Privacy Policy
Last updated 29 September 2026 · Devtech, LLC d/b/a Agency Pilot
1. Who we are and our two roles
Agency Pilot is provided by Devtech, LLC, an Ohio limited liability company doing business as Agency Pilot ("Agency Pilot", "we", "us"). We provide software for marketing agencies. This policy explains how we handle personal data on agencypilot.io, in the web application at app.agencypilot.io, in the LeadPulse app, through AI app connections, and through the tracking script agencies install on their clients' websites.
We handle personal data in two different roles:
- As a controller for information about the people who sign up for and use Agency Pilot (agency owners and team members), for our own billing and support, and for visitors to agencypilot.io. This policy describes that processing.
- As a processor or service provider for the data agencies put into the Service or collect with it — their clients' records, leads, sales and conversations, data from connected accounts, and data about visitors to their clients' websites. For that data, the agency (and its client) decides what is collected and why; we process it on their instructions under our Data Processing Addendum. If your data is in an agency's account, contact that agency or the business concerned first.
2. What we collect
Account and agency information
Name, email address, password (stored only as a hash by our authentication provider) or Google sign-in identifier, agency name, role, profile details, two-factor settings, notification preferences, and the settings you choose.
Billing information
Plan, invoices, billing address and payment status. Card details are collected and stored by our payment processor; we never receive full card numbers.
Customer Data
What agencies and their clients store in the Service: client and contact records, leads (names, emails, phone numbers, messages and their sources), sales and job values, projects and tasks, documents, support tickets, conversation history including texts, call recordings and emails, forms and submissions, and reports.
Connected account data
When an agency or client connects Google, Meta or another platform, we receive the tokens and the account data needed for the features requested — for example ad spend and campaign performance, website traffic, search performance and Business Profile metrics. See section 4.
Usage and device information
Log data such as IP address, browser, device and pages or features used in the web app and LeadPulse app, and error reports that help us fix problems. The LeadPulse app may show device and app details on its Diagnostics screen and, if you turn on notifications, store a device token to deliver them.
Communications
Messages you send us, and records of support conversations.
agencypilot.io
Our marketing site does not use advertising or analytics cookies. Its pages load fonts from Google Fonts, which receives your IP address as part of delivering them.
3. Data from websites using our script
When an agency installs the Agency Pilot tracking script on a client's website, we collect the following on behalf of that agency and business (see our Website Visitor Notice):
- How the visitor arrived: referrer, landing page, UTM tags, ad click identifiers (such as gclid, gbraid, wbraid, fbclid, msclkid, ttclid, li_fat_id) and ad parameters such as campaign and keyword.
- Visit information: IP address and the network and approximate location derived from it, browser, device, screen, language and time zone, pages viewed, time on site, scroll depth, clicks and taps, and timing of form interactions (not the values typed, unless recording of typed text is enabled).
- Identifiers: a random visitor ID and visit ID stored in cookies, and a device fingerprint derived from browser characteristics, used for attribution and fraud detection.
- Form submissions the website sends as leads: typically name, email, phone and message, with the visit's source.
- Signals used to detect fraud and bots, including whether the IP address belongs to a datacenter, VPN, proxy or Tor, automation indicators, and checks on the quality of submitted contact details.
- For heatmaps, occasional masked snapshots of the page layout, with emails and long numbers removed.
- If the business has enabled session recording: a recording of page changes, mouse movement, clicks and scrolling. Password and card fields are never recorded and pages containing them are not recorded; typed text and sensitive fields are hidden unless the business turns those settings on. An optional consent banner can require the visitor's permission first, and Global Privacy Control signals are treated as a refusal.
- Heartbeat checks of the website's availability.
4. Google and Meta data
Agency Pilot's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide the features a person connected it for — showing performance in reports and dashboards, granting the access shown on an onboarding link, or uploading sales the agency chose to send — and not for advertising, not to build profiles, and not to train general AI models. People at Agency Pilot do not read it except with permission, for security, or to comply with law. The security page lists every Google and Meta permission we request and why.
Data received from Meta is used only for the connected features, is not shared with third parties other than our processors, and is deleted on request. When someone removes Agency Pilot from their Facebook settings, Meta notifies us and the connection is revoked. Deletion requests sent through Meta receive a confirmation code and a page where the request's status can be checked.
Geo grid scans and other map features use Google Maps. When you view a map, Google receives information such as your IP address, as described in the Google Privacy Policy.
Anyone can revoke Agency Pilot's access to their Google account at myaccount.google.com under third-party connections, and to Meta under Settings → Business integrations. Access an agency received inside those platforms (for example as a user or partner) is managed in each platform.
5. How we use information
- To provide the Service: accounts, onboarding links, reporting, rank tracking, audits, attribution, messaging, the client portal and app.
- To detect and prevent fraud, abuse and security incidents, including click-fraud and fake-lead detection.
- To bill you and manage your subscription and credits.
- To send service messages such as invitations, notifications, scheduled reports and security alerts.
- To support you and respond to requests.
- To maintain and improve the Service, using aggregated or de-identified information where we can.
- To comply with law and enforce our terms.
We do not sell personal data, and we do not use Customer Data or Google or Meta user data for our own advertising.
6. Legal bases
Where the GDPR or UK GDPR applies to our controller processing, we rely on: performance of our contract with you (providing the Service); legitimate interests (security, fraud prevention, improving the Service, and marketing to business contacts, balanced against your rights); consent where we ask for it; and legal obligation. For data we process as a processor, the agency or business is responsible for the legal basis.
7. AI features and AI app connections
AI features. Some features send limited data to third-party AI model providers:
- keyword suggestions, report narratives, geo grid analyses, competitor analyses and roadmaps send business names, websites, keywords, locations, scan results and report figures;
- AI search visibility checks send business names, keywords and locations to AI assistants through our search data provider.
We don't send leads' contact details or website visitors' data to AI model providers. Our providers process this data under terms that don't allow it to be used to train their models, and we don't use Customer Data to train general-purpose AI models.
AI app connections. If you connect an AI app (such as an AI assistant) to your account, it can read, on your behalf, the data your login can see. It cannot change anything, and session recordings and heatmaps are excluded. The data you ask it to retrieve is sent to that app's provider and is handled under its privacy policy. We log each AI app request (user, tool and time) for security and keep those logs for 90 days. You can disconnect an AI app at any time in Settings.
9. The shared fraud network
To recognise fraud that moves between businesses, we combine fraud signals from all websites using our script. Identifiers such as IP addresses, IP ranges, device fingerprints, emails and phone numbers are converted to salted, one-way hashes before they enter the network, alongside non-identifying features of each visit and labels such as "fake lead" or "real customer". An agency can see a count band (for example, "sent to 5 or more other businesses") but never another agency's visitors, leads or which businesses were involved.
10. International transfers
We are based in and host the Service in the United States. If you use the Service from elsewhere, your data will be transferred to and processed in the United States. Where the law requires, we use appropriate safeguards such as standard contractual clauses.
11. How long we keep it
| Data | Kept for |
|---|---|
| Account and Customer Data | While the account is active. After an agency account closes: read-only for 90 days, then archived (no longer updated or accessible) until one year after closing, then permanently deleted, with notice to the agency and its clients before each step. Kept longer only where law requires. |
| A client's data after it disconnects from an agency | Read-only for the client for 90 days. The agency keeps the leads and results it collected while connected. |
| Connected account tokens | Until disconnected or the account closes. |
| Raw website visit data | 13 months. |
| Heatmap page snapshots | 90 days. |
| Session recordings | 30, 60 or 90 days as configured; deleted 7 days after an agency's paid period ends; 90-day maximum. |
| IP lookups cache | 24 hours. |
| AI app request logs | 90 days. |
| Hashed fraud-network signals | As long as useful for fraud detection; they cannot be used to identify a person directly. |
| Billing records | As long as tax and accounting law requires. |
12. Security
We protect data with encryption in transit (TLS) and at rest for connection tokens (AES-256-GCM), row-level security that isolates each agency's data, role-based access, optional two-factor authentication, signed webhooks and monitoring. No system is perfectly secure; if we learn of a breach affecting your data we will notify you as the law requires. More on our security page.
13. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete or port your personal data, to object to or restrict processing, to withdraw consent, and to complain to a data protection authority. Agency users can update most information in their profile and settings. To make a request about data we control, email [email protected]; we will verify the request and respond within the time the law requires.
If your data is held by an agency or business that uses Agency Pilot — for example as a lead or a visitor to their website — please contact that business. If you contact us, we will pass the request on and assist them.
14. US state privacy rights
Residents of California and other US states with comprehensive privacy laws may have rights to know, access, correct and delete personal information, and to opt out of its sale, sharing for cross-context behavioural advertising, or use for targeted advertising. We do not sell personal information or share it for cross-context behavioural advertising, and we do not use sensitive personal information to infer characteristics. You may use an authorised agent, and we will not discriminate against you for exercising your rights. For Customer Data we act as a service provider to the business concerned.
15. Children
The Service is for businesses and is not directed at children under 13 (or under 16 where that is the relevant age). We do not knowingly collect their personal data, and agencies may not use the tracking script on sites directed at children.
16. Changes
We will update this policy as the Service changes and show the date at the top. For material changes we will notify account owners by email or in the app before they take effect.
17. Contact
Privacy questions and requests: [email protected], or by mail to Devtech, LLC, an Ohio limited liability company doing business as Agency Pilot, 3416 Erhart Road, Litchfield, Ohio 44253.
