Privacy Policy
Effective Date: April 21, 2026
This Privacy Policy explains how Techno Believe Solutions Ltd, trading as Marketing So High ("MSH", "we", "us", or "our"), collects, uses, and protects your personal information when you use our platform at marketingsohigh.com and associated services.
1. Information We Collect
We collect the following types of information when you use our platform:
Account Information
When you create an account, we collect your name, email address, and authentication credentials. If you sign in via Google or Microsoft, we receive your basic profile information from those providers.
Usage Data
We collect information about how you interact with our platform, including pages visited, features used, content created, and actions taken within the dashboard. This helps us improve our services and provide analytics.
Content Data
When you use our AI content generation, outreach, and SEO tools, we process the content you create, edit, and distribute. This includes marketing copy, outreach messages, SEO keywords, and campaign configurations.
Platform Connection Data
When you connect third-party platforms (such as LinkedIn, Facebook, Medium, Reddit, WordPress, or others), we store the necessary authentication tokens and credentials to interact with those platforms on your behalf. This may include access tokens, refresh tokens, and platform-specific identifiers.
Billing Information
Payment processing is handled by Stripe. We do not store your full credit card details on our servers. We retain your subscription status, plan type, and billing history.
2. How We Use Your Information
We use the information we collect for the following purposes:
- Service Delivery: To provide, maintain, and improve our AI-powered marketing platform, including content generation, distribution, outreach automation, and SEO tools.
- Content Distribution: To publish and distribute your marketing content to connected third-party platforms on your behalf.
- Analytics and Insights: To provide you with performance analytics, engagement tracking, and marketing intelligence across your campaigns.
- AI Processing: To generate, optimize, and personalize marketing content using artificial intelligence models.
- Communication: To send you service-related notifications, updates, and support communications.
- Security: To detect, prevent, and address technical issues, fraud, and unauthorized access.
3. Third-Party Services
Our platform integrates with various third-party services to provide its functionality. When you connect your accounts, we interact with these services on your behalf:
- Meta (Facebook, Instagram, Threads): For content distribution and page management via the Meta Graph API. Scopes we request:
pages_show_list,pages_manage_posts,pages_read_engagement,pages_manage_engagement,pages_read_user_content,read_insights. We post content you authored to pages you own, read engagement metrics to report performance, and never modify content outside the scope of your authorization. Data is never sold or used for advertising targeting. - Pinterest: For pinning content to boards you own via the Pinterest API v5. Scopes we request:
boards:read,boards:write,pins:read,pins:write,user_accounts:read. We create pins you authored, read board metadata to surface pick-a-board UI, and never sell, rent, or use this data for advertising. - TikTok: For uploading video content via the TikTok Content Posting API. Scopes we request:
user.info.basic,user.info.stats,video.upload,video.list. We upload videos you authored with your explicit per-post approval, read account stats to display publishing status, and never sell or use this data for advertising. - LinkedIn: For content publishing, outreach messaging, and engagement tracking.
- Google: For authentication (Google Sign-In) and analytics integration.
- Tumblr: For content distribution and blog post publishing.
- Reddit: For content distribution to relevant communities.
- Medium: For article publishing and content distribution.
- WordPress: For blog content publishing and SEO content deployment.
- Stripe: For secure payment processing and subscription management.
- AI Providers (Google Gemini, OpenAI, Anthropic, Groq, OpenRouter): For AI-powered content generation and analysis. Content sent to these providers is processed according to their respective privacy policies.
Each third-party service has its own privacy policy governing the use of your data. We encourage you to review the privacy policies of any platform you connect to our service.
External Data Sources We Fetch From
In addition to the platforms you connect, our competitive-intelligence and SEO features fetch data from external sources on your behalf. We disclose these in compliance with GDPR Articles 13–14 and CCPA § 1798.100:
- Firecrawl & Jina AI Reader: When you request competitor research or pricing-page analysis, we fetch the publicly-available pages of URLs you supply via these scraping services. We do not bypass paywalls. We pass the content through an LLM to extract structured facts (pricing, features, positioning). Raw scraped content is retained for 90 days, then deleted.
- DataForSEO: A licensed search-data provider. We send keyword queries to retrieve search volume, competition, SERP snapshots, and backlink data for the domains you research. DataForSEO acts as an independent data controller for the aggregated SERP data it returns.
- Public Google Search results: Our outreach engine uses Google Programmable Search to locate publicly-listed LinkedIn profile URLs for prospects you research (e.g.
site:linkedin.com/in "Name" "Company"). We retrieve only the URL and snippet that Google indexes publicly — we do not scrape LinkedIn directly. - RDAP (Registration Data Access Protocol): The mailbox warmup engine queries
rdap.orgfor the registration date of email-sending domains. Only the domain name is sent; no user data leaves our infrastructure. - Hacker News + Google News RSS: Public news feeds queried by name for competitor mentions. No personal data is sent in the query.
You can opt out of competitive-intelligence scraping by not initiating research requests; the warmup engine's RDAP queries are required for safe-ramp behavior and run only when you opt mailboxes into the warmup pool.
4. Google User Data
When you connect your Google account to MSH via the "Connect Google" flow in Settings → External Data, we request read-only access to the following Google APIs:
- Google Search Console (
https://www.googleapis.com/auth/webmasters.readonly) — we read query impressions, clicks, click-through rate, and ranking position for properties you have verified in Search Console. This powers our agents' ability to ground content recommendations in real search performance data. - Google Analytics 4 (
https://www.googleapis.com/auth/analytics.readonly) — we read pageview, user engagement, and conversion metrics for GA4 properties you grant access to. This powers our dashboards and lets agents identify which content drives traffic.
Limited Use
MSH's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, data received from Google APIs:
- is used only to provide and improve the user-facing features you see in MSH (dashboards, agent answers, content recommendations);
- is not transferred to others except as necessary to provide or improve the user-facing features, comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users;
- is not used for serving advertisements, including retargeting, personalized, or interest-based advertising;
- is not sold, rented, or licensed to any third party;
- is not used to train generalized or third-party machine-learning or AI models. We do not send Google API data to model providers to improve their models. When our agents answer questions about your data, the data is sent to LLM providers solely to generate a response for you and is subject to those providers' zero-retention contractual guarantees where available.
- is not accessed by humans except (a) with your explicit consent, (b) as necessary for security or to comply with law, (c) for operational debugging when anonymized or aggregated, or (d) to provide user support you have requested.
Storage & Retention
The OAuth refresh token we receive is stored encrypted at rest in our Supabase database. Query results from GSC and GA4 are fetched on-demand when agents or dashboards request them; we may cache results for up to 30 days to reduce redundant API calls and improve performance. You can disconnect at any time from Settings → External Data. On disconnection we:
- revoke the OAuth refresh token with Google,
- delete the stored credentials from our database,
- delete any cached query results within 24 hours.
You can additionally revoke MSH's access to your Google account at any time by visiting myaccount.google.com/permissions.
Data Deletion
To request deletion of all Google user data we hold about you, either click "Disconnect" next to the integration in Settings → External Data (immediate), or submit a request at marketingsohigh.com/data-deletion.
5. Data Storage and Security
- Your data is stored securely using Supabase, a trusted cloud database platform with enterprise-grade security, encryption at rest, and encryption in transit.
- Platform credentials and API keys are stored using encryption and are never exposed in plain text through our user interface.
- We implement Row Level Security (RLS) policies to ensure that users can only access data belonging to their own organization.
- We use HTTPS/TLS encryption for all data transmitted between your browser and our servers.
- We do not sell, trade, or rent your personal information to third parties.
6. Data Retention
We retain your personal data for as long as your account is active or as needed to provide you with our services. If you request deletion of your account, we will remove your personal data within 30 days, except where we are required to retain it for legal, regulatory, or legitimate business purposes. Aggregated, anonymized data that cannot identify you may be retained indefinitely for analytical purposes.
7. Your Rights
Under the General Data Protection Regulation (GDPR) and applicable data protection laws, you have the following rights regarding your personal data:
- Right of Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can request that we correct any inaccurate or incomplete personal data.
- Right to Erasure: You can request that we delete your personal data, subject to certain legal exceptions.
- Right to Data Portability: You can request a machine-readable copy of your data to transfer to another service.
- Right to Restrict Processing: You can request that we limit the processing of your personal data in certain circumstances.
- Right to Object: You can object to the processing of your personal data for certain purposes, including direct marketing.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw that consent at any time.
To exercise any of these rights, please contact us at dev@marketingsohigh.com. We will respond to your request within 30 days.
8. Cookies and Local Storage
We use a minimal set of cookies and browser storage mechanisms:
- Authentication Cookie (msh-auth): Used to maintain your login session. This is an essential cookie required for the platform to function.
- Supabase Session Cookies: Used for secure authentication via Supabase. These are essential cookies.
- Local Storage: We use browser localStorage to save your preferences, such as selected organization, project, and UI settings (e.g., theme preference). This data stays on your device and is not transmitted to our servers.
- Analytics: We use Google Analytics and Microsoft Clarity to understand how users interact with our platform. These services may set their own cookies. You can opt out of analytics tracking using your browser settings or by installing the respective opt-out extensions.
9. Children's Privacy
Our platform is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected data from a child under 16, we will take steps to delete that information promptly. If you believe a child under 16 has provided us with personal data, please contact us immediately.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by updating the "Effective Date" at the top of this policy and, where appropriate, providing additional notice through our platform or via email. We encourage you to review this policy periodically.
11. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Techno Believe Solutions Ltd
Trading as Marketing So High

