Privacy Policy
Introduction
ADageOne, LLC ("ADage1", "we", "us", "our") operates adage1.com and the ADage1 brand management platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website or platform. Please read this policy carefully. If you disagree with its terms, please discontinue use of our services.
Information We Collect
We collect information you provide directly and information generated through your use of the platform:
- Account data: name, email address, company or organization name, and role, provided at registration or via a demo request form.
- Usage data: pages visited, features used, session duration, browser type, and device information collected automatically via PostHog analytics.
- Asset metadata: file names, tags, upload timestamps, version history, and organization context associated with assets you store on the platform.
- Authentication data: OAuth tokens from Google, GitHub, or Microsoft Azure AD sign-in; email one-time passcode (OTP) session identifiers. We do not store OAuth access tokens beyond the session.
- Communications: the content of demo request form submissions, support emails, and any other messages you send us.
How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the ADage1 platform and website.
- Send transactional emails such as account verification, password reset links, and demo request confirmations.
- Analyze usage patterns to improve platform features, performance, and user experience.
- Respond to support requests, questions, and feedback.
- Comply with applicable legal obligations and enforce our Terms of Service.
We do not sell your personal information to third parties. We do not use your data for behavioral advertising.
Data Storage and Security
We take reasonable technical and organizational measures to protect your data:
- Application data is stored in MongoDB hosted on a cloud provider with encryption at rest.
- Asset files are stored in Google Cloud Storage with access controlled by organization-scoped bucket policies.
- Authentication sessions are managed by Better Auth with encrypted session tokens.
- All data in transit between your browser and our servers is encrypted using TLS/HTTPS.
- Access to production systems and databases is restricted to authorized personnel on a need-to-know basis.
No method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.
Cookies and Tracking
- Authentication cookies: We use session cookies to keep you signed in. These are strictly necessary and cannot be disabled without preventing login.
- Analytics: PostHog collects anonymized usage data (page views, feature interactions) to help us understand how the platform is used. You can opt out by enabling "Do Not Track" in your browser or by adjusting your browser's cookie settings.
- We do not use advertising cookies, retargeting pixels, or third-party tracking scripts beyond PostHog.
Third-Party Services
We use the following third-party services to operate our platform. Each operates under its own privacy policy:
- Google: OAuth sign-in and Google Cloud Storage for asset files.
- GitHub: OAuth sign-in.
- Microsoft Azure AD: Enterprise SSO for organizational accounts.
- Resend: Transactional email delivery (demo confirmations, account notifications).
- PostHog: Product analytics and session recording.
- Cloudflare: CDN, DNS, and Pages hosting for adage1.com.
Data Retention
- Account data: Retained for the life of your account, plus 90 days following account deletion to allow for recovery.
- Asset files: Retained according to your organization's settings and storage plan.
- Analytics data: Retained for 24 months, then aggregated or deleted.
- Demo request submissions: Retained for 12 months.
Your Rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete personal data.
- Request deletion of your personal data.
- Export your data in a portable format.
- Opt out of marketing communications at any time via the unsubscribe link in any email we send.
California residents (CCPA): We do not sell personal information. You have the right to know what data we collect and to request deletion. Contact us to exercise these rights.
To exercise any of the above rights, email us at hello@adage1.com. We will respond within 30 days.
Children's Privacy
ADage1 is a business-to-business platform not directed at children under the age of 13. We do not knowingly collect personal information from anyone under 13. If we become aware that we have collected data from a child, we will delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time. We will post the revised policy on this page with an updated effective date. For material changes, we will notify users by email at least 14 days before the change takes effect. Your continued use of ADage1 after the effective date constitutes acceptance of the updated policy.
Contact
If you have questions about this Privacy Policy or how we handle your data, please contact us: