Privacy Policy
Last updated: July 23, 2026
Overview
Rallik (“Rallik,” “we,” “us”) provides an agentic marketing strategy workspace at rallik.com. This policy explains what personal information we collect, how we use it, how we handle data you connect from third-party marketing platforms, and the choices you have.
By creating an account or using Rallik, you agree to this Privacy Policy. If you do not agree, please do not use the service.
Information we collect
We collect information in these ways:
- Account information - name, email address, organization membership, and authentication identifiers when you sign up or sign in (including magic-link email and, if enabled, Google OAuth).
- Workspace content - the product descriptions, strategy inputs, chat messages, generated panels, content pieces, and related metadata you create in Rallik.
- Connected marketing account data - when you choose to connect an advertising or analytics account (Google or Meta), we read performance and reporting data from that account on your behalf. See “Connected marketing accounts” below for exactly what we access and how we use it.
- Usage and billing data - credit balances, generation activity, subscription status, and payment-related records processed through our billing partner (Polar). We do not store full payment card numbers on our servers.
- Technical data - device/browser type, IP address, session cookies, and diagnostic logs needed to operate, secure, and improve the service.
How we use your information
We use the information above to:
- Provide, maintain, and improve Rallik's strategy and content features.
- Authenticate you and manage individual and team workspaces.
- Run AI-assisted generation, grounding, and quality checks on your inputs.
- Display, summarize, and audit the performance of marketing accounts you connect, and use those insights to inform the strategy and content Rallik generates for you.
- Meter credits, process subscriptions, and send billing-related communications.
- Send transactional email (sign-in links, account notices) via our email provider.
- Detect abuse, enforce our Terms of Service, and protect the security of the platform.
- Comply with legal obligations and respond to lawful requests.
We do not sell your personal information.
Connected marketing accounts
Rallik allows you to connect selected third-party marketing accounts so that the service can analyze performance and ground recommendations in your actual business data. Connecting is optional, and you may disconnect an account at any time.
Google connections - Access to Google Ads, Google Analytics 4, and Google Search Console is strictly read-only. Rallik can retrieve reporting and performance information, but cannot create, edit, publish, pause, delete, or otherwise modify anything in your Google accounts.
Meta connections - Rallik uses Meta account data for reporting, analysis, audits, strategy, and recommendations. In your setup, Meta access is read-only and does not allow account modifications.
Depending on the connection and permissions you select, we may access:
- Google Ads (scope
adwords) - campaign, ad group, ad, and search-term reporting: impressions, clicks, cost, conversions, and conversion value. - Google Analytics (GA4) (scope
analytics.readonly) - aggregated traffic and conversion metrics by channel and landing page. - Google Search Console (scope
webmasters.readonly) - organic search queries, pages, clicks, impressions, and average position. - Meta (Facebook/Instagram) Ads (permission
ads_read) - ad account, campaign, ad set, ad, and ad insights: impressions, clicks, spend, reach, frequency, and conversions.
How connected data is used. Connected platform information is used only to (a) display performance inside your workspace; (b) produce audits, reports, alerts, and recommendations; and (c) identify changes that may deserve your attention. We do not sell connected-platform data, use it to advertise to you or others, share it with unrelated advertisers or data brokers, or use it to train generalized AI models.
How it is stored. Access and refresh tokens are encrypted at rest and used only by our servers to provide the requested connection. Synced metrics are stored in our secure database and tied to your workspace.
Disconnecting and deletion. You may disconnect an account from Workspace or Settings → Connections. On disconnect we delete the stored tokens and, where supported, request revocation from the provider. You can also request deletion of synced data by deleting the relevant source or workspace, using our data-deletion flow, or emailing support@rallik.com. You can revoke access directly from your Google account permissions or your Meta business integrations settings.
Google user data - Limited Use
Rallik's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, data obtained from Google Ads, Google Analytics, and Google Search Console is used only to provide and improve user-facing features within Rallik; is not transferred or sold except as necessary to provide those features, comply with law, or as part of a merger or acquisition; is not used for advertising; and is not used to train generalized or standalone artificial-intelligence models. Humans do not read this data except with your explicit consent, for security purposes, to comply with applicable law, or in aggregated/anonymized form for internal operations.
Meta Platform data
Data obtained through Meta APIs is handled in accordance with the Meta Platform Terms and Developer Policies. We read Meta advertising and organic performance insights solely to provide the features described above. Rallik never publishes, schedules, or changes anything in your Meta accounts. To request deletion of data Rallik obtained from Meta, disconnect the account in Settings → Connections or email support@rallik.com, and we will delete the associated tokens and metrics.
AI processing and third-party providers
To generate and validate your strategy, audits, and content, Rallik sends portions of your workspace content - and, when you request an analysis or report, the performance metrics read from your connected accounts - to our language-model provider. That provider processes the data only to perform this task on our behalf, under terms that prohibit using it to train or improve its models, and returns the result to you.
Data received from Google or Meta APIs is used solely to power features inside your own Rallik workspace. It is never used for advertising, never sold or transferred to data brokers or advertisers, and never used to develop, improve, or train generalized or standalone AI/ML models.
AI output may be inaccurate or incomplete. You are responsible for reviewing generated strategy and content before use.
How we share information
We share information only as needed to operate Rallik:
- Polar - payment processing, subscriptions, tax/receipt handling as Merchant of Record.
- Hosting and database - cloud infrastructure that stores encrypted application data.
- Email delivery - transactional messages such as magic-link sign-in.
- Realtime services - live updates to your workspace while generation runs.
- Team members - if you join or create an organization workspace, other members of that workspace may access shared projects according to their role.
- Legal and safety - when required by law or to protect rights, safety, and integrity of the service.
We do not sell your personal information and we do not share data obtained from Google or Meta APIs with third parties except the infrastructure sub-processors above that operate on our behalf to deliver the service.
Data retention
We retain account and workspace data while your account is active. Connected-account tokens are retained only while the connection is active and are deleted on disconnect. Synced performance metrics are retained to power your reports and are deleted when you delete the data, disconnect the source (if you choose to remove data too), or close your account. If you delete a project or close your account, we delete or anonymize associated data within a reasonable period, except where we must retain records for billing, security, or legal compliance.
Security
We use industry-standard measures including encrypted transport (HTTPS), encryption of third-party access tokens at rest, access controls, and database security practices. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
Your choices and rights
Depending on where you live, you may have the right to:
- Access, correct, or delete personal information we hold about you.
- Export workspace data you created in Rallik.
- Disconnect any linked marketing account and delete its synced data.
- Object to or restrict certain processing.
- Withdraw consent where processing is consent-based.
To make a request, email support@rallik.com. We may need to verify your identity before responding.
International transfers
Rallik may process and store information in countries other than where you live. When we transfer data internationally, we use appropriate safeguards consistent with applicable law.
Children
Rallik is not directed to children under 16, and we do not knowingly collect personal information from them. Contact us if you believe a child has provided us data.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the “Last updated” date. Material changes may also be communicated by email or in-product notice.
Contact
Questions about privacy, or to request data deletion: support@rallik.com