Privacy Policy

Last Updated: July 17, 2026

This Privacy Policy describes how BrightLake ("we," "us," or "our") collects, uses, shares, and protects personal data in connection with the BrightLake platform and services (the "Service").

This Privacy Policy applies primarily to business customers and authorized users accessing the Service on behalf of an organization. Our processing of personal data is governed by this Privacy Policy, the Terms of Service, and, where applicable, the Data Processing Addendum ("DPA").

1. Scope and Roles

BrightLake provides a business-to-business, AI-powered advertising, analytics, and market intelligence platform. In the course of providing the Service, BrightLake generally processes personal data on behalf of its customers in accordance with their instructions.

For purposes of applicable data protection laws:

  1. Customers generally act as the controller or business with respect to Personal Data included in Customer Data; and

  2. BrightLake generally acts as a processor or service provider with respect to such Personal Data, unless otherwise expressly stated or where BrightLake processes personal data for its own independent purposes, in which case BrightLake will act as a controller with respect to such processing.

The Service is not designed to process sensitive personal data or user-level advertising data. Customers should not submit sensitive personal data to the Service unless expressly authorized by BrightLake in writing.

2.Information We Collect

2.1 Information You Provide Directly

We collect information that you, your organization, or your authorized users voluntarily provide to us when accessing or using the Service. This information may include, without limitation:

  1. Account and Contact Information: names, email addresses, job titles, and other contact details associated with your account;

  2. Organization and Account Details: company name, organizational identifiers, account configuration settings, and preferences;

  3. Authentication and Access Information: usernames, credentials, access permissions account roles, and related authentication information associated with authorized users;

  4. Commercial and Account Administration Information: billing contacts, order information, subscription information, and other commercial records, where applicable;

  5. Customer Content and Inputs: advertising campaign configurations, settings, metadata, performance parameters, market intelligence queries, and other business content submitted to or processed through the Service; and

  6. AI Feature Inputs: prompts, queries, instructions, or other information submitted when using AI-Powered Features.

We do not intend to collect or process sensitive personal data (such as government-issued identification numbers, financial account credentials, precise location data, health information, or biometric identifiers, or information about children). You should not submit sensitive personal data to the Service unless expressly requested or authorized by BrightLake in writing.

2.2 Information from Third-Party Platforms

When you connect, link, or integrate third-party platforms or services with the Service, BrightLake may access data made available by such platforms in accordance with your authorization, applicable integration settings, and the privacy policies and terms governing those third-party services. This data may include advertising performance metrics, attribution data, campaign information, and related analytics from platforms such as Apple Ads, MMPs, or other third-party services you choose to integrate.

Specifically, when you integrate your Apple Ads account, we may access and process categories of data that may include:

  1. Account and Configuration Information: Organization names, account IDs, and configuration settings;

  2. Campaign Management Data: Campaign names, ad group details, keyword data, creative-related information, and associated metadata;

  3. Bidding and Budgetary Information: Budget allocations, bid settings, and historical spend;

  4. Performance and Attribution Metrics: Impressions, taps, installs, and conversion data, post-install event metrics, and other aggregated or platform-provided performance information.

Certain features may also incorporate data obtained from third-party market, app, keyword, creative, or competitive intelligence data providers. These providers supply business, market, app, keyword, creative, ranking, or competitive intelligence data to BrightLake in response to customer-initiated or feature-related queries. BrightLake does not intentionally provide Personal Data to such providers.

You may revoke BrightLake's access to third-party platform data at any time by disconnecting the applicable integration through the Service or by modifying the authorization settings within the relevant third-party platform. Revoking access may limit or disable certain features of the Service.

2.3 Information Collected Automatically

When you access or use the Service, we may automatically collect certain technical, usage, and log information generated by your interaction with the Service. This information may include, without limitation:

  1. Device and Technical Information: IP addresses, unique device identifiers, browser types, operating system versions, and related technical attributes of your hardware and software;

  2. Usage and Activity Data: Timestamps of access, features utilized, pages viewed, interactions with the Service interface, and related usage patterns;

  3. Log and Diagnostic Information: System logs, error reports, and performance telemetry data used to monitor, maintain, and optimize the Service; and

  4. Security and Fraud Prevention Data: Information used to detect, investigate, and prevent unauthorized access, security incidents, or misuse of the Service.

This information is processed to operate, secure, analyze, and improve the Service, as well as to comply with applicable legal and regulatory obligations. See section below, “Cookies and Other Tracking Technologies” for more information.

2.4 Cookies and Other Automated Technologies

We may use cookies and similar automated technologies to collect certain information automatically when you access or use the Service. These technologies help us operate the Service, maintain security, remember user preferences, understand usage patterns, and improve performance and functionality.

The cookies we may use can be categorized as follows:

  1. Essential Cookies, which are necessary for the operation and security of the Service, including user authentication, session management, access control, and fraud prevention.

  2. Analytics and Performance Cookies, which help us understand how the Service is used, diagnose technical issues, measure performance, and improve the reliability and functionality of the Service. Information collected through these cookies is used in an aggregated or de-identified form where reasonably feasible.

  3. Functional Cookies, which allow the Service to remember preferences and configuration settings, such as language preferences or organization selection, to enhance user experience.

  4. Advertising and Marketing Cookies, which may be used to measure the effectiveness of our marketing activities, understand how users interact with our website or Service, and support advertising, remarketing, or marketing analytics activities. These technologies may be provided by third-party service providers, such as analytics or advertising technology providers.

    Some cookies may be placed by third-party service providers that support the operation, security, analytics, performance, or marketing of the Service. These providers may process information on our behalf and are subject to contractual, confidentiality, and data protection obligations where applicable.

Your Choices. You may manage cookie preferences through your browser settings. Please note that disabling certain cookies may affect the availability or functionality of the Service. If advertising or marketing cookies are enabled in the future, BrightLake will provide additional disclosures and choices as required by applicable law.

3. How We Use Information

We only process the information we collect necessary to achieve the following business and operational purposes, governed by our legal basis for processing (such as contractual necessity, legitimate interests, or legal compliance):

  1. Provision of Services: To operate, maintain, and provide the core functionality of the Service, including account management, advertising and analytics workflows, integrations with customer-authorized platforms, reporting, and dashboard functionality.

  2. AI-Powered Analytics: To process Customer Data and user-provided inputs through AI-Powered Features in order to generate insights, recommendations, forecasts, conversational responses, and analytical outputs. BrightLake does not intentionally transmit Personal Data to Third-Party AI Providers for AI-Powered Features.

  3. Market and Competitive Intelligence: To provide app, keyword, creative, ranking, market, or competitive intelligence features using data obtained from third-party data providers.

  4. Evaluation, Testing, and Service Improvement. To evaluate and improve the Service, including through testing, quality assurance, benchmarking, model evaluation, error analysis, and product development. Where reasonably feasible, we use aggregated, anonymized, de-identified, filtered, summarized, or otherwise limited data for these purposes.

  5. Communication and Account Management: To send administrative notices, respond to account or support inquiries, and provide updates regarding service changes or security alerts , or operational matters.

  6. Security and Integrity: To monitor for fraud, abuse, security incidents, unauthorized access, and other misuse of the Service, and to protect the rights, safety, and security of BrightLake, our customers, and others.

  7. Legal Compliance: To comply with applicable laws, respond to lawful requests , enforce our Terms of Service, and establish, exercise, or defend legal claims.

4. Information Sharing and Disclosure

BrightLake does not sell personal information for monetary consideration. We share information only as described below and in accordance with applicable data protection and privacy laws. If BrightLake enables advertising or marketing technologies that involve disclosures constituting a “sale,” “sharing,” or targeted advertising under applicable U.S. state privacy laws, BrightLake will provide applicable notices and choices as required by law:

  1. Service Providers and Subcontractors: We share information with vendors and service providers that perform services on our behalf, such as cloud hosting, infrastructure, security, analytics, error monitoring, logging, and operational support. These providers are authorized to process information only as necessary to provide services to BrightLake and are subject to confidentiality and data protection obligations.

  2. Third-Party AI Providers: To enable AI-Powered Features, BrightLake may transmit Customer Data and user-provided inputs to Third-Party AI Providers, which may include providers such as DeepSeek, OpenAI, Google, Anthropic, or other providers identified in the applicable DPA, subprocessor list, or service documentation. BrightLake does not intentionally transmit Personal Data, including enterprise user contact information or login-related identifiers, to Third-Party AI Providers for AI-Powered Features.

  3. Third-Party Platforms and Data Providers: When you choose to connect third-party platforms or services to the Service, or when certain features use third-party market, app, keyword, creative, or competitive intelligence data providers, we may share or receive data with such third parties as necessary to provide the Service, at your direction or in accordance with the applicable third-party terms. BrightLake does not intentionally provide Personal Data to third-party competitive intelligence data providers.

  4. Professional Advisors and Legal Authorities: We may disclose information to legal, financial, audit, insurance, or other professional advisors, or to regulators, courts, law enforcement, or government authorities where required by law or reasonably necessary to establish, exercise, or defend legal rights.

  5. Corporate Transactions: In connection with a merger, acquisition, financing, reorganization, sale of assets, or similar transaction, information may be transferred as part of the transaction, subject to applicable confidentiality and data protection obligations.

5. AI Governance and Data Integrity

As an AI-powered platform, BrightLake maintains internal governance practices designed to support responsible use of artificial intelligence and appropriate handling of data processed in connection with AI-powered features of the Service. To the extent BrightLake uses aggregated, anonymized, or de-identified data for internal research, analytics, or service improvement purposes, you may request that your Customer Data not be used for such purposes by contacting us. Such requests will be honored where reasonably practicable and subject to applicable legal and contractual obligations.

5.1 Purpose-Limited Processing

BrightLake processes and transmits to third-party AI service providers only those categories of data that are reasonably necessary to generate the requested insights, analyses, or outputs. Such data may include limited campaign-related metadata and user-provided inputs submitted through AI-powered features. BrightLake does not intentionally transmit Personal Data, including enterprise user names, email addresses, phone numbers, login information, IP addresses, device identifiers, Cookie IDs, session IDs, or Apple Ads account identifiers, to Third-Party AI Providers for AI-Powered Features.

5.2 Input Filtering and Data Minimization

Before transmitting Customer Data to Third-Party AI Providers, BrightLake may apply filtering, summarization, rewriting, de-identification, or other data minimization techniques designed to reduce unnecessary or personal information in AI prompts and inputs.

5.3 Use of Third-Party AI Providers

BrightLake uses Third-Party AI Providers to enable AI-Powered Features. Such providers may vary depending on customer configuration, feature availability, routing, cost, performance, reliability, and failover requirements. Customer Data transmitted to Third-Party AI Providers is processed in accordance with the applicable provider terms, policies, configurations, and data handling practices.

5.4 Model Training and Evaluation

BrightLake does not use identifiable Personal Data to train or fine-tune AI models. BrightLake may use Customer Data, prompts, outputs, interaction records, and related metadata in aggregated, de-identified, filtered, summarized, rewritten, or otherwise limited forms for evaluation, testing, quality assurance, benchmarking, service improvement, and research purposes. Customers may request to opt out of model improvement or evaluation use where such opt-out is made available by BrightLake and is technically feasible.

5.5 Human Oversight

AI-powered features of the Service are intended to function as decision-support tools. AI-generated outputs, including insights, recommendations, forecasts, and analyses, are provided for informational and analytical purposes and should be reviewed and evaluated by authorized users before implementation.

5.6 Data Security

Data transmitted to third-party AI Providers is protected through administrative, technical, and organizational measures designed to safeguard data in transit and during processing, consistent with applicable security standards and BrightLake's data protection practices.

6. Data Security

BrightLake implements and maintains administrative, technical, and organizational measures designed to protect the information we process against unauthorized access, disclosure, alteration, or destruction. These measures may include access controls, encryption, logging and monitoring, security review, and other safeguards appropriate to the nature of the information and the Service.

While we use commercially reasonable safeguards, no method of transmission over the Internet or method of electronic storage is completely secure. Accordingly, we cannot guarantee absolute security. If we become aware of a security incident involving personal data, we will take steps to investigate and respond in accordance with applicable law and our contractual obligations.

7. Data Retention

BrightLake retains personal data only for as long as reasonably necessary to provide the Service, maintain user accounts, support security and auditability, comply with legal obligations, resolve disputes, enforce agreements, and maintain business records.

Customer Data that does not constitute personal data may be retained for extended periods as described below and in the applicable Terms of Service and DPA. Retention periods may vary depending on the nature of the data, the purposes for which it is processed, and applicable legal, regulatory, tax, accounting, security, operational, or contractual requirements.

In general, we apply the following retention principles:

  1. Account and Contact Information. Account identifiers, contact details, authentication-related information, and access records are retained for the duration of the customer relationship and for a limited period thereafter as reasonably necessary for account administration, security, compliance, and dispute resolution.

  2. Customer Business Data. Customer Data that does not constitute personal data, including campaign data, performance metrics, Apple Ads imported data, MMP-derived non-user-level data or files, imported advertising data, market or competitive intelligence queries and data, AI interaction history, tool usage records, diagnostic records, and related business or operational data, may be retained for extended periods to support service continuity, historical analytics, auditability, troubleshooting, evaluation, product improvement, security, legal, business, and operational purposes..

  3. AI Interaction Data. Prompts, outputs, tool calls, model metadata, token usage, and related interaction records may be retained to support service continuity, quality assurance, evaluation, troubleshooting, auditability, and service improvement.

  4. Usage Logs, Audit Logs, and Diagnostic Data. Technical logs, user activity logs, audit logs, diagnostic information, security logs, and error monitoring records may be retained for security, fraud prevention, troubleshooting, compliance, audit, and operational purposes.

  5. Personal Data. To the extent Customer Data includes Personal Data, BrightLake retains such Personal Data for as long as reasonably necessary for the purposes described in this Privacy Policy or as required or permitted by applicable law. BrightLake will respond to valid requests relating to Personal Data in accordance with applicable law, subject to legal, security, technical, and contractual limitations.

  6. Backups. Backup data is deleted or overwritten in accordance with BrightLake's standard backup rotation practices.

  7. Aggregated and Anonymized Data. BrightLake may retain aggregated or anonymized data that does not identify Customer, any Authorized User, or any individual for an indefinite period for analytics, research, benchmarking, service improvement, and statistical purposes.

  8. Commercial and Contract Records. Where applicable, BrightLake may retain order forms, invoices, billing contacts, and related commercial records for periods required by applicable tax, accounting, financial reporting, and legal requirements.

8. Your Choices and Control

You may have certain choices and controls regarding how information is provided to and processed through the Service, as described below:

  1. Third-Party Integrations: BrightLake's access to data from third-party platforms or services (such as Apple Ads or MMPs) is contingent upon the authorizations you grant. You may manage or revoke BrightLake's access to such data at any time by:
  • Disconnecting the applicable third-party account through the integration settings within the Service; or

  • Modifying the authorization settings or API permissions directly within the third-party platform.

  • Note: Revoking access may limit or disable certain AI-powered features that rely on real-time data from these integrations.

  1. AI Feature Inputs: You control the Customer Content and inputs submitted when using AI-powered features of the Service. You may limit the scope of data processed by third-party AI service providers by choosing not to include sensitive, confidential, or proprietary information in your AI prompts or inputs.

  2. Communication Preferences: You may opt out of receiving promotional communications from BrightLake by following the unsubscribe instructions included in such communications. You will continue to receive transactional, service-related, or administrative messages that are necessary for the operation of the Service.

9. Your Rights under Applicable Law

Depending on your location and applicable law, you may have certain rights with respect to your personal data, which may include the right to:

  1. Access: Request access to your personal data and obtain a copy of the specific pieces of information we process about you;

  2. Correction: Request the rectification of inaccurate or incomplete personal data held by us;

  3. Deletion: Request the erasure of your personal data, subject to applicable legal, tax, or contractual limitations and retention requirements;

  4. Object or Restrict: Object to or request the restriction of certain processing of your personal data, including processing based on our legitimate interests or for direct marketing purposes;

  5. Data Portability: Request the transfer of your personal data to another party in a technically feasible, structured, and machine-readable format; and

  6. Withdraw Consent: Where our processing is based on your consent, you may withdraw such consent at any time without affecting the lawfulness of processing carried out prior to the withdrawal.

To exercise these rights, you may submit a request through your BrightLake account settings or by contacting us via the details provided in the "Contact Us" section below. We may require verification of your identity before responding to your request and reserve the right to decline or limit requests as permitted or required by applicable law. These rights apply to personal data and do not apply to Customer Data that does not constitute personal data, including non-personal business, advertising, market intelligence, aggregated, anonymized, or de-identified data.

10. International Data Transfers

BrightLake is headquartered in the United States and may use service providers located in the United States and other jurisdictions. As a result, personal data may be transferred to, stored in, or processed in jurisdictions outside your country of residence, including the United States, where data protection laws may differ from those in your jurisdiction.

Where required by applicable data protection laws, BrightLake relies on appropriate safeguards for international transfers of personal data, including Standard Contractual Clauses, the UK Addendum, adequacy decisions, or other lawful transfer mechanisms. BrightLake also implements technical and organizational measures designed to protect personal data transferred internationally.

BrightLake does not intentionally transmit Personal Data, including enterprise user contact information, login-related identifiers, IP addresses, device identifiers, Cookie IDs, session IDs, or Apple Ads account identifiers, to Third-Party AI Providers or third-party competitive intelligence data providers for AI-Powered Features or market intelligence features.

Customer Data that does not constitute Personal Data may be processed or transferred as necessary to provide the Service, including through Third-Party AI Providers, Third-Party Platforms, and third-party data providers, subject to the Agreement and applicable confidentiality, security, and contractual obligations.

11. Regional and Statutory Disclosures

This section provides additional disclosures that may apply depending on your location and applicable law. Because BrightLake provides a business-to-business service, many of the personal data we process relates to business representatives, account administrators, and authorized users acting on behalf of an organization.

11.1 U.S. State Privacy Disclosures

Depending on your state of residence and applicable law, you may have certain rights with respect to your personal data, including rights to request access, correction, deletion, portability, or to opt out of certain processing activities.

BrightLake does not sell personal data for monetary consideration and does not share personal data for cross-context behavioral advertising. In the current version of the Service, BrightLake does not use personal data for targeted advertising. If BrightLake enables advertising or marketing technologies that involve targeted advertising, sale, or sharing under applicable U.S. state privacy laws, BrightLake will update this Privacy Policy and provide applicable notices, choices, or opt-out mechanisms as required by law.

Where BrightLake processes personal data on behalf of a business customer, BrightLake generally acts as a processor or service provider, and the customer is responsible for providing any required notices and responding to individual rights requests, unless otherwise required by applicable law.

11.2 California Privacy Disclosures

This section applies to California residents to the extent California privacy laws, including the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), apply to BrightLake's processing of personal information.

BrightLake provides a business-to-business service. The personal information we collect generally relates to business representatives, account administrators, and authorized users accessing the Service on behalf of an organization. In the preceding twelve (12) months, we may have collected limited categories of personal information, such as business contact information, account and authentication information, device and browser information, IP addresses, Cookie IDs, session identifiers, usage logs, security logs, and other information reasonably necessary to operate, secure, support, and improve the Service.

We collect and use such personal information for the purposes described in this Privacy Policy, including to provide the Service, manage accounts, authenticate users, maintain security, communicate with customers, comply with legal obligations, and improve the Service.

BrightLake does not sell personal information for monetary consideration and does not share personal information for cross-context behavioral advertising. The Service is not designed to collect or process sensitive personal information, and you should not submit sensitive personal information to the Service unless expressly authorized by BrightLake in writing.

To the extent required by applicable California law, California residents may have the right to request access to, correction of, or deletion of personal information; to request information about the categories of personal information we collect, use, and disclose; to opt out of sale or sharing of personal information; and to not be discriminated against for exercising privacy rights.

Because BrightLake primarily provides a business-to-business service, certain personal information may be processed on behalf of our business customers. Where we process personal information on behalf of a customer, we may refer your request to that customer or assist the customer in responding to your request, as required by applicable law.

11.3 European Residents (GDPR/UK GDPR)

For individuals in the EEA and UK, BrightLake processes personal data as a "Processor" or "Service Provider" on behalf of our business clients. Where BrightLake processes personal data for its own independent purposes, BrightLake acts as a controller with respect to such processing. Where required by applicable law, we process personal data based on the following legal grounds:

  1. Performance of a Contract: To provide the Service in accordance with our Terms of Service and specific client instructions.

  2. Legitimate Interests: To improve the Service, maintain security, prevent fraud, auditability, support AI-Powered Features, and communicate with business customers, provided such interests do not override your fundamental rights.

  3. Compliance with Legal Obligations: applicable legal, regulatory, tax, accounting, security, or compliance obligations; and

  4. Consent: Where you have provided express consent for a specific processing activity.

  5. Right to Complain: You have the right to lodge a complaint regarding our data practices with your local data protection authority.

12. Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately. If we learn that we have collected personal information through the Service from a child without the consent of the child's parent or guardian as required by law, we will comply with applicable legal requirements to delete the information. No one under the age of 13 is authorized to use our Service or share any information with us, including personal information. Under no circumstances may anyone under age 13 use the Service. Parents or legal guardians of children under 13 cannot agree to these terms on their behalf.

13. Changes to This Privacy Policy

We reserve the right to modify this Privacy Policy from time to time, we will notify you by updating the date of this Privacy Policy and posting it on the Service or other appropriate means. Depending on the change that we make to this policy, we might notify you of the change or ask for your consent to it. Any modifications to this Privacy Policy will be effective upon our posting the modified version (or as otherwise indicated at the time of posting). Your continued use of the Service after changes become effective constitutes acceptance of the revised Privacy Policy.

14. Contact Us

If you have questions or complaints about this Privacy Policy or our data practices, please contact us:

BrightLake International Inc.
One Dock Street, Suite 402,

Stamford, CT 06902
United States

Email: service@brightlake.ai