MyGoodLens Privacy Policy
Last updated: July 22, 2026
This privacy policy describes how MyGoodLens, a SaaS platform for competitive advertising and email monitoring, collects, uses, protects, and shares your personal data, in compliance with the General Data Protection Regulation (GDPR).
1. Data collected
1.1 Data collected via Google OAuth
When you choose to sign in via Google, we only collect the following information:
- Email address: to create and manage your MyGoodLens account.
- First and last name: to personalize your experience.
- Profile picture (optional): to display your avatar in the interface.
Important:
We NEVER collect your Google password. Authentication is handled directly by Google via secure tokens (OAuth 2.0).
We do NOT access:
- Your Google contacts.
- Your Gmail inbox or messages.
- Your Drive documents.
- Your location data.
- Any other information not mentioned above.
You can revoke MyGoodLens's access to your Google account at any time from your Google account security settings.
1.2 Other data collected
We also collect the following data to provide and improve our services:
- Account information: first name, last name, email address, company.
- Tracked brands: the list of brands you add to your monitoring workspace.
- Public ads: ad content retrieved via the Meta Ads Library (public source).
- Newsletter emails: competitor emails that you or your colleagues forward to a dedicated import address.
- Usage data: pages visited, frequency of use, technical logs.
2. Use of data
Personal data is used for the following purposes:
- Provide, maintain, and improve our monitoring platform.
- Centralize Meta ads and competitor emails from tracked brands.
- Generate AI analyses (brand descriptions, target audiences, competitors).
- Provide responsive customer support.
- Communicate about product updates, with your consent.
3. Legal basis for processing
We process your data based on the following grounds:
- Contractual performance: to provide subscribed services.
- Legitimate interest: for improving our platform and analyzing public advertising content.
- Consent: for marketing communications.
- Legal obligation: if we are required to respond to requests from competent authorities.
4. Data retention period
Your account data is retained as long as your account is active, then deleted or anonymized within 12 months after account deletion.
Public ads and emails collected as part of monitoring may be kept for competitive history purposes (up to 24 months), even after deactivation, without re-identifying you.
5. Security measures
We apply robust technical and organizational measures:
- Encryption of data in transit (SSL/TLS) and at rest.
- Secure hosting on certified infrastructure (Supabase, Cloudflare).
- Restricted data access by internal roles (Postgres RLS).
- Regularly audited access logs.
6. Data sharing
We never sell your data. The only cases of sharing are as follows:
- Supabase — database hosting and authentication.
- Cloudflare — edge infrastructure and content delivery.
- Apify — retrieval of public advertising data from the Meta Ads Library.
- Anthropic (Claude) & Lovable AI Gateway — AI analysis of brand content.
- Exa — web search for brand profile enrichment.
- Legal obligations (e.g., court order).
7. Automated decisions
We do not use your data for automated decisions with legal effect or significant impact without human intervention. The AI analyses produced (descriptions, audiences, competitors) are decision aids, without automation of legal consequences.
8. Your rights
Revoking Google access
If you signed in via Google, you can revoke MyGoodLens's access at any time:
- Google: myaccount.google.com/permissions
Other GDPR rights
In accordance with GDPR, you may at any time:
- Access your personal data.
- Request rectification or deletion.
- Withdraw your consent.
- Object to processing.
- Request data portability.
- Restrict processing in certain cases.
You can exercise these rights by contacting us at contact@mygoodlens.com. A response will be provided within 30 days.
9. Data transfers outside the EU
Some of our subprocessors (Anthropic, Cloudflare, Apify) may process data outside the European Union. In such cases, we ensure that standard contractual clauses or other appropriate safeguards are put in place.
10. Policy changes
We reserve the right to modify this policy at any time. In the event of a major change, we will inform you by email or via our interface. Your continued use of our service constitutes acceptance of the updated version.