Privacy Policy
Last updated: July 2026
1. Who we are and who controls your data
Campaign Medic is a software platform operated by ISEQO LTD, a company registered in England and Wales under company number 17341372, with its registered office at 124-128 City Road, London, England, EC1V 2NX. In this policy, "Campaign Medic", "we", "us" and "our" refer to ISEQO LTD operating the Campaign Medic product.
For the purposes of applicable UK data-protection law (the UK GDPR and the Data Protection Act 2018), ISEQO LTD is the controller of the personal data described in this policy. You can contact us about privacy at privacy@campaignmedic.com.
2. Information we collect
- Account information — your name, email address, and (for email/password sign-up) a hashed password. If you sign in with Google, we receive your name, email address and profile image from Google.
- Authentication data — a session token that keeps you signed in, and, for password accounts, email-verification and password-reset tokens.
- Advertising and analytics access tokens — when you connect Google Ads, Meta Ads, LinkedIn Ads, Google Analytics 4 or Google Search Console, the platform stores the OAuth access and refresh tokens those services issue. These tokens are encrypted at rest and used only to read the data you ask us to analyse and to apply changes you explicitly approve.
- Campaign and performance data — campaign, ad group, ad, keyword, search-term, placement and demographic data, together with metrics such as impressions, clicks, spend, conversions and conversion value, retrieved from your connected accounts when an audit or analysis runs. We store the recommendations produced, the operations you approve, and before/after measurement snapshots so the audit history and Impact Monitor work. A short-lived cache of your campaign list (a few minutes) may be held in memory to reduce repeated API calls during chat.
- Chat content — messages you send in the in-app assistant and the assistant's replies, stored so your conversation history is available to you.
- Billing information — subscriptions are processed by Stripe. We store your Stripe customer and subscription identifiers and your plan status. We never receive or store your full card number or security code.
- Usage and audit logs — records of audits you run, operations you approve or undo, and plan-usage counts, used to show your history, measure impact and enforce plan limits.
3. How we use your data
- To provide the service — reading your connected accounts, producing recommendations, applying changes you approve, and measuring their impact.
- To operate your account, authenticate you, and keep the service secure.
- To send service and transactional emails (such as verification, password resets, billing notices, audit results and, where you have not opted out, product notifications). You can control optional notification emails in Settings and unsubscribe from them at any time.
- To process payments and enforce plan limits.
- To detect, prevent and investigate abuse, fraud and security issues.
We do not sell your personal data, and we do not use your advertising data to build profiles for advertising to you.
4. Advertising and analytics integrations
We access Google Ads using OAuth 2.0 with the adwords scope, and Google Analytics 4 and Search Console with read-only scopes when you choose to connect them. Meta Ads and LinkedIn Ads are connected with their respective OAuth flows. Refresh tokens are stored encrypted at rest and are never shared with third parties. You can disconnect any integration from the Connect page in the app, and revoke access from the relevant provider's own account-security settings, at any time.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. AI processing
Audits and the in-app assistant use large language models to analyse your campaign data and generate recommendations. Depending on the provider selected for your workspace, the relevant campaign data and your chat messages are sent to Anthropic (Claude), OpenAI or Google (Gemini) for processing. These providers act as processors on our behalf and may process data outside the UK (see section 9). If you use a Bring-Your-Own-Key plan, requests are made using your own API key with the provider you choose.
6. Cookies
We use strictly-necessary cookies to keep you signed in and to remember your active workspace. We do not use advertising cookies or third-party tracking pixels. Where a cookie notice is shown, it reflects this limited use.
7. Data retention
We retain your account data for as long as your account is active. Audit history, recommendations and operation logs are retained according to your plan's history window — 30 days on the Free plan and up to 730 days (two years) on paid plans. When you delete your account, your account data and connected-account tokens are removed from our live systems, and any residual copies in routine encrypted backups are deleted in the normal backup-rotation cycle.
8. Account deletion
You can delete your account at any time from Settings. Deleting your account removes your personal data, workspaces you solely own, and the connected-account tokens they contain. You can also export your data before deleting. Deletion is permanent.
9. International processing
We are based in the United Kingdom. Some of our processors — including our AI providers, Stripe (payments) and Resend (email delivery) — may process data outside the UK, including in the United States. Where personal data is transferred outside the UK, we rely on appropriate safeguards such as the UK International Data Transfer Agreement or equivalent contractual protections.
10. Your rights
Under UK data-protection law you have the right to access, correct, delete or receive a portable copy of your personal data, and to object to or restrict certain processing. To exercise any of these rights, email privacy@campaignmedic.com and we will respond within one month. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.
11. Security
All data is transmitted over HTTPS. Passwords are hashed with bcrypt. OAuth and integration tokens are encrypted at rest using AES-256-GCM. We apply least-privilege access across our infrastructure. No system is perfectly secure — if you believe you have found a vulnerability, please disclose it responsibly to security@campaignmedic.com.
12. Changes to this policy
We may update this policy from time to time. We will notify you of material changes by email or by a notice in the app. Continued use of the service after a change takes effect constitutes acceptance of the updated policy.
13. Company information
ISEQO LTD · Registered in England and Wales, company number 17341372 · Registered office: 124-128 City Road, London, England, EC1V 2NX · Privacy contact: privacy@campaignmedic.com.