Privacy Policy
Version of March 9, 2026 — superseded
This version was replaced on September 26, 2026 by the current privacy policy.
The text below is reproduced as it was published on www.apogee.ad until September 26, 2026. The application (app.apogee.ad/privacy) showed a French version of this policy that differed on some points; it is reproduced on the French page. The Terms of Service of the same period are archived here: Terms of Service, version of March 9, 2026.
Although dated March 9, 2026, these texts had been amended on September 23, 2026, on the website and in the application: product tips and offers emailed to account holders, previously listed as "Marketing communications (with consent)" and "Consent: marketing communications", were moved to the legitimate interest basis, and ActiveCampaign was replaced by Resend and Inngest in the list of providers. The application's text had also been expanded on May 4, 2026 (PostHog and analytics cookies).
1. Data Controller
APOGEE SAS
32 Rue de Paris, 92100 Boulogne-Billancourt, France
DPO contact: hello@apogee.ad
2. Data Collected
- Identification data: name, first name, email (via Meta OAuth)
- Connection data: IP address, browser, approximate geolocation
- Meta Ads data: ad accounts, campaigns, creatives, performance metrics (accessed via Meta tokens authorized by the user)
- Payment data: managed by Stripe (Apogee does not store card numbers)
- Usage data: pages visited, actions performed, files uploaded
3. Processing Purposes
- Providing and improving the service
- Account and billing management
- Customer support
- Usage analysis and product improvement
- Product tips and occasional offers by email to account holders, based on our legitimate interest (existing customer relationship). Every email has a one-click unsubscribe link, and you can object at any time by writing to hello@apogee.ad.
4. Legal Bases
- Contract performance: service delivery
- Legitimate interest: service improvement, security, product tips and occasional offers by email to account holders (existing customer relationship)
- Consent: resource requests and related emails for people without an account (resource forms)
5. Hosting and Subprocessors
Data is hosted in Europe:
- Backend: Railway (europe-west4, Netherlands)
- Frontend: Vercel (global CDN, EU data)
- Database: Supabase (EU)
- Payments: Stripe
- Email delivery: Resend
- Scheduled jobs: Inngest
- AI: Anthropic (Claude), Google (Gemini)
- Notifications: Discord (webhooks)
6. Data Retention
- Account data: retained for the duration of the subscription + 3 years after deletion
- Connection data: 12 months
- Billing data: 10 years (legal obligation)
- Uploaded files: deleted 30 days after account deletion
7. User Rights
In accordance with GDPR, you have the following rights: access, rectification, deletion, portability, restriction, objection. Contact hello@apogee.ad.
Response time: 30 days.
Complaint to the CNIL: www.cnil.fr
8. Cookies
Apogee uses essential cookies for the operation of the service (authentication, preferences). No third-party advertising cookies.
9. Meta Tokens
The user authorizes Apogee to access their Meta Ads accounts via OAuth. Tokens are encrypted and stored in the database. The user can revoke access at any time from their Meta settings.
10. Security
Data is protected by: HTTPS encryption, encrypted OAuth tokens, per-user data isolation, access logging.
11. Transfers Outside the EU
Some subprocessors (Anthropic, Vercel CDN) may process data in the United States. These transfers are governed by the European Commission's Standard Contractual Clauses (SCCs).
12. Amendments
This policy may be modified. Users will be notified by email.