Privacy Policy
How Optimus Pass handles scans, reports, account data, agency data, and optional measurement.
Our Privacy Commitment
Optimus Pass is designed to minimize data exposure. Different features have different privacy characteristics, described below.
Anonymous Scans
Scans require a verified account. Free accounts do not require a credit card. Authenticated scans are processed through our secure API and stored as reports so you can revisit them from your account. Free access is protected with account quotas and privacy-preserving abuse controls.
Authenticated Scans
When you are signed in and scan ad copy, we store the scan results — including the ad text you scanned, the platform and ad field selected, detected violations, semantic flags, findings, risk scores, rewrite suggestions, and the number of detectors used — so you can view and revisit your full compliance reports from your account. We also store a content hash (a one-way fingerprint of your text) and scan metadata for abuse monitoring. You can permanently delete your account and its associated reports from Account Settings, or contact us for assistance.
URL Audits
Landing page and site audits fetch the URL you provide through our secure backend service. The fetched content is analyzed and discarded — not stored or used for training.
What We Collect
When you create an account, we collect:
- Email address (for account identification)
- Billing information (processed by Stripe; we do not store payment details)
- Plan type and subscription status
- Optional display name and company name entered in Account Settings
- Scan history and reports (the ad text you scanned, content hash, findings, violations, semantic flags, risk scores, rewrite suggestions, platform, ad field, timestamp)
What We Never Collect
- Ad-account or advertising-platform credentials
- We do not sell customer data, and advertisers do not receive access to your private scans, ad copy, or report content.
Agency Data
Agency plan users may store their own workflow data to run their business, such as client names, client domains, and project or workflow information. This data belongs to the agency account that entered it and is governed by this policy like any other account data. Agency share links expose only the limited public report view — no account data and no detector internals — expire on the stated date, and stop working immediately when revoked.
Service Providers and Measurement
To operate Optimus Pass and to understand how it is used, we rely on a small number of service providers. This can include hosting and infrastructure, billing and payment processing (Stripe), and — when configured — advertising measurement partners.
When advertising measurement is enabled, we may send limited technical and attribution data to those partners so we can measure conversions and understand how campaigns perform. This is restricted to event and conversion metadata such as the event type, the page where it occurred, a conversion reference, and any value/currency relevant to the event, plus an anonymous visitor identifier.
Scanner/ad copy, compliance findings, scanned page content, and unnecessary raw personal data are not sent in these measurement payloads. Partners receive the limited signals described above and cannot read your scans or your ad copy.
Analytics and measurement providers are only used when their integration is enabled for launch and are configured to run with the smallest useful set of event data.
Optional Reddit and OpenAI browser measurement pixels load only after you choose “Allow measurement.” If you decline, those browser pixels are not initialized. You can clear the saved preference in your browser storage to choose again.
Analytics
We use Vercel Analytics to understand site traffic. This collects anonymous, aggregated metrics without cookies or personal identifiers. No ad copy or compliance data is included.
Contact
Questions about this policy? Contact us at privacy@optimuspass.com. Last updated: August 2026.