Key questions and answers about how we protect your data. For full details, see our agreements and Privacy Policy linked below.
No. None of the Maxma platform uses individual-level information or PII. For products that need first-party data (e.g. MMM and Incrementality Testing), we ask for aggregated, non-PII data — for example, metrics at date × geo granularity.
Customer data is hosted securely in Amazon Web Services in the United States. We maintain a dedicated managed database per client for primary inputs and outputs across our products. Data stores are not exposed to the public internet — access is restricted to our application hosts and whitelisted IPs only (no open public IP access), to reduce the risk of unauthorized access. You can delete your data at any time or when you exit.
Tokens and keys (e.g. platform integration tokens for ad platforms) are encrypted and stored securely using AWS KMS (Key Management Service).
We do not use your data to train generalized AI models, whether ours or a provider’s. Maxma builds models for you — such as your marketing mix model — from your own data, and your agent learns from your account’s data to do better work for you; those models and that learning stay within your account and are not shared with other customers. Improvements to the Maxma service more broadly are informed by aggregate product usage, never by your raw data, your business information, or your customers’ records.
We use trusted third-party AI service providers for AI-assisted features, including Anthropic (Claude) and OpenAI. Information sent to LLMs should be non-identifying unless you choose to add identifying details (e.g. let LLM know your company name). These providers process data under commercial API terms that prohibit using submitted content to train their generalized models.
Yes. We are SOC 2 Type 1 certified. Customers can request our SOC 2 report under NDA.