Plain-English summary: Cofoundr AI helps you run your Facebook and Instagram ad campaigns.
You sign in with Facebook. We never see your password. We use your data only to run the
service you asked for, we keep access keys encrypted, and you can ask us to delete your data
at any time.
This Privacy Policy explains how Cofoundr AI ("we", "us", "the Service") collects, uses, stores, and protects
information when you use the Cofoundr AI platform.
1. Who we are
Cofoundr AI is an AI-assisted advertising platform built for performance marketing agencies.
For any privacy question or request, contact us at the email in the Contact section below.
2. Information we collect
- Account information - your name and email, and the basic Facebook profile
details you approve when you sign in with Facebook Login.
- Advertising data - the ad accounts, Pages, campaigns, performance metrics,
and audiences associated with the accounts you connect, accessed through the Meta Marketing API.
- Lead data - where you run lead-generation campaigns, the lead information
submitted by your prospects, which we process on your behalf so you can retrieve and export it.
- Usage data - actions you take in the Service and basic technical logs
(such as timestamps and IP address) used for security and troubleshooting.
- Billing data - handled by our payment processor; we do not store full
card details.
3. How we use your information
- To provide the Service: building, launching, optimising, and reporting on the campaigns you request.
- To authenticate you and keep your account and data secure.
- To meter usage against your subscription plan and process payments.
- To detect, investigate, and prevent fraud, abuse, or security incidents.
- To generate anonymized, aggregated industry benchmarks that help all users understand how their performance compares to similar accounts (see Section 3a below).
We do not sell your personal information, and we do not use your advertising or lead data for
any purpose other than operating the Service for you.
3a. Anonymized performance benchmarks
We aggregate anonymized performance metrics (such as cost-per-result, click-through rate, and
frequency) across accounts to generate industry benchmarks grouped by business type and budget tier.
These benchmarks help you understand how your campaigns compare to similar accounts on the platform.
- What is included: only numerical performance metrics (CPA, CTR, ROAS, frequency, daily spend). No account names, campaign names, creative content, audience data, or any identifying information.
- How it works: individual account data is combined into statistical summaries (medians and percentiles). A minimum of 5 contributing agencies is required before any global benchmark is surfaced, ensuring no individual account can be identified.
- Your choice: you can opt out of contributing to platform-wide benchmarks at any time in Settings. When opted out, your data is excluded from global benchmarks, but you still receive benchmark insights from your own accounts. Opting out does not affect any other feature of the Service.
- Retention: raw performance snapshots used for benchmark computation are automatically deleted after 90 days. Aggregated benchmarks (which contain no identifying information) are retained indefinitely.
4. Facebook / Meta data
When you connect your account, you authorise the Service through Meta's official Facebook
Login. We receive a secure access token that lets the Service act on your behalf for the
permissions you approve. We never receive or store your Facebook password.
Access tokens are stored encrypted and are used only on our secure servers to make the API calls
you request. Our use of information received from Meta APIs follows Meta's Platform Terms
and Developer Policies.
4a. MCP Remote Server
If you use the MCP Remote Server feature, you grant Cofoundr permission to expose your connected ad account data to external AI tools (such as Claude, ChatGPT, or other MCP-compatible clients) via API tokens you generate.
- What is shared - only the ad account data you explicitly scope to each API token. You control which accounts each token can access.
- Write actions - MCP tokens with "readwrite" mode can perform actions on your ad accounts (pause, scale, create). Each write action is logged and counts against your monthly credit allocation.
- Token security - API tokens are stored as irreversible hashes. The plaintext token is shown once at creation and cannot be retrieved. You can revoke any token at any time from Settings.
- Third-party AI tools - when you connect an MCP token to a third-party AI tool, that tool receives your ad data according to its own privacy policy. Cofoundr is not responsible for how third-party AI providers handle data once it leaves our servers.
5. How we share information
We share information only with service providers who help us operate the platform, under
appropriate confidentiality and data-protection obligations:
- Hosting - our application and database infrastructure provider.
- Payments - our payment processor, for subscription billing.
- AI processing - our AI provider, to generate strategies, creatives, and analysis.
We may also disclose information if required by law.
6. Data retention and deletion
We keep your data for as long as your account is active or as needed to provide the Service.
You can disconnect your Facebook account at any time, and you may request deletion of your data
by emailing us at the address below. We will delete or de-identify your personal data within a
reasonable period, except where retention is required by law. You can also remove the app's
access from your Facebook settings under Settings > Business Integrations.
7. Security
We use industry-standard safeguards including encryption of access tokens at rest, restricted
server-side access, activity logging, and least-privilege permissions. No system is perfectly
secure, but we work to protect your information and to respond promptly to any incident.
8. Children
The Service is intended for businesses and is not directed to individuals under 18. We do not
knowingly collect data from children.
9. Changes to this policy
We may update this Policy from time to time. We will post the updated version here and revise
the effective date above.
10. Contact
Questions or requests (including data deletion): [email protected]