Intellisea
Home Services Why Us Contact · Launch App →
← Back to Home

Privacy Policy

Last Updated: August 12, 2026  ·  Previously updated August 11, 2026, August 10, 2026 and May 17, 2026

Intellisea ("we," "our," or "us") is committed to protecting the privacy and security of our users. This Privacy Policy describes how we collect, use, store, share, and safeguard information when you use the Intellisea platform — an agentic AI-powered digital marketing SaaS application.

By accessing or using Intellisea, you agree to the terms of this Privacy Policy. If you do not agree, please discontinue use of the platform.

If you are looking for something specific: section 3 sets out, platform by platform, exactly what we access from your connected accounts — Google, Facebook and Instagram, LinkedIn, and everything else — and section 6 covers retention and deletion. To have data deleted, or simply to disconnect an account, see our Data Deletion page; you do not need to be signed in to make a request.

1. Information We Collect

1.1 Account Information

When you register for Intellisea, we collect:

  • Full name, email address, and password (encrypted)
  • Organization name, industry, and business details
  • Billing and payment information (processed by third-party payment providers)
  • Team member information added via organization invitations

1.2 User-Generated Content

Content you create or upload within the platform, including:

  • Chat conversations with AI agents
  • Strategy board documents and campaign plans
  • Content templates, media assets, and generated videos
  • Deployment calendars and task assignments
  • Business facts, knowledge base entries, and organizational memory

1.3 Connected Platform Data

When you connect an integration, you authorise us to act on that account on your behalf. We access, and in most cases can also write to, the following platforms. Section 3 describes each one in detail — what is accessed, why, how it is stored, and how to revoke it.

  • Google Analytics: Website traffic, audience and device breakdowns, conversion data, and GA4 property configuration
  • Google Ads: Campaign performance, ad spend, keyword data, and campaign creation and management
  • Google Search Console: Search rankings, indexing status, crawl data, sitemaps, and URL indexing requests
  • Google Business Profile: Business listings, reviews, questions, posts, photos, hours, and local performance
  • Google Tag Manager: Containers, tags, triggers and variables, including publishing container versions
  • Google Drive: Only the individual files you select through Google's own file picker, so they can be imported into your media library
  • Meta — Facebook Pages: Your Facebook profile name and email, the Pages you manage, Page posts and their metrics, comments, reactions, mentions, Page messages, Page and post insights, lead forms and lead form submissions, and Meta ad accounts and campaigns
  • Meta — Instagram: The Instagram professional account connected to Intellisea, its profile metadata, its media and media metrics, comments, and account, media and story insights
  • LinkedIn: Your LinkedIn member profile and email, the organization Pages you administer, page and post content and analytics, follower and visitor demographics, comments and reactions, and LinkedIn ad accounts, campaigns, conversion data, audiences and lead generation forms and submissions
  • WordPress and connected websites: Posts, pages, media, menus, widgets, comments, forms, plugins, themes and site settings on the site you connect
  • Slack and Microsoft Teams: Message interactions with our AI agents in the channels or chats where you invite them, and the identity of the member sending them
  • Stripe: Read-only access to the connected Stripe account's business details and payment and subscription records, where you connect one

This platform data is used to let our AI agents understand your business and carry out the marketing work you ask for. We do not sell, share, or redistribute your connected platform data to any external party. It is processed only on our own infrastructure and by the subprocessors listed on our Subprocessors page.

Some of this data includes personal information about people who are not Intellisea users — for example the contact details a person submits through a Facebook or LinkedIn lead form, the content of a message someone sends to your Facebook Page, or a comment left on one of your posts. We process that information solely to carry out your instructions in relation to your own accounts, and only for as long as described in section 6. Where you supply us with contact data of your own — for instance to build a LinkedIn matched audience — you are responsible for having a lawful basis to do so.

1.4 Usage & Technical Data

  • Browser type, device information, IP address
  • Pages visited, features used, session duration
  • Error logs and performance metrics

2. How We Use Your Information

We use collected information to:

  • Power AI Agents: Our agentic AI system (CEO Agent, Director Agents, and Specialist Agents) uses your business context, third-party platform data, and conversation history to deliver personalized marketing intelligence, strategies, and content.
  • Maintain Persistent Memory: AI agents retain organizational knowledge across sessions so every team member benefits from shared context. This memory is scoped exclusively to your organization.
  • Generate Content: Create AI-generated text, images, videos, and voiceovers for your marketing campaigns using your brand guidelines and business data.
  • Improve the Platform: Analyze aggregated, anonymized usage patterns to improve features, performance, and user experience. We never use your proprietary business data for training general AI models.
  • Communicate: Send account-related notifications, feature updates, and support responses.

3. Connected Platform Data & AI-Specific Practices

This section is the detailed, platform-by-platform account of what Intellisea does with data from the accounts you connect. Subsections 3.1 to 3.4 cover Google, 3.5 covers Meta (Facebook Pages and Instagram), 3.6 covers LinkedIn, and 3.7 covers the remaining integrations. Subsections 3.8 and 3.9 cover our use of AI models.

Two things are true of every platform below, so they are stated once rather than repeated. First, access tokens are held only in AWS Secrets Manager, encrypted, and are never written to our application database or exposed to your browser. Second, data from your connected accounts is never used to train, fine-tune or improve any AI model — see subsection 3.8.

3.1 Google API Services — Limited Use Disclosure

Intellisea's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, Intellisea:

  • Only uses Google user data to provide and improve the user-facing features of the Intellisea platform that are visible and apparent to the user
  • Does not transfer Google user data to third parties unless necessary to provide the service, required by law, or with explicit user consent
  • Does not use Google user data for serving advertisements
  • Does not allow humans to read Google user data unless: (a) we have the user's affirmative consent, (b) it is necessary for security purposes, (c) it is necessary to comply with applicable law, or (d) the data is aggregated and anonymized for internal operations

3.2 Every Google API Scope We Request

This is the complete list. Each Google integration requests only the scopes for that integration, and only when you connect it — connecting Google Analytics does not grant anything listed against Search Console or Business Profile. The "Access" column states plainly whether the scope is used to read data, or also to change something in your Google account, because that is the distinction that matters most.

Google service Scope Access What we use it for
Google Identity openid Read Confirms which Google account completed the connection, so the integration is attached to the right person.
Google Identity userinfo.email Read Reads the email address of the Google account you connect. We display it on the Integrations page so you can see which account is linked, and we use it to recognise the same Google account if you connect it to more than one Intellisea organization. We do not use it to send you marketing.
Google Analytics analytics.readonly Read Reads your GA4 reporting data — sessions, traffic sources, landing pages, conversions, audience and geographic breakdowns, device data and real-time users — to produce the performance reporting and recommendations in the platform.
Google Analytics analytics.edit Read and write Configures measurement on your GA4 property when you ask us to: creating, updating and deleting key events (conversions), creating custom dimensions and custom metrics, reading and creating data streams, updating property settings, reading the property's Google Ads links, and linking a Google Ads account to the property. It also switches enhanced measurement on or off for an individual data stream — whether GA4 automatically records scrolls, outbound clicks, site search, video engagement and file downloads. And it builds audience segments for you: an audience defined by an event, or by a dimension such as country or device category, and archiving one when it is no longer wanted. Linking an Ads account deserves spelling out on its own, because it joins two of your own accounts rather than changing a setting inside one: it connects this GA4 property to a Google Ads account you nominate, so that audiences built in GA4 can be used for remarketing in Google Ads and so Ads campaign data appears in your GA4 reporting. An agent creates such a link only as part of work you have asked for, and only for an Ads account your own Google sign-in already administers — we cannot reach an account you do not have access to. Unless you tell us otherwise the link is created with ads personalisation enabled, which permits Google to use the GA4 data flowing across it for personalised advertising; ask us and we will create it with personalisation switched off, or remove the link altogether. The read-only scope cannot create a conversion event, which is why this scope is needed. Configuration can therefore be removed as well as added, but your reporting history itself is never deleted.
Google Ads adwords Read and write Reads campaign, ad group, keyword, budget and performance data for reporting and optimisation advice; and, when you deploy a campaign from Intellisea, creates and updates campaigns, ad groups, keywords, ads, budgets and bidding on your Google Ads account. The same access also deletes — campaigns, keywords, ads, placements, ad extensions, audience segments, location targets and ad schedules can be removed outright, not merely paused. It sets up the conversion actions that measure results, and it configures who sees your ads: audience segments, geographic and proximity targeting, device and language targeting, ad schedules, and demographic exclusions. Building a display, video or Performance Max ad also writes image files into your account: we fetch each image from a URL, resize it into the landscape, square and logo shapes Google requires, and upload it there as a reusable asset. It can also apply Google's own recommendations to your account — a change Google proposed and an agent accepted for you, rather than one you asked for by name. We do not upload your customers' personal data to Google Ads. This integration has no contact-list or Customer Match upload of any kind, and when an audience is targeted it is one that already exists in your own Google Ads account. Campaign changes spend your money, so this is the scope to think hardest about before granting.
Google Search Console webmasters Read and write Reads search performance data (queries, pages, clicks, impressions, position), index coverage, URL inspection results, Core Web Vitals, mobile usability, structured data and link reports; and lists, submits and deletes sitemaps for your verified sites. The read-only scope cannot submit a sitemap, which is why the read-write scope is requested.
Google Search Console indexing Write Notifies Google that a page on your site is new, updated, or has been removed, so newly published content is crawled sooner. It submits URLs on your own verified property only. It reads no personal data.
Google Tag Manager tagmanager.readonly Read Reads your container's existing tags, triggers, variables and versions so we can tell you what measurement is already in place before changing anything. It also lists the Tag Manager accounts and containers you have access to, so you can choose which container to connect in the first place.
Google Tag Manager tagmanager.edit.containers Read and write Creates, updates and deletes the tags inside your container, and creates the triggers and variables those tags depend on — for example adding a conversion tag for a campaign we are running for you. Changes are made in a workspace first. This scope also creates a brand-new container in your Tag Manager account when your site does not have one yet, and gives you the snippet to install on your site. Creating a container adds something new to your Google account rather than changing what is already there, so it is the biggest thing this scope allows — and an agent can do it while setting measurement up for you.
Google Tag Manager tagmanager.edit.containerversions Write Saves the draft in your Tag Manager workspace as a numbered container version — the snapshot Google keeps in your container's version history — and generates the preview link we use to test a change before it reaches your visitors. Google authorises both of those with this scope alone rather than with the publish scope, which is why publishing could not work until we requested it. Neither of those changes anything for your visitors: a saved version is inert until it is published, and a preview version is never live. Our agents are given the tool that saves a version, and not the one that publishes it.
Google Tag Manager tagmanager.publish Write Makes a saved container version the live one, so a measurement change takes effect on your website. It works together with the version scope above rather than on its own — that one saves the version, this one publishes it, and without both a tag we configure for you would sit unpublished and measure nothing. This is the only step that changes what loads for your visitors, so it is the one we have deliberately kept away from our agents: publishing is not among the tools they are given. It happens only where a signed-in member of your team can review what would change and confirm it: on the Integrations page, and — as we roll this out — on a confirmation card in the chat itself, shown directly after an agent has made a Tag Manager change, so that the person who asked for the change is the person who approves it going live. Wherever it appears, they see the container, the version currently live and the exact list of unpublished changes before confirming. That request cannot name a container, workspace or version — it publishes the container connected to the organization the signed-in person belongs to, and nothing else.
Google Business Profile business.manage Read and write Reads your business locations, listing details and attributes, reviews, customer questions, photos and local performance insights; and, on your instruction, publishes and deletes Business Profile posts, replies to reviews and deletes a reply it has left, answers customer questions, and updates listing details, business hours and special hours. Google publishes only this one scope for the Business Profile APIs — there is no narrower read-only alternative.
Google Drive drive.file Read, per file Imports images and files you pick into your Intellisea media library. This is the narrow per-file Drive scope: it gives us access only to the specific files you select in Google's own file picker, one selection at a time. We cannot see, list or search the rest of your Drive, and we deliberately do not request a broader Drive scope.

We request no other Google scopes. In particular Intellisea does not request access to Gmail, Google Calendar, Google Contacts, your Drive as a whole, or any scope Google classifies as restricted.

3.3 How We Access, Use, Store, and Share Google User Data

  • Access: Google user data is accessed when you take an action in Intellisea that needs it — asking for a performance report, deploying a campaign, opening an analytics view — and also on a schedule. Scheduled access happens in two ways: automated tasks you have configured or approved as part of a campaign or deployment plan, and background maintenance such as refreshing an expiring OAuth token. Scheduled work runs whether or not you are signed in; our AI & Automation Disclosures page explains what runs unattended and how to stop it.
  • Use: Google user data is used to display insights, generate recommendations, carry out the marketing actions you have authorised, and produce reports for you and the other members of your Intellisea organization. It is used for nothing else. It is not used for advertising to you, and it is not used to train AI models.
  • Storage: OAuth access and refresh tokens are encrypted and stored in AWS Secrets Manager. Integration metadata — which account is connected, which property or container was selected, the account email, and connection timestamps — is stored in AWS DynamoDB. Raw API responses are held in a short-lived cache measured in minutes and are not otherwise retained. Where a figure is recorded so that trends can be shown over time, or written into a report or a piece of content, it is stored in DynamoDB and kept for as long as your account is open; it is removed when you disconnect the integration or when the organization's data is deleted.
  • Sharing: Google user data is never sold, never shared with third parties for their own purposes, and never used for serving advertisements. It is processed on AWS infrastructure and, where an agent needs to reason over it, sent to an AI model running on Amazon Bedrock under terms that forbid retention and training. Our Subprocessors page is the complete list of who can touch it.

3.4 Revoking Google Access

You can disconnect any Google integration at any time from the Integrations page within Intellisea. Upon disconnection:

  • The OAuth access and refresh tokens are immediately deleted from AWS Secrets Manager
  • The integration record is removed from our database
  • Cached data from that integration is purged
  • Agents lose the ability to read from or write to that account immediately
  • You can also revoke access directly from your Google Account permissions page, which works even if you cannot sign in to Intellisea

To have stored data deleted as well as access revoked, see our Data Deletion page.

3.5 Meta Platform Data — Facebook Pages and Instagram

Intellisea connects to Meta so that our agents can manage your Facebook Page and your Instagram professional account: reading how your content performs, publishing and scheduling posts, handling comments and messages, and running Meta advertising campaigns. Everything in this subsection applies only to the Pages and accounts you yourself select during the connection flow.

What we access, and why

When you connect Meta, you complete Facebook's own login and permission screen. The permissions we request, and what each is for, are:

Meta permission Access What we use it for
public_profile Read Reads the name and Facebook ID of the person connecting, and the email address on that Facebook account where it is available, so the connection can be labelled and attributed on the Integrations page.
pages_read_engagement Read Lists the Facebook Pages you manage so you can choose one, and reads that Page's profile and settings, its posts and their metrics, reactions, mentions, media library, lead forms, and Page and post insights. This is what the reporting and content history in the platform is built from.
pages_manage_posts Write Publishes content to your Page in your Page's name: text, single-photo, multi-photo, video, Reel and link posts; schedules posts for a future date; edits the text of an existing post; and deletes a post. It also updates the Page's About text, website and phone number when you ask us to.
pages_manage_engagement Write Manages the comment threads under your Page's posts on your behalf: replying as the Page, liking, hiding, unhiding and deleting comments. Comment content includes the names and words of members of the public who commented.
pages_messaging Read and write Reads your Page's Messenger conversations and sends replies as the Page, within the 24-hour response window Meta permits. Message content is personal data belonging to the person who wrote to you; we process it only to show it to you and to send the reply you or an agent composes, and we do not use it for any other purpose.
leads_retrieval Read Retrieves the submissions from lead generation forms on your Page, so the leads your advertising produces are visible in Intellisea. These submissions contain the personal contact details the person entered — typically name, email address and phone number. We store them against your organization, show them to you, and never use them for our own marketing or share them with anyone else.
ads_management Read and write Reads your Meta ad accounts and their campaign, ad set, creative and performance data; and creates and manages campaigns, ad sets, ad creatives and ads, boosts an existing Page post, looks up targeting options, estimates audience sizes, and creates custom and lookalike audiences. Campaigns and boosted posts that Intellisea creates are created in a paused state and do not begin spending until they are activated.
business_management Read Resolves which Business Manager assets — principally ad accounts — the Page you connected is entitled to use, so advertising work is carried out against the right account. Meta also lists this permission as a dependency of the advertising and Page permissions above.
instagram_basic Read Reads the profile metadata (account ID and username), media, media metrics and comments of the Instagram professional account linked to your Page, plus account, media and story insights.
instagram_content_publish Write Publishes to that Instagram account: single images, carousels, videos, Reels and Stories, with captions, and deletes media you ask us to remove.

Intellisea also supports connecting an Instagram professional account directly, without a Facebook Page, using Instagram's own login. That route requests instagram_business_basic, instagram_business_content_publish, instagram_business_manage_comments and instagram_business_manage_messages, and is used for the same purposes as the equivalent rows above: reading the account's profile and media, publishing content, and managing comments and direct messages on your behalf.

Instagram publishing has prerequisites set by Meta, not by us: the account must be an Instagram professional (Business or Creator) account, and on the Facebook route it must be linked to the Facebook Page you connect. A personal Instagram account cannot be used.

We do not request access to your personal Facebook profile beyond your name, ID and email; your friends list; your personal timeline or posts; your Instagram personal account; WhatsApp; or Meta's Threads platform.

How Meta data is stored and for how long

  • Tokens. The long-lived Facebook user token, the Page access token, and the long-lived Instagram token where the direct Instagram route is used, are stored encrypted in AWS Secrets Manager and nowhere else. They are not written to our database and are never sent to your browser. Long-lived Meta tokens expire after about 60 days; we re-exchange a token only within the last 7 days of its life so the connection continues to work.
  • Connection metadata. The selected Page ID and name, the linked Instagram account ID and username, the ad account ID, the connecting account's email, and connection and refresh timestamps are stored in AWS DynamoDB. During the connection flow itself, the list of Pages you can choose from is held in a temporary record that expires automatically after one hour.
  • Content and metrics. Post, media, engagement, insights and advertising data we retrieve is held in a short-lived cache measured in minutes. Figures recorded so that performance can be compared over time, and content our agents drafted or published for you, are stored in DynamoDB and kept while your account is open; they are removed when you disconnect Meta or when the organization's data is deleted.
  • Lead form submissions and Page messages. Retained against your organization while your account is open, because they are your business records, and removed when the connection is disconnected or the organization's data is deleted.

Who Meta data is shared with

Nobody outside the processing chain that runs the platform. Meta data is not sold, not shared with other Intellisea customers, not used for our own advertising, and not used to train AI models. It is processed on Amazon Web Services and, where an agent must reason over it — for example to draft a reply to a comment or summarise how a post performed — the relevant content is sent to an AI model on Amazon Bedrock under terms that prohibit retention and training. The complete list of subprocessors is on our Subprocessors page. Within Intellisea, Meta data is visible only to members of the organization that connected the account.

Our use of Meta's platforms and data is governed by the Meta Platform Terms and Developer Policies, and we handle Meta Platform Data in accordance with them.

How to disconnect or delete Meta data

  • Inside Intellisea: Integrations → find the Meta connection → Disconnect. The stored tokens are deleted from Secrets Manager immediately, the integration record is removed, and agents lose all access to the Page and Instagram account at once.
  • From Facebook, if you cannot sign in to Intellisea: Settings & Privacy → Settings → Apps and Websites, then remove Intellisea. From Instagram: Settings → Website permissions → Apps and websites. Either ends our access straight away.
  • To have data we already hold deleted, follow our Data Deletion instructions. You do not need an Intellisea account or a signed-in session to make that request, and you do not need to be the account owner — that page is the route for anyone whose Facebook Page or Instagram account was connected by someone else.

3.6 LinkedIn Platform Data

Intellisea connects to LinkedIn to manage your company Page and, where you use it, your LinkedIn advertising. As with Meta, access is limited to the organization Pages and ad accounts you administer and select.

The permissions we request are as follows.

LinkedIn scope Access What we use it for
openid, email Read Identifies the LinkedIn member who completed the connection and reads their email address, so the connection can be labelled and attributed.
r_basicprofile Read Reads the connecting member's name, and their member ID, at the moment of connection, so the Integrations page can show whose authorisation the connection runs under. We do not read your feed, your connections, or your messages.
r_organization_admin Read Reads the company Pages you administer, the Page's administrators, page view and visitor analytics, follower growth, and follower and visitor demographics. LinkedIn supplies demographic breakdowns in aggregate — by industry, function, seniority, location and company size — and not as identifiable individuals.
r_organization_social Read Reads your company Page's posts, their comments and reactions, and per-post analytics such as impressions, clicks and engagement rate. Comment and reaction data includes the names of the LinkedIn members who left them.
w_organization_social Write Publishes to your company Page in the Page's name: text posts, image posts, video posts, PDF document carousels, link and article shares, and polls. It also edits and deletes posts, reposts content, reacts to posts as the Page, replies to and deletes comments, and uploads the images, video and documents those posts use.
rw_organization_admin Read and write Updates your company Page's own details when you ask us to — its description, website URL and specialties — and replaces its logo and cover image.
w_member_social Requested; not exercised This scope would allow posting to your personal LinkedIn feed. Intellisea publishes only to company Pages, never to a member's personal feed, and no feature in the platform uses this scope. It is disclosed here rather than left unlisted.
r_1st_connections_size Requested; not exercised This scope returns the number of first-degree connections a member has. No feature in Intellisea reads it. It is disclosed here rather than left unlisted.
r_ads, r_ads_reporting Read Reads your LinkedIn ad accounts, campaign groups, campaigns, creatives, budgets and spend, campaign and creative analytics, demographic performance breakdowns, conversion data, lead generation forms and their submissions, and audience size estimates.
rw_ads Read and write Creates and manages LinkedIn advertising on your ad account: campaign groups, campaigns, single-image ad creatives, message and conversation ads, budgets, bids and targeting; pausing, activating and archiving campaigns; conversion rules; and matched audiences, including website retargeting audiences and audiences built by uploading a contact list.

Two points deserve to be called out rather than left inside the table.

  • Lead generation submissions. Where you run LinkedIn lead generation ads, the submissions we retrieve contain the personal details the member provided — typically name, email address, job title and company. They are stored against your organization, shown to you, and used for nothing else.
  • Contact list uploads. If you build a matched audience from a contact list, the email addresses in that list are sent to LinkedIn for matching. That data comes from you, not from LinkedIn, and you are responsible for having a lawful basis to upload it. We transmit it to LinkedIn for that purpose and do not use it for anything else.

LinkedIn data is stored on the same basis as everything else described in this section: tokens encrypted in AWS Secrets Manager, connection metadata and recorded figures in DynamoDB kept while your account is open, API responses cached only for minutes, processed only on AWS and by the subprocessors we list. Access tokens are refreshed automatically while the connection remains active.

To revoke access: Integrations → Disconnect inside Intellisea, which deletes the stored token immediately; or from LinkedIn directly under Settings & Privacy → Data privacy → Permitted services. Our use of LinkedIn's APIs is governed by the LinkedIn API Terms of Use and, for advertising and Page management, the LinkedIn Marketing API Terms.

3.7 Other Connected Platforms

  • WordPress and connected websites. When you connect a WordPress site — through our plugin or by supplying application credentials — agents can read and change that site: creating, updating and deleting posts and pages, uploading and editing media, managing menus, widgets, categories and tags, moderating and replying to comments, editing theme files and CSS, changing a limited set of site options, managing plugins, and clearing caches. Site credentials are stored encrypted in AWS Secrets Manager. Content published to your site is public by definition and remains yours. Any personal data on that site — comment authors, form submissions — is processed only as needed to carry out the action you asked for.
  • Slack and Microsoft Teams. Where you invite our agents into Slack or Teams, we receive the messages addressed to them, the identity of the sender, and the channel or conversation reference, so a reply can be delivered and so approval requests can be sent to the right person. We do not read messages that are not directed to our agents.
  • Stripe. Where you connect a Stripe account, we request read-only access. We read the account's business details and its payment and subscription records to report on revenue alongside marketing performance. We cannot create charges, move money, or change anything in your Stripe account. Separately, Stripe is also our own payment processor for Intellisea subscriptions — see our Subprocessors page.

3.8 AI Model Usage

Intellisea leverages large language models and generative AI services (including Amazon Bedrock, AWS infrastructure, and third-party AI APIs) to power its agent network. Important disclosures:

  • No Model Training on Your Data: Your business data, conversations, and content are never used to train, fine-tune, or improve general-purpose AI foundation models. Your data is used solely to serve your organization's requests in real time.
  • Prompt Isolation: Each organization's data is logically isolated. AI agents process your data within your organization's context only. No cross-organization data leakage occurs.
  • Generated Content Ownership: All content generated by AI agents on your behalf (text, images, videos, strategies) is owned by you and your organization.

3.9 Third-Party AI Services

We use the following AI infrastructure providers under strict data processing agreements:

  • Amazon Web Services (Bedrock, S3, DynamoDB, Lambda): Core infrastructure for AI model inference, data storage, and compute
  • HeyGen: AI spokesperson video generation (data transmitted only when you initiate video creation)
  • Replicate: AI image and media generation
  • Sync Labs: Audio and video synchronisation for generated video

All AI service providers are contractually bound to not retain, log, or use your data beyond the immediate processing of your request. Our Subprocessors page is the authoritative and current list.

4. Data Storage & Security

4.1 Infrastructure

  • All data is stored on Amazon Web Services (AWS) in the United States (us-east-1 region)
  • Data at rest is encrypted using AES-256 encryption
  • Data in transit is encrypted using TLS 1.2+
  • Authentication is managed through Amazon Cognito with secure token-based sessions

4.2 Access Controls

  • Role-based access controls within organizations restrict data visibility per team member
  • API keys and OAuth tokens for third-party integrations are encrypted and stored securely — never exposed in client-side code
  • Administrative access to production systems is restricted to authorized personnel with multi-factor authentication

4.3 Incident Response

In the event of a data breach, we will notify affected users within 72 hours of discovery, consistent with applicable data protection regulations.

5. Data Sharing

We do not sell your personal information or business data. We may share data only in these circumstances:

  • Service Providers: Third-party vendors who assist in operating the platform (hosting, payment processing, email delivery) under strict confidentiality agreements
  • Legal Compliance: When required by law, regulation, subpoena, or court order
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, with prior notice to users
  • With Your Consent: When you explicitly authorize sharing with a third party

6. Data Retention & Deletion

How to make a deletion request, and what happens next, is set out in full on our Data Deletion page. You do not need to be signed in, and you do not need to be the account owner, to use it. If all you want is to stop us accessing a connected Facebook Page, Instagram account, Google account, LinkedIn Page or website, disconnecting the integration is enough and takes effect immediately — section 1 of that page explains how.

6.1 Active Accounts

We retain your data for as long as your account remains active and as needed to provide services to your organization. Responses we fetch from your connected accounts are cached only briefly — minutes, not months. Where we record a figure so that performance can be tracked over time, that record is kept while your account is open, and is removed when you disconnect the integration it came from or when the organization's data is deleted.

6.2 Account Deletion

When an organization's account is deleted, all associated data is deleted from our systems. This includes:

  • All user accounts within the organization
  • Chat histories, AI conversation logs, and persistent memory
  • Strategy boards, content templates, and generated media
  • Deployment plans and task records
  • Business facts, knowledge base entries, and organizational context
  • Connected integration tokens and cached third-party data
  • All files stored in cloud storage (S3) under the organization's tenant

Deletion is carried out by a member of our team, by hand, within 30 days of the request. Certain steps happen immediately on confirmation rather than waiting for that: the subscription is cancelled, scheduled and future-dated publishing is stopped and pulled back, connected integrations are disconnected and their credentials deleted, and the organization is put into a closed state in which no agent can act on it and no credits can be spent. Once the deletion itself has been carried out, the data cannot be recovered.

Records we are required to keep for tax, accounting and anti-fraud purposes — invoices, payment records and billing history, held by us and by our payment processor — are retained for the period the law requires and used for nothing else.

6.3 Individual User Removal

Organization administrators can remove individual team members at any time. Removed users lose access immediately, and their personal authentication data is deleted. Shared organizational content (strategy boards, chat histories contributed to) remains with the organization.

7. Your Rights

Depending on your jurisdiction, you may have the following rights:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate personal data
  • Deletion: Request deletion of your personal data (subject to legal retention requirements)
  • Portability: Request your data in a machine-readable format
  • Objection: Object to certain types of data processing
  • Restriction: Request restricted processing of your data

To exercise any of these rights, contact us at privacy@intellisea.com. For deletion specifically, our Data Deletion page sets out the routes available and the address to write to; it works whether or not you hold an Intellisea account.

8. Cookies & Tracking

Two different surfaces are covered here, and they behave differently.

8.1 The Intellisea application (app.intellisea.com)

The application uses cookies and browser storage that are strictly necessary to operate it: keeping you signed in, maintaining your session, and remembering interface preferences. It carries no advertising tags and no analytics tags.

8.2 Our public website (www.intellisea.com)

Our marketing website is a separate surface, and it does use third-party advertising and analytics technology. It loads a Google Tag Manager container that runs:

  • Google Analytics 4 (property G-6G18JLGXGF) — measures which pages are visited, how visitors arrive, and how the site performs. This data is not anonymous: Google Analytics assigns each browser a pseudonymous identifier stored in the _ga and _ga_6G18JLGXGF cookies, and your IP address is transmitted to Google.
  • Google Ads conversion tracking (accounts 878300497 and 17474305515) — records when a visit that began with one of our adverts results in an enquiry.
  • Google Ads remarketing — adds your browser to advertising audience lists held by Google, so that our adverts can be shown to you on other websites and Google services. This is third-party advertising technology and it tracks across sites. It sets the _gcl_au cookie.
  • Google reCAPTCHA — on pages carrying a contact form, to distinguish genuine enquiries from automated abuse.

The recipient of this data is Google (Google LLC, and Google Ireland Limited for visitors in the EEA and the UK), acting for these purposes as an independent controller under its own terms. We do not sell this data, and it is not connected to any Intellisea account.

The full inventory — every cookie, its purpose, how long it lasts, and how to opt out — is set out in our Cookie & Tracking Notice, which also explains how to switch this off.

8.3 A correction

An earlier version of this section stated that we did not use third-party advertising cookies or cross-site tracking pixels, and that analytics data was aggregated and anonymised. That was inaccurate: the advertising and analytics technology described above was already running on our website. We corrected this section on 10 August 2026 and published the Cookie & Tracking Notice at the same time.

9. Children's Privacy

Intellisea is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from minors. If we become aware that we have collected data from a minor, we will delete it promptly.

10. International Data Transfers

If you access Intellisea from outside the United States, your data may be transferred to and processed in the United States. By using the platform, you consent to this transfer. We ensure appropriate safeguards are in place consistent with applicable data protection laws.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or an in-app notification. Continued use of the platform after changes constitutes acceptance of the updated policy.

12. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact:

Intellisea Privacy Team
Email: privacy@intellisea.com

© 2026 Intellisea. All rights reserved.

Marketing Services · Knowledge Base · Articles · Contact · Launch App →
Privacy Policy·Terms & Conditions·Cookie Policy·Data Deletion·Legal