Privacy Policy

Last updated 14 September 2026

This policy explains what data Acumin collects, why, and how we protect it. We keep it minimal and honest: we use data to produce your reports and run the service, and we never sell it. Acumin is a product of Acumin Intelligence (Pty) Ltd, a company registered in South Africa (registration number 2026/495251/07).

1. Who we are

Acumin is operated by Acumin Intelligence (Pty) Ltd, a company registered in South Africa (registration number 2026/495251/07). Our registered address is 13 Hyacinth Road, 32 Oak Tree Gardens, Durbanville, Cape Town, Western Cape 7550, South Africa.

Acumin Intelligence (Pty) Ltd is the data controller for the personal information described in this policy. For any questions, or to make a data-protection request, email privacy@acumin.ai.

2. What data we collect

Data you give us directly — your name, email address, and anything else you provide when you create an account, set up a brand, or contact us.

Connected platform data — when you connect or name an account, we request access limited to what each feature needs. Everything we READ is read-only. We also WRITE to your accounts, but only in three shapes, and only ever at your instruction: the post you wrote and approved, at the time you chose; the comment or direct-message reply you typed, when you click send; and nothing else. We never write anything you have not seen and approved first.

• YouTube — public channel and video metrics (views, likes, comments, engagement, posting cadence, upload history) for the channels you ask us to analyse. If you connect your own YouTube channel, we additionally read its private analytics (views, watch time, traffic sources) with your consent via Google OAuth (scope yt-analytics.readonly), read-only. If you choose to reply to a comment from inside Acumin, we post that reply on your behalf using the YouTube Data API (scope youtube.force-ssl) — only the reply you write, only when you click send. If you choose to publish a video from Acumin, we upload it to your channel using the same scope (youtube.force-ssl, which is the only scope YouTube offers for either action) — only the video, title and thumbnail you attached and approved, only at the time you scheduled it. We never upload anything you have not chosen, and we never change, unlist or delete a video already on your channel.

Acumin's use of and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. When you connect a YouTube channel, your use of the YouTube-connected features is also governed by the YouTube Terms of Service, and Google's own handling of the data accessed through those APIs is described in the Google Privacy Policy. You can review and revoke Acumin's access to your Google account at any time at myaccount.google.com/permissions.

• Instagram & Facebook (via Meta) — access through the Meta Graph API, read-only except for the publishing described in the two bullets below. For brand and competitor benchmarking we use Instagram Business Discovery (permission: instagram_basic) to read the public profile and media metrics (username, follower count, post metadata, likes, comments, and views where available) of the Instagram Business or Creator accounts you ask us to analyse — your own brand's account and any competitor handles you confirm. If you connect your own account via Facebook Login, we read: the list of Facebook Pages you manage (pages_show_list); the name and username of the Instagram Business account linked to the Page you select (instagram_basic); and the businesses and ad accounts you manage (business_management) — used only to identify and connect the correct accounts, and we store only their names and ids. If you connect your own Instagram account and choose to engage, we additionally let you reply to comments (permission: instagram_business_manage_comments) and read and reply to direct messages (permission: instagram_business_manage_messages) — sending only the replies you write, only when you click send.

• Your own Facebook Page — if you connect a Facebook Page you manage, we read the posts that Page itself published (permission: pages_read_engagement): the post text, its date and link, its picture, and its like, comment and share counts, so your Facebook performance appears in your analytics alongside your other channels. We read the counts only, never the names or profiles of the people who liked or commented. We do not read posts made by visitors to your Page, and we cannot read any Page you do not manage. If you choose to publish from Acumin, we post to that Page (permission: pages_manage_posts) — only a post you wrote and approved, only at the time you scheduled it. We never like, follow, delete, or edit anything already on your Page.

• Publishing to Instagram — if you connect your own Instagram Business account and choose to publish from Acumin, we create the post you approved (permission: instagram_business_content_publish), and, when you have written one, add your first comment to it (permission: instagram_business_manage_comments). Only content you wrote and approved, only at the time you scheduled it.

• Meta advertising performance — if you connect a Meta ad account, we read its campaign performance metrics (spend, impressions, reach, results) via the Marketing API (permission: ads_read) to show you organic-versus-paid analytics. Read-only — we never create, edit, pause, or spend on campaigns.

• TikTok — if you connect your own TikTok account, we read your basic profile (scope user.info.basic) and your public video list and metrics (scope video.list) via TikTok's Login Kit and Display API, read-only, to include your TikTok performance in your analytics. We do not access other users' TikTok data. If you choose to send a video from Acumin to TikTok, it is uploaded to your TikTok inbox as a DRAFT (scope video.upload) — nothing is posted publicly. You open it in TikTok, review it, and publish it there yourself. Acumin cannot post directly to TikTok, and does not do so even where an account's permissions would allow it.

• LinkedIn — signing in with LinkedIn reads only your name, profile photo and email from your LinkedIn profile (scopes openid, profile, email), to identify you. Connecting a LinkedIn company Page is a separate, optional step that uses a different LinkedIn application: we read which company Pages you administer (scope rw_organization_admin) so you can choose one, and publish to the Page you chose (scope w_organization_social) — only a post you wrote and approved, only at the time you scheduled it. We read no LinkedIn analytics: LinkedIn's free tier exposes none, and we never invent a metric we cannot see.

• X — if you connect your X account we read your public profile and its public metrics (scope users.read), read-only, to show your X presence alongside your other channels. Acumin never posts to X, and requests no permission that would let it: X copy written in Acumin is yours to post yourself.

• Comments and direct messages — when you use the Engagement inbox we read comments on your own posts and your direct-message conversations so you can triage and reply. We store only the metadata needed to manage replies and remind you of Instagram's 24-hour reply window — the conversation id, the other participant's handle, timestamps, status, and a short preview snippet. We do not store the full text of your direct messages; full message bodies are fetched live from the platform only when you open a conversation.

Usage and technical data — standard server logs, session data, and feature-usage information needed to operate, secure, and improve the service.

Cookies — we use a small number of cookies for sign-in/session management. We don't sell data to ad networks, and we never share anything you connect to Acumin — your analytics, your content, your clients — with an advertiser. You can control cookies through your browser settings.

Site analytics — to see which pages get read and where visitors arrive from, we use Cloudflare Web Analytics. It is cookieless: it stores nothing on your device, sets no identifier, and cannot follow you to any other site. Because it takes nothing from you, we don't ask permission for it — and because it tracks pages rather than people, we can't use it to single you out.

Advertising measurement — on our public marketing pages we use the Meta Pixel to measure whether our own advertising works: it tells us that a visit or a sign-up followed an ad we paid for. It runs only if you accept it, it is not present on your logged-in Acumin pages, and it never sees the data inside your account. If you decline, the pixel does not load at all. You can change your mind at any time through your browser settings, or by clearing this site's stored data.

3. How we use your data

To generate your Signals, Concept Reads, Creative Briefs, Launch Playbooks, Content Analysis reports, and Pre-Flight reads.

To power always-on intelligence surfaces — Competitor Watch, Category Trend Radar, Rising Signal alerts, Performance Pulse, Share of Voice, and Audience Sentiment.

To operate, maintain, secure, and improve the service, and to communicate with you about your account, plan, or support requests.

To meet our legal obligations and enforce our Terms of Service.

We do not use your private or connected-account data to train third-party AI models, and we never sell your data.

4. Read-only analytics, you-authored publishing

Our analytics integrations are read-only. Acumin will never like, follow, advertise, edit, or delete anything on any account you connect or analyse, and it will never read a competitor's private data or an account you do not control.

Acumin does publish, and only ever what you wrote and approved. Every post goes through you first: it is drafted in Acumin, you edit it, you approve it, and you choose when it goes out. Nothing publishes without that approval, and approving one post never approves the next. You can withdraw an approved post at any time before it is sent. We never generate and publish in one step, never post on your behalf without your approval, and never publish anything you have not read.

Scheduling means what you would expect and nothing more: a post you approved goes out at the time you chose. It is not permission to post on your behalf in general, and it applies to posts only — replies and messages are never scheduled and never automatic.

Replies are separate and stricter. When you reply to a comment or a direct message we send only the exact message you typed, only at the moment you click send, and only from the account you connected. We never message anyone automatically and never initiate outreach on your behalf.

5. Platform data and Meta's Platform Terms

Our access to and use of Instagram, Facebook, and Meta advertising data complies with the Meta Platform Terms and Developer Policies. We use Meta platform data solely to provide the analytics and publishing features described above, we store the minimum needed, we keep access tokens encrypted, and we delete that data when you disconnect, request deletion, or when it is no longer needed for the service.

We publish to your Instagram account or Facebook Page only at your instruction, only content you wrote and approved inside Acumin, and only to accounts you yourself connected. We do not publish on a schedule you did not set, do not post to any account or Page you do not manage, and do not use Meta platform data for advertising, profiling, or resale.

6. Who we share it with

We don't sell your data. To run the service we share limited data with trusted sub-processors, each contractually bound to protect it and use it only as we direct:

• Supabase — database and file storage.

• Cloudflare — hosting, CDN, and security.

• Anthropic — language-model inference for report phrasing; your data is not used to train its models.

• Google / YouTube — retrieving YouTube data via the YouTube Data API and YouTube Analytics API.

• Meta Platforms — Instagram, Facebook Page, and ad-performance data via the Graph and Marketing APIs, and the posts you approve for publishing to your own Instagram account and Facebook Page.

• TikTok — profile and public video data via the Login Kit and Display API, and draft video uploads to your own TikTok inbox.

• LinkedIn — sign-in identity, and company-Page publishing via the Community Management API.

• X — public profile and public metrics via the X API.

• Dodo Payments — subscription billing and payment processing (Merchant of Record).

We share data only as needed to provide the service, or where required by law.

7. Data retention and deletion

We keep your data for as long as your account is active or as needed to provide the service.

When you disconnect a platform, the access token we stored for that connection is deleted from our systems. You can also revoke Acumin's access directly from the platform (for example in your Meta, TikTok, or Google account settings) at any time.

You can request deletion of your data at any time by emailing privacy@acumin.ai, and we'll action it within 30 days. We may keep anonymised, aggregated data that no longer identifies you for product improvement.

Instagram / Facebook data deletion: if you've connected Instagram or a Facebook Page and want that data removed, follow the steps on our Data Deletion page at acumin.ai/data-deletion, as required by Meta's platform policies.

8. Security

We use industry-standard technical and organisational measures to protect your data, including encrypted storage of platform access tokens (AES-GCM), access controls, and regular reviews. No method of transmission or storage over the internet is completely secure, but we work to keep your information safe and respond promptly to any incident.

9. Your rights

Depending on where you live, you may have rights over your personal data, including to: access a copy of it; correct inaccurate data; delete it; receive it in a portable, machine-readable format; restrict or object to processing; and withdraw consent (by disconnecting any linked platform at any time).

To exercise any of these, email privacy@acumin.ai and we'll respond within 30 days. If you're in South Africa, you may also lodge a complaint with the Information Regulator under POPIA; if you're in the EU or UK, with your local data protection authority; California residents have rights under the CCPA.

10. International data transfers

Acumin is operated from South Africa. If you're located elsewhere, your data may be transferred to and processed in South Africa and in the countries where our sub-processors operate. Where we transfer data internationally, we take steps to ensure appropriate safeguards consistent with applicable law (including POPIA and, where relevant, the GDPR).

11. Children

Acumin is a business tool that is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with data, email privacy@acumin.ai and we'll delete it promptly.

12. Third-party platforms

Acumin connects to third-party platforms (Meta, YouTube, TikTok, and others) that are governed by their own privacy policies. We are not responsible for their practices — please review their policies before connecting an account.

13. Changes to this policy

We'll post any material changes here and refresh the “last updated” date above. Where changes are significant, we'll let you know by email.

14. Contact

Questions about your data or this policy? Email privacy@acumin.ai, or write to Acumin Intelligence (Pty) Ltd, 13 Hyacinth Road, 32 Oak Tree Gardens, Durbanville, Cape Town, Western Cape 7550, South Africa. We'll respond within 30 days.