Privacy Policy
Overview
Rallik is an AI marketing strategy workspace, and is the data controller for the information described here. This policy explains what we collect, how we use data you connect from Google and Meta, and the choices you have.
By creating an account you agree to this policy. If you do not agree, please do not use the service.
What we collect
- Account information — your name, email address, and authentication details. You sign in with an email address and password, or with Google if you choose. We never see your Google password, and we store passwords only as a salted hash, never in a readable form.
- Workspace content — everything you create in Rallik: your messages to the strategist, the strategy pieces you accept, campaigns, channels, assets, open questions and recorded results.
- Connected advertising data — if you connect a Google or Meta account, the reporting figures we read on your behalf. See Connected accounts for exactly what and why.
- Usage and billing — how many strategies, replies and web lookups you have used, and your subscription status. Payments are handled by Polar as Merchant of Record; card numbers never reach our servers.
- Technical data — IP address, browser type, session cookies and server logs needed to run and secure the service.
How we use it
- To run the service and keep your strategies available to you.
- To authenticate you and keep your account secure.
- To generate strategy proposals, research and recommendations from what you tell us and what your connected accounts report.
- To apply plan limits and process subscriptions.
- To detect abuse and enforce our Terms.
- To meet legal obligations.
We do not sell your personal information, and we do not use it to advertise to you.
Connected advertising accounts
Connecting an account is optional and can be undone at any time from Connections in the app. Everything Rallik does with these accounts is read-only. Rallik cannot create, edit, pause, publish, delete or spend anything on any connected platform, and does not request the permissions that would allow it to.
| Platform | Permission requested | What we read |
|---|---|---|
| Google Ads | adwords | Campaign, ad group and ad reporting — impressions, clicks, cost, conversions and conversion value. Also keyword ideas and search volume, requested through the Keyword Planner service when you ask for keyword research. |
| Google Analytics 4 | analytics.readonly | Aggregated traffic and conversion metrics by channel and page. |
| Google Search Console | webmasters.readonly | Organic queries, pages, clicks, impressions and average position. |
| Meta Ads | ads_read | Ad account, campaign, ad set and ad insights — impressions, clicks, spend, reach, frequency and conversions. |
ads_read is the read-only Meta permission. ads_management, which would allow changes, is never requested.
How connected data is used
Only to show performance inside your own workspace, to produce audits and recommendations for you, and to flag changes worth your attention. It is never sold, never shared with advertisers or data brokers, never used to target advertising, and never used to train generalized AI models.
How it is stored
Access and refresh tokens are encrypted at rest with AES-256-GCM and are used only by our servers to fulfil your requests. Performance figures we sync are stored in our database, tied to your account.
Disconnecting and deletion
Disconnect a platform from Connections and we delete the stored tokens. To remove everything, use Delete account on your Account page, which erases your strategies, conversations, campaigns, connections and synced metrics. You can also revoke access directly at Google account permissions or Meta business integrations, or email support@rallik.com.
Google user data — Limited Use
Rallik's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Data from Google Ads, Analytics and Search Console is used only to provide user-facing features inside Rallik; is not transferred except as needed to provide those features, comply with law, or as part of a merger or acquisition; is not used for advertising; and is not used to train generalized or standalone AI models. No human reads it except with your explicit consent, for security, to comply with law, or in aggregated anonymised form.
Meta platform data
Data obtained through Meta APIs is handled under the Meta Platform Terms and Developer Policies, and is read solely to provide the features above. Rallik never publishes, schedules or changes anything in your Meta accounts. To request deletion, disconnect the account in Connections, delete your account, or email support@rallik.com.
AI processing
To produce strategy proposals and research, Rallik sends parts of your workspace content — and, when you ask for analysis, figures read from your connected accounts — to a third-party language model provider acting on our behalf. The provider processes it to answer that request and returns the result. Data received from Google or Meta APIs is never used to develop, improve or train generalized or standalone AI models.
Rallik also performs web searches on your behalf when research would change a recommendation. Those searches carry your query, not your account identity.
AI output can be wrong or incomplete. You review and approve every proposal before it becomes part of your strategy — nothing is saved until you accept it.
Who else processes your data
- Polar — payments, subscriptions, tax and receipts, as Merchant of Record.
- Cloud hosting and database providers — running the application and storing its data.
- Resend — delivering account verification and password recovery emails.
- Our language model and web research providers — as described above.
- Legal and safety — where required by law or to protect the service and its users.
We do not share data obtained from Google or Meta APIs with anyone beyond the providers above that operate on our behalf.
Retention
We keep your account and workspace data while your account exists. Connection tokens are kept only while that connection is active and are deleted when you disconnect. Deleting your account removes your data immediately, except records we must keep for billing, tax or legal reasons.
Security
Encrypted transport (HTTPS), AES-256-GCM encryption of third-party tokens at rest, hashed passwords, and access controls that scope every query to the signed-in account. No system is perfectly secure and we cannot guarantee absolute security.
Your rights
Depending on where you live, you may have the right to:
- Access and export — download everything we hold from Download my data on your Account page.
- Deletion — Delete account on the same page removes it all.
- Correct information we hold about you.
- Object to or restrict certain processing.
- Withdraw consent where processing relies on it.
- Complain to your local data protection authority.
Both export and deletion are self-service and immediate. For anything else, email support@rallik.com. We may need to verify your identity first.
International transfers
We may process data in countries other than yours, using appropriate safeguards as required by applicable law.
Children
Rallik is not for under-16s and we do not knowingly collect their data. Contact us if you believe a child has provided us information.
Changes
We may update this policy. The revised version appears here with a new date, and material changes will also be notified by email or in the app.
Contact
Rallik
support@rallik.com