Privacy Policy
What Reckon collects from you and from your connected ad accounts, why, who processes it, and how to get it back or deleted.
Effective 6 September 2026
This policy explains how Zu Technologies Pvt Ltd ("supermargin", "we") handles personal data in Reckon by supermargin ("Reckon"), the advertising analytics workspace at https://usereckon.ai.
Reckon reads advertising data. It does not write to your ad accounts, does not buy media, and does not use your advertising data to target anyone. Everything below follows from that.
1. Who we are, and in which role
Zu Technologies Pvt Ltd operates Reckon. Which privacy role we hold depends on the data:
- Controller / Data Fiduciary
- For account and billing data about you as a Reckon user, your name, email, workspace membership, and how you use the product. We decide why that data exists.
- Processor / Data Processor
- For the advertising data we sync from the ad accounts you connect, including any personal data inside it. Your organisation decides why it exists; we act on your instructions. The Data Processing Addendum governs that relationship.
Privacy contact: privacy@supermargin.ai. Our Grievance Officer under India's Digital Personal Data Protection Act, 2023 is reachable at grievance@supermargin.ai.
2. Whose data this covers
Three groups of people appear in Reckon, and they have different relationships with us:
- Users: the people who sign in to a Reckon workspace.
- Visitors: anyone who reads our marketing site without signing in.
- People inside connected data: most often the authors of public comments on the Facebook and Instagram posts behind your ads. They are not our users and never asked us for anything, which is why the limits in section 5 exist.
3. What we collect
| Category | What it is | Where it comes from | Why |
|---|---|---|---|
| Identity and account | Name, email address, profile image, workspace and role, authentication events | You, via our authentication provider (Clerk) | To create your account, put you in the right workspace, and keep the account secure |
| Workspace configuration | Business details, target economics (margin, target return, budget guardrails), metric preferences, brand settings | You | The decision engine cannot judge an ad without the economics it is judged against |
| Ad account connection data | Ad account ids and names, the encrypted OAuth token for each connection, connection status | Meta and Google, at the moment you authorise them | To sync the accounts you selected, and to stop syncing when you revoke |
| Advertising performance data | Campaigns, ad sets, ads, daily and windowed metrics (spend, impressions, clicks, conversions, reach), targeting and placement segments | Meta Marketing API, Google Ads API | The dashboards, the verdict queue, the daily brief |
| Creative assets and derived tags | Images, videos and ad copy from your ads, copies of them in our storage, transcripts, and model-generated labels describing hook, format and angle | Meta and Google, then our own processing | To explain which creative works and why |
| Page-post comments | The comment text, the commenter's public display name, timestamps, like and reply counts, and the post the comment sits under | Meta, where you have granted comment access | Comment Insights: what audiences say under the ads you are running |
| Public competitive research | Ads and advertiser details published in the Meta Ad Library and the Google Ads Transparency Center | Those public libraries | The competitor views you ask for, by domain or brand |
| Product usage and diagnostics | Pages viewed, features used, device and browser type, IP address, error traces, performance traces, request logs | Automatically, as you use the product | To keep the service up, debug failures, and see which features earn their keep |
| Support and correspondence | What you write to us and what we write back | You | To answer you, and to keep a record that we did |
We do not ask for special category data (health, biometrics, religion, politics, sexual orientation) and Reckon has no field for it. We do not knowingly collect data from children; the product is sold to businesses and is not directed at anyone under 18.
4. Data from Meta and Google
You connect ad accounts through the platforms' own OAuth screens. We never see your Meta or Google password, and the tokens we receive are encrypted at rest with a key held outside the database.
- Meta
- We request
ads_read, the read-only Marketing API permission. Where your workspace uses Comment Insights we additionally requestpages_read_user_content, which is what lets us read the public comments on the posts behind your active ads. We request nothing that can create, edit, pause or spend. - We request
https://www.googleapis.com/auth/adwordsfor read-only Google Ads reporting, plusopenidandemailso we can tell which Google identity authorised the connection. Reckon is a reporting-only Google Ads API client: it reads reports and never mutates a campaign.
Reckon's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
With Platform Data from Meta and Google, we do not:
- sell it, license it, or transfer it to a data broker or information broker;
- use it to target advertising, build advertising audiences, or enrich a profile of any individual;
- use it to decide anyone's eligibility for credit, insurance, housing, employment or any similar benefit;
- use it for surveillance, or share it with anyone conducting surveillance;
- combine one customer's platform data with another customer's, or with data acquired elsewhere about the same individuals;
- use it to train general-purpose or foundation AI models, ours or anyone else's.
Reckon is not affiliated with, endorsed by, or sponsored by Meta Platforms, Inc. or Google LLC. Meta, Facebook, Instagram, Google and Google Ads are their owners' trademarks. Our interfaces are our own and are not designed to resemble the Meta Ads Manager or Google Ads interfaces.
Detail on those platform obligations, including what Google Ads API access you can obtain directly, is on the Platform Disclosures page.
6. Why we process, and on what legal basis
| Purpose | Data used | Legal basis (GDPR/UK GDPR) |
|---|---|---|
| Provide the workspace: sync accounts, render dashboards, rank the verdict queue, send the daily brief | Identity, configuration, connection, advertising, creative, comments | Performance of a contract (Art. 6(1)(b)); for data about non-users, legitimate interests (Art. 6(1)(f)) |
| Keep the service secure and available: authentication, rate limiting, error and performance monitoring, abuse investigation | Identity, usage, diagnostics | Legitimate interests (Art. 6(1)(f)): running a service that stays up and is not abused |
| Support and communication about your account | Identity, correspondence | Contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)) |
| Improve the product: which features are used, where flows break, which model outputs were wrong | Usage, diagnostics, aggregated performance patterns | Legitimate interests (Art. 6(1)(f)); consent where required for analytics cookies |
| Marketing emails about Reckon | Identity | Consent (Art. 6(1)(a)), withdrawable in one click |
| Meet legal, tax and regulatory obligations, and establish or defend legal claims | As required | Legal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f)) |
Where India's DPDP Act applies, we process user data on the basis of consent given at sign-up or the certain legitimate uses the Act recognises; you can withdraw consent as easily as you gave it, by writing to the Grievance Officer or deleting your account.
7. Automated processing and AI
Reckon uses AI models in four places: describing and tagging creative, transcribing ad audio, summarising comment themes, and answering questions in Ask. What that means concretely:
- Creative assets, ad copy, transcripts, comment text and performance figures are sent to the model providers listed in the sub-processor list.
- We use enterprise API tiers whose terms do not permit the provider to train foundation models on our customers' content, and we do not train models on your data ourselves.
- Model output is a recommendation, not a decision with legal or similarly significant effect on any person. Reckon never acts on your ad account, a human decides and executes every change.
- Model output can be wrong. Every insight is shown with the evidence it came from so you can check it, and states plainly when data is missing, syncing or unavailable rather than filling the gap.
9. International transfers
Our team and our sub-processors operate across several countries, so data may be processed outside the country you are in, including in the United States, the European Union and India. Where personal data leaves the UK or EEA, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant), on an adequacy decision where one covers the destination, and on the technical measures in section 11. Ask us at privacy@supermargin.ai for the transfer terms that apply to your workspace.
10. How long we keep it
| Data | Kept for |
|---|---|
| Advertising, creative and comment data for an active workspace | Up to 25 months of history, so year-on-year comparison works, unless you ask for less |
| Data synced from an ad account you disconnect | The stored token is destroyed the moment you disconnect and nothing further is read. The history already synced is kept until you ask us to delete it, or the workspace closes |
| Account and workspace records | For as long as the account is open, then deleted within 30 days of closure |
| Diagnostics, error traces and request logs | Up to 90 days |
| Records we must keep by law (tax, accounting, dispute) | For the statutory period, then deleted |
| Backups | Rotated out within 90 days, so deleted data leaves the backups by then too |
Disconnecting an ad account inside Reckon removes the connection and its stored token but does not by itself erase the data already synced: that is what the deletion request in the next section is for.
11. How we protect it
- Encryption in transit (TLS) and at rest; platform OAuth tokens are separately encrypted with an application key that is not stored in the database.
- Authentication and session management by a specialist provider; roles and per-workspace scoping enforced on every API request, not in the interface.
- Secrets held in a managed secret store, not in code or images.
- Least-privilege access for staff, granted for a reason and reviewed; production access is logged.
- Continuous error, performance and uptime monitoring, with alerting.
More detail is on the Security page. If you believe you have found a vulnerability, write to security@supermargin.ai; see that page for our disclosure commitments. No system is perfectly secure, and we do not claim otherwise; if a breach affects your data we will tell you within 72 hours of establishing that it did.
12. Your rights
Depending on where you live, you have some or all of these rights. We honour them for everyone, regardless of where you live, unless the law requires otherwise.
- Access: a copy of the personal data we hold about you.
- Correction: fix data that is wrong or incomplete.
- Deletion: have your data erased; see the deletion instructions.
- Portability: receive your data in a machine-readable format, or have it sent onward.
- Objection and restriction: object to processing based on legitimate interests, or ask us to pause processing while a dispute is resolved.
- Withdraw consent: at any time, without affecting what was lawful before.
- Opt out: of sale, sharing, targeted advertising and profiling with legal effects. We do none of these, so there is nothing to opt out of, but the right stands.
- Non-discrimination: we will not degrade the service because you exercised a right.
- Nominate: under India's DPDP Act, nominate someone to exercise your rights if you die or become incapacitated.
Write to privacy@supermargin.ai from the address on your account. We acknowledge within 72 hours and answer within 30 days, extendable once where the law allows and we tell you why. If the data sits inside a customer's workspace we act as processor: we will route your request to that customer and support them in answering it.
Unhappy with the outcome? Escalate to our Grievance Officer at grievance@supermargin.ai. You may also complain to the Data Protection Board of India, to your EU/UK supervisory authority, or to your state Attorney General, without going through us first.
14. Changes to this policy
We update this policy when the product changes. The effective date at the top always reflects the last substantive change. For material changes we notify workspace administrators by email at least 14 days before they take effect, and for changes that require your consent we ask for it rather than assuming it.
15. Contact
- Privacy
- privacy@supermargin.ai
- Grievance Officer (DPDP Act)
- grievance@supermargin.ai
- Security
- security@supermargin.ai
- Everything else
- hello@supermargin.ai
5. Comments, and the people who wrote them
Comment Insights reads public comments on the Page and Instagram posts behind your active ads. Those comments were written by members of the public. We hold them to a narrower standard than the rest of the product:
Where GDPR applies, the customer is the controller for this processing and relies on legitimate interests (understanding public response to their own advertising), balanced against the limits above. A commenter who wants their data removed from Reckon can write to us directly and we will act on it, and tell the customer.