Privacy Policy

Last updated: June 6, 2026 · 日本語版

1. Operator

Marty (the "Service") is an AI-powered Meta Ads management assistant for D2C businesses, operated by staff-ai.jp.
  • Service name: Marty
  • Service URL: https://marty.staff-ai.jp
  • Contact: mail@marketing-diy-lab.com

2. Information We Collect

2-1. Information you provide

  • Email address and password (at sign-up)
  • Chat messages and instructions you enter
  • Images you attach for creative generation
  • Inquiry information received via a landing page (LP) form: name, email address, phone number, company name, message body, together with referral information at submission time (UTM parameters, referrer), source IP address, browser information (User-Agent), and the timestamp of consent to this Privacy Policy. We store this on the Service so the Service user (the LP operator) can respond to the inquiry.

2-2. Information from Meta (Facebook)

When you connect a Meta Ads account via OAuth, we retrieve:
  • Meta Ad Account ID, name, currency
  • Campaigns / ad sets / ads structure (name, status, budget, targeting, creative)
  • Ad performance data (impressions, clicks, spend, conversions, etc.)
  • OAuth access token (stored encrypted, auto-refreshed every 60 days)

We do NOT collect personal profile information, friend lists, or post content. Only information necessary for ad management is retrieved.

3. Meta Permissions and Their Purpose

We request the following Meta Graph API permissions and use each strictly for the purpose described:
  • ads_read: To fetch ad performance metrics (impressions, conversions, ROAS, etc.) for the user's ad account and display them in the KPI dashboard and daily AI report.
  • ads_management: To execute actions approved by the user in the Marty UI (pause/resume campaigns, change daily budget, create new ads). We never modify ads without explicit user approval(with the exception of user-configured automation rules with conditions the user has set).
  • business_management: To list the ad accounts under the user's Meta Business Manager so the user can choose which account to connect to Marty.
  • email, public_profile: For identity verification at connection time and display of the user's name.

4. How We Use the Information

  • Analyze and visualize ad performance (KPI dashboard)
  • Generate AI-powered operational suggestions and improvement advice
  • Execute ad operations approved by the user (pause/resume/budget/create)
  • Send the daily AI report by email
  • Send alert emails when thresholds are exceeded
  • Implicitly learn the user's decision patterns from operation logs to improve the precision of future suggestions (personalization)
  • Store and display inquiry information received via LP forms(so the LP operator can respond to inquiries, conduct sales activities, and improve the service)

5. Third-Party Sub-processors

We do not sell or transfer your personal information to third parties without your consent. We use the following service providers as processors:
  • Meta Marketing API (Meta Platforms, Inc.): Ad data retrieval and operations
  • Anthropic Claude API (Anthropic, PBC): AI analysis and text generation
  • Supabase (Supabase, Inc.): Authentication, database, file storage
  • Stability AI (Stability AI Ltd.): Creative image generation and editing
  • Resend (Resend, Inc.): Email delivery
  • Vercel (Vercel, Inc.) / Fly.io (Fly.io, Inc.): Hosting

Each provider handles data according to their own privacy policy.

6. Data Storage and Security

  • All communication is encrypted via TLS (HTTPS).
  • Meta OAuth access tokens are encrypted at rest.
  • The database uses Row Level Security (RLS) to fully isolate users from each other.
  • Passwords are stored as bcrypt hashes by Supabase Auth, never in plaintext.

7. Data Retention

  • Ad performance data: Retained while the account is connected (for historical analysis)
  • Chat history: Retained while the account is connected
  • Operation logs (for personalization): Last 30 days used for aggregation; older entries may be pruned
  • After account deletion: all data is deleted within 30 days (including backups)
  • Inquiry information received via LP forms: While the LP operator uses the Service, we retain it for a guideline period of 3 years from the last contact (the last inquiry received or response made), after which it is progressively deleted (a period informed by Japanese commercial record-keeping practice and the GDPR principle of not retaining data longer than necessary). If an LP project is deleted, the associated inquiry history remains, detached from the LP reference, until the end of that period (for historical analysis). If the person who submitted the inquiry requests deletion, we will respond within 7 business days under the procedure in §8.5 (mail@marketing-diy-lab.com).

8. Your Rights

You may exercise the following rights regarding our Service:
  • Right of access: Request disclosure of your stored data
  • Right of rectification: Request correction of inaccurate data
  • Right of erasure: Request deletion of your data (see Data Deletion Instructions )
  • Right to revoke OAuth: Disconnect Meta OAuth at any time via Facebook Settings → Business Integrations → Remove Marty
  • Reset of learned data: One-click deletion of operation logs and behavior profile via the Personalization section in Settings

Requests should be sent to mail@marketing-diy-lab.com. We will respond within 7 business days.

8.5 Requests Regarding LP Form Submitters' Information (DSR)

If you submitted information through an inquiry form on a landing page (LP) operated by a Service user (and you are not yourself a registered Service user), you may make the following requests (Data Subject Requests) regarding your own information stored within the Service:
  • Access (disclosure): Request disclosure of your stored information
  • Rectification: Request correction of inaccurate information
  • Erasure: Request deletion of your information (deletion of personally identifying data only, or of the entire record)

Please contact us by email at contact@staff-ai.jpwith "DSR" in the subject line. After verifying your identity, we will respond within 7 business days as a rule.

For erasure requests, we delete personally identifying information (name, email address, phone number, company name, message body, etc.). We may retain only aggregate counts for service improvement in a form that cannot identify you.

9. Cookies and Similar Technologies

We use cookies and localStorage only to maintain authenticated sessions. We do not use third-party advertising or analytics cookies.

10. Children

Marty is a B2B tool for businesses and is not directed at users under 13. If a user under 13 is found to have registered inadvertently, we will delete their data promptly.

11. Changes to This Policy

This policy may be updated to reflect changes in law or our service. For significant changes, we will notify users on the Service and via the registered email address. Updated policy takes effect from the date posted.

12. Contact

For questions about this policy or our data practices:
Email: mail@marketing-diy-lab.com
Operator: staff-ai.jp
Marty — AI Marketing Agent · staff-ai.jp