Last updated July 31, 2026
Overview
This policy applies to campyon.ai and the Campyon application (together, the “Service”). It also covers campaign.ge, our former address, which now redirects here. When you create an account, build workspaces, connect ad platforms, or browse the marketing site, we process personal data as described below.
We collect only what the product needs to work, store it in the EU, and do not sell it. If anything here is unclear, email support@campaign.ge.
Information we collect
Account & profile
When you sign up we store:
- Email address and authentication identifiers
- Username, display name, and profile preferences
- Workspaces you create or are invited to, and your role in them
- Whether you've agreed to our terms and have product access
Workspace content
Anything you build inside a workspace: businesses, dashboards, audiences, campaign drafts, notes, uploaded logos and banners. This content is private to the workspace and visible only to the members you invite.
Ad-platform integrations
When you connect Meta, Google, or TikTok via OAuth, we store the access and refresh tokens issued by that provider, the ad accounts you authorize, and the data we fetch on your behalf (campaign metadata, performance metrics, audience insights). We never request more scopes than the feature requires, and you can disconnect at any time from the workspace integrations page.
Usage analytics
With your consent, we capture pageviews, feature interactions, and a randomly-generated visitor id via PostHog. On our public marketing pages we also record a replay of your visit, with every form field masked, so we can see where the site trips people up. We ask every visitor for that consent up front and record nothing until you accept. Signed-in workspace pages are never recorded. See Cookies & analytics for the full picture.
Technical data
Server logs containing IP address, user-agent, and request metadata, retained briefly for security and abuse prevention. The IP address itself is not retained beyond that window.
Error reports
When the Service hits an unexpected error, we send a report to Sentry so we can fix it. Before you accept cookies, that report contains the technical context only: error message, stack trace, page URL, and browser version. We strip your user id, cookies, and request headers from the report before it leaves your browser. Note that the page URL itself may contain identifying path segments while you are signed in (your username and workspace name appear in paths under /workspace/). We treat capturing this as a legitimate interest under GDPR because the page URL is the smallest context we need to locate and fix the bug.
After you accept cookies, the report also includes your user id and email (so we can reach out if your specific account is hitting a problem), plus a short video-like recording of the seconds leading up to the error. This error recording sits in a rolling buffer and is thrown away unless something breaks and flushes it, so it never captures a normal browsing session. Form input values are masked. It is separate from the product-analytics replay under Cookies & analytics, which records ordinary visits on our public pages.
How we use information
- Provide the Service. Authenticate you, render your workspaces, and fetch the ad-platform data you authorized.
- Communicate. Send transactional emails (sign-up confirmation, password reset, security notifications, workspace invites) from
noreply@campaign.ge. That mailbox is unmonitored; for replies, contact support@campaign.ge. - Improve the product. Review aggregated usage patterns to understand which features get used and where people get stuck.
- Diagnose errors.When something breaks, the error context (stack trace, page, optional user id once you've consented) goes to Sentry so we can reproduce and fix it.
- Security and compliance. Detect abuse, prevent unauthorized access, and meet our legal obligations.
We do not sell your personal data, and we do not use your workspace content to train machine-learning models.
Job applications
Companies on Campyon can post open roles on our public job board. If you apply to one of those roles through a form on campyon.ai, we first send a one-time code to your email to confirm it's yours, then collect what you put in the form: your name, email address, an optional cover note, an optional portfolio link, and your CV if you attach one. The verification code and the IP address that requested it are kept only briefly, then deleted automatically.
Your application goes to the company you applied to. They decide what happens with it. For that data, the hiring company is the data controller and Campyon is a processor acting on their behalf. We store applications and CVs in the EU (Supabase), restrict access to the hiring company's workspace, and never use applicant data for anything other than delivering it to that company. We process it on the basis of the consent you give when submitting the form.
Applications are deleted automatically 90 days after the posting closes, CV files included. To have your application removed earlier, contact the company you applied to, or email support@campaign.geand we'll handle it within 30 days.
Data retention
- Account data. Kept while your account is active. Deletion requests are honoured within 30 days, excluding records we are legally required to keep.
- Workspace content. Kept until you delete it or the workspace, then removed from production within 30 days and from backups within 90 days.
- Integration tokens. Revoked immediately when you disconnect a provider; cached data from that provider is purged on the next sync.
- Job applications. Deleted, including CV files, 90 days after the job posting closes.
- Analytics events. Retained for up to 12 months in PostHog, then aggregated or deleted.
- Error reports. Retained for up to 90 days in Sentry.
- Session replays. Both the product-analytics replays (PostHog, public pages only) and the error replays (Sentry, the seconds around a crash) are kept for up to 30 days, then deleted. Neither is created before you consent.
- Server logs. Retained for up to 30 days for security and debugging.
Where we store your data
Account and workspace data are stored in the European Union (Supabase EU region). Analytics events and product-analytics replays are stored in the EU (PostHog EU). Error reports and error replays are stored in the EU (Sentry, Frankfurt). Some sub-processors (notably Vercel's edge network and certain email providers) may process data in other regions; in those cases we rely on Standard Contractual Clauses or equivalent transfer mechanisms.
Your rights
You can contact us to exercise rights over your data. Residents of the EU/EEA, UK, and Switzerland have the following rights under the GDPR:
- Access. Request a copy of the personal data we hold about you.
- Rectification. Correct anything inaccurate or incomplete.
- Erasure. Delete your account and personal data.
- Restriction. Pause certain processing while we resolve a dispute.
- Portability. Receive your data in a machine-readable format.
- Objection. Object to processing based on legitimate interest.
- Withdraw consent. Withdraw analytics consent at any time, with no effect on the Service.
Email support@campaign.ge from the address on your account and we will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
Security
We protect your data with TLS in transit, encryption at rest on all managed databases, scoped database access via row-level security, encrypted OAuth tokens, and least-privilege access for the team. No system is fully secure. If you discover a vulnerability, please email support@campaign.ge with the details. We acknowledge security reports within two business days.
Children's privacy
The Service is not directed to children under 16. We don't knowingly collect personal data from children. If you believe a child has provided us with data, contact us and we'll delete it.
Changes to this policy
We may update this policy from time to time. The date at the top of this page reflects the most recent change. For material changes we will notify you by email or via an in-app notice before they take effect.
Contact us
Questions, requests, or concerns about this policy or your data:
Email support@campaign.ge
We aim to respond within two business days; statutory requests within 30 days.