Skip to main content

Data and security

How Hero Marketer handles the data you give it.

What we store

Roughly four categories:

Authentication

  • Your Hero Marketer login. Email, name, hashed credentials. Supabase, our auth provider, manages your login.
  • OAuth tokens for Google Ads. Hero Marketer uses these only to make API calls to Google Ads on your behalf. Hero Marketer stores refresh tokens to keep the connection alive. Access tokens are short lived, and Hero Marketer refreshes them without any action from you. You can revoke the connection at any time (see Google Ads scopes, below).

Product information

  • Product descriptions you wrote during onboarding or product setup.
  • Product context, which Hero Marketer derives from those descriptions.
  • Website URLs you configured.

Campaign records

  • Campaigns built through Hero Marketer. The campaign's targeting, keywords, ad copy, and creation date.
  • Drafts of campaigns in progress (the wizard saves your progress).

Hero AI conversation history

  • Chat sessions and messages. Every saved chat (up to 10 per Google Ads account), including the full message history and cost data for each session. Each Google Ads account has its own list of chats.
  • AI usage events. Per call audit records of how many tokens each AI model used and what credits Hero Marketer charged. Hero Marketer uses these records for billing accuracy, the transaction history in billing settings, and the personalized cost estimates Hero AI shows before you send a message.

What we do not store

  • Live campaign performance metrics. Hero Marketer pulls these from Google Ads on demand. It caches them only briefly, to keep the product fast.
  • Your Google Ads payment method or billing details. Google holds this.
  • Your Hero Marketer card details. Paddle, our billing provider, holds this. We see only what Paddle exposes (last four digits, expiration, billing address).
  • Anything outside Google Ads. We do not have access to your CRM, email, calendar, or other tools.

Where data lives

  • Application database. Supabase (Postgres). We host it in US data centers.
  • AI providers. Hero AI sends your inputs to its AI providers (Anthropic and Google) per query to generate each answer. Our agreements with these providers govern how they handle your data.
  • Billing. Paddle handles cards, invoices, tax, and region specific compliance.
  • Auth. Supabase auth.

We pick providers with strong privacy and security practices. You can request SOC 2 Type II reports from major providers (Google Cloud, Supabase, Paddle) through their normal channels.

Encryption

  • In transit. All connections use HTTPS/TLS.
  • At rest. Supabase, our hosting provider, encrypts database storage at the disk level. Supabase restricts and logs access to the underlying data.

Access controls

Internally:

  • Engineering and customer support staff can access account level data when investigating issues. Hero Marketer logs this access.
  • No one else has access to your data without your explicit consent.

We do not sell, rent, or share your data with third parties for marketing purposes.

When you connect Google Ads, Hero Marketer requests a single OAuth scope: adwords. It is the standard scope for Google Ads API access. Hero Marketer needs it to read account info, fetch keyword data, and create campaigns. Google's consent screen lets you pick which account to connect.

Hero Marketer does not request access to Gmail, Drive, Calendar, or any other Google service.

You can revoke access at any time at myaccount.google.com/permissions. See Disconnect Google Ads.

Compliance

  • GDPR. We comply with GDPR for EU users. We honor the right to access, the right to deletion, and data portability. Contact support to use these rights.
  • CCPA. We comply with CCPA for California users. You get the same rights as GDPR, plus the right to opt out of the sale of personal information (we do not sell data anyway).
  • SOC 2. Our hosting and infrastructure providers (Supabase, Google Cloud, Paddle) are SOC 2 Type II certified. Hero Marketer itself is not SOC 2 certified.

Data retention

  • Active subscription. Hero Marketer retains your data for the life of your subscription.
  • After cancellation. Hero Marketer retains your data for 90 days. After that, it may archive your account.
  • After deletion request. Hero Marketer removes your data within 30 days, including from backups.

Exporting your data

You can request an export of:

  • Your product descriptions and analysis.
  • Your campaign records and metadata.
  • Your Hero AI conversation history.

Contact support with the request. We deliver it as a JSON or CSV bundle within 5 business days.

Note: live performance metrics are not part of the export because they are not stored. Pull those directly from Google Ads. Use Google's report export tools.

Deletion

To fully delete your account and data:

  1. Contact support with a deletion request.
  2. We confirm by email and remove access immediately.
  3. We purge data from production systems within 7 days.
  4. Backups that contain the data expire within 30 days.

After deletion, no one can recover your data. To reactivate, you must start fresh.

Reporting a security issue

If you believe you found a security vulnerability in Hero Marketer:

Contact support and prefix the subject with "Security:". We treat security reports as the highest priority. Please do not post details publicly until we have a chance to investigate and respond.

Data Processing Agreement (DPA)

For customers who require a signed DPA (under GDPR or other regulations):

Contact support and request the DPA template. We countersign and send back a signed copy.

Next