Skip to content
Hypeon
Hypeon

Privacy Policy

Last updated:

Who we are

Hypeon (“we”) operates a creative and competitive ad-intelligence platform built on the EU/EEA and UK ad libraries (Meta, Google, Microsoft, Pinterest, TikTok). Contact: info@hypeon.ai.

What we collect

  • Account data: email, display name, Firebase UID. Required to authenticate you.
  • Billing data: Stripe customer ID, subscription tier, invoice history. Card numbers are stored by Stripe, not by us.
  • Usage data: brands you research, queries you ask, MCP tool calls (with arguments and outcome), rate-limit counters. Used to operate the product, prevent abuse, and debug failures.
  • Content you create: brand context, uploaded assets, prompts, and the creative we generate for you. Stored so you can come back to your work.
  • Public ad data: we ingest publicly available records from the Meta Ad Library, Google Ads Transparency Center, Microsoft Ad Library, Pinterest Ad Library and TikTok Creative Center. These records are not personal data about you.

How we use it

  • To deliver the product you signed up for.
  • To bill you and provide receipts.
  • To enforce per-plan limits and prevent abuse.
  • To improve the product. We may analyze aggregated usage. We do not sell personal data, ever.

Storage and retention

Data is stored on Google Cloud Platform in the United States (region us-central1). Account and billing records are retained while your account exists, then deleted within 90 days of account closure unless we are legally required to retain them. MCP audit logs are retained for 365 days. Cached public ad data has no fixed retention: it is refreshed continuously and may be superseded at any time.

Third-party processors

We share the minimum data necessary with:

  • Google Cloud Platform: hosting, database (Cloud SQL Postgres), cache (Memorystore Redis), object storage and logging.
  • Firebase Authentication (Google): sign-in and identity tokens.
  • Stripe: billing, subscription management, payment cards.
  • Anthropic, Google (Gemini), OpenAI: LLM providers used by the in-product AI agents. Your prompts and the relevant brand and ad data are sent to the model that handles the request.
  • Decodo: residential proxy network used by the ad-library crawlers.
  • Trustpilot, Google Places: public review data sources for the brand-reputation feature.

MCP connector

Hypeon offers an MCP (Model Context Protocol) connector so you can call our tools from Claude, ChatGPT, Cursor, VS Code and other MCP-aware clients. When you connect:

  • The client authenticates against Hypeon via OAuth 2.1 with PKCE. We never see your client's credentials, only the OAuth flow.
  • Each tool call is recorded in our audit log with your user id, the tool name, the arguments, the latency, and the success or error status. Full request and response bodies are not stored.
  • MCP tool responses contain the same data the in-product UI shows. No additional fields are exposed via MCP that are not exposed in-app.
  • Plan tier and per-tool quotas apply. Exceeding them returns a rate-limit response, not a charge.

Your rights (GDPR and UK GDPR)

You can request access, correction, deletion, export, or restriction of your personal data. You can also object to processing or withdraw consent. Email info@hypeon.ai and we will respond within 30 days. You may also lodge a complaint with your local data-protection authority.

Cookies

We use first-party cookies for sign-in (Firebase session) and a CSRF token. We do not use third-party advertising cookies on our sites.

Security

All traffic is encrypted in transit with TLS 1.2 or later. Data at rest is encrypted by our cloud provider. MCP access tokens are JWTs scoped to a single user, refresh tokens rotate on every use, and revoked tokens cannot be replayed.

Changes

We will note material changes at the top of this page and, when the change affects how we handle existing data, notify you by email at least 14 days before it takes effect.

Contact

Privacy questions or data requests: info@hypeon.ai.