Privacy Policy
Effective date: September 10, 2026
Marketing OS (“the Service”) is operated by KeyesCode LLC (“we”, “us”). This policy describes what information we collect when you use the Service, how we use it, and the choices you have — including how to have it deleted.
Information we collect
Account information. When you register we collect your name, email address, and a password (stored only as a cryptographic hash). You may also provide business details such as your business name, website, industry, and economics like average deal value — used to tailor recommendations to your business.
Meta advertising data. If you connect a Meta (Facebook) ad account, we access — through Meta’s official Marketing API and with your explicit authorization via Facebook Login — the ad account you select, including its campaigns, ad sets, ads, budgets, statuses, and performance metrics (spend, impressions, clicks, and conversions). We store a copy of this data to power reporting and recommendations. The OAuth access token Meta issues is stored encrypted (AES-256) at rest.
Google Analytics and Search Console data. If you connect Google for reporting, we request read-only access (analytics.readonly and webmasters.readonly). We read the list of Google Analytics 4 properties and Search Console sites you can access, then daily traffic and search performance metrics (such as sessions, clicks, impressions and top search queries) for the property and site you select. We also store your Google email address to label the connection.
YouTube data. If you connect a YouTube channel to the Social Poster, we request two scopes. With youtube.readonly we read your own channel’s ID, title and thumbnail once, when you connect. We use them to show you which channel your posts will go to. With youtube.upload we upload only the videos you choose to publish, with the title, description, tags and privacy setting you enter. We do not read your other videos, comments, subscribers or analytics, and we never edit or delete videos on your channel.
Social publishing accounts. If you connect a Facebook Page, an Instagram professional account, a TikTok account or a YouTube channel, we store the account’s ID, name and profile picture. We also store the captions, images and videos you compose in the Social Poster so we can publish them when you press Publish or at the time you schedule.
Access tokens. The OAuth access and refresh tokens that Meta, Google, TikTok and YouTube issue are stored encrypted (AES-256) at rest and are never shown in the Service.
Usage records. We keep records of actions taken in the Service — for example which recommendations you approved or rejected — so the Service can function and improve its suggestions for you.
Free tools. The public tools at /tools need no account. The calculators run entirely in your browser and send us nothing at all. The AI visibility checker is the exception: to run a scan we send the business, the question and the answer engine you chose to our rank-tracking provider, and we store that request along with its result and a one-way cryptographic hash of your IP address. The hash cannot be reversed to an address; it exists only to enforce the daily limits on a tool that costs us money per use, and the stored result is reused to answer the same question for a week rather than paying to ask it again. We do not ask for or store an email address on these pages.
How we use information
We use the information above solely to provide the Service to you:
- Displaying your advertising performance in dashboards and reports.
- Generating optimization recommendations and campaign plans. To do this, relevant advertising performance data is processed by the AI model provider your organization uses on our behalf.
- Applying changes you explicitly approve to your ad account via the Meta Marketing API.
- Publishing the posts you compose to the Facebook Pages, Instagram accounts, TikTok accounts and YouTube channels you connect, only when you publish or schedule them.
- Building reports and goal suggestions from your Google Analytics and Search Console metrics. To do this, those metrics are processed by the AI model provider your organization uses (for example Anthropic, OpenAI or Google) on our behalf.
- Operating, securing, and supporting the Service.
We do not sell your data, use it for advertising of our own, use one customer’s data to serve another customer, or share Meta platform data with third parties except the service providers listed below.
Google user data
Marketing OS’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We use Google user data only to provide the features described above to you.
- We do not sell it, use it for advertising, or transfer it to anyone except the service providers listed below, as needed to provide those features, for security, or to comply with the law.
- People at KeyesCode LLC do not read it unless you ask us to, it is needed for security, or the law requires it.
- We do not use Google user data to develop, improve or train AI or ML models.
The YouTube connection uses YouTube API Services. By connecting a YouTube channel you agree to the YouTube Terms of Service, and Google’s handling of your data is described in the Google Privacy Policy.
Service providers
We use a small number of infrastructure providers to run the Service: cloud hosting and managed databases and file storage (Railway), and AI processing (the AI model provider your organization uses). Each processes data only as needed to provide their service to us and is bound by their own contractual and security obligations. We comply with Meta’s Platform Terms and Developer Policies in our handling of all data obtained from Meta.
Data retention and deletion
We retain your data while your account is active. You can delete your data at any time:
- Disconnect Meta: disconnecting your ad account in Settings revokes our access going forward.
- Disconnect a social account: disconnecting a Facebook Page, Instagram account, TikTok account or YouTube channel in Settings → Integrations deletes the stored account details and its tokens.
- Disconnect Google reporting: disconnecting Google in Settings → Integrations stops all further syncing of Analytics and Search Console data.
- Revoke Google or YouTube access: you can remove Marketing OS’s access at any time from your Google Account permissions page.
- Remove the app on Facebook: removing Marketing OS from your Facebook account’s Apps and Websites settings automatically revokes our access.
- Request deletion: initiating a data deletion request through Facebook triggers automatic deletion of the advertising data we obtained through your authorization — the stored connection, the synced ad account and its campaigns, ad sets, ads, metrics, and derived recommendations — and returns a confirmation code and status page. You can also email us at contact@keyescode.com to request deletion of your entire account.
Security
All traffic to the Service is encrypted in transit (HTTPS). Access and refresh tokens for every connected platform are encrypted at rest with AES-256; passwords are stored as salted hashes and are never retrievable. Access to production systems is restricted to KeyesCode LLC.
Cookies
The Service uses only the cookies required to keep you signed in (authentication session cookies). We do not use advertising or cross-site tracking cookies.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal information. Contact us at contact@keyescode.com and we will honor applicable requests. The Service is intended for business use and is not directed at children under 16.
Changes to this policy
If we make material changes we will update the effective date above and, where appropriate, notify you in the Service or by email.
Contact
KeyesCode LLC · contact@keyescode.com