Privacy Policy
How Optimus Pass handles scans, reports, account data, agency data, and optional measurement.
By Grady Coleman (Founder) · Last updated:
What should you know first? Key takeaways
The policy below covers two products with different data footprints. According to the product design, the ad-copy scanner reads text you paste and the visibility audit fetches one public URL you submit, and both keep only what the account needs to show reports again later. The chart summarizes what each product touches.
- A verified account is required for every scan; signed-in scans save reports to your account.
- Optimus Pass never collects ad-account credentials and never sells customer data to advertisers.
- Billing is processed by Stripe; Optimus Pass does not store payment details.
- Measurement pixels load only after you choose to allow measurement, and the choice is reversible.
What is the privacy commitment?
Optimus Pass is designed to minimize data exposure. Different features have different privacy characteristics, described below.
Do I need an account to run a scan?
Yes. A verified account is required for every scan, and your email must be confirmed first. This applies to both products: the Visibility audit on a public page and the Ad Compliance review of submitted ad copy. Free accounts include 3 lifetime checks with no credit card required. Scans are processed through our secure API and stored as reports so you can revisit them from your account. Free access is protected with account quotas and privacy-preserving abuse controls.
What happens in an authenticated scan?
When you are signed in and scan ad copy, we store the scan results — including the ad text you scanned, the platform and ad field selected, detected violations, semantic flags, findings, risk scores, rewrite suggestions, and the number of detectors used — so you can view and revisit your full compliance reports from your account. We also store a content hash (a one-way fingerprint of your text) and scan metadata for abuse monitoring. You can permanently delete your account and its associated reports from Account Settings, or contact us for assistance.
How are URL audits handled?
Landing page and site audits fetch the URL you provide through our secure backend service. The fetched content is analyzed and discarded — not stored or used for training.
What data does Optimus Pass collect?
When you create an account, we collect:
- Email address (for account identification)
- Billing information (processed by Stripe; we do not store payment details)
- Plan type and subscription status
- Optional display name and company name entered in Account Settings
- Scan history and reports (the ad text you scanned, content hash, findings, violations, semantic flags, risk scores, rewrite suggestions, platform, ad field, timestamp)
What data does Optimus Pass never collect?
- Ad-account or advertising-platform credentials
- We do not sell customer data, and advertisers do not receive access to your private scans, ad copy, or report content.
How is agency data handled?
The Agency plan includes 250 checks per month, and agency users may store their own workflow data to run their business, such as client names, client domains, and project or workflow information. This data belongs to the agency account that entered it and is governed by this policy like any other account data. Agency share links expose only the limited public report view — no account data and no detector internals — expire on the stated date, and stop working immediately when revoked.
Which service providers process data?
According to our infrastructure design, operating Optimus Pass and understanding how it is used relies on a small number of service providers. This can include hosting and infrastructure, billing and payment processing (Stripe), and — when configured — advertising measurement partners.
When advertising measurement is enabled, we may send limited technical and attribution data to those partners so we can measure conversions and understand how campaigns perform. This is restricted to event and conversion metadata such as the event type, the page where it occurred, a conversion reference, and any value/currency relevant to the event, plus an anonymous visitor identifier.
The measurement payloads exclude scanner and ad copy, compliance findings, scanned page content, and unnecessary raw personal data, so none of those are sent in these measurement payloads. According to the integration design, partners receive only the limited signals described above and cannot read your scans or your ad copy.
Analytics and measurement providers are only used when their integration is enabled for launch and are configured to run with the smallest useful set of event data.
Optional Reddit and OpenAI browser measurement pixels load only after you choose “Allow measurement.” If you decline, those browser pixels are not initialized. You can clear the saved preference in your browser storage to choose again.
How is site traffic measured?
We use Vercel Analytics to understand site traffic. This collects anonymous, aggregated metrics without cookies or personal identifiers. No ad copy or compliance data is included.
How do I ask about this policy?
Questions about this policy? Contact us at privacy@optimuspass.com. Last updated: .
What do people ask about privacy?
Does Optimus Pass see my ad account?+
No. According to the plan terms, Optimus Pass never collects ad-account or advertising-platform credentials. You paste copy or submit a URL directly, and the review runs on exactly what you submitted. Compared with tools that require account connections, there is nothing to disconnect and no token that can leak.
How long are my scans kept?+
Scans save reports to your account so you can revisit them. A verified account is required for every scan, on both products. You can permanently delete your account and its associated reports from Account Settings at any time, and deletion removes the stored ad text, findings, and scan metadata together.
Is my data used to train models?+
No. According to this policy, fetched URL content is analyzed and discarded, never stored or used for training. Scanner inputs are used only to produce your report and to operate abuse controls. Partners receive only limited event metadata and cannot read your scans or ad copy.
What happens if I decline measurement?+
According to this policy, optional Reddit and OpenAI browser measurement pixels load only after you choose to allow measurement. If you decline, those pixels are never initialized. You can clear the saved preference in your browser storage to choose again, and declining changes nothing about scans, reports, or account access.
How does billing handle my payment details?+
According to this policy, billing information is processed by Stripe and Optimus Pass does not store payment details. The account keeps only the plan type and subscription status needed to enforce check allowances across the Free, Professional, and Agency tiers.
What data does the visibility audit touch?+
According to this policy, a visibility audit fetches the single public URL you submit through the secure backend, analyzes the fetched content, and discards it without storing it. The saved report contains the findings and scores, not the page content itself. Compared with the ad scanner, which stores the exact text you pasted so you can revisit it, the audit keeps less source material by design.
Who can see my agency client data?+
According to this policy, agency workflow data belongs to the agency account that entered it, and only that account can see client names, domains, and project information. Share links expose only the limited public report view with no account data and no detector internals, and they stop working immediately when revoked or when the stated expiry date passes.
How do I export or review what you hold about me?+
According to this policy, authenticated scans save reports to your account precisely so you can review everything held about your usage in one place. Account Settings shows the plan type, subscription status, and saved reports together, and permanent deletion removes the stored ad text, findings, and scan metadata at the same time.
How does data handling compare across account types?
| Aspect | Free account | Paid account |
|---|---|---|
| Scan storage | Saved to account | Saved to account |
| Credit card | Never required | Only via Stripe on paid plans |
| Deletion | Full delete in Account Settings | Full delete in Account Settings |
Which sources support these practices?
Each reference below is public documentation or research, cited so the practices above are verifiable rather than asserted. According to the published guidance, enforcement and platform behavior remain platform decisions. A reference is not an endorsement of Optimus Pass.