Intellisea ("we," "our," or "us") is committed to protecting the privacy and security of our users. This Privacy Policy describes how we collect, use, store, share, and safeguard information when you use the Intellisea platform — an agentic AI-powered digital marketing SaaS application.
By accessing or using Intellisea, you agree to the terms of this Privacy Policy. If you do not agree, please discontinue use of the platform.
If you are looking for something specific: section 3 sets out, platform by platform, exactly what we access from your connected accounts — Google, Facebook and Instagram, LinkedIn, and everything else — and section 6 covers retention and deletion. To have data deleted, or simply to disconnect an account, see our Data Deletion page; you do not need to be signed in to make a request.
When you register for Intellisea, we collect:
Content you create or upload within the platform, including:
When you connect an integration, you authorise us to act on that account on your behalf. We access, and in most cases can also write to, the following platforms. Section 3 describes each one in detail — what is accessed, why, how it is stored, and how to revoke it.
This platform data is used to let our AI agents understand your business and carry out the marketing work you ask for. We do not sell, share, or redistribute your connected platform data to any external party. It is processed only on our own infrastructure and by the subprocessors listed on our Subprocessors page.
Some of this data includes personal information about people who are not Intellisea users — for example the contact details a person submits through a Facebook or LinkedIn lead form, the content of a message someone sends to your Facebook Page, or a comment left on one of your posts. We process that information solely to carry out your instructions in relation to your own accounts, and only for as long as described in section 6. Where you supply us with contact data of your own — for instance to build a LinkedIn matched audience — you are responsible for having a lawful basis to do so.
We use collected information to:
This section is the detailed, platform-by-platform account of what Intellisea does with data from the accounts you connect. Subsections 3.1 to 3.4 cover Google, 3.5 covers Meta (Facebook Pages and Instagram), 3.6 covers LinkedIn, and 3.7 covers the remaining integrations. Subsections 3.8 and 3.9 cover our use of AI models.
Two things are true of every platform below, so they are stated once rather than repeated. First, access tokens are held only in AWS Secrets Manager, encrypted, and are never written to our application database or exposed to your browser. Second, data from your connected accounts is never used to train, fine-tune or improve any AI model — see subsection 3.8.
Intellisea's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, Intellisea:
This is the complete list. Each Google integration requests only the scopes for that integration, and only when you connect it — connecting Google Analytics does not grant anything listed against Search Console or Business Profile. The "Access" column states plainly whether the scope is used to read data, or also to change something in your Google account, because that is the distinction that matters most.
| Google service | Scope | Access | What we use it for |
|---|---|---|---|
| Google Identity | openid | Read | Confirms which Google account completed the connection, so the integration is attached to the right person. |
| Google Identity | userinfo.email | Read | Reads the email address of the Google account you connect. We display it on the Integrations page so you can see which account is linked, and we use it to recognise the same Google account if you connect it to more than one Intellisea organization. We do not use it to send you marketing. |
| Google Analytics | analytics.readonly | Read | Reads your GA4 reporting data — sessions, traffic sources, landing pages, conversions, audience and geographic breakdowns, device data and real-time users — to produce the performance reporting and recommendations in the platform. |
| Google Analytics | analytics.edit | Read and write | Configures measurement on your GA4 property when you ask us to: creating, updating and deleting key events (conversions), creating custom dimensions and custom metrics, reading and creating data streams, updating property settings, reading the property's Google Ads links, and linking a Google Ads account to the property. It also switches enhanced measurement on or off for an individual data stream — whether GA4 automatically records scrolls, outbound clicks, site search, video engagement and file downloads. And it builds audience segments for you: an audience defined by an event, or by a dimension such as country or device category, and archiving one when it is no longer wanted. Linking an Ads account deserves spelling out on its own, because it joins two of your own accounts rather than changing a setting inside one: it connects this GA4 property to a Google Ads account you nominate, so that audiences built in GA4 can be used for remarketing in Google Ads and so Ads campaign data appears in your GA4 reporting. An agent creates such a link only as part of work you have asked for, and only for an Ads account your own Google sign-in already administers — we cannot reach an account you do not have access to. Unless you tell us otherwise the link is created with ads personalisation enabled, which permits Google to use the GA4 data flowing across it for personalised advertising; ask us and we will create it with personalisation switched off, or remove the link altogether. The read-only scope cannot create a conversion event, which is why this scope is needed. Configuration can therefore be removed as well as added, but your reporting history itself is never deleted. |
| Google Ads | adwords | Read and write | Reads campaign, ad group, keyword, budget and performance data for reporting and optimisation advice; and, when you deploy a campaign from Intellisea, creates and updates campaigns, ad groups, keywords, ads, budgets and bidding on your Google Ads account. The same access also deletes — campaigns, keywords, ads, placements, ad extensions, audience segments, location targets and ad schedules can be removed outright, not merely paused. It sets up the conversion actions that measure results, and it configures who sees your ads: audience segments, geographic and proximity targeting, device and language targeting, ad schedules, and demographic exclusions. Building a display, video or Performance Max ad also writes image files into your account: we fetch each image from a URL, resize it into the landscape, square and logo shapes Google requires, and upload it there as a reusable asset. It can also apply Google's own recommendations to your account — a change Google proposed and an agent accepted for you, rather than one you asked for by name. We do not upload your customers' personal data to Google Ads. This integration has no contact-list or Customer Match upload of any kind, and when an audience is targeted it is one that already exists in your own Google Ads account. Campaign changes spend your money, so this is the scope to think hardest about before granting. |
| Google Search Console | webmasters | Read and write | Reads search performance data (queries, pages, clicks, impressions, position), index coverage, URL inspection results, Core Web Vitals, mobile usability, structured data and link reports; and lists, submits and deletes sitemaps for your verified sites. The read-only scope cannot submit a sitemap, which is why the read-write scope is requested. |
| Google Search Console | indexing | Write | Notifies Google that a page on your site is new, updated, or has been removed, so newly published content is crawled sooner. It submits URLs on your own verified property only. It reads no personal data. |
| Google Tag Manager | tagmanager.readonly | Read | Reads your container's existing tags, triggers, variables and versions so we can tell you what measurement is already in place before changing anything. It also lists the Tag Manager accounts and containers you have access to, so you can choose which container to connect in the first place. |
| Google Tag Manager | tagmanager.edit.containers | Read and write | Creates, updates and deletes the tags inside your container, and creates the triggers and variables those tags depend on — for example adding a conversion tag for a campaign we are running for you. Changes are made in a workspace first. This scope also creates a brand-new container in your Tag Manager account when your site does not have one yet, and gives you the snippet to install on your site. Creating a container adds something new to your Google account rather than changing what is already there, so it is the biggest thing this scope allows — and an agent can do it while setting measurement up for you. |
| Google Tag Manager | tagmanager.edit.containerversions | Write | Saves the draft in your Tag Manager workspace as a numbered container version — the snapshot Google keeps in your container's version history — and generates the preview link we use to test a change before it reaches your visitors. Google authorises both of those with this scope alone rather than with the publish scope, which is why publishing could not work until we requested it. Neither of those changes anything for your visitors: a saved version is inert until it is published, and a preview version is never live. Our agents are given the tool that saves a version, and not the one that publishes it. |
| Google Tag Manager | tagmanager.publish | Write | Makes a saved container version the live one, so a measurement change takes effect on your website. It works together with the version scope above rather than on its own — that one saves the version, this one publishes it, and without both a tag we configure for you would sit unpublished and measure nothing. This is the only step that changes what loads for your visitors, so it is the one we have deliberately kept away from our agents: publishing is not among the tools they are given. It happens only where a signed-in member of your team can review what would change and confirm it: on the Integrations page, and — as we roll this out — on a confirmation card in the chat itself, shown directly after an agent has made a Tag Manager change, so that the person who asked for the change is the person who approves it going live. Wherever it appears, they see the container, the version currently live and the exact list of unpublished changes before confirming. That request cannot name a container, workspace or version — it publishes the container connected to the organization the signed-in person belongs to, and nothing else. |
| Google Business Profile | business.manage | Read and write | Reads your business locations, listing details and attributes, reviews, customer questions, photos and local performance insights; and, on your instruction, publishes and deletes Business Profile posts, replies to reviews and deletes a reply it has left, answers customer questions, and updates listing details, business hours and special hours. Google publishes only this one scope for the Business Profile APIs — there is no narrower read-only alternative. |
| Google Drive | drive.file | Read, per file | Imports images and files you pick into your Intellisea media library. This is the narrow per-file Drive scope: it gives us access only to the specific files you select in Google's own file picker, one selection at a time. We cannot see, list or search the rest of your Drive, and we deliberately do not request a broader Drive scope. |
We request no other Google scopes. In particular Intellisea does not request access to Gmail, Google Calendar, Google Contacts, your Drive as a whole, or any scope Google classifies as restricted.
You can disconnect any Google integration at any time from the Integrations page within Intellisea. Upon disconnection:
To have stored data deleted as well as access revoked, see our Data Deletion page.
Intellisea connects to Meta so that our agents can manage your Facebook Page and your Instagram professional account: reading how your content performs, publishing and scheduling posts, handling comments and messages, and running Meta advertising campaigns. Everything in this subsection applies only to the Pages and accounts you yourself select during the connection flow.
When you connect Meta, you complete Facebook's own login and permission screen. The permissions we request, and what each is for, are:
| Meta permission | Access | What we use it for |
|---|---|---|
| public_profile | Read | Reads the name and Facebook ID of the person connecting, and the email address on that Facebook account where it is available, so the connection can be labelled and attributed on the Integrations page. |
| pages_read_engagement | Read | Lists the Facebook Pages you manage so you can choose one, and reads that Page's profile and settings, its posts and their metrics, reactions, mentions, media library, lead forms, and Page and post insights. This is what the reporting and content history in the platform is built from. |
| pages_manage_posts | Write | Publishes content to your Page in your Page's name: text, single-photo, multi-photo, video, Reel and link posts; schedules posts for a future date; edits the text of an existing post; and deletes a post. It also updates the Page's About text, website and phone number when you ask us to. |
| pages_manage_engagement | Write | Manages the comment threads under your Page's posts on your behalf: replying as the Page, liking, hiding, unhiding and deleting comments. Comment content includes the names and words of members of the public who commented. |
| pages_messaging | Read and write | Reads your Page's Messenger conversations and sends replies as the Page, within the 24-hour response window Meta permits. Message content is personal data belonging to the person who wrote to you; we process it only to show it to you and to send the reply you or an agent composes, and we do not use it for any other purpose. |
| leads_retrieval | Read | Retrieves the submissions from lead generation forms on your Page, so the leads your advertising produces are visible in Intellisea. These submissions contain the personal contact details the person entered — typically name, email address and phone number. We store them against your organization, show them to you, and never use them for our own marketing or share them with anyone else. |
| ads_management | Read and write | Reads your Meta ad accounts and their campaign, ad set, creative and performance data; and creates and manages campaigns, ad sets, ad creatives and ads, boosts an existing Page post, looks up targeting options, estimates audience sizes, and creates custom and lookalike audiences. Campaigns and boosted posts that Intellisea creates are created in a paused state and do not begin spending until they are activated. |
| business_management | Read | Resolves which Business Manager assets — principally ad accounts — the Page you connected is entitled to use, so advertising work is carried out against the right account. Meta also lists this permission as a dependency of the advertising and Page permissions above. |
| instagram_basic | Read | Reads the profile metadata (account ID and username), media, media metrics and comments of the Instagram professional account linked to your Page, plus account, media and story insights. |
| instagram_content_publish | Write | Publishes to that Instagram account: single images, carousels, videos, Reels and Stories, with captions, and deletes media you ask us to remove. |
Intellisea also supports connecting an Instagram professional account directly, without a Facebook Page, using Instagram's own login. That route requests instagram_business_basic, instagram_business_content_publish, instagram_business_manage_comments and instagram_business_manage_messages, and is used for the same purposes as the equivalent rows above: reading the account's profile and media, publishing content, and managing comments and direct messages on your behalf.
Instagram publishing has prerequisites set by Meta, not by us: the account must be an Instagram professional (Business or Creator) account, and on the Facebook route it must be linked to the Facebook Page you connect. A personal Instagram account cannot be used.
We do not request access to your personal Facebook profile beyond your name, ID and email; your friends list; your personal timeline or posts; your Instagram personal account; WhatsApp; or Meta's Threads platform.
Nobody outside the processing chain that runs the platform. Meta data is not sold, not shared with other Intellisea customers, not used for our own advertising, and not used to train AI models. It is processed on Amazon Web Services and, where an agent must reason over it — for example to draft a reply to a comment or summarise how a post performed — the relevant content is sent to an AI model on Amazon Bedrock under terms that prohibit retention and training. The complete list of subprocessors is on our Subprocessors page. Within Intellisea, Meta data is visible only to members of the organization that connected the account.
Our use of Meta's platforms and data is governed by the Meta Platform Terms and Developer Policies, and we handle Meta Platform Data in accordance with them.
Intellisea connects to LinkedIn to manage your company Page and, where you use it, your LinkedIn advertising. As with Meta, access is limited to the organization Pages and ad accounts you administer and select.
The permissions we request are as follows.
| LinkedIn scope | Access | What we use it for |
|---|---|---|
| openid, email | Read | Identifies the LinkedIn member who completed the connection and reads their email address, so the connection can be labelled and attributed. |
| r_basicprofile | Read | Reads the connecting member's name, and their member ID, at the moment of connection, so the Integrations page can show whose authorisation the connection runs under. We do not read your feed, your connections, or your messages. |
| r_organization_admin | Read | Reads the company Pages you administer, the Page's administrators, page view and visitor analytics, follower growth, and follower and visitor demographics. LinkedIn supplies demographic breakdowns in aggregate — by industry, function, seniority, location and company size — and not as identifiable individuals. |
| r_organization_social | Read | Reads your company Page's posts, their comments and reactions, and per-post analytics such as impressions, clicks and engagement rate. Comment and reaction data includes the names of the LinkedIn members who left them. |
| w_organization_social | Write | Publishes to your company Page in the Page's name: text posts, image posts, video posts, PDF document carousels, link and article shares, and polls. It also edits and deletes posts, reposts content, reacts to posts as the Page, replies to and deletes comments, and uploads the images, video and documents those posts use. |
| rw_organization_admin | Read and write | Updates your company Page's own details when you ask us to — its description, website URL and specialties — and replaces its logo and cover image. |
| w_member_social | Requested; not exercised | This scope would allow posting to your personal LinkedIn feed. Intellisea publishes only to company Pages, never to a member's personal feed, and no feature in the platform uses this scope. It is disclosed here rather than left unlisted. |
| r_1st_connections_size | Requested; not exercised | This scope returns the number of first-degree connections a member has. No feature in Intellisea reads it. It is disclosed here rather than left unlisted. |
| r_ads, r_ads_reporting | Read | Reads your LinkedIn ad accounts, campaign groups, campaigns, creatives, budgets and spend, campaign and creative analytics, demographic performance breakdowns, conversion data, lead generation forms and their submissions, and audience size estimates. |
| rw_ads | Read and write | Creates and manages LinkedIn advertising on your ad account: campaign groups, campaigns, single-image ad creatives, message and conversation ads, budgets, bids and targeting; pausing, activating and archiving campaigns; conversion rules; and matched audiences, including website retargeting audiences and audiences built by uploading a contact list. |
Two points deserve to be called out rather than left inside the table.
LinkedIn data is stored on the same basis as everything else described in this section: tokens encrypted in AWS Secrets Manager, connection metadata and recorded figures in DynamoDB kept while your account is open, API responses cached only for minutes, processed only on AWS and by the subprocessors we list. Access tokens are refreshed automatically while the connection remains active.
To revoke access: Integrations → Disconnect inside Intellisea, which deletes the stored token immediately; or from LinkedIn directly under Settings & Privacy → Data privacy → Permitted services. Our use of LinkedIn's APIs is governed by the LinkedIn API Terms of Use and, for advertising and Page management, the LinkedIn Marketing API Terms.
Intellisea leverages large language models and generative AI services (including Amazon Bedrock, AWS infrastructure, and third-party AI APIs) to power its agent network. Important disclosures:
We use the following AI infrastructure providers under strict data processing agreements:
All AI service providers are contractually bound to not retain, log, or use your data beyond the immediate processing of your request. Our Subprocessors page is the authoritative and current list.
In the event of a data breach, we will notify affected users within 72 hours of discovery, consistent with applicable data protection regulations.
We do not sell your personal information or business data. We may share data only in these circumstances:
How to make a deletion request, and what happens next, is set out in full on our Data Deletion page. You do not need to be signed in, and you do not need to be the account owner, to use it. If all you want is to stop us accessing a connected Facebook Page, Instagram account, Google account, LinkedIn Page or website, disconnecting the integration is enough and takes effect immediately — section 1 of that page explains how.
We retain your data for as long as your account remains active and as needed to provide services to your organization. Responses we fetch from your connected accounts are cached only briefly — minutes, not months. Where we record a figure so that performance can be tracked over time, that record is kept while your account is open, and is removed when you disconnect the integration it came from or when the organization's data is deleted.
When an organization's account is deleted, all associated data is deleted from our systems. This includes:
Deletion is carried out by a member of our team, by hand, within 30 days of the request. Certain steps happen immediately on confirmation rather than waiting for that: the subscription is cancelled, scheduled and future-dated publishing is stopped and pulled back, connected integrations are disconnected and their credentials deleted, and the organization is put into a closed state in which no agent can act on it and no credits can be spent. Once the deletion itself has been carried out, the data cannot be recovered.
Records we are required to keep for tax, accounting and anti-fraud purposes — invoices, payment records and billing history, held by us and by our payment processor — are retained for the period the law requires and used for nothing else.
Organization administrators can remove individual team members at any time. Removed users lose access immediately, and their personal authentication data is deleted. Shared organizational content (strategy boards, chat histories contributed to) remains with the organization.
Depending on your jurisdiction, you may have the following rights:
To exercise any of these rights, contact us at privacy@intellisea.com. For deletion specifically, our Data Deletion page sets out the routes available and the address to write to; it works whether or not you hold an Intellisea account.
Two different surfaces are covered here, and they behave differently.
The application uses cookies and browser storage that are strictly necessary to operate it: keeping you signed in, maintaining your session, and remembering interface preferences. It carries no advertising tags and no analytics tags.
Our marketing website is a separate surface, and it does use third-party advertising and analytics technology. It loads a Google Tag Manager container that runs:
G-6G18JLGXGF) — measures which pages are visited, how visitors arrive, and how the site performs. This data is not anonymous: Google Analytics assigns each browser a pseudonymous identifier stored in the _ga and _ga_6G18JLGXGF cookies, and your IP address is transmitted to Google.878300497 and 17474305515) — records when a visit that began with one of our adverts results in an enquiry._gcl_au cookie.The recipient of this data is Google (Google LLC, and Google Ireland Limited for visitors in the EEA and the UK), acting for these purposes as an independent controller under its own terms. We do not sell this data, and it is not connected to any Intellisea account.
The full inventory — every cookie, its purpose, how long it lasts, and how to opt out — is set out in our Cookie & Tracking Notice, which also explains how to switch this off.
An earlier version of this section stated that we did not use third-party advertising cookies or cross-site tracking pixels, and that analytics data was aggregated and anonymised. That was inaccurate: the advertising and analytics technology described above was already running on our website. We corrected this section on 10 August 2026 and published the Cookie & Tracking Notice at the same time.
Intellisea is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from minors. If we become aware that we have collected data from a minor, we will delete it promptly.
If you access Intellisea from outside the United States, your data may be transferred to and processed in the United States. By using the platform, you consent to this transfer. We ensure appropriate safeguards are in place consistent with applicable data protection laws.
We may update this Privacy Policy from time to time. Material changes will be communicated via email or an in-app notification. Continued use of the platform after changes constitutes acceptance of the updated policy.
If you have questions or concerns about this Privacy Policy or our data practices, please contact:
Intellisea Privacy Team
Email: privacy@intellisea.com