Privacy Policy
Magister Marketing AI Agent Platform
Effective date: March 14, 2026 · Last updated: August 18, 2026
Overview
Magister Marketing ("Magister," "we," "us") is an autonomous AI marketing platform. Free and Connect experiences run without a dedicated Magister-hosted machine; the Agent plan includes an isolated cloud machine. Depending on the plan and features you enable, Magister can manage marketing tasks, interact with third-party services, send communications, and search the web. This privacy policy explains what data we collect, how we use it, who we share it with, and what rights you have over your data.
Data We Collect
Account Information
When you create an account, we collect your email address, authentication credentials managed by Supabase (we never store or access plaintext passwords), display name, and avatar URL.
Billing Information
Payments are processed by Stripe. We store your Stripe subscription ID, plan tier, and subscription status. We do notstore credit card numbers, bank account details, or other payment credentials — Stripe handles all payment data directly.
Chat & Conversations
We store the full conversation history between you and your AI agent, including message content, timestamps, and which AI model generated each response. This data is stored in Supabase and is scoped to your account.
Agent Machine Data
If you use the Agent plan, we provision an isolated AI agent machine on Fly.io. We store the Fly.io app and machine IDs, region, status, and activity timestamps associated with that machine.
Usage Data
We track LLM token counts, costs, and the model used for each request. This data is used for billing enforcement and plan limits.
Integration Tokens
When you connect third-party services (including Google, GitHub, Vercel, Webflow, Wix, WordPress, Shopify, PostHog, Slack, and supported social or advertising accounts), we store the resulting access and refresh tokens. DataForSEO credentials are stored if you provide them. All integration tokens are encrypted at rest using Fernet symmetric encryption.
External AI Clients and MCP Connectors
When you authorize an external AI client such as Claude, ChatGPT, Codex, Cursor, or Grok through Magister's MCP connector, that client can request the Magister and connected-service data covered by the organization and scopes you approve. With the default read scope this includes your brands' past Magister chat history (the same conversations members of that brand see in the app), workflow run history, permission requests, and the record of what the agent drafted or shipped. Tool responses are returned to that client and are also subject to the client provider's privacy terms. Separately scoped tools can send bounded request data to the server-side research and integration providers listed below or initiate writes you request. Magister continues to enforce its server-side scopes, roles, budgets, and each tool's documented immediate-confirmation requirement. Connected-service credentials remain encrypted on Magister's servers and are never returned to the external AI client.
BYOK API Keys
If you bring your own API keys for LLM providers (Anthropic, OpenAI, or Gemini), we store them encrypted at rest. These keys are used to route your AI requests directly to the provider of your choice, billed to your own account, instead of through our platform.
Email Data
When you enable agent email features, emails sent and received through the agent can include sender, recipient, subject, and body. This data is stored to enable the email workflows you request.
Analytics
We use Fathom Analytics on our public marketing site only (not within the authenticated app). Fathom is a privacy-focused analytics service that does not use cookies, does not track individuals, and is GDPR compliant. We collect only anonymous page view data.
Cookies
We use Supabase session cookies solely for authentication. We do not use tracking cookies, advertising cookies, or any third-party cookie-based tracking.
How We Use Your Data
- To provide and operate the Magister platform and your personal AI agent
- To process your chat messages through AI language models
- To execute marketing tasks on your behalf via connected integrations
- To process payments and enforce plan limits
- To send transactional emails (account confirmation, billing receipts)
- To monitor usage for billing and abuse prevention
- To improve the service (using aggregated, non-identifying data only)
We do not sell your data. We do not use your data for advertising. We do not train AI models on your conversations.
Third-Party Services
We share data with the following third-party services as necessary to operate the platform:
| Service | Data Shared | Purpose |
|---|---|---|
| Supabase | All user data (encrypted at rest) | Database and authentication |
| Fly.io | Machine provisioning commands | AI agent infrastructure |
| Stripe | Billing events | Payment processing |
| Anthropic | Chat prompts and conversation context | Claude model inference (no training on API data per Anthropic Commercial Terms §B) |
| OpenAI | Chat prompts and conversation context | GPT model inference (no training on API data per OpenAI API Data Usage Policy) |
| External AI clients you authorize | MCP tool requests and the authorized Magister or connected-service data returned by those tools | Using Magister from Claude, ChatGPT, Codex, Cursor, Grok, or another MCP client you choose |
| Google (Gemini) | Chat prompts and conversation context | Gemini model inference (paid-tier commitment: no training on prompts or responses) |
| Resend | Email content and recipients | Transactional email delivery |
| Brave Search | Search queries | Web search (agent capability) |
| DataForSEO | Keyword queries and public website domains | Keyword, ranking, search-volume, and SEO research |
| ScrapeCreators | Selected social channel, topic, result limit, and public creator identifiers | Influencer discovery and public contact evidence |
| Bright Data | Public website URLs, public-page requests, and configured AI-visibility queries | Website retrieval and public search or AI-visibility measurement |
| Zernio | Connected social and advertising account identifiers, content, campaign settings, and analytics requests | Social publishing, account analytics, and paid-ad management when you connect those accounts |
| Composio | Connected Gmail authorization and email delivery requests | Sending email through the Gmail account you connect |
| Fathom Analytics | Page views (anonymous, no cookies) | Website analytics |
| Google (Ads, Analytics, Search Console, Tag Manager, Drive, Calendar) | OAuth tokens and API requests on your behalf (see “Google User Data” section below) | Google integrations (only when you connect them) |
| GitHub, Vercel, Webflow, Wix, WordPress, Shopify, PostHog, Slack | API calls on your behalf | Third-party integrations (only when you connect them) |
Third-party integrations are activated only when you explicitly connect them or invoke a separately scoped built-in provider feature. Your agent accesses connected services with the permissions you grant, while metered research providers receive only the bounded request data needed for the tool you invoke.
Google User Data
This section describes how Magister handles data received from Google APIs in compliance with the Google API Services User Data Policy, including the Limited Use requirements.
Google scopes we request
When you connect a Google account in Settings → Connections, Magister requests only the minimum scopes required to provide the features you asked for:
- Google Ads (
adwords) — lets your agent manage ad campaigns, read performance reports, and adjust bids, keywords, and ad copy on your behalf. - Google Analytics 4 (
analytics.readonly) — lets your agent query read-only GA4 performance data to help you track the impact of marketing changes. The agent never modifies GA4 configuration. - Google Search Console (
webmasters.readonly) — lets your agent read search performance, top queries, and coverage data for your verified sites. - Google Tag Manager (
tagmanager.readonly) — lets your agent audit tag configuration and verify that analytics and conversion tracking tags are correctly published. Read-only; never modifies GTM resources. - Google Drive (
drive.file) — lets your agent create new Docs, Sheets, Slides, and folders on your behalf. This is a per-file scope: the agent can only access files it creates, never your existing Drive contents. - Google Calendar (
calendar) — lets your agent schedule marketing events, content deadlines, and reminders when you explicitly request it.
How we store Google user data
Google OAuth access and refresh tokens are stored encrypted at rest in our Supabase database using Fernet symmetric encryption. Tokens are never written to your agent machine or any other runtime environment. Our gateway injects the real token server-side at request time and strips it from the response path, so the agent runtime never sees your Google credentials.
How long we retain Google user data
We retain Google OAuth tokens and any metadata fetched from Google APIs only for as long as the integration is connected. When you disconnect a Google integration from Settings → Connections, the associated tokens and metadata are deleted immediately. When you delete your Magister account, all Google user data is permanently removed.
Limited Use of Google user data
Magister's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We do not sell Google user data to any third party.
- We do not use Google user data for advertising, including retargeting, personalized advertising, or interest-based advertising.
- We do not use Google user data to train, fine-tune, or improve generalized or non-personalized AI/ML models.
- We do not allow humans to read Google user data except with your explicit consent, for security investigations, to comply with applicable law, or where the data has been aggregated and anonymized for internal operations.
- We do notshare Google user data with any third party except to provide the features you have explicitly asked your agent to perform (for example, forwarding your request to Google's own APIs).
How to revoke access to Google user data
You can revoke Magister's access to your Google account at any time from two places:
- Inside Magister:Settings → Connections → Disconnect. This immediately deletes the OAuth tokens and associated metadata from our database.
- From your Google account: https://myaccount.google.com/permissions. This revokes Magister's OAuth grant at the Google level even if the integration is still listed inside Magister.
Security
- Encryption at rest: All third-party API keys, OAuth tokens, and BYOK keys are encrypted using Fernet symmetric encryption before storage.
- Encryption in transit: All traffic between your browser, our servers, and third-party services is transmitted over HTTPS/TLS.
- Tenant authorization: User-facing database access is restricted through Supabase Row-Level Security (RLS) policies and server-side authorization checks.
- Credential isolation: OAuth tokens and API keys are never stored on your AI agent machine. They are injected server-side by our gateway at request time. The only credential on your machine is a scoped, per-user gateway token.
- Isolated Agent infrastructure: Agent plan machines are dedicated and isolated. Agent environments are not shared across customers.
Your Rights
- Access: You can view your data at any time through the app dashboard, including chat history, usage data, and connected integrations.
- Deletion: You can delete your account from account settings or contact us at team@magistermarketing.com for help. Deletion removes associated data, including any agent machine, chat history, and integration tokens, subject to limited retention required by law.
- Export: Contact us to request an export of your data.
- Revoke integrations:You can disconnect any third-party service at any time from Settings → Integrations. Revoking an integration immediately deletes the associated OAuth tokens from our database.
Data Retention
- Chat history: Stored until you delete your account.
- Usage data: Stored until you delete your account.
- Integration tokens: Stored until you disconnect the integration or delete your account.
- MCP authorization and activity: Connector grants and operational activity are retained under the same account, security, billing, and deletion controls as other Magister usage data. Revoking a connector stops new access; deleting your account removes its associated active grants and records subject to limited retention required by law.
- De-identified service metrics: Account deletion may add coarse usage and cancellation categories to a monthly cohort with no account identifiers, free text, exact timestamps, or exact per-account totals. A cohort is available for service improvement only after at least ten separate account deletions contribute, the calendar month closes, and a one-day publication grace passes. Cohorts below that threshold are deleted within 180 days; qualifying aggregate statistics may be retained for trend analysis and cannot be used to restore or identify a deleted account.
- On account deletion: Any agent machine is destroyed, your Stripe subscription is cancelled, and associated data is removed from our active systems, subject to limited retention required by law. This action is irreversible.
Children
Magister is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If you believe a child under 18 has provided us with personal data, please contact us and we will delete it.
International Data Processing
Your data is processed and stored in the United States through our infrastructure providers (Supabase, Fly.io, Vercel). By using Magister, you consent to the transfer and processing of your data in the United States.
Changes to This Policy
We may update this privacy policy from time to time. If we make material changes, we will notify you by email or through a notice in the app. The "Last updated" date at the top of this page reflects when the policy was most recently revised.
Contact
For privacy questions, data requests, or concerns, contact us at team@magistermarketing.com.