Adalyst ("Adalyst," "we," "us," or "our") is a service operated by Prabhjot Kaur Chadha, a sole trader trading as Adalyst, based in the United Kingdom. Adalyst is available at adalyst.app and any related applications, dashboards, features, and services we provide (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, store, and otherwise process personal information when you visit the Service, create an account, connect third-party services, upload content, purchase a subscription, or otherwise use Adalyst.
For personal information related to your account, subscription, billing, and direct use of the Service, Prabhjot Kaur Chadha (trading as Adalyst) is the data controller under UK GDPR and other applicable law. For data you instruct us to process through the Service on your behalf, Adalyst acts as a data processor or service provider, depending on the context and applicable law.
By using the Service, you acknowledge the practices described in this Privacy Policy.
This Privacy Policy applies to personal information we collect when you:
This Privacy Policy does not apply to websites, applications, or services we do not own or control, including LinkedIn, Google, Microsoft, Meta, HubSpot, Salesforce, Stripe, and Resend. Those services are governed by their own privacy policies and terms.
We collect the following categories of information.
When you create an account, we collect your email address and account-related information needed to create, authenticate, and manage your account.
If you sign in using Google, we receive your Google account identifier and the information needed to support that authentication method, such as your email address. We do not store your Google password.
When you connect a third-party platform to your Adalyst account, we store encrypted OAuth access tokens and refresh tokens so we can interact with that platform's API on your behalf. We never store or receive the passwords you use with the underlying platform.
Depending on the permissions you grant and the features you use, we may access and process the following categories of data from each connected platform:
LinkedIn Ads (LinkedIn Marketing API)
Google Ads
Google Analytics
HubSpot
Meta (Facebook, Instagram Ads)
Microsoft Ads
Salesforce
BigQuery
We only access data from platforms you explicitly connect, and only the scopes authorised through the provider's OAuth flow. You can review the scopes at the point of connection and revoke access at any time from the Adalyst connections page or from the provider's own account settings.
We collect and store the content you upload or submit through the Service, including:
Uploaded content is stored securely and associated with your account.
We use Stripe to process payments. We store billing-related identifiers and subscription information needed to manage your account and subscription, such as:
We do not store your full credit card number, CVV, or full payment credentials. Payment information is processed by Stripe in accordance with Stripe's own privacy and security practices.
We collect limited usage and operational data needed to operate, secure, and administer the Service, including:
If you contact us, including by email or in connection with a support or privacy request, we may collect:
We use a strictly necessary session cookie to authenticate requests and keep you signed in. We may also use third-party analytics and advertising technologies as described in Section 8 of this Privacy Policy.
The Service may allow you to upload or process content that includes information about other individuals, such as campaign-related or lead-related data.
You are responsible for ensuring that you have the necessary rights, permissions, notices, and legal basis to provide that information and instruct us to process it. We process that information only as needed to provide the Service, perform your instructions, and comply with our legal obligations.
We use personal information for the following purposes:
Operational data, including ad platform data, CRM records, and account-level metadata, is isolated per organisation and is not shared with other customers. For product research, benchmarking, and recommendation quality, Adalyst may derive de-identified aggregate statistics across its customer base. These aggregates contain no company names, no personal data, and are suppressed below a minimum cohort size of five organisations.
Aggregates are used to improve the accuracy of the recommendations Adalyst surfaces to all customers and to support Adalyst’s internal product research.
Your organisation may opt out of benchmark contribution at any time by emailing privacy@adalyst.app. Opting out stops further contribution; it does not affect your access to benchmarks Adalyst has already produced.
If you are located in the European Economic Area, the United Kingdom, or Switzerland, our legal bases for processing personal information generally include:
Where we rely on consent, you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing that occurred before withdrawal.
We disclose personal information only as reasonably necessary to operate the Service, fulfill your requests, or comply with law.
We may share information with third parties you choose to connect through the Service, including:
We engage a limited set of sub-processors to help us host, secure, deliver, maintain, and operate the Service — including infrastructure hosting, transactional email, payment processing, and the large language model processing that powers Adalyst's analysis features. These providers process information on our behalf only as necessary to provide services to us or as otherwise required by law. The live, authoritative list of named sub-processors — including purpose, data categories, and processing region — is published at adalyst.app/sub-processors. Workspaces can opt in to be emailed when the list changes.
We may disclose information if we believe doing so is necessary to:
We may disclose information in connection with a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar business transaction, subject to customary confidentiality and legal safeguards.
We may share information when you instruct us to do so or otherwise consent to the sharing.
Adalyst's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We do not sell your personal information.
We do not share personal information for cross-context behavioral advertising.
When you sign in with Google or Microsoft, or connect any of the third-party platforms Adalyst supports (including LinkedIn Ads, Google Ads, Google Analytics, HubSpot, Meta, Microsoft Ads, Salesforce, and BigQuery), you authorise us to access and use information from those services consistent with the permissions you grant and the features you choose to use. Scope details for each platform are listed in Section 2(b).
You can revoke access at any time by:
When you disconnect a connected platform, we stop future API access and invalidate the stored OAuth tokens for that platform as part of the disconnection process.
Disconnecting a third-party account does not automatically delete information already created, retrieved, or stored in your Adalyst account unless you also delete that content or request account deletion. See Section 10 (Data Retention) for retention periods by data category.
Adalyst uses a session cookie called adalyst_session that is strictly necessary for authentication and core Service functionality. Because this cookie is essential to the operation of the Service, disabling it may prevent you from logging in or using the platform properly.
We may use third-party analytics services such as Google Analytics, PostHog, or similar tools to understand how our Service is used, measure performance, and improve the user experience. These services may use cookies, device identifiers, and similar technologies to collect information about your interactions with the Service, including pages visited, time spent, and general location data derived from your IP address.
We may use third-party advertising technologies such as the LinkedIn Insight Tag, Google Ads remarketing, Meta (Facebook) Pixel, or similar tools to measure the effectiveness of our advertising, deliver relevant advertisements to you on other platforms, and build custom audiences for retargeting purposes. These technologies may collect information such as your IP address, browser type, pages visited, and interactions with our Service.
Information collected by these tools is subject to the privacy policies of the respective third-party providers, including:
You can control or disable non-essential cookies through your browser settings. You may also opt out of interest-based advertising through the following:
Please note that opting out of non-essential cookies does not affect the essential session cookie required for authentication.
We retain personal and operational information only for as long as reasonably necessary to provide the Service, meet our legal and contractual obligations, and fulfil the purposes described in this Privacy Policy. Default retention periods are:
| Category | Default retention |
|---|---|
| Account and organisation data | For the duration of the service relationship. On workspace deletion, a 30-day soft-delete window applies, after which data is hard-deleted: rows are removed from the primary database and from object storage, and the workspace's audit data-encryption key is destroyed so any residual audit ciphertext becomes unreadable. |
| Uploaded content (spreadsheets, images, creatives) | 90 days by default. Purged on workspace deletion. |
| Platform integration data (ad platform, CRM, analytics snapshots) | 400 days by default. Purged on workspace deletion. |
| LLM prompt/response audit records | 400 days by default. Stored encrypted with a per-workspace key; purged by a daily retention sweep when older than the configured window. |
| DLP incident records (detector hits on outbound LLM calls) | Follows the audit retention window above. Only the detector type and severity are stored; never the matched content. |
| Data export archives | Signed download links expire 24 hours after generation; the archive object is deleted at the next daily sweep after expiry. |
| Legal agreements (DPAs, BAAs, SCCs, MSAs) | Retained for the duration of the service relationship and purged on workspace deletion. Superseded versions remain on file for the period required by applicable law. |
| OAuth tokens for connected platforms | Until you disconnect the platform, the token expires, or you revoke access at the provider. |
| Platform audit logs (authentication, permission changes, exports, deletions) | 24 months from the event. |
| Billing, invoicing, and tax records | 7 years, to comply with UK and US tax and accounting requirements. |
| Support correspondence | 36 months from the last interaction. |
| Backups | Rolling 30-day window; older backups are automatically overwritten. |
| De-identified aggregated data | Retained indefinitely. Cannot be re-identified back to your organisation. See Section 5. |
Per-workspace retention may be customised by a workspace administrator in Settings → Data policy; the values shown above are defaults. Workspace administrators can also request a full data export at any time from Settings → Export, and initiate workspace deletion from Settings → Delete.
If you delete your workspace, we remove or anonymise your personal information within the retention windows above, except where we are required or permitted to retain certain information by law, for legitimate security or fraud-prevention purposes, to resolve disputes, to enforce our agreements, or as part of routine backup and disaster-recovery processes for the periods above.
You may request a copy of your personal information or its deletion at any time by emailing privacy@adalyst.app. See Section 13 (Your Rights and Choices) for details.
We implement reasonable technical and organizational measures designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure.
These measures include:
No method of transmission over the internet or method of electronic storage is completely secure. While we work to protect your information, we cannot guarantee absolute security.
Adalyst and the third-party providers we use may process personal information in countries other than the country where you live. As a result, your information may be transferred to and processed in jurisdictions that may have data protection laws different from those in your jurisdiction.
Where required by applicable law, we will use appropriate safeguards for international transfers of personal information, which may include contractual protections or other lawful transfer mechanisms.
You may contact us using the details below for more information about applicable transfer safeguards.
Depending on your jurisdiction, you may have the right to:
You may also:
To exercise privacy rights, contact us at privacy@adalyst.app.
We may need to verify your identity before fulfilling a request. In some cases, we may deny or limit a request where permitted by law. If applicable law provides a right to appeal our decision on a privacy request, you may do so by replying to our response or contacting us again at the same email address.
If your request relates to data primarily controlled by a third party — such as LinkedIn, Google, Microsoft, Meta, HubSpot, Salesforce, or Stripe — we may direct you to that provider for the portions of data it controls independently.
You can delete your data from Adalyst in three ways:
You can also revoke Adalyst's access directly from each provider:
Limited records may be retained following deletion only where required by law (for example, billing and tax records for seven years; see Section 10).
The Service is not intended for anyone under the age of 18, and we do not knowingly collect personal information from anyone under 18.
If we learn that we have collected personal information from a child without appropriate authorization, we will take steps to delete that information.
We may update this Privacy Policy from time to time. When we do, we will post the revised version on this page and update the "Last updated" date at the top of the Policy.
If we make material changes, we may also provide additional notice, such as by email or through the Service, where required by law.
Your continued use of the Service after the updated Privacy Policy becomes effective means that you acknowledge the revised Policy.
This Service is operated by Prabhjot Kaur Chadha, a sole trader trading as Adalyst, based in the United Kingdom. The Operator is the data controller for personal information processed through the Service, except where Adalyst processes data on a customer's instructions, in which case the Operator acts as a data processor.
For privacy questions, deletion requests, or to exercise your rights under UK GDPR, contact us at privacy@adalyst.app. A postal address is available on request.
UK residents may also lodge a complaint with the Information Commissioner's Office at ico.org.uk.