Inhouse Marketing← Back to home

Privacy Policy

Version 2026-08-29 · Last updated: 29 August 2026

Client-cell model providers. Your agent runs through Nous Research's Nous Portal: Ada on xAI's Grok 4.6 (x-ai/grok-4.6), and every specialist and scheduled job on DeepSeek's V4.1 Flash (deepseek/deepseek-v4.1-flash). Your conversations, the Google Ads data the agents' tools return, and scheduled-job inputs are processed by these providers on our account. This note governs your cell's model traffic; the provider list in the sections below still describes the earlier control-plane routing and is being re-issued for this service.

1. Introduction

This Privacy Policy describes how Shoutout Digital Pty Ltd ("we", "us", or "our") collects, uses, stores, and protects personal information when you use Inhouse Marketing — the service whose AI agents, Ada and Grace, monitor and operate your own Google Ads account.

We are committed to protecting your privacy and complying with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This policy follows those principles: what we collect, why, where it is stored, who processes it for us, how long it is kept, and the rights you have over it.

ABN: 76 940 404 243

Contact: hello@inhousemarketing.ai

2. What we collect

Information from Google Ads

When you authorize access to your Google Ads account, we collect and access:

  • Google Ads account information (account IDs, customer IDs, names, settings)
  • Campaign data (names, IDs, statuses, budgets, settings)
  • Ad performance data (impressions, clicks, cost, conversion metrics, historical performance)
  • Campaign structure (ad groups, ads, keywords, audiences, targeting)

Note: We do not collect or store Google passwords. Authentication is handled by Google OAuth 2.0.

Information you provide

  • Your name, email address, and sign-in details (managed by our authentication provider, Clerk)
  • Your business details and the goals, guardrails, and preferences you set
  • Your conversations with Ada — chat messages, onboarding answers, and the approval decisions you make
  • Communication preferences and settings

Billing information

Payments are processed by Stripe. Your card details are entered into Stripe’s checkout and are never seen or stored by us. We receive and keep your subscription status, invoices, usage records, and billing history.

Records the service creates

  • Actions the agents take in your advertising account, and their verification results
  • Credit usage and metering records
  • The record of which versions of our legal documents you accepted, and when

Usage and performance data

We collect technical data including device and browser information, IP address, feature usage analytics, and interaction patterns, to operate and improve the service.

Connected services you choose

If you connect third-party services (for example Meta, Instagram, WordPress, Google Business Profile, or Mailchimp), we receive the data from those services that the connection grants, through our integration partner Composio. Connecting them is optional and separate from Google Ads.

3. How we use your information

Your information is used exclusively for:

  1. Operating the service: analysis, recommendations, and the agent actions described in our Terms of Service
  2. Generating performance reports and historical trends for your account only
  3. Billing, metering, and managing your subscription
  4. Managing your service account and authentication
  5. Support, security, fraud prevention, and meeting our legal obligations

Importantly: your Google Ads data is used only for analysis and action on YOUR account. We do not:

  • Use your data to train machine learning models ourselves
  • Sell or trade your data
  • Use your data for our own advertising or marketing targeting
  • Share your data with competitors or unrelated third parties
  • Combine your account data with another customer’s account data

4. AI processing and automated decision-making

Ada and Grace are AI agents. To produce their responses, analysis, and (within the limits in our Terms of Service) actions in your account, prompts containing account data excerpts and your conversation content are sent to third-party AI model providers for inference — that is, to generate the answer you or the agent asked for, and nothing else.

The providers that process this content, depending on the workload and current routing, are:

  • Alibaba Cloud Model Studio (Singapore) — currently serves Ada and Grace conversations, using the GLM model from Zhipu. Full conversation content, including Google Ads data returned by the agents’ tools, is processed at this endpoint.
  • xAI (United States) — agent model traffic under current deployed routing.
  • OpenAI (United States) — specialist audit and composition workloads, and text embeddings for the agents’ memory features. Prompts and embedding inputs can include Google Ads performance summaries, your goal settings, and memory text.
  • Moonshot AI (China) — specialist evaluation (judge) workloads, whose prompts can include Google Ads performance summaries and goal context.

The set of providers can change as routing is tuned; this policy is updated when it does, and the current version is always shown at the top of this page.

The automated actions the agents take concern your advertising account settings. The service does not make automated decisions that produce legal or similarly significant effects on you as an individual, and you can ask a human to review anything the agents have said or done by contacting us (section 14).

5. How the agents act in your account

Within the safety envelope you approve during onboarding, the agents may execute bounded changes to existing campaigns when the relevant action class is enabled by your policy and the evidence and caps are met. This can include pausing or enabling an existing campaign; adjusting budgets and bids or a bidding strategy; creating or changing ads, headlines, and descriptions; and adding or removing keywords and negative keywords. A new campaign is proposal-only: the agents may prepare a proposal for your review, but they do not create or launch it unless you explicitly approve the build and launch. Nothing outside the approved autonomous action classes happens until you approve it. The agents will ask, and will wait for your approval, before creating a new campaign or launching one, and before any action outside the approved envelope, classes, or caps. Every action is recorded, verified against your account afterwards, and anything that cannot be verified is flagged and surfaced for review in the dashboard; where the advertising platform allows, a change can be reversed. The Terms of Service (section 2) describe this authority model in full; the records of agent actions are part of the data this policy covers.

6. Data storage and security

Your data is stored in encrypted form at rest using AES encryption in a PostgreSQL database hosted on Supabase, on Amazon Web Services infrastructure provisioned in the Sydney (ap-southeast-2) region.

Encryption: API tokens and sensitive credentials are encrypted using AES before storage in our token vault.

Isolation and access controls: every customer’s data is isolated by database row-level security, and access is restricted to authorized system processes, our recommendation engine, and our infrastructure team (on-call support only).

We implement standard security practices including:

  • HTTPS encryption for all data in transit
  • Database-level access controls and per-customer row-level security
  • Encrypted credential storage
  • Regular security audits

7. Who we share information with

We do not share your Google Ads data with third parties except as required to deliver the service. We use the following services to host, process, or transmit data:

  • Supabase (database hosting, on AWS Sydney) — stores account data, ads data, conversations, and billing records, encrypted at rest
  • Vercel (dashboard hosting) — serves the web application and processes standard web request logs. Application compute runs in Sydney, Australia; requests are routed through Vercel's global edge network, which may terminate connections outside Australia.
  • Railway (compute hosting, United States) — runs the worker and a dedicated agent instance per customer, which process account data and conversations; our provisioning tooling posts service configuration to Railway’s API
  • Clerk (authentication, United States) — manages sign-in, your email address, and session metadata
  • Stripe (payments, United States) — processes card payments, invoices, billing details, and usage metering records; we never see full card numbers
  • Google (Google Ads API and sign-in, United States) — the source of your advertising data, under your Google account’s own permissions
  • Alibaba Cloud Model Studio (Singapore) — AI model inference for Ada and Grace conversations, as described in section 4
  • xAI (United States), OpenAI (United States), and Moonshot AI (China) — AI model inference and text embeddings for the agents, as described in section 4
  • Composio (integrations, United States) — optional third-party connections you choose to make; OAuth flows and connected-account data pass through Composio
  • Discord (messaging, United States) — only if you choose to talk with Ada over Discord; message content transits Discord’s platform, and operational alert posts may include account identifiers
  • Inngest (background jobs, United States) — schedules and runs background work; job payloads may include account identifiers and work records
  • Resend (email, United States) — delivers billing usage-alert emails to the billing owner’s email address

We may also enable error-tracking and usage-monitoring tools (such as Sentry or Langfuse) per environment; where enabled, diagnostic records may include account identifiers. We will update this list as the processors that handle customer data change.

8. Cross-border disclosure

Our primary database is hosted in Australia. Some processors listed in section 7 are located overseas — principally the United States; Singapore, in the case of Alibaba Cloud; and China, in the case of Moonshot AI — so using the service involves disclosing information to recipients in those countries.

Before disclosing personal information overseas (APP 8), we take reasonable steps to ensure recipients handle it consistently with the Australian Privacy Principles — through contractual commitments and by limiting what each recipient receives to what its function requires. By using the service you consent to these disclosures; if you do not consent, please do not use the service, and contact us about deletion of what we already hold (section 10).

9. Data retention and deletion

While your account is active

We keep your data while your account is active and as needed to operate the service. Historical Google Ads snapshots are retained to enable trend analysis and reporting.

After cancellation

When your subscription ends, your account data — conversations, reports, and history — is retained for 30 days from the date the cancellation takes effect. During those 30 days you can export your data, and read-only access and support remain available. After that period, access to the service ends. We do not delete account data automatically: deletion is on request (section 10), and we then delete your data from our primary systems, subject to the records below that the law requires or permits us to keep. Copies held in encrypted backups are not restored to live systems and are overwritten as backups cycle out in the ordinary course, so deletion from primary systems takes full effect as those backups cycle.

Records kept longer

  • Billing and tax records are retained as required by Australian tax law (generally five years)
  • The record of which versions of our legal documents you accepted, and when, is retained as evidence of our agreement
  • Security and audit logs are retained for a limited period to protect the service

What happens when you disconnect Google Ads

When you disconnect your Google Ads account or revoke access:

  1. We cease all data collection from Google Ads immediately
  2. Historical snapshots and cached Google Ads data already collected are handled under the retention rules above — they are not deleted automatically, and you can request their deletion at any time
  3. Your other account data is handled as described above

10. Your rights under the Privacy Act

Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you have the right to:

  • Access the personal information we hold about you (APP 12)
  • Correct personal information that is inaccurate, out of date, or incomplete (APP 13)
  • Request deletion of your personal information, subject to the legal retention requirements in section 9
  • Complain about our handling of your personal information, and have that complaint investigated

To exercise any of these rights, email us at hello@inhousemarketing.ai. We will verify your identity before acting, and we respond within 30 days. You can also export your account data from the dashboard while your account is active and during the 30-day post-cancellation period.

11. How to revoke access

You can revoke our access to your Google data at any time:

  • Visit your Google Account permissions page and remove Inhouse Marketing.
  • Use the disconnect option in our dashboard (Connections → Disconnect).

Revoking access stops future data collection. Section 9 describes how the data we already hold is retained and how to request its deletion.

12. Google API Services User Data Policy

Limited Use Commitment:

Inhouse Marketing’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Your data accessed through Google APIs is used only to provide the service you authorized and for no other purpose. We do not:

  • Transfer data to third parties except as necessary to provide the service
  • Use data for advertising, targeting, or marketing purposes
  • Combine data from multiple accounts
  • Use data to build alternative services or competitive products
  • Retain data longer than necessary to provide the service

This is our binding commitment under the Google API Services User Data Policy.

13. Cookies and tracking

The dashboard uses only strictly necessary cookies — sign-in and session cookies from our authentication provider, and preference storage for the interface. We do not use third-party advertising cookies or cross-site trackers on the dashboard.

14. Complaints and escalation

If you believe we have breached the Privacy Act or the Australian Privacy Principles, contact us first at hello@inhousemarketing.ai. We will acknowledge your complaint, investigate it, and respond within 30 days.

If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC):

  • Online: oaic.gov.au/privacy/privacy-complaints
  • Phone: 1300 363 992
  • Post: GPO Box 5288, Sydney NSW 2001

15. Changes to this policy

We may update this policy as the service and its processors evolve. Each version carries its own version identifier and date, shown at the top of this page. When a new version takes effect for your account we will tell you in the dashboard or by email and ask you to accept it before you continue using the paid service. Your acceptance of earlier versions stays on record and is never changed retroactively.

16. Contact us

Email: hello@inhousemarketing.ai

Address: 328 Albany Hwy, Victoria Park WA 6100

ABN: 76 940 404 243

← Back to home

Version 2026-08-29 · Last updated: 29 August 2026