Skip to content
Denver Media Tech

Legal

Privacy Policy

This explains what Denver AI Tech collects when you use the platform or this website, why we hold it, who else processes it, and how you get it back or get it deleted.

Last updated: 5 October 2026

1. Who we are

Denver Media Tech is a product of Denver AI Tech.

Denver AI Tech is a solo-operated B2B software and services business run by Mohd Sultan Siddiqui. For the personal data described here we are the data controller. For data inside your connected advertising, analytics and commerce accounts, you remain the controller and we act as your processor.

Privacy questions, access requests and complaints all go to the same place: hello@denveraitech.com.

2. What we collect

Four buckets, and nothing outside them:

  • Account data. The email address you sign in with, the display name your identity provider returns, and which workspaces you can access. Sign-in happens through Google OAuth — we never receive or store your Google password.
  • Business profile. Your business or workspace name, market, timezone, currency, industry vertical, brand-voice settings, competitor watchlist, notification preferences, and the email address, WhatsApp number or Slack channel you want alerts delivered to.
  • Connected-platform credentials. OAuth access and refresh tokens, and the account identifiers they are scoped to, for each platform you choose to connect. For API-key platforms (Yelp, TripAdvisor, Shopify) we store the business or shop identifier you paste in.
  • Platform metrics and content. The data we read back on your behalf: ad spend and performance, Google Business Profile insights and reviews, analytics and search-console metrics, orders and revenue, CRM pipeline records, calendar bookings. Plus what the platform produces from it — digests, drafts, approval decisions, generated PDF reports, chat transcripts with the in-app assistant and any thumbs-up/down feedback you leave, and an audit log of every action taken.

The current Get started page directs you to authenticated workspace signup; it does not collect an email or submit a public score request. A pilot application is prepared locally for you to review and send through your own email app. Historical GMB Health Score requests may contain the business name, city, email and target keyword supplied at the time, together with the protected result. Vercel Speed Insights records anonymous page-performance measurements. We do not run advertising trackers or set marketing cookies on this site.

3. Why we use it

  • To operate the service you signed up for: reading your connected accounts, spotting anomalies, drafting recommendations, and delivering digests and reports.
  • To send the notifications you configured, on the channels you chose.
  • To answer your questions in the in-app assistant, which reads your own workspace data to ground its replies.
  • To keep an audit trail so you can see exactly what was done, when, and who approved it.
  • To bill you, support you, and tell you about material changes to the service.

We do not sell personal data. We do not share it with advertisers. We do not use your business data, your platform metrics, or your chat transcripts to train any machine-learning model — ours or anyone else's.

4. Google user data

Denver AI Tech's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Concretely, when you connect Google Business Profile, Google Ads, Google Analytics or Search Console:

  • We request read scopes for the specific products you connect, plus write access to Google Business Profile only where you have asked us to post review replies or profile updates on your approval.
  • Google data is used only to provide and improve the user-facing features you connected it for — monitoring, digests, reports and drafts inside your own workspace.
  • We do not transfer Google user data to third parties except the sub-processors listed below that are necessary to run the service, or where you direct us to, or where law requires it.
  • We do not use Google user data for advertising, and we do not allow humans to read it except with your explicit permission for support, for security investigations, or where the law requires it.
  • You can revoke our access at any time from your Google Account permissions page or from the Connections screen in the dashboard. Revoking stops all future reads immediately.

5. How it is protected

  • OAuth access and refresh tokens are encrypted at rest with Fernet symmetric encryption before they are written to the database. The encryption key lives only in the backend service environment, never in the database and never in the browser.
  • All traffic between your browser, our services and upstream platforms is over TLS.
  • Every dashboard request is authenticated and scoped: the backend checks, on every call, that the signed-in user actually has access to the workspace being requested.
  • Error and diagnostic telemetry is scrubbed before it leaves our systems — authorization headers, cookies, passwords, tokens, API keys and encryption keys are redacted automatically.
  • Access to production data is limited to the operator, and only where needed to run or repair the service.

No system is perfectly secure. If we become aware of a breach affecting your personal data we will notify you without undue delay and, where required, within 72 hours of becoming aware of it.

6. Sub-processors

We keep the vendor list short on purpose. These are the third parties that may process your data as part of delivering the service:

Sub-processorWhat it doesData location
AyrshareSocial posting and Google reviews: connects your social accounts, publishes the posts you approve, and reads your Google reviews.Not yet confirmed
Anthropic PBCAI writing: Claude models write post drafts, review-reply drafts and chat replies from the workspace data sent with each request.Not yet confirmed
OpenAI and Google (Gemini)AI pictures: the picture studio and post pictures send your picture request and any reference photos you attach to make the picture. Writing posts with these models is not switched on.Not yet confirmed
LangChain, Inc. (LangSmith)Agent task traces for debugging, only if we switch it on: a task's request and summary with email addresses and phone numbers removed, the tools it used and what it cost. No brand facts, reviews, drafts or prompts. Not switched on.Not yet confirmed
Amazon Web ServicesHosting for the application servers and scheduled jobs.ap-south-1 (Mumbai, India)
Supabase Inc.Database and sign-in: accounts, workspaces, encrypted connection keys, logs and chat history.ap-south-1 (Mumbai, India)
Vercel Inc.Hosting for this website and the customer dashboard, plus Speed Insights performance metrics.Not yet confirmed
Twilio SendGridEmail: approval emails, invitations, reports and review-request emails.Not yet confirmed
Stripe Inc.Billing: subscriptions and card payments. Card details go to Stripe directly; we never see or store them.Not yet confirmed
Google Places API (Google LLC)Local rankings: the search phrases, area and business names used for local ranking and competitor checks.Not yet confirmed

Platforms you connect directly to us — Google Analytics, Search Console, Google Ads, Google Business Profile, Meta, Shopify, HubSpot, Stripe, Square, Klaviyo, Mailchimp, Xero, QuickBooks, Pipedrive, Calendly, Slack, Yelp, TripAdvisor and similar — are processed only if and when you choose to connect them. Data flows from your account to us, not the other way round.

Our application servers and database run in the AWS and Supabase ap-south-1 region (Mumbai, India). The other providers above may process data in other countries, including the United States. If you are in the UK, EEA or Switzerland, that means your data is transferred outside it; we rely on the vendors' standard contractual clauses for those transfers. Email us if you need the details for your own records.

7. How long we keep it

  • Account, workspace and configuration data: for as long as your subscription is active.
  • OAuth tokens: until you disconnect the platform, revoke access upstream, or close your account — whichever happens first. Disconnecting expires the stored token immediately.
  • Platform metrics, digests, reports, chat transcripts and audit logs: up to 24 months, so year-over-year comparisons work. You can ask us to shorten this.
  • Lead-magnet submissions from this website (business name, city, email): 24 months, or until you ask us to remove them.
  • Billing and invoice records: retained as long as tax and accounting law requires, typically 7 years. These are held by Stripe and in our accounting records.
  • Encrypted backups: rotated out within 30 days.

After you close your account we delete or irreversibly anonymise the rest within 30 days, except the billing records above.

8. Your rights

Wherever you are, we will honour these. Depending on where you live some of them are also a legal right (UK/EU GDPR, California CCPA/CPRA and similar):

  • Access — a copy of the personal data we hold about you.
  • Portability — an export of your workspace data in a machine-readable format (JSON or CSV).
  • Correction — fix anything inaccurate.
  • Erasure — delete your account and associated data.
  • Restriction and objection — tell us to stop a particular processing activity.
  • Withdraw consent — disconnect any platform at any time, from the dashboard or from that platform's own settings.
  • Complain — to your local supervisory authority, though we'd rather you told us first so we can fix it.

To exercise any of these, email hello@denveraitech.com from the address on your account. We acknowledge within 5 business days and complete the request within 30 days. There is no charge. For deletion specifically, the step-by-step process is on the data deletion page.

9. Children

The platform is a business tool sold to businesses. It is not directed at anyone under 18 and we do not knowingly collect data from children. If you believe a child has given us personal data, email us and we will delete it.

10. Changes to this policy

When this policy changes we update the “last updated” date at the top. If a change materially affects how we handle your data, we will email active customers before it takes effect.