1. Who is responsible for your data
Onwards Analytics, based in Australia, operates Mockingbird and is the entity responsible for the personal information described here. Under the Australian Privacy Act 1988 we treat ourselves as bound by the Australian Privacy Principles, and where the GDPR applies we act as controller for account data and as processor for the content you put into a workspace.
Privacy questions, access requests and complaints: [email protected].
2. What we collect
- Account information — your email address, display name if you set one, and a hashed password. We never see your password in plain text.
- Workspace content — brand profile, logos, fonts, product descriptions, the competitors you ask us to watch, and the creative the service generates for you.
- Competitor advertisements — collected from Meta's public Ad Library. These are ads businesses have published publicly; we do not access anything behind a login and we do not read anyone's personal feed.
- Meta connection data — if you connect Meta, an access token (encrypted at rest in Supabase Vault), your ad account and page identifiers, and campaign-level performance metrics. Aggregate numbers, not individual people who saw your ads.
- Billing information — handled by Stripe. We store a customer identifier, subscription status and invoice history; we do not store card numbers.
- Usage and technical data — which features were used and what they cost us to run, plus request logs at the edge that include IP addresses.
- Legal acceptances — when you accept these documents, we record which version, the time, and the originating IP address where the request carries one.
- Anything you email us — support correspondence, kept so we can help you next time.
3. Cookies, and what is stored in your browser
Mockingbird uses the Meta pixel on its pages, and our server reports purchases to Meta's Conversions API. We use this for one thing: to measure whether our own Meta ads lead to sign-ups and purchases.
Meta receives the pages you visit on mockingbird.digital, when you start checkout, and when you buy (amount and currency). At purchase our server also sends a SHA-256 hash of your email address, your browser's user agent and the Meta cookie identifiers below, so Meta can match the purchase to an ad click. We never send card details, your brand data or anything you create in Mockingbird.
The pixel sets two cookies on our domain: _fbp, and _fbc if you arrived from a Meta ad. Meta handles this data under its own privacy policy. Your browser's tracking protection or an ad blocker will stop the pixel, and Mockingbird works the same without it. There is no Google Analytics and no tag manager.
What the browser does hold, in local storage rather than cookies:
- Your signed-in session, so a refresh does not sign you out.
- Which workspace you last had open, and small interface preferences.
- A record that you accepted these documents at signup, held only until it can be written to your account.
All of it is strictly necessary to run the service. Clearing your browser storage signs you out and loses nothing else.
4. Why we use it
- To run the service you asked for: collecting ads, ranking them, generating creative, and uploading it to Meta when you choose to.
- To bill you, and to meter credits so you are charged for what you used.
- To send transactional email — invitations, digests, billing and security notices.
- To keep the service working and secure: debugging, abuse prevention, and cost control.
- To improve ranking and output quality using aggregated, de-identified signals. One customer's brand assets are never used to generate another customer's ads.
- To meet legal obligations, such as keeping financial records.
Where the GDPR applies, our lawful bases are performance of a contract (running the service and billing you), legitimate interests (security, abuse prevention, product quality) and legal obligation (financial records). We do not rely on consent for anything except optional marketing email, which you can decline without losing access.
We do not sell personal information, and we do not use your data to train models we own.
5. Who we share it with
Mockingbird runs on services operated by other companies. These are the ones in use, what each is given, and where they process it.
| Provider | What it does | What it receives | Where |
|---|---|---|---|
| Supabase | Database, file storage and authentication — the system of recordAccount, workspace, brand profile, competitor ads, generated creative, encrypted Meta tokens | Account, workspace, brand profile, competitor ads, generated creative, encrypted Meta tokens | Sydney, Australia (ap-southeast-2); vendor is US-based |
| Cloudflare | Web hosting, API endpoints and DNSRequests in transit, IP addresses in edge logs | Requests in transit, IP addresses in edge logs | Global edge network; vendor is US-based |
| Stripe | Subscription billing and card processingName, email, billing address, card details (held by Stripe, not by us) | Name, email, billing address, card details (held by Stripe, not by us) | United States and Ireland |
| Meta | Public Ad Library data, your ad account if you connect it, and measuring our own Meta ads (Meta pixel and Conversions API)Ad account and page identifiers, campaign performance metrics, creative you upload; pages visited, checkout starts, purchase amount, hashed email and browser identifiers | Ad account and page identifiers, campaign performance metrics, creative you upload; pages visited, checkout starts, purchase amount, hashed email and browser identifiers | United States |
| Google (Gemini API) | Reading competitor ads, and writing brand-swapped copy and imagesCropped competitor ad images, your brand profile | Cropped competitor ad images, your brand profile | United States |
| Ideogram | Image generation and typography passesImage prompts, reference images | Image prompts, reference images | United States |
| Apify | Collecting advertisements from Meta's public Ad LibraryCompetitor names and page identifiers you ask us to watch | Competitor names and page identifiers you ask us to watch | European Union (Czechia) |
| OpenAI | Text synthesis for the CMO assistantWorkspace performance summaries and brand profile text | Workspace performance summaries and brand profile text | United States |
| Anthropic | Text synthesis for the CMO assistantWorkspace performance summaries and brand profile text | Workspace performance summaries and brand profile text | United States |
| Resend | Transactional email — invitations, digests, billing noticesEmail address, the contents of the email | Email address, the contents of the email | United States |
We also disclose information where the law requires it, and to a buyer if the business is sold — in which case we would tell you first.
6. Sending data overseas
Your database and files sit in Sydney. The generation pipeline does not: a cropped competitor image and your brand profile are sent to providers in the United States and the European Union to be processed, and the result comes back. Payment and email providers are also overseas. The table above says which.
This is an overseas disclosure under Australian Privacy Principle 8. We choose providers that offer contractual data-protection terms and that commit not to train their models on paid API content, but we cannot guarantee an overseas recipient will handle your information in the way the Australian Privacy Principles require. By using the service you accept that these transfers happen — they are how the product works.
7. AI providers specifically
Image and copy generation uses Google's Gemini API on a paid tier, plus Ideogram for some image work. The CMO assistant uses OpenAI or Anthropic for text. We use paid API tiers rather than consumer products because the paid terms say content sent to the API is not used to train the provider's models.
What leaves Australia is the cropped competitor ad, your brand profile, and performance summaries. Your Meta access token never does.
8. How long we keep it
- Account and workspace data: for as long as the account is open.
- Competitor ads and generated creative: while the workspace exists, so the ranking and brand memory keep working.
- Deleted workspaces: deleting a workspace hides it from everyone immediately and revokes its invitations, but the records stay in the database until they are purged. There is no automatic purge job yet — email us and we will erase them within 7 days.
- Billing records: at least 5 years after the transaction, because Australian tax law requires it. This is one of the few things we cannot delete on request.
- Edge request logs: short-lived, retained by Cloudflare under its own retention policy.
- Legal acceptance records: kept for as long as they may be needed as evidence of consent, which is the life of the account plus any limitation period.
9. Security
Multi-tenant isolation is enforced in the database, not only in the application: every table is keyed to a workspace and gated by row-level security. Meta tokens are encrypted at rest. The security page describes the architecture in more detail — including what we do not claim. We are not SOC 2 certified and hold no privacy attestation.
If we become aware of a data breach likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.
10. Your rights
Under the Australian Privacy Act you can:
- Ask what personal information we hold about you, and get a copy. We will respond within 30 days and will not charge you for the request.
- Ask us to correct anything inaccurate or out of date. Your name, email and password can be changed yourself from the account page.
- Complain to us about how we have handled your information. Email us first — if you are not satisfied with the answer, you can take it to the Office of the Australian Information Commissioner at oaic.gov.au.
- Deal with us anonymously for general enquiries, though not for an account, which needs an email address.
If the GDPR or UK GDPR applies to you, you also have rights of erasure, restriction, objection and portability, and the right to complain to your local supervisory authority. Use the same email address and say which right you are exercising.
Deletion requests go to [email protected]. We will confirm what was erased and what we had to keep for tax purposes.
11. Children
Mockingbird is a business tool and is not intended for anyone under 18. We do not knowingly collect information from children. If you believe a child has created an account, tell us and we will remove it.
12. Changes to this policy
Each version carries a version date. Material changes are emailed to account owners before they take effect, and the version you accepted is recorded against your account.
Open items for the legal review
These are unresolved in this draft. They need a decision from Onwards Analytics and a lawyer's sign-off before this page stops being a draft.
- The registered entity, ABN and postal address that must appear on an APP-compliant policy, plus whether a named Privacy Officer is required.
- Whether Onwards Analytics' turnover puts it inside or outside the Privacy Act's small-business exemption, and whether to opt in regardless.
- Whether the GDPR actually applies — if EU or UK customers are targeted, an Article 27 representative may be required and is not appointed.
- Whether a Data Processing Addendum is needed for customers who ask for one, and whose template to use.
- Confirmation of each vendor's current processing locations and sub-processors; the table here is drawn from the code and the vendors' public documentation, not from executed contracts.
- The real retention period for deleted workspaces once a purge job exists — this draft says the honest thing, which is that there is not one yet.
- Whether the 5-year financial record retention should be 7 years to match company record-keeping practice.