1. Information We Collect
1.1 Personal Information
We collect information that you provide directly to us, including:
- Name and email address
- Account credentials
- Payment information (processed securely through our payment processor)
- Company information
- Communication preferences
1.2 Usage Information
We automatically collect information about your use of the Service, including:
- Log data (IP address, browser type, pages visited)
- Device information
- Usage patterns and preferences
- Performance data
1.3 Content Information
We collect and store:
- Creative briefs and ideas you generate
- Brand profiles and assets you upload
- Feedback and ratings on generated content
1.4 Connected AI Hosts (ChatGPT, Claude, and other MCP clients)
You may connect a third-party AI host — including ChatGPT / OpenAI Apps, Claude and the Claude connectors directory, and other Model Context Protocol (MCP) clients — to your Ad Legends account. Our public MCP endpoint is https://www.adlegends.ai/api/mcp/public. Connecting is optional and happens only after you complete our OAuth consent, where you see and approve the access being granted.
For the public MCP connection we request these scopes: openid, email, brands:read, ads:read, and ads:generate. A separate, broader connection is described in Section 1.4a.
When you connect a host to the public MCP, that host can receive:
- Your email address and confirmation that it is verified, plus an account identifier, from our sign-in (UserInfo) endpoint. If you connect with sign-in only and do not grant the email scope, we return only the account identifier. We do not return your name, phone number, or profile picture.
- Connection details — whether you are connected, the scopes you granted, how many brands are accessible, the connection profile, and suggested next actions. This does not include your email or account identifier.
- Brand information — a brand's name, description, domain, whether ads can be generated for it, and whether brand guidelines exist — and your brand guidelines when that tool is used. Brand lists return a narrower set of fields than a single brand lookup.
- Advertising strategy, strategic brief, and ad content that you or the host generates, along with the record identifiers the host needs to continue a task across tools (for example, a brief or ad-session identifier).
- Before a paid generation, a credit estimate and a short-lived confirmation receipt that authorizes that one request. You approve the receipt, and the matching tool then uses it to run the generation.
The confirmation receipt is a short-lived spend authorization for that exact request and expires within about ten minutes. It is not a login password, API key, or refresh token — treat it as a receipt, not an account secret.
We do not read your AI host's chat history, its memory or conversation summaries, or files you upload to that host. Ad Legends only receives the requests the host sends to our tools. We return only the fields described above, and we do not add name, phone, picture, or internal diagnostic data to enrich a host.
1.4a The Full Ad Legends Connection
Separately from the public MCP above, you can connect an AI host to your full Ad Legends account for your own use. This connection is intended for the account owner, covers a broader set of Ad Legends tools, and may request additional scopes that you approve at consent — including the ability to make changes to your brands and to read your credit and billing status. It is not part of the public directory listing.
Everything in Sections 1.4, 2.1, 2.2, and 4.4 applies to this connection as well: it runs only after your OAuth consent, it is limited to the brands and actions you authorize, your content is still processed under Zero Data Retention and never-train terms, and we still do not ingest your host's chat history, memory, or uploaded files. Because this connection can act on your behalf, review the scopes on the consent screen before you approve.
2. AI Data Processing and Model Training
2.1 Zero Data Retention
Ad Legends follows Zero Data Retention (ZDR) principles for AI processing. Your content and prompts sent to AI models are processed ephemerally and are never used to train, fine-tune, or improve any AI models. Your creative work remains exclusively yours.
2.2 Data Isolation and Who Can See Your Content
All user workspaces, brand data, and creative assets are logically isolated from other Ad Legends customers. Other customers cannot access your workspace. That isolation does not mean no one outside Ad Legends ever sees authorized content — two separate paths exist.
Upstream generation providers. When you use AI generation features, Ad Legends routes the prompt and the brand context needed for that request to upstream model providers, including OpenAI, Anthropic, Google, and Adobe, as named in our Terms of Service and AI Content Policy. This routing is under Zero Data Retention and no-training terms: your content is processed to produce the output and is not used to train, fine-tune, or improve those providers' models. See Section 2.1.
Connected AI hosts you authorize. If you connect a host such as ChatGPT or Claude, that host receives the sign-in claims and tool data described in Sections 1.4 and 1.4a, because you directed us to share them. We do not send your workspace to a host you have not connected. A connected host's own retention, training, and privacy practices are governed by that host's policy, not this one.
Ad Legends does not sell your creative work. Isolation means customer-to-customer separation plus Zero Data Retention on our generation path. It is not a claim that model providers never process a generation request, and it is not a claim that a host you connect never receives the data you authorized.
2.3 Operational Logging
For system reliability and abuse prevention, limited operational logs may be retained for up to 30 days before automatic purging. These logs do not contain your creative content or brand materials.
When you use a connected AI host, we record limited metadata about each tool call — such as which tool ran, its status, timing, and any credits charged — for reliability, abuse prevention, and debugging. These records do not contain your prompts, tool inputs, or generated content.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our Service
- Process transactions and send related information
- Send administrative information and updates
- Respond to your comments and questions
- Monitor and analyze usage patterns
- Detect, prevent, and address technical issues
- Protect against fraudulent or illegal activity
- Operate OAuth connections and the public MCP endpoint, including issuing short-lived confirmation receipts for paid generations you request through a connected host, and showing that host only the brand and creative records within the scope you granted
5. Security and Compliance
5.1 Infrastructure Security
Ad Legends operates on SOC 2 Type II–compliant infrastructure. Our security measures include:
- Encryption of all data in transit (TLS 1.2+) and at rest (AES-256)
- Database-level isolation with automated credential rotation
- Globally redundant, encrypted asset storage
- Regular security assessments and penetration testing
5.2 Data Hosting Location
All user data and AI processing occurs on servers located in the United States. We do not process data in jurisdictions outside the US without explicit disclosure.
5.3 Subprocessors
We use a limited number of vetted subprocessors to provide the Service. All subprocessors are contractually bound to equivalent data protection standards and undergo regular security reviews. A list of subprocessors is available upon request for enterprise customers.
6. Data Retention
We keep different records for different reasons, and we do not use a single "as long as necessary" rule to cover all of them.
- Operational logs are retained for up to 30 days and then automatically purged. They do not contain your creative content or brand materials.
- The connection metadata described in Section 2.3, which does not include your content, is retained for up to 30 days and then automatically purged.
- Confirmation receipts for paid generations expire within about ten minutes and cannot be used after that.
- OAuth grants and connection tokens are kept so a connected host can reach the MCP until you disconnect. We store connection tokens in hashed form, not in the clear, and we honor revocation immediately. When you disconnect or a token expires, we delete the token records within 30 days, and may keep a minimal security-audit record of the grant — an account and connected-host reference with timestamps — for up to 90 days.
- Account records and your brand, strategy, brief, and ad content are retained for the life of your account — so we can provide the Service and fulfill the reads you authorize — or until you delete them. After you delete a record or your account, we securely delete or anonymize it within 30 days, and it ages out of encrypted backups within 90 days.
- Payment records are retained as required for tax and accounting purposes, generally up to seven years. Card details are held by our payment processor, not by Ad Legends.
Enterprise agreements may set different retention periods (Section 7).
7. Enterprise and Organizational Accounts
Organizations that deploy Ad Legends to their employees, contractors, or affiliates through our enterprise or partner programs should note:
- Individual users register directly with Ad Legends; the referring organization does not transmit personal data to us as part of the referral
- Organization administrators may have visibility into aggregate usage statistics but do not have access to individual user content
- Enterprise agreements may include additional data processing terms
- Custom data retention and deletion policies are available for enterprise customers
8. Your Rights and Choices
8.1 Access and Update
You can access and update your personal information through your account settings or by contacting us.
8.2 Data Portability
You have the right to request a copy of your personal data in a structured, commonly used format.
8.3 Deletion and Revocation
You can request deletion of your account and personal information through your account settings or by contacting us at privacy@adlegends.ai. A deletion request covers your account and the personal information we hold for it, the brand profiles, guidelines, strategies, briefs, ads, and ad sessions in your workspace, and your OAuth grants to connected AI hosts so those hosts can no longer call the MCP on your behalf. We honor deletion requests within 30 days, subject to the legal exceptions stated in this policy — such as records we must keep for tax, fraud, or legal process.
You can also revoke a single connected-host grant without deleting your Ad Legends account — in your Ad Legends connection settings, by disconnecting the app in ChatGPT or Claude, or by asking us to revoke that grant. After revocation, the host can no longer use that grant to read brands or generate ads. Revocation does not by itself delete your Ad Legends workspace.
8.4 Marketing Communications
You can opt out of marketing communications at any time by clicking the unsubscribe link in our emails or updating your preferences.
10. International Data Transfers
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for such transfers.
11. Children's Privacy
Our Service is intended for general audiences and is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13.
12. Third-Party Links
Our Service may contain links to third-party websites. We are not responsible for the privacy practices of these external sites.
A connected AI host such as ChatGPT or Claude is a third-party service. Its privacy policy, not this one, governs what it does with the data you authorized us to send.
13. California Privacy Rights
California residents have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect and the right to request deletion of personal information.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date.
15. Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us at:
- Email: privacy@adlegends.ai
- Address:
Ad Legends, Inc. (a Delaware corporation)
590 East Riverside Drive
Bastrop, TX 78602
16. Data Protection Officer
For privacy-related inquiries, you can also contact our Data Protection Officer at dpo@adlegends.ai.