Privacy Policy

Last updated: October 8, 2026  ·  Datylux

This Privacy Policy explains how Datylux (“we”, “us”, or “our”) collects, uses, stores, and protects your information when you use our website and platform at datylux.com. This policy describes our data practices; it does not replace any consent required by law. Optional analytics and marketing tracking remain off unless you enable them.

1. Information We Collect

Account Information

When you create an account, we collect your email address and, if you sign up via Google, your name and Google profile photo. This information is used solely to create and manage your account.

Saved Application Data

Data you explicitly choose to save within the app — including named campaign snapshots, budget pacing setups, campaign plans, and plan snapshots — is stored securely in our database (hosted by Supabase), associated with your account and protected by row-level security. Access is restricted to your account and authorized service operations.

Imported CSV Data

When you import CSV files into Datylux, that data is processed entirely in your browser. Raw CSV data is not transmitted to our servers and is not stored by us. When you close or refresh the tab, the imported data is cleared from memory. Only data you explicitly choose to save is persisted server-side.

AI Feature Data

When you use the Datylux AI feature, summarized campaign context is sent to our server and forwarded to Anthropic’s Claude API. This may include totals, percentages, platform names, campaign names where present in summaries, KPI values, campaign goals, and the AI question or prompt you submit. Raw CSV files, payment card data, and individual-level rows are not sent to the AI provider. This data is not stored by Datylux after the request completes. Anthropic’s standard commercial/API handling may retain API inputs and outputs for a limited period, generally up to 30 days unless a longer retention exception or separate agreement applies. By using the AI feature, you consent to this processing. Anthropic’s privacy policy governs their handling of API requests.

Usage and Technical Data

With your consent, we use Google Analytics 4 to collect aggregated, pseudonymous usage data — such as page views, session duration, browser type, device type, approximate location, and which features you interact with. Google Analytics is not loaded until you accept analytics cookies. Google advertising signals and advertising personalization are disabled in our analytics configuration. This information helps us improve the product. It is not linked to your name or email and is not sold. You can opt out at any time via the Cookie preferences link in the footer; if you opt out, we stop loading Google Analytics, clear its accessible first-party cookies, and refresh a page where it was already running to stop further tracking.

Marketing and Advertising Measurement Data

With your marketing permission, Datylux uses the LinkedIn Insight Tag on selected public marketing pages and an optional trial-confirmation page to measure Datylux ads. LinkedIn may process standard visit, cookie, browser/device and network information under its Privacy Policy. You can change your choice at any time through Cookie preferences; browser GPC and DNT signals disable marketing.

For the approved LinkedIn campaign, we keep first and latest campaign source, medium, campaign and creative codes through sign-in and checkout. We retain only the approved codes, not the full advertising URL, email, imported CSV/report contents or targeting attributes. These codes may be linked to your Datylux account for a fixed 30-day window; revisiting does not extend that window. A confirmed Pro trial can be measured once after a server check and your current marketing permission. Signup and checkout clicks are not confirmed trials. Our manual LinkedIn conversion argument contains a conversion ID and no revenue value, account identifier, email, authentication credential, Stripe identifier, payment information or CSV/report data.

No new measurement trial record is created without valid marketing permission that began by the trial's start. A consented trial record contains your account identifier, a hashed trial identity and start/claim/expiry information for up to 90 days. Its linked campaign codes expire at the original 30-day attribution deadline. Necessary subscription and payment records continue under our existing billing practices.

Withdrawing marketing permission stops optional measurement on this browser immediately and clears local campaign codes. For a signed-in account, removal is sent to our existing server: acknowledgment clears account-linked campaign codes and prevents pending trial conversions. If offline or unable to reach the server, removal remains pending and is retried when that account reconnects or signs in. Another offline or anonymous browser has its own choice until it updates or signs in. Withdrawal does not erase necessary billing records or minimal consented-trial deduplication records before their retention deadline. It cannot retract requests already sent or information already received by LinkedIn; use LinkedIn's privacy controls for that information.

Payment Information

If you subscribe to a paid plan, payments are processed by Stripe. We do not store your credit card details. Stripe’s privacy policy governs the handling of your payment information.

2. How We Use Your Information

We do not sell personal information for money. If you enable marketing cookies, the LinkedIn Insight Tag may disclose identifiers and browsing information to LinkedIn for Datylux ad measurement and retargeting. This may constitute a sale, sharing for cross-context behavioral advertising, or targeted advertising under applicable privacy laws. You can opt out using Cookie preferences. We honor Global Privacy Control (GPC) and Do Not Track (DNT) signals by disabling marketing tracking, including when marketing was previously enabled. Datylux does not serve third-party ads inside the product.

3. Legal Basis for Processing (EEA & UK Users)

If you are located in the European Economic Area or United Kingdom, we process your personal data under the following legal bases:

4. Data Storage and Security

Your account data is stored in Supabase, a managed cloud database platform with encryption at rest and in transit using industry-standard TLS. Row-level security is used to restrict users to their own saved data. Authorized service processes and administrators may access data as needed to operate, support, and secure the service. Our serverless infrastructure is hosted on Netlify.

While we take reasonable and appropriate technical measures to protect your information, no system is completely secure. We encourage you to use a strong, unique password and keep your credentials confidential. If you suspect unauthorised access to your account, contact us immediately at support@datylux.com.

5. Third-Party Sub-Processors

Datylux uses the following third-party services to operate the platform. Their privacy roles depend on the service and processing activity; some may act as independent controllers for certain purposes:

We rely on each provider’s data processing terms and maintain Data Processing Agreements (DPAs) where required and available for sub-processors that handle personal data on our behalf. We do not share your data with any other third parties except as required by law or as necessary to provide the service.

6. Cookies and Local Storage

Datylux uses the following client-side storage. For a complete cookie list, see our Cookie Policy. You can manage analytics and marketing cookies via the Cookie preferences link.

We do not use advertising cookies, retargeting pixels, or any cookies that track you across other websites unless you accept optional marketing cookies. Datylux does not serve third-party ads inside the product.

Cookie choices expire after 180 days and are requested again after a material consent-policy change. Your browser stores the choice, timestamp, policy version, privacy-signal status, and a limited local history of choices. These browser records are separate from the minimal account consent state described below. Clearing browser site data removes local records; it does not itself acknowledge account removal to our server.

7. Data Retention

Campaign measurement: Account-linked server measurement is enabled only after automatic cleanup and its monitoring are verified operational. The following retention and cleanup periods apply to records collected while it is enabled. Account-linked campaign codes, including copies in trial records, expire after 30 days and are removed by daily housekeeping within 24 hours of expiry. Minimal consented trial records expire after 90 days and are deleted within 24 hours. Minimal account consent state contains an account identifier, grant/denial flag, revision and grant/expiry/update times. It is retained until 180 days after the last authenticated consent update to prevent older valid browser choices from reversing withdrawal. Routine authenticated consent updates can extend this period for active accounts; ordinary state reads do not. Expired consent state is deleted by daily housekeeping within 24 hours. Existing account deletion cascades to these measurement records.

Browser measurement storage: Consented campaign codes and an account binding expire after 30 days. A pending-removal receipt contains only an account identifier, random nonce and creation time, for up to 30 days and at most 20 accounts. It is removed on matching acknowledgment. These are logical deadlines: physical browser deletion occurs when the site next runs, so an inactive device may retain expired entries. Existing cookie choice/history lasts up to 180 days with at most 20 choices. This new account-linked trial measurement requires a fresh purpose-specific marketing choice; analytics remains separate.

We retain your account data for as long as your account remains active. When you delete your account or submit a valid deletion request, we delete applicable personal data without undue delay and within the deadlines required by applicable law. We may retain information where legally required or permitted, including necessary billing, fraud-prevention, security, and legal-claims records. Backup copies may remain until overwritten under the applicable backup retention schedule; retained copies must remain protected and must not be restored to ordinary use in a way that reverses a valid deletion request. Datylux does not store AI query data after the request completes. Anthropic’s standard commercial/API handling may retain API inputs and outputs for a limited period, generally up to 30 days unless a longer retention exception or separate agreement applies.

Downloaded copies: Downloading your data does not delete your account or your saved data. Copies that you download to your own device are under your control; Datylux does not impose a 30-day deletion deadline on those copies and cannot erase them from your device.

8. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

You can exercise your access, deletion, and portability rights directly within the app:

Where processing is based on consent, you may withdraw consent without affecting the lawfulness of prior processing. For analytics cookies, use the Cookie preferences link. For AI feature data processing, stop using the AI feature or contact us if you need help with a prior request.

California Residents (CCPA / CPRA)

To the extent the California Consumer Privacy Act (CCPA), as amended by the CPRA, applies, California residents have the following rights. Our cookie and marketing opt-out controls are available to all visitors:

To exercise these rights, use the in-app tools above or contact us at support@datylux.com. We may need to verify your identity before fulfilling certain requests by confirming the email address associated with your account.

UK and EEA Residents

If you are located in the United Kingdom or European Economic Area, you also have the right to lodge a complaint with your local supervisory authority (for example, the UK Information Commissioner’s Office at ico.org.uk) if you believe we have processed your personal data unlawfully.

9. International Data Transfers

Datylux is operated from the United States. If you access the platform from outside the United States, your data may be transferred to and processed in the United States or other countries where our sub-processors operate. We take appropriate steps to ensure such transfers comply with applicable data protection laws, including through standard contractual clauses where required.

10. Children’s Privacy

Datylux is not directed at or intended for use by anyone under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have inadvertently collected such information, we will delete it promptly. If you believe a child has provided us with personal data, please contact us at support@datylux.com.

11. Data Accuracy Disclaimer

Datylux displays analytics based on data you import. We make no representations about the accuracy or completeness of imported data or the calculations derived from it. You are solely responsible for ensuring that data you import is accurate. Datylux is not liable for any decisions made based on inaccurate, incomplete, or misinterpreted data.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or new features. When we make material changes, we will update the date at the top of this page and, where appropriate, notify you by email or by a notice within the platform. Where a change requires new consent, we will request it before using your information for that purpose.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your data, please contact us at support@datylux.com.