This Privacy Policy explains what personal data 1000ants collects, why we collect it, how we use it, who we share it with, and the rights you have over it. We are committed to processing personal data only where there is a lawful basis to do so, and to telling you plainly what we do — without legalese where we can avoid it.

This policy is written in compliance with the EU General Data Protection Regulation (Reg. (EU) 2016/679 — "GDPR") and the Estonian Personal Data Protection Act (Isikuandmete kaitse seadus).

On this page

  1. Controller & EU representative
  2. What we collect
  3. How we use it
  4. Lawful basis
  5. Sub-processors
  6. International transfers
  7. Retention
  8. Your rights
  9. Cookies & analytics
  10. Children
  11. Security
  12. Changes

1. Controller & EU Representative

The data controller responsible for processing your personal data is:

Controller TwentyOne Monkeys OÜ, trading as 1000ants
Tartu mnt 67/1-13b, 10115 Tallinn
Estonia
Registry code: 17570457
Managing Director: Johannes Pfeiffer
Email: contact@1000ants.ai

We have not appointed a Data Protection Officer (DPO). Under Art. 37 GDPR this is not required: we are a small company that does not carry out large-scale regular and systematic monitoring of data subjects and does not process special categories of data on a large scale.

2. What We Collect

1000ants is a marketing operating system. Customers connect their third-party marketing accounts (e.g. Google Ads, Meta Ads, LinkedIn, Zoho CRM), and our agents observe, draft, and — where explicitly authorised — execute actions on those accounts. The categories of personal data we process are listed below.

2.1 Account & profile data

2.2 OAuth tokens for connected providers

When you authorise 1000ants to connect to a third-party marketing platform (Google Ads, Meta, LinkedIn, Zoho), we receive and store OAuth refresh and access tokens that allow us to query that platform on your behalf. These tokens are encrypted at rest using symmetric Fernet encryption and stored in our database in a table separate from your account profile (account_secrets). We never share these tokens with any party other than the issuing provider themselves.

2.3 Synced marketing data

On your explicit instruction, 1000ants fetches data from your connected marketing platforms and stores it in our database so our agents can analyse it. Depending on the platforms you connect, this may include:

This data may contain personal data of third parties (e.g. names of leads or contacts in your CRM, demographic segments from your ad accounts). You remain the controller of that data; 1000ants is the processor. A Data Processing Agreement (DPA) is available on request at contact@1000ants.ai.

2.4 Agent & product usage data

2.5 Marketing-site & analytics data

3. How We Use Your Data

4. Lawful Basis (Art. 6 GDPR)

5. Sub-processors

1000ants is built on a small set of trusted infrastructure and AI providers. Each of these processes some category of data on our behalf. We have appropriate data processing terms in place with each (e.g. Standard Contractual Clauses where the provider is outside the EU/EEA).

Provider Purpose Data processed Location
Supabase, Inc. Primary database, authentication, file storage All application data (encrypted at rest) United States (us-east-2)
Anthropic PBC LLM API (Claude Sonnet / Haiku) for agent reasoning + content drafting Chat messages, Brand Core context, drafter prompts. Anthropic does not train on data submitted via the API. United States
Perplexity AI, Inc. Web research (Sonar API) used during strategy generation Research prompts derived from your workspace (e.g. competitor names, market questions) United States
Google LLC Google Ads API (sync + execute), Google Fonts (DM Sans) Google Ads OAuth tokens; campaign / search-term data on read; mutate operations on write (e.g. negative keywords) — only on your explicit approval United States & EU
Meta Platforms, Inc. Meta Marketing API (Facebook / Instagram ads) Meta OAuth tokens; campaigns, ad sets, ads, insights on read; ad / creative creation + pause on write (write capability enabled only after Meta's Marketing API Access Tier approval and your explicit step-by-step approval) United States & Ireland
LinkedIn Corporation LinkedIn API (publish to personal timeline) LinkedIn OAuth tokens; post drafts that you have approved for publishing; published-post receipts United States & Ireland
Resend (Plus Five Five, Inc.) Transactional e-mail delivery (sign-up, password reset, notifications) Your name and e-mail address, and the content of the message sent to you United States
Zoho Corporation Zoho CRM API (read CRM records) Zoho OAuth tokens; CRM records (deals, leads, accounts, contacts) on read only — 1000ants does not write back to Zoho in this release Region depends on your Zoho data centre (EU / US / IN / AU)
Google Analytics (Google Ireland Ltd.) Marketing-site analytics on 1000ants.ai (consent-gated) Anonymised page-view, session, device data — only with your consent via the cookie banner Ireland & United States

A current, dated list of sub-processors is available on request. We notify customers in advance of any material change to this list (typically 30 days).

6. International Transfers

Several of our sub-processors are located in the United States. Where personal data of EU/EEA data subjects is transferred to the United States, we rely on the European Commission's Standard Contractual Clauses (SCCs, Decision (EU) 2021/914) and, where applicable, the EU-US Data Privacy Framework, as concluded between the relevant sub-processor and 1000ants.

The controller itself (TwentyOne Monkeys OÜ) is established in Estonia and therefore within the European Union. The operational processing of your data takes place in the US-East-2 region of Supabase and in the data centres of our other sub-processors as listed above. Those transfers to the United States take place on the basis of the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) and, where applicable, the sub-processor's certification under the EU-US Data Privacy Framework. You may request a copy of the relevant safeguards by writing to the address above.

7. Retention

We retain personal data only as long as we need it:

Some data must be retained longer to comply with legal obligations (e.g. tax-relevant records). Where this is the case, that data is restricted from further processing.

8. Your Rights

Under the GDPR you have the following rights regarding your personal data:

To exercise any of these rights, please email contact@1000ants.ai. We respond within one month, as required by Art. 12(3) GDPR.

9. Cookies & Analytics

1000ants uses two kinds of cookies on its marketing site (1000ants.ai) and inside the product:

We do not use third-party advertising cookies, retargeting pixels, or social-tracking pixels on 1000ants.ai.

10. Children

1000ants is a B2B service intended for business users. It is not directed at, and we do not knowingly collect personal data from, children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.

11. Security

We take technical and organisational measures appropriate to the risk, including:

No system is perfectly secure. In the event of a personal-data breach likely to result in a high risk to your rights and freedoms, we will notify you and the relevant supervisory authority without undue delay (within 72 hours where feasible), as required by Art. 33 / 34 GDPR.

12. Changes to This Policy

We may update this Privacy Policy as the product evolves or to reflect legal changes. Material changes will be communicated by email to active workspace owners and through a notice in the product. The "Last updated" date at the top of this page always reflects the current version.

Contact

Questions about this Privacy Policy or how we handle your data: contact@1000ants.ai.
TwentyOne Monkeys OÜ, Tartu mnt 67/1-13b, 10115 Tallinn, Estonia — registry code 17570457.