FindAgent CMO

Privacy Policy

Last updated: 7 October 2026

1. Who we are

FindAgent CMO is an AI marketing assistant operated by FindAgent (“FindAgent”, “we”, “us”). This policy explains what data FindAgent CMO collects, how it is used, who it is shared with and how you can control it. The FindAgent marketplace has its own privacy policy at findagent.cloud/privacy.

2. Data we access

  • Sign-in data. You sign in with GitHub or Google. We receive your email address and basic profile details (name and avatar). We do not store a password.
  • Website data. The public pages of the website you connect, which we crawl to understand your site.
  • Google Analytics and Search Console data, if you connect them: Google Analytics sessions, users and top pages, and Search Console clicks, impressions, click-through rate, average position and top queries and pages. We request read-only access (the analytics.readonly and webmasters.readonly scopes). Daily aggregate figures are stored so trends can be shown.
  • Google Ads data, if you connect a Google Ads account: campaign and ad-group settings, budgets, bid targets, ad headlines and descriptions, and performance metrics such as impressions, clicks, cost and conversions.
  • Access tokens. When you connect a Google account we store the OAuth access token and refresh token that Google issues so we can keep reading your data until you disconnect.

3. How we use it

We use your data only to run the product for you: to show analysis, to generate suggestions and drafts, to answer your questions in chat, and, once you approve them, to make the changes you approved in your own accounts. We do not use Google user data for advertising, and we do not sell it.

4. AI processing

FindAgent CMO uses Anthropic's Claude models to analyse your site and to write suggestions and answers. To do that, the following can be sent to Anthropic: the public content of your site, the knowledge documents in your workspace, summarised Google Analytics and Search Console figures (for example total clicks, impressions and top queries) that are part of your site's knowledge summary, and, when you ask the chat about traffic or performance, the Google Analytics and Search Console figures returned for that question. When Google Ads is connected and you ask the chat about your ads, campaign names, status, budgets, the account currency and per-campaign performance figures (for example spend, clicks, impressions and conversions) may be sent in the same way.

This happens to produce the analyses, answers and drafts you see in the product, including scheduled runs. We do not use Google user data to train AI or machine-learning models.

Text from your knowledge documents, such as crawled pages and generated strategy documents, may also be sent to an embeddings provider so that search over those documents works. Google Analytics, Search Console and Google Ads data is not part of those documents.

5. Storage and security

Your data is stored in a managed PostgreSQL database. Google access tokens and refresh tokens are encrypted at rest with AES-256-GCM before they are stored, and the service refuses to start in production without the encryption key. The application is served over HTTPS and is hosted on Vercel.

6. Who we share data with

We do not sell your data. We share it only with the service providers that run FindAgent CMO, and only as needed for them to do so:

  • Vercel, which hosts the application.
  • Supabase, which provides the database.
  • Anthropic, whose models process your data as described in section 4.
  • An embeddings provider (Voyage AI by default) for document search, as described in section 4.
  • An error-monitoring service (Sentry), if enabled, which receives error reports from which we remove authorisation headers, cookies and tokens.

We may also disclose data where the law requires it or to protect the security of the service.

7. Retention, deletion and revoking access

When you disconnect an integration in FindAgent CMO, we delete the stored access and refresh tokens for it. Disconnecting does not revoke the grant on Google's side, so you should also remove FindAgent CMO at myaccount.google.com/permissions.

Analysis, drafts, knowledge documents and daily summary figures stay in your workspace until you ask us to delete them. To have your account and data deleted, email team@katatechnology.co.

8. Google user data and Limited Use

FindAgent CMO's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In line with those requirements:

  • We use Google user data only to provide and improve the user-facing features described in this policy.
  • We do not use it for serving advertisements, including retargeting or interest-based advertising.
  • We do not sell it or transfer it to data brokers or information resellers.
  • We do not use it to develop, improve or train generalised AI or machine-learning models.
  • People at FindAgent do not read it unless you give us your permission for specific data, it is necessary for security purposes or to comply with the law, or it is aggregated and anonymised for internal operations.

9. Children

FindAgent CMO is not for anyone under 16 and we do not knowingly collect their data.

10. Changes

We may update this policy as the product changes. We will post the new version here and change the “last updated” date.

11. Contact

Questions or requests: team@katatechnology.co.