1. Introduction
Growth By AI LLC, a Delaware limited liability company, doing business as Apricode AI ("Apricode," "we," "us," or "our") operates a SaaS marketing technology platform accessible at www.apricodeai.com and through related mobile applications and services (collectively, the "Service").
This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you visit our website, create an account, use our platform, or otherwise interact with us. It also describes the choices you have regarding your information and how you can contact us to exercise your privacy rights.
By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access or use the Service. This Privacy Policy applies to all users of the Service, including account holders, team members, and visitors.
Apricode is a product operated by Growth By AI LLC, a Delaware limited liability company. All payments are processed by Paddle.com Market Limited (or a Paddle affiliate), acting as Merchant of Record.
2. Information We Collect
We collect information that you provide directly, information generated through your use of the Service, and information from third-party platforms you connect.
2.1 Account Information
When you register for an account, we collect your name, email address, company name, job title, phone number (optional), and billing information (processed by our payment providers). If you sign up through a single sign-on (SSO) provider, we receive your name, email, and profile picture from that provider.
2.2 Usage Data
We automatically collect data about how you interact with the Service, including features accessed, campaigns created or modified, analytics dashboards viewed, AI-generated content requests, reports exported, automation rules configured, and timestamps and duration of sessions. This data helps us improve the Service and provide personalized experiences.
2.3 Platform Integration Data
When you connect third-party advertising and analytics platforms to Apricode — such as Google Ads, Meta Ads, TikTok Ads, LinkedIn Ads, Pinterest Ads, X (Twitter) Ads, Snapchat Ads, Amazon Ads, Google Analytics, and similar services — we access and process data from those platforms as authorized by you. This may include campaign performance metrics, audience data, creative assets, spend data, conversion data, and other advertising-related information. We access this data solely to provide the integration functionality you have requested.
2.4 Device & Technical Data
We collect your IP address, browser type and version, operating system, device type, screen resolution, referring URL, pages viewed, and interaction patterns. We use this information to ensure compatibility, detect anomalies, prevent fraud, and improve the performance of the Service.
2.5 Cookies & Tracking Technologies
We use cookies, web beacons, pixels, and similar tracking technologies to maintain your session, remember your preferences, analyze traffic patterns, and measure the effectiveness of our marketing efforts. For detailed information about our use of cookies, see Section 10 (Cookies Policy) below.
3. How We Use Your Information
We process your information for the following purposes, each with a lawful basis under applicable data protection laws:
3.1 Provide and Improve the Service
We use your information to operate, maintain, and improve the Service, including managing your account, delivering features you request, processing payments, providing customer support, and developing new features based on aggregated usage patterns. Legal basis: performance of contract, legitimate interest.
3.2 AI-Powered Features
Our platform leverages artificial intelligence to deliver core functionality including campaign optimization recommendations, creative content generation (text, images, and video), predictive analytics and forecasting, audience insights, automated budget allocation, ad fatigue detection, and marketing mix modeling. Your campaign data and platform integration data are processed by AI models to generate these insights. See Section 4 (Data Processing & AI) for detailed information about how AI processes your data.
3.3 Analytics and Reporting
We use your data to generate cross-platform analytics dashboards, attribution reports, executive briefings, and performance benchmarks. These reports are generated solely for your account and are not shared with other customers.
3.4 Communication
We may send you service-related communications such as account confirmations, technical notices, security alerts, and support responses. With your consent, we may also send marketing communications about new features, product updates, educational content, and industry insights. You can opt out of marketing communications at any time by clicking the "unsubscribe" link in any email or updating your notification preferences.
3.5 Security and Fraud Prevention
We process technical data and usage patterns to detect and prevent unauthorized access, ad fraud, account abuse, and other malicious activities. This includes real-time anomaly detection, IP reputation analysis, and automated threat response. Legal basis: legitimate interest, legal obligation.
4. Data Processing & AI
Artificial intelligence is fundamental to the Apricode platform. We are committed to transparency about how AI models interact with your data.
4.1 How AI Models Process Your Data
When you use AI-powered features, your data — including campaign metrics, creative briefs, audience descriptions, and performance data — is sent to AI models for processing. These models analyze your data to generate recommendations, creative content, predictions, and insights. AI processing occurs in real time or asynchronously depending on the feature. All AI requests are logged for audit purposes, and token usage is tracked per tenant for cost management and billing.
4.2 No Training on Customer Data Without Consent
We do not use your data to train, fine-tune, or improve general-purpose AI models without your explicit, informed consent. Your campaign data, creative assets, and business information are used solely to deliver the specific AI features you request within your account. Our agreements with third-party AI providers (OpenAI, Anthropic, Google) include contractual provisions prohibiting the use of API-submitted data for model training.
4.3 Multi-Tenant Data Isolation
Apricode is built on a strict multi-tenant architecture. Every database query is scoped to your organization through Row-Level Security (RLS) policies enforced at the database level. AI model requests are isolated per tenant — your data is never commingled with another customer's data during processing, storage, or retrieval. Each tenant's data is logically segregated through organization-scoped identifiers, and access controls are enforced at every layer of the application stack.
5. Data Sharing & Third Parties
We do not sell, rent, or trade your personal information. We share data only as described below, and only to the extent necessary to provide the Service:
5.1 AI Service Providers
We transmit data to AI providers — including OpenAI, Anthropic (Claude), and Google (Gemini) — to power AI features such as content generation, campaign optimization, and predictive analytics. Data sent to these providers is used exclusively for real-time inference (generating outputs for your requests) and is subject to data processing agreements that prohibit the use of your data for model training. We select providers based on their privacy practices and contractual commitments.
5.2 Advertising Platform APIs
When you connect advertising platforms (Google Ads, Meta Ads, TikTok Ads, LinkedIn Ads, Pinterest Ads, X Ads, Snapchat Ads, Amazon Ads, and others), we exchange data with those platforms through their official APIs as necessary to provide integration functionality. This includes retrieving campaign data, pushing optimizations, and syncing audiences as directed by you. Your credentials for these platforms are encrypted and stored securely.
5.3 Payment Processors
We use Paddle.com Market Limited (or a Paddle affiliate) as Merchant of Record. Payment card details are transmitted directly to Paddle and are never stored on our servers. Paddle is a PCI DSS certified payment provider. We receive only a tokenized reference, limited card metadata, and transaction confirmation.
5.4 Infrastructure Providers
The Service is hosted on Amazon Web Services (AWS) infrastructure, with Cloudflare providing CDN, DDoS protection, and DNS services. These providers process data on our behalf under strict data processing agreements. We also use Sentry for error monitoring and Resend for transactional email delivery.
5.5 Legal and Safety Disclosures
We may disclose your information if required by law, regulation, legal process, or governmental request, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, the safety of others, investigate fraud, or respond to a government request.
5.6 Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your personal information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on the Service of any change in ownership or uses of your personal information, as well as any choices you may have.
6. Data Security
We implement industry-leading security measures to protect your data at every layer:
- Encryption at rest: All data is encrypted using AES-256-GCM encryption. Database backups and file storage are encrypted with AWS KMS-managed keys.
- Encryption in transit: All communications between your browser and our servers are protected with TLS 1.2 or higher. Internal service-to-service communication is also encrypted.
- Multi-tenant isolation: Row-Level Security (RLS) policies enforce data isolation at the database level, ensuring that one customer can never access another customer's data, even in the event of an application-layer vulnerability.
- Access controls: Role-based access control (RBAC) with principle of least privilege. Multi-factor authentication (MFA) and SAML SSO available on Growth and Enterprise plans.
- SOC 2 Type II: We are pursuing SOC 2 Type II certification, with completion planned for Q4 2026. Our current security practices align with SOC 2 Trust Service Criteria.
- Security audits: We conduct regular penetration testing, vulnerability scanning, and third-party security assessments. Findings are remediated according to severity-based SLAs.
- Incident response: We maintain a documented incident response plan. In the event of a data breach, we will notify affected users and relevant supervisory authorities within 72 hours as required by GDPR and other applicable regulations.
While we strive to use commercially acceptable means to protect your personal information, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security, but we are committed to continuously improving our security posture.
7. Data Retention
7.1 Active Accounts
We retain your personal information and account data for as long as your subscription is active or as needed to provide you with the Service. Campaign data, analytics history, and AI-generated content are retained for the duration of your subscription to enable historical reporting and trend analysis.
7.2 Account Closure
When you close your account or your subscription expires without renewal, we will delete or anonymize your personal information within 30 calendar days. During this 30-day window, your data remains available should you choose to reactivate your account. After the deletion period, personal data is permanently removed from our production systems and will be purged from backups within 90 days.
7.3 Anonymized and Aggregated Data
We may retain anonymized, aggregated analytics data that cannot be used to identify you. This data is used to improve the Service, generate industry benchmarks, and conduct research. Anonymized data is not subject to deletion requests as it is no longer considered personal data.
7.4 Legal Obligations
We may retain certain information for longer periods when required to comply with legal obligations, resolve disputes, enforce our agreements, or as otherwise permitted by applicable law. For example, billing records may be retained for up to seven years for tax and accounting purposes.
8. Your Rights
Depending on your location and applicable laws, you may have the following rights regarding your personal information:
8.1 Rights Under the General Data Protection Regulation (GDPR)
If you are located in the European Economic Area (EEA) or the United Kingdom, you have the right to:
- Access — Request a copy of the personal data we hold about you.
- Rectification — Request correction of inaccurate or incomplete personal data.
- Erasure — Request deletion of your personal data ("right to be forgotten"), subject to certain exceptions.
- Data portability — Receive your personal data in a structured, commonly used, machine-readable format, and transmit it to another controller.
- Restriction of processing — Request that we limit the processing of your personal data in certain circumstances.
- Objection — Object to processing of your personal data based on our legitimate interests.
- Withdraw consent — Where processing is based on consent, withdraw your consent at any time without affecting the lawfulness of prior processing.
- Lodge a complaint — File a complaint with your local data protection supervisory authority.
8.2 Rights Under the California Consumer Privacy Act (CCPA/CPRA)
If you are a California resident, you have the right to:
- Know — Request disclosure of the categories and specific pieces of personal information we have collected, the sources, business purposes, and categories of third parties with whom we share it.
- Delete — Request deletion of your personal information, subject to certain exceptions.
- Correct — Request correction of inaccurate personal information.
- Opt out of sale/sharing — We do not sell your personal information. We do not share personal information for cross-context behavioral advertising.
- Non-discrimination — We will not discriminate against you for exercising any of your CCPA rights.
8.3 Rights Under Turkey's Personal Data Protection Law (KVKK)
If you are located in Turkey, you have rights under the Kişisel Verilerin Korunması Kanunu (KVKK), Law No. 6698, including the right to:
- Learn whether your personal data has been processed.
- Request information regarding processing activities.
- Learn the purpose of processing and whether data is used accordingly.
- Know the third parties to whom your data has been transferred.
- Request correction of incomplete or inaccurate data.
- Request deletion or destruction of your personal data under conditions set forth in Article 7 of KVKK.
- Object to any adverse result arising from automated processing.
- Claim compensation for damages caused by unlawful processing.
8.4 How to Exercise Your Rights
To exercise any of the rights described above, please contact our Data Protection Officer at privacy@apricodeai.com. We will respond to your request within 30 days (or the applicable statutory period). We may need to verify your identity before processing your request. If your request is complex or you have made a large number of requests, we may extend the response period by an additional 60 days, in which case we will notify you of the extension and the reason.
9. International Data Transfers
Growth By AI LLC is a Delaware limited liability company headquartered in the United States. Your information may be transferred to, stored, and processed in the United States and other countries where our service providers operate. These countries may have data protection laws that differ from those of your jurisdiction.
When we transfer personal data from the EEA, UK, or Switzerland, we rely on the following transfer mechanisms to ensure adequate protection:
- Standard Contractual Clauses (SCCs) — We use the European Commission's Standard Contractual Clauses with our sub-processors and service providers, supplemented by additional technical and organizational measures where appropriate.
- EU-U.S. Data Privacy Framework — Where applicable, we rely on the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework as certified by the U.S. Department of Commerce.
- Adequacy decisions — We may transfer data to countries that the European Commission has determined provide an adequate level of data protection.
For transfers from Turkey, we comply with the requirements of the KVKK and the Turkish Data Protection Authority (KVKK Kurulu) regarding cross-border data transfers, including obtaining necessary approvals or implementing appropriate safeguards.
11. Children's Privacy
The Service is not directed to individuals under the age of 16, and we do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@apricodeai.com. If we become aware that we have collected personal information from a child under 16 without verification of parental consent, we will take steps to delete that information promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will:
- Update the "Last updated" date at the top of this page.
- Send an email notification to the account owner's registered email address at least 30 days before the changes take effect.
- Display a prominent notice within the Service (such as a banner or in-app notification).
- For changes that materially affect how we process your data or reduce your rights, we will seek your explicit consent where required by applicable law.
We encourage you to review this Privacy Policy periodically. Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Growth By AI LLC
Data Controller · d/b/a Apricode AI
Address: 477 Madison Avenue, Manhattan, NY 10022, USA
Tax ID: 384362304
Data Protection Officer: privacy@apricodeai.com
General Inquiries: privacy@apricodeai.com
Website: www.apricodeai.com
We aim to respond to all privacy-related inquiries within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.