Privacy Policy
Effective date: September 7, 2026
1. Introduction
Welcome to NotFair ("we," "our," or "us"). We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our web application NotFair.
2. Information We Collect
We may collect the following types of information when you use our Service:
- Personal Information: Includes your name, email address, workspace membership, and the account or profile identifiers a connected provider returns when you sign in or authorize NotFair.
- Google OAuth Data: When you authorize NotFair with Google, we request
openid,email, andprofileto identify your Google account, plus the product scope for each Google service you choose to connect:https://www.googleapis.com/auth/adwordsfor Google Ads,https://www.googleapis.com/auth/analytics.readonlyandhttps://www.googleapis.com/auth/analytics.editfor Google Analytics, andhttps://www.googleapis.com/auth/webmastersfor Google Search Console. Each connection is authorized separately — we only request a product's scope when you connect that product. - Stored Connection Data: We store the access or refresh credentials needed to maintain each connection, the scopes you granted, selected account or property identifiers, account names and basic account metadata, and session or connection metadata. Depending on the provider, this can include advertising account IDs, business or company IDs, HighLevel location IDs, a provider username, currency, and timezone. Provider credentials are kept in restricted server-side storage and are never returned to ChatGPT, Claude, or another MCP client.
- Google Ads Data: We access Google Ads account data such as campaigns, ad groups, keywords, search terms, recommendations, budgets, and performance metrics solely to provide campaign analysis, reporting, and changes that you request or approve through NotFair.
- Google Analytics Data: If you connect Google Analytics, we use
analytics.readonlyto list the GA4 properties your Google account can access and to run the reports you request (Data API reports, realtime reports, and dimension/metric metadata), andanalytics.editsolely to perform the Google Analytics configuration changes you explicitly request through NotFair — creating or archiving custom dimensions and creating or removing key events. We do not useanalytics.editfor anything else, and we do not modify your Analytics configuration without your instruction. - Google Search Console Data: If you connect Google Search Console, we access your verified properties, search analytics (queries, clicks, impressions, CTR, position), URL inspection results, and sitemaps to answer the questions you ask, and submit or remove sitemaps only when you request it.
- Meta Ads Data: If you connect Meta Ads, we access the advertising accounts and Pages you authorize, including campaigns, ad sets, ads, creatives, images, videos, audiences, conversion events, delivery status, budgets, and performance metrics. We use write access only for the advertising actions you request through NotFair or a connected MCP client.
- LinkedIn Ads Data: If you connect LinkedIn Ads, we access authorized advertising accounts, campaign groups, campaigns, creatives, analytics, conversions, lead-generation forms, and lead responses. Lead responses can contain personal information submitted by a lead and are returned only when you request that data through an authorized account.
- X Ads Data: If you connect X Ads, we access authorized advertising accounts, campaigns, line items, targeting criteria, tailored audiences, media, conversion data, and performance metrics. We use write access only for the advertising actions you request.
- GoHighLevel Data: If you connect GoHighLevel, we may access the companies or locations you authorize and their contacts, conversations and messages, opportunities, calendars and events, forms, surveys, users, workflows, invoices, orders, transactions, subscriptions, products, media, and custom objects. NotFair requests write scopes for contacts, opportunities, calendar events, and tags; those records are changed only when you request it.
- WordPress Data: When you connect a website, we store its connection information and encrypted integration credential. At your request, NotFair may read or change its content, media, settings, users, and supported integration records, including store orders and customers. Requested results are returned to your authorized AI client. MCP and SEO access can be removed independently. We do not sell this data or use it to train generalized AI models.
- MCP and AI Client Data: When you connect NotFair to ChatGPT, Claude, or another MCP client, we receive the tool name and arguments the client sends, use them to perform the requested operation, and return the resulting provider data to that client. NotFair does not send provider access or refresh credentials to the client.
- Usage Data: Information about how you access and use the Service, such as your IP address, browser type, and operating system.
- Attribution and Product-Use Data: Information about how you reached NotFair, such as campaign parameters and a Meta click identifier, and limited first-party milestones such as signup, a completed subscription payment, and your first NotFair MCP write-tool request.
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the NotFair service.
- Authenticate you and connect the advertising, analytics, Search Console, CRM, and website accounts or properties you choose.
- Read data from connected providers and perform the actions you explicitly request through NotFair or an authorized MCP client.
- Generate reports, recommendations, and historical tracking for your connected accounts and properties.
- Monitor and analyze usage and trends to improve user experience.
- Measure and improve our own advertising using limited first-party signup, payment, and product-use milestones.
- Communicate with you about updates, security alerts, and support messages.
4. Data Retention and Deletion
We retain provider connection credentials and selected account metadata while the connection remains active so the service can operate without requiring you to re-authorize for every request. NotFair-issued session and connector access credentials expire according to the connection type and can be refreshed while the underlying authorization remains active. We retain operation and security records as needed to provide the service, investigate abuse, comply with law, and maintain account integrity.
Tool-call argument payloads are removed from operation records after 100 days, and read-operation records are deleted after 365 days. Write-operation receipts are retained as account change history while the workspace is active and until an applicable deletion request is completed, subject to limited security, legal, or compliance retention. Expired OAuth authorization codes are deleted after a seven-day grace period, and unused dynamic OAuth client registrations are eligible for deletion after 60 days.
You can disconnect a provider from NotFair to remove the active provider connection. Disconnecting NotFair in ChatGPT, Claude, or another MCP client stops that client from using the connector, and you can also revoke provider access in the provider's own security or app settings. To request deletion of stored connection or account data, contact us at tong@notfair.co. We may retain limited records when required for security, legal, or compliance purposes.
5. Data Sharing and Disclosure
We do not sell your personal information. We may share your information only in the following circumstances:
- With service providers who assist us in operating our Service (e.g., hosting, analytics).
- With the advertising, analytics, Search Console, CRM, or website provider you connect, as needed to make the API requests you direct.
- With Claude or another MCP client you authorize, when NotFair returns the requested tool result to that client. Your use of that client is also governed by its own privacy terms.
- With Meta through the Meta Conversions API to measure and improve our own advertising. For eligible Meta-attributed users, we may send a signup, a completed positive subscription payment, or the first NotFair MCP write-tool request together with a hashed email address and hashed NotFair user identifier, plus a Meta click identifier when available. The write-request milestone does not include the tool name, connected ads platform, account, campaign, request contents, or provider result.
- To comply with legal obligations or protect our rights.
- With your consent or at your direction.
6. Connected Provider Data
NotFair's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
We do not use Google user data for advertising, we do not sell Google user data, and we do not use it to train generalized AI or machine-learning models. We only use Google user data to provide or improve the user-facing features you connect it for: Google Ads account analysis and management, Google Analytics reporting and the configuration changes you request, and Google Search Console reporting and sitemap management. Humans do not read this data except with your explicit permission (for example, a support request), for security purposes, or where required by law.
We apply the same purpose limitation to data received from Meta, LinkedIn, X, GoHighLevel, and WordPress: we use it to provide the connected features you request, protect and operate the service, and meet legal obligations. We do not sell connected-provider data or use it to train generalized AI or machine-learning models. Each provider's own terms and privacy policy also apply to its platform and APIs.
We do not send Google user data, connected-platform data, tool arguments, account or campaign details, or provider operation results to Meta. The first MCP write-tool request shared with Meta records only that you asked NotFair to perform a first-party product action; provider-confirmed successful writes remain in NotFair's internal measurement.
7. Security
We implement appropriate technical and organizational measures to protect your data. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page.
9. Contact Us
If you have any questions about this Privacy Policy, please contact us at: tong@notfair.co