← All legal documents

Privacy Policy

What Reckon collects from you and from your connected ad accounts, why, who processes it, and how to get it back or deleted.

Effective 6 September 2026

This policy explains how Zu Technologies Pvt Ltd ("supermargin", "we") handles personal data in Reckon by supermargin ("Reckon"), the advertising analytics workspace at https://usereckon.ai.

Reckon reads advertising data. It does not write to your ad accounts, does not buy media, and does not use your advertising data to target anyone. Everything below follows from that.

1. Who we are, and in which role

Zu Technologies Pvt Ltd operates Reckon. Which privacy role we hold depends on the data:

Controller / Data Fiduciary
For account and billing data about you as a Reckon user, your name, email, workspace membership, and how you use the product. We decide why that data exists.
Processor / Data Processor
For the advertising data we sync from the ad accounts you connect, including any personal data inside it. Your organisation decides why it exists; we act on your instructions. The Data Processing Addendum governs that relationship.

Privacy contact: privacy@supermargin.ai. Our Grievance Officer under India's Digital Personal Data Protection Act, 2023 is reachable at grievance@supermargin.ai.

2. Whose data this covers

Three groups of people appear in Reckon, and they have different relationships with us:

  • Users: the people who sign in to a Reckon workspace.
  • Visitors: anyone who reads our marketing site without signing in.
  • People inside connected data: most often the authors of public comments on the Facebook and Instagram posts behind your ads. They are not our users and never asked us for anything, which is why the limits in section 5 exist.

3. What we collect

Categories, sources and purposes
CategoryWhat it isWhere it comes fromWhy
Identity and accountName, email address, profile image, workspace and role, authentication eventsYou, via our authentication provider (Clerk)To create your account, put you in the right workspace, and keep the account secure
Workspace configurationBusiness details, target economics (margin, target return, budget guardrails), metric preferences, brand settingsYouThe decision engine cannot judge an ad without the economics it is judged against
Ad account connection dataAd account ids and names, the encrypted OAuth token for each connection, connection statusMeta and Google, at the moment you authorise themTo sync the accounts you selected, and to stop syncing when you revoke
Advertising performance dataCampaigns, ad sets, ads, daily and windowed metrics (spend, impressions, clicks, conversions, reach), targeting and placement segmentsMeta Marketing API, Google Ads APIThe dashboards, the verdict queue, the daily brief
Creative assets and derived tagsImages, videos and ad copy from your ads, copies of them in our storage, transcripts, and model-generated labels describing hook, format and angleMeta and Google, then our own processingTo explain which creative works and why
Page-post commentsThe comment text, the commenter's public display name, timestamps, like and reply counts, and the post the comment sits underMeta, where you have granted comment accessComment Insights: what audiences say under the ads you are running
Public competitive researchAds and advertiser details published in the Meta Ad Library and the Google Ads Transparency CenterThose public librariesThe competitor views you ask for, by domain or brand
Product usage and diagnosticsPages viewed, features used, device and browser type, IP address, error traces, performance traces, request logsAutomatically, as you use the productTo keep the service up, debug failures, and see which features earn their keep
Support and correspondenceWhat you write to us and what we write backYouTo answer you, and to keep a record that we did

We do not ask for special category data (health, biometrics, religion, politics, sexual orientation) and Reckon has no field for it. We do not knowingly collect data from children; the product is sold to businesses and is not directed at anyone under 18.

4. Data from Meta and Google

You connect ad accounts through the platforms' own OAuth screens. We never see your Meta or Google password, and the tokens we receive are encrypted at rest with a key held outside the database.

Meta
We request ads_read, the read-only Marketing API permission. Where your workspace uses Comment Insights we additionally request pages_read_user_content, which is what lets us read the public comments on the posts behind your active ads. We request nothing that can create, edit, pause or spend.
Google
We request https://www.googleapis.com/auth/adwords for read-only Google Ads reporting, plus openid and email so we can tell which Google identity authorised the connection. Reckon is a reporting-only Google Ads API client: it reads reports and never mutates a campaign.

Reckon's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

With Platform Data from Meta and Google, we do not:

  • sell it, license it, or transfer it to a data broker or information broker;
  • use it to target advertising, build advertising audiences, or enrich a profile of any individual;
  • use it to decide anyone's eligibility for credit, insurance, housing, employment or any similar benefit;
  • use it for surveillance, or share it with anyone conducting surveillance;
  • combine one customer's platform data with another customer's, or with data acquired elsewhere about the same individuals;
  • use it to train general-purpose or foundation AI models, ours or anyone else's.

Reckon is not affiliated with, endorsed by, or sponsored by Meta Platforms, Inc. or Google LLC. Meta, Facebook, Instagram, Google and Google Ads are their owners' trademarks. Our interfaces are our own and are not designed to resemble the Meta Ads Manager or Google Ads interfaces.

Detail on those platform obligations, including what Google Ads API access you can obtain directly, is on the Platform Disclosures page.

5. Comments, and the people who wrote them

Comment Insights reads public comments on the Page and Instagram posts behind your active ads. Those comments were written by members of the public. We hold them to a narrower standard than the rest of the product:

  • We store only what the platform returns for a public comment: the message, the author's public display name, timestamps, and engagement counts.
  • We use them to summarise what an audience is saying about an ad: nothing else. We do not build a profile of a commenter, contact them, look them up elsewhere, or use their comment for targeting.
  • Themes and sentiment are traceable to the comments they were drawn from. Reckon does not fabricate representative quotes.
  • Comments are visible only inside the workspace whose ads they sit under.
  • Delete the comment on the platform, or the underlying post, and it stops being resynced; ask us and we will remove what we hold.

Where GDPR applies, the customer is the controller for this processing and relies on legitimate interests (understanding public response to their own advertising), balanced against the limits above. A commenter who wants their data removed from Reckon can write to us directly and we will act on it, and tell the customer.

6. Why we process, and on what legal basis

PurposeData usedLegal basis (GDPR/UK GDPR)
Provide the workspace: sync accounts, render dashboards, rank the verdict queue, send the daily briefIdentity, configuration, connection, advertising, creative, commentsPerformance of a contract (Art. 6(1)(b)); for data about non-users, legitimate interests (Art. 6(1)(f))
Keep the service secure and available: authentication, rate limiting, error and performance monitoring, abuse investigationIdentity, usage, diagnosticsLegitimate interests (Art. 6(1)(f)): running a service that stays up and is not abused
Support and communication about your accountIdentity, correspondenceContract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f))
Improve the product: which features are used, where flows break, which model outputs were wrongUsage, diagnostics, aggregated performance patternsLegitimate interests (Art. 6(1)(f)); consent where required for analytics cookies
Marketing emails about ReckonIdentityConsent (Art. 6(1)(a)), withdrawable in one click
Meet legal, tax and regulatory obligations, and establish or defend legal claimsAs requiredLegal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f))

Where India's DPDP Act applies, we process user data on the basis of consent given at sign-up or the certain legitimate uses the Act recognises; you can withdraw consent as easily as you gave it, by writing to the Grievance Officer or deleting your account.

7. Automated processing and AI

Reckon uses AI models in four places: describing and tagging creative, transcribing ad audio, summarising comment themes, and answering questions in Ask. What that means concretely:

  • Creative assets, ad copy, transcripts, comment text and performance figures are sent to the model providers listed in the sub-processor list.
  • We use enterprise API tiers whose terms do not permit the provider to train foundation models on our customers' content, and we do not train models on your data ourselves.
  • Model output is a recommendation, not a decision with legal or similarly significant effect on any person. Reckon never acts on your ad account, a human decides and executes every change.
  • Model output can be wrong. Every insight is shown with the evidence it came from so you can check it, and states plainly when data is missing, syncing or unavailable rather than filling the gap.

8. Who else sees the data

Sub-processors
Vendors that host, monitor or process data for us under written terms, listed with their purpose and location on the sub-processor page. We give notice before adding one.
Your own workspace
Anyone your administrators invite into the workspace can see the workspace's data. Membership is your call, not ours.
The platforms
Meta and Google receive the API requests we make on your behalf, which is inherent to reading your accounts.
Professional advisers and acquirers
Auditors and lawyers under confidentiality, and a counterparty in a merger, acquisition or asset sale, who inherits this policy until they lawfully replace it, and who we will tell you about.
Authorities
Where the law compels it. We check that a demand is valid and lawful, tell the affected customer unless we are legally forbidden to, and narrow what we hand over.

We do not sell personal data and we do not share it for cross-context behavioural advertising, as those terms are defined by the CCPA/CPRA and comparable US state laws. We have not done so in the preceding twelve months.

9. International transfers

Our team and our sub-processors operate across several countries, so data may be processed outside the country you are in, including in the United States, the European Union and India. Where personal data leaves the UK or EEA, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant), on an adequacy decision where one covers the destination, and on the technical measures in section 11. Ask us at privacy@supermargin.ai for the transfer terms that apply to your workspace.

10. How long we keep it

DataKept for
Advertising, creative and comment data for an active workspaceUp to 25 months of history, so year-on-year comparison works, unless you ask for less
Data synced from an ad account you disconnectThe stored token is destroyed the moment you disconnect and nothing further is read. The history already synced is kept until you ask us to delete it, or the workspace closes
Account and workspace recordsFor as long as the account is open, then deleted within 30 days of closure
Diagnostics, error traces and request logsUp to 90 days
Records we must keep by law (tax, accounting, dispute)For the statutory period, then deleted
BackupsRotated out within 90 days, so deleted data leaves the backups by then too

Disconnecting an ad account inside Reckon removes the connection and its stored token but does not by itself erase the data already synced: that is what the deletion request in the next section is for.

11. How we protect it

  • Encryption in transit (TLS) and at rest; platform OAuth tokens are separately encrypted with an application key that is not stored in the database.
  • Authentication and session management by a specialist provider; roles and per-workspace scoping enforced on every API request, not in the interface.
  • Secrets held in a managed secret store, not in code or images.
  • Least-privilege access for staff, granted for a reason and reviewed; production access is logged.
  • Continuous error, performance and uptime monitoring, with alerting.

More detail is on the Security page. If you believe you have found a vulnerability, write to security@supermargin.ai; see that page for our disclosure commitments. No system is perfectly secure, and we do not claim otherwise; if a breach affects your data we will tell you within 72 hours of establishing that it did.

12. Your rights

Depending on where you live, you have some or all of these rights. We honour them for everyone, regardless of where you live, unless the law requires otherwise.

  • Access: a copy of the personal data we hold about you.
  • Correction: fix data that is wrong or incomplete.
  • Deletion: have your data erased; see the deletion instructions.
  • Portability: receive your data in a machine-readable format, or have it sent onward.
  • Objection and restriction: object to processing based on legitimate interests, or ask us to pause processing while a dispute is resolved.
  • Withdraw consent: at any time, without affecting what was lawful before.
  • Opt out: of sale, sharing, targeted advertising and profiling with legal effects. We do none of these, so there is nothing to opt out of, but the right stands.
  • Non-discrimination: we will not degrade the service because you exercised a right.
  • Nominate: under India's DPDP Act, nominate someone to exercise your rights if you die or become incapacitated.

Write to privacy@supermargin.ai from the address on your account. We acknowledge within 72 hours and answer within 30 days, extendable once where the law allows and we tell you why. If the data sits inside a customer's workspace we act as processor: we will route your request to that customer and support them in answering it.

Unhappy with the outcome? Escalate to our Grievance Officer at grievance@supermargin.ai. You may also complain to the Data Protection Board of India, to your EU/UK supervisory authority, or to your state Attorney General, without going through us first.

13. Cookies and tracking

We use the cookies required to sign you in and keep you signed in, and a small amount of product analytics. We do not run advertising or cross-site tracking cookies. The Cookie Policy names each one and how to refuse the optional ones.

14. Changes to this policy

We update this policy when the product changes. The effective date at the top always reflects the last substantive change. For material changes we notify workspace administrators by email at least 14 days before they take effect, and for changes that require your consent we ask for it rather than assuming it.

15. Contact