The agent sets only the cookies it needs to work, and none for advertising or analytics: a session cookie after you sign in (30 days), a short-lived cookie that binds a sign-in to the browser that started it, and, on the admiry.ai front page, two visitor cookies for the draft you are working on (one holds the draft’s key, the other a one-way hash of that key, which the page for connecting an assistant reads), both 24 hours while anonymous and 30 days once you have signed in and claimed the draft. All are HttpOnly and sent only over HTTPS.
  • Access keys and grants. Keys you paste into an assistant and OAuth grants you give an assistant are stored hashed; Admiry keeps their label, when they were made and last used, and which business they open. You can see and revoke every one on your Settings page.
  • IP address. Kept with sign-in attempts and API calls for rate limiting and abuse prevention.

E-mail you send to Admiry

You, or an assistant working for you, can write to Admiry at hello@agent.admiry.ai and continue the consultation and your plan by e-mail. Admiry does not read your mailbox: it sees only what is sent to that address.

  • What is kept: the words you wrote (not the quoted history below them), the message headers needed to keep the thread together, the sender address, and the outcome (answered, handed to a person, dropped). Attachments are not opened or kept.
  • Who processes it: Resend, which receives and sends the mail, and the model provider of section 5, which reads your words to place them in the consultation or answer a question about your plan, under the same terms as the consultation itself.
  • For how long: the text of a message for 90 days, then it is forgotten; the thread and its outcomes stay with your business record. When Admiry hands a message to a person, a notice with your address and the first 500 characters of that message also goes to Admiry’s operator mailbox, where it is kept as ordinary business e-mail and is not forgotten after 90 days.
  • Who may write for your business: your sign-in address, and any address you allow on your Settings page or when you first see a plan that was started by e-mail. Each allowed address is listed there and can be revoked at any time. No e-mail can launch, approve or spend: that stays on the plan page after you sign in.

Google Ads

If you link your own Google Ads account, Admiry keeps your Customer ID, the state of the link, and, once linked, the campaign, performance and cost data it needs to run and report on your ads. It changes ads only within the limit you set and only after you approve a plan. It never changes your billing, payment method or who has access to the account.

If you choose the prepaid option, Admiry opens a Google Ads account for your business inside its own manager account, and keeps that account’s number and its performance and cost data. Details are in the Prepayment Addendum you accept when you set up ads in the Admiry conversation; your Settings page lists the texts you accepted.

Payments

Prepaid balances are paid by card on Stripe’s checkout page. Admiry never sees or stores your card number; it keeps the amount, the date, Stripe’s identifiers for the payment, and your balance and statement. Stripe’s own privacy policy applies to the payment page.

The audit log

Every action taken for your business, by you, by your assistant or by Admiry’s own scheduled jobs, is written to an audit log with who did it and when. You and your assistant can read it at any time. It exists so that you can always see what happened to your money.

Leads from your pages

If you put Admiry’s page script and form on a page of yours (the page kit your assistant gives you), Admiry records each visit to that page and each tap on its call, e-mail and booking links, with the time and the Google Ads click identifier the visitor arrived with (gclid, gbraid or wbraid). The script keeps that identifier in the visitor’s browser tab (session storage) and sets no cookies of its own; these records carry no contact details and no IP address. When a visitor sends the form, Admiry keeps what they typed (name, phone, e-mail, the service, a preferred time, ZIP code and message) as a lead for your business and e-mails it to you through Resend. You, and the assistants you allow to see leads, can read them.

Once Admiry has set up conversion tracking in your Google Ads account, the script also loads Google’s tag on that page to report conversions to that account; Google’s own cookies and privacy policy apply to it.

Leads and these records are kept while your business is on Admiry and deleted with it (section 10). Admiry does not yet purge lead contact details on a schedule or let you delete a single lead yourself; until it does, write to the address in section 13 and the leads you name are deleted.

4. Your AI assistant

When you use Admiry through Meta Muse, Claude, ChatGPT or another assistant, the conversation happens inside that assistant, under its own terms and privacy policy, not ours. Admiry receives only what the assistant sends to its tools: your answers, your instructions and the business it is acting for. Admiry sends back the data the tool returns and a short sentence for the assistant to relay to you.

An assistant acts with the access you gave it. A key or grant that can only read cannot change anything; anything that spends money still needs your approval on the plan page or by an approval code. You can revoke an assistant’s access at any time on your Settings page, and Admiry stops honouring it immediately.

5. How Admiry uses AI

The agent uses a large language model to turn your description and website into a business record, to read free-text answers in the consultation, and to draft plans and ad text. The model is Meta’s Model API. Under the tier Admiry uses, Meta may use the prompts and completions to improve its models. What reaches the model is the description of your business, the text of your public website, your consultation answers and the plan being drafted. Your e-mail address, sign-in details, access keys, Google Ads credentials and payment details are never part of a prompt.

Text an AI writes for you (ads, pages, plans) is shown to you for approval before it is used anywhere public, and you are responsible for what you approve.

6. The advertising platform

Advertisers on ads.admiry.ai have accounts that Admiry creates for them. For each account Admiry keeps a username, a hashed password, an API key, server-side session records, the campaigns, creatives, targeting lists and apps the advertiser sets up, and a record of payments received and spend. Uploaded creative assets are stored under their content hash. Measurement partners (MMPs) the advertiser connects send Admiry install and in-app event data for that advertiser’s campaigns. Signing in to ads.admiry.ai sets one HttpOnly session cookie, which ends when you sign out or the session expires; the platform sets no advertising or analytics cookies.

7. Ad delivery data

To buy ad space for advertisers, Admiry receives bid requests from ad exchanges, in real time, for people it has no relationship with. Apart from the leads your own pages collect for you (section 3), this is the one place Admiry processes personal data about people who are not its customers, so it is described in full.

What a bid request contains

  • the device’s IP address and, from it, an approximate location (country, region, city);
  • the device’s advertising identifier (IDFA or GAID) when the platform and the person allow it, or a signal that the person has limited ad tracking;
  • device make, model, operating system and browser (the user agent);
  • the app or site and the ad placement, and the exchange’s own identifiers;
  • privacy signals sent with the request: COPPA, GDPR, the US privacy string, GPP, and the device’s limit-ad-tracking and do-not-track flags.

What Admiry does with it

  • decide whether and how much to bid, and which ad to show;
  • cap how often one device sees an advertiser’s ads;
  • detect fraud and invalid traffic;
  • measure results (impressions, clicks, installs and in-app events reported by measurement partners);
  • train the models that predict whether an ad is relevant.

Admiry honours the privacy signals it receives: a request flagged under COPPA is treated as a child’s and never profiled; requests with a GDPR flag, a US privacy opt-out, a GPP section or a limit-ad-tracking or do-not-track flag are served without an identity profile. Admiry does not sell this data, does not build profiles of named people, and does not combine it with the data in sections 2 to 6.

Your choices on your device

You can reset or turn off your advertising identifier in your phone’s settings (iOS: Settings, Privacy & Security, Tracking; Android: Settings, Privacy, Ads). Admiry respects those settings on the next request it sees from your device. You can also write to the address in section 13 with your advertising identifier and ask that Admiry delete the records that carry it.

8. Who sees your data

Admiry does not sell personal data. It shares data only with the services it needs to run:

  • Google: sign-in, the Places lookup, and the Google Ads API for the accounts you link or Admiry opens for you.
  • Meta: the Model API described in section 5; and Meta Muse, when it is the assistant you choose.
  • Stripe: card payments for prepaid balances.
  • Resend: e-mail we send you, e-mail you send to Admiry, and the application forms on the website.
  • Hosting: Akamai (Linode) servers, Google Cloud and Amazon Web Services storage, all in the United States.
  • Ad exchanges and measurement partners: the bid responses and event data that ad delivery requires (section 7).

Each of them processes data under its own terms and only for the purpose Admiry engages it for. Admiry will also disclose data when the law requires it, or to protect Admiry, its customers or the public from fraud or harm, and it will tell you when it is allowed to.

9. How long we keep it

Retention periods by kind of data
DataKept for
Application e-mails from the websiteUntil we have replied and decided; then deleted
A business you started on the homepage but never claimedStops working after 24 hours (7 days when started by e-mail); what it holds is kept, not yet deleted on a schedule, and deleted on request
A consultation that was never finishedCloses after 24 hours while anonymous, 7 days once claimed or started by e-mail; the answers stay with the business record
E-mail you send to Admiry (the text)90 days, then forgotten; the thread and its outcomes stay with your business; a message handed to a person also stays in the operator mailbox
Sign-in sessions30 days, or until you sign out
Keys and OAuth grantsUntil you revoke them; OAuth access tokens 1 hour, refresh tokens 30 days
Your business record, plan and audit logWhile your business is active, and 30 days after you delete it
Payment recordsAs long as the law requires for accounting, normally 7 years
Leads and visit counts from your pagesWhile your business is on Admiry, and deleted with it; not yet purged on a schedule; a lead is deleted sooner on request
Bid and event logs (ad delivery)30 days in full; summarised records up to 180 days
Model training sets built from those logs90 days
Server access logsOnly as long as security and operations need them

10. Your choices and deletion

You can, at any time and without asking us:

  • read and correct your business record and plan on the plan page, or through your assistant;
  • revoke any key, assistant or allowed e-mail address on your Settings page;
  • unlink your Google Ads account from inside Google Ads (Admin, then Access and security);
  • sign out, which ends the session on that browser.

To delete your account and everything Admiry holds about your business, e-mail privacy@admiry.ai from the address you signed in with. Admiry stops any running ads, refunds an unspent prepaid balance to the card that paid it, and deletes the business record, plan, leads, keys, grants and audit log within 30 days. It keeps only what accounting law requires (the payment records) and the summarised ad delivery records that carry no identifier of yours.

You can also ask for a copy of your data at the same address. Admiry answers within 30 days. If you are in a place whose law gives you further rights (for example California residents under the CCPA, or residents of the European Economic Area or the United Kingdom), you may exercise them the same way, and Admiry will not treat you differently for doing so.

11. Security

Everything travels over HTTPS. Passwords, keys, sessions and tokens are stored as hashes, never in the clear. Access keys expire, OAuth tokens rotate, and a stolen refresh token used twice revokes the whole grant. Anything that spends money needs an approval you give outside the assistant. Servers are in access-controlled environments and databases are backed up. No system is perfectly secure; if a breach affects your data, Admiry will tell you by e-mail without undue delay.

12. Children

Admiry’s products are for businesses and are not directed to anyone under 18. Admiry does not knowingly collect data from children; a bid request flagged as a child’s under COPPA is never profiled. If you believe a child has given Admiry personal data, write to the address below and it will be deleted.

13. Changes and contact

When this policy changes, the date at the top changes, and business owners and advertisers with an account are told by e-mail before a change that affects them takes effect. Earlier versions are available on request.

Questions, requests and complaints: privacy@admiry.ai.
Admiry.ai, a Barton Alto Holdings, LLC company, United States.