Trust Center

Privacy Policy

Effective Date: July 2, 2026

1. Introduction

This Privacy Policy explains how m18t (accessible at m18t.com and its subdomains) collects, uses, stores, shares, and protects your personal information when you use our brand-operations platform and related services.

m18t is an operations workspace for people building and running brands — in one tool you plan a product, write and publish its content, generate brand-aware imagery, and keep multiple brands separate. This Policy applies to every User of the Platform, and to visitors of our marketing site.

By creating an account or using our Services, you acknowledge that you have read and understood this Privacy Policy.

2. Data Controller

m18t Amman, Hashemite Kingdom of Jordan

m18t is currently a founder-operated service in beta. Support and all privacy, data-rights, and legal inquiries are handled directly through the single address above.

3. Information We Collect

3.1. Information You Provide Directly

Category Data Fields Purpose
Account Information Email address, name, password (stored only as a salted hash) Account creation and authentication
Brand Profiles Brand name, website URL, description, logo, colors/palette, primary locale, social handles Brand identity, and injection into AI prompts and image generation
Workspace Content Content pieces (blog/news/web/social/video), product-development specs, artifacts, whiteboards, events, email drafts, tags, prompts Delivering the workspace features you use
Uploaded Assets Images and files you upload to your asset library, plus alt text and metadata Media management and publishing
AI Inputs & Outputs Canvas image-generation chats, prompts you run, and their generated results Powering AI features you invoke
Connected-Account Credentials API keys and access tokens for the third-party services you connect (your AI providers, Meta, your CMS, storage, analytics) Enabling BYOK integrations — stored encrypted (see §11)
News Sources RSS/source URLs you add and the articles fetched from them Running the news pipeline you configure
Newsletter Subscription Email address, consent Our build-in-public updates (opt-in)
Support Communication Anything you send us by email Responding to you

3.2. Information Collected Automatically

Category Data Fields Purpose
Usage Data Pages visited, features used, actions taken, session activity Product analytics and improvement
Device Information Browser type, operating system, screen size, device type Compatibility and optimization
Log Data IP addresses, access times, error logs Security monitoring and debugging
AI Usage Metrics Per-call model, prompt reference, and an estimated token count Rough usage accounting (not billing)
Authentication Events Login times, session identifiers, logout events Security and access auditing

3.3. Information from Connected Third Parties

When you connect your own accounts (BYOK), we process data returned by those services on your behalf:

Source Data Purpose
Your AI Providers (OpenAI, Google Gemini, Anthropic, etc.) AI-generated responses to the prompts you submit Delivering AI features under your key
Meta (Facebook / Instagram) Page/account tokens and post engagement counts (likes, comments, shares) Publishing to, and syncing metrics from, your own pages
Your Headless CMS (e.g. Strapi) Publish confirmations and record identifiers Pushing your content to your own CMS

4. How We Use Your Information

4.1. Service Delivery

Providing, operating, and maintaining the Platform; storing and processing your Content; routing AI calls to the provider whose key you supply; publishing your content to the channels you connect; managing your account and subscription.

4.2. Service Improvement

Analyzing aggregate usage patterns, diagnosing bugs, and monitoring performance.

4.3. Communications

Transactional emails (account verification, security notices, system notifications) and — only with your explicit opt-in — our build-in-public newsletter.

4.4. Security and Fraud Prevention

Monitoring for unauthorized access, rate-limiting abuse, enforcing tenant and brand isolation, and maintaining audit logs.

5. Legal Basis for Processing

Legal Basis Applies To
Consent Account creation, newsletter, non-essential cookies
Contractual Necessity Service delivery — data storage, processing, integrations
Legitimate Interest Service improvement, security, aggregate analytics
Legal Obligation Compliance with applicable law and record-keeping

6. Data Sharing and Sub-Processors

We do not sell, rent, or trade your personal data. We share data only with the infrastructure sub-processors below, strictly to run the Platform:

Sub-Processor Purpose Region
Google Cloud Platform Compute, hosting, and the servers where your tenant database and files live Middle East (me-central1)
Google Cloud Storage Encrypted off-site backups Middle East / Global
Cloudflare DNS, CDN, and DDoS protection in front of the origin Global edge
PostHog Product analytics and error monitoring United States (via our first-party proxy)
Google Analytics / Google Ads Marketing-site analytics and campaign measurement (opt-in only) United States
Google Workspace Transactional email delivery United States / Europe

AI and other connected providers are not our sub-processors. Because m18t is bring-your-own-key (BYOK), calls to AI providers, Meta, and your CMS run on your accounts and credentials. Those providers process that data as your processors, under the agreement between you and them — not under this Policy. See §7.

7. AI and Your Data — BYOK Disclosure

7.1. Bring Your Own Key. m18t does not provide AI tokens and operates no AI models of its own. Every AI feature (content generation, SEO assistance, Canvas image generation, news drafting) runs on an API key you supply and connect. We route the request to the provider you chose; we do not resell or mark up AI usage.

7.2. Your provider's terms govern AI data. When you use an AI feature, your input is transmitted to your chosen provider under your account. That provider's data-retention and training policies — not ours — govern how it handles that data. We encourage you to review them, since it is your account.

7.3. We do not train on your data. m18t does not use your Content, assets, or AI inputs and outputs to train any machine-learning model.

7.4. What we store. We store the AI inputs and outputs you generate inside your workspace (e.g. Canvas chats and generated images) so the features work, plus a lightweight usage log (model, prompt reference, estimated tokens, timestamp).

7.5. What we do NOT do. We do not sell your data, do not use your data for advertising, and do not share your identifiable workspace data with any provider for their own purposes.

8. Cross-Border Data Transfers

Your data may be processed outside your country of residence. Our primary hosting is on Google Cloud Platform in the Middle East region (me-central1). Analytics (PostHog, Google) and email delivery are processed in the United States and/or Europe. AI processing occurs wherever your chosen provider operates, under your own account. We rely on adequacy decisions, standard contractual clauses, and Google Cloud's security certifications (SOC 2, ISO 27001) where applicable.

9. Data Retention

Data Type Retention Period
Account & Workspace Data For as long as your account is active
After Cancellation / Deletion Retained at least 30 days for re-activation and export, then scheduled for permanent deletion of your tenant database and storage bucket
Encrypted Backups Rolling window of approximately 30 days
System & Error Logs Approximately 90-day rolling window
Product Analytics Per our analytics provider's retention settings

10. Your Rights

Right Description
Right of Access Request a copy of your personal data.
Right to Rectification Request correction of inaccurate data.
Right to Erasure Request deletion, subject to any legal retention requirement.
Right to Data Portability Export your workspace data in a machine-readable format.
Right to Restrict Processing Restrict how we process your data.
Right to Object Object to processing based on legitimate interest.
Right to Withdraw Consent Withdraw consent (e.g. newsletter, non-essential cookies) at any time.

To exercise any of these rights, contact us at [email protected]. We will respond within thirty (30) days.

11. Data Security

11.1. Technical Measures

  • Encryption in Transit: HTTPS/TLS for all traffic, terminated behind Cloudflare.
  • Encryption at Rest: Connected-account credentials are encrypted with AES-256-GCM before storage; infrastructure-level encryption covers the underlying disks.
  • Physical Tenant Isolation: Each account's operational data lives in its own dedicated database file and its own object-storage bucket. Cross-account access is architecturally prevented, not just filtered.
  • Brand Isolation: Within your account, every entity is scoped to a brand so brands stay cleanly separated.
  • Secret Handling: Your connected keys are decrypted only at runtime to make the call you asked for; they are never logged and never returned to the browser.

11.2. Organizational Measures

  • Limited, founder-level access to production data.
  • Google Cloud infrastructure (SOC 2, ISO 27001).
  • Continuous off-site backup replication of tenant databases.

No method of transmission or storage is perfectly secure; we work to protect your data but cannot guarantee absolute security.

12. Children's Privacy

The Services are intended for professional use and are not directed at individuals under eighteen (18). We do not knowingly collect data from children.

13. Cookies and Tracking Technologies

We use cookies and similar technologies. For details, see our Cookie Policy.

14. Third-Party Links

The Platform and marketing site may link to third-party services (including the sources you add to the news pipeline). We are not responsible for their privacy practices.

15. Changes to This Privacy Policy

We may update this Policy as the Platform evolves. Material changes will take effect no earlier than thirty (30) days after notification via email and/or an in-platform notice, and will be noted on our build-in-public blog.

16. Contact and Complaints

We will acknowledge your inquiry within five (5) business days and provide a substantive response within thirty (30) days.

17. Jurisdiction-Specific Provisions

Jordan

These data-protection practices align with applicable Jordanian law, the home jurisdiction of m18t.

European Economic Area & United Kingdom (GDPR / UK GDPR)

If you are in the EEA or UK, you have the full rights described in §10, including the right to lodge a complaint with your local supervisory authority.

Other Jurisdictions

Your local law may grant you additional rights. Contact us and we will honor any right applicable to you to the extent required by law.


m18t | Amman, Jordan