Privacy Policy
Effective August 11, 2026
This policy explains how aematic ("aematic", "we"), a platform operated by Lifeguard Technology, Inc., handles personal information in connection with the aematic platform and the aematic.ai website.
The two roles we play
Read this section first. It determines which of the rest applies to you.
As a controller. When you visit aematic.ai, contact us, or use the aematic platform as a customer, we decide how your information is used. We are responsible directly to you, and the rest of this policy describes what we do.
As a processor. Our customers are brands that advertise. They install our measurement script on their own websites, and we process the resulting information on their instructions in order to measure their advertising. In that case the brand decides what is collected and why. They are responsible for the privacy notice and consent on their site, and if you want to exercise your rights over that information, you should contact the brand whose website you visited. We help them respond, but we do not act on their data on our own initiative. The terms on which we process data for our customers are set out in our Data Processing Addendum.
Information we collect as a controller
When you use the aematic platform. Your name, work email address, the organization you belong to, and your role. Authentication is handled by Clerk, and we do not store your password. We also record how you use the product, so we can improve it.
When you visit aematic.ai. Standard web analytics, and anything you submit through a form, such as a sign-up or contact request.
When you email us. Your message and contact details.
Information we process on behalf of our customers
When a brand installs our measurement script on their website, we receive the following about visitors to that brand's site:
- Pages viewed, the referring website, and timestamps
- Device type, operating system, and browser
- Country and region. We use the visitor's IP address to determine these and then discard it. We do not store IP addresses collected by our script.
- A first-party device identifier, which lets us connect an advertisement click to a later purchase on the same device
- Advertising click information, such as campaign parameters and the time of the click
- Conversions, such as an order or a sign-up, including the value and currency
- Hashed identifiers. Where a brand sends us an email address or account identifier, it must be hashed (SHA-256) before it reaches us. We do not accept raw email addresses, phone numbers, or similar direct identifiers through this pathway.
We do not collect payment card details, government identifiers, health information, biometric information, or precise location. We do not record keystrokes, form contents, or screen sessions.
A brand may separately choose to send us conversion data from their own servers. If they include optional fields such as an IP address or user agent, we store and forward those as sent. We never request or derive them ourselves.
How we use information
- To provide, operate, and secure the aematic platform
- To measure advertising performance for the brand whose site the data came from
- To communicate with customers about their account
- To improve our products, including through aggregated and de-identified data that does not identify any individual or any customer
- To meet legal obligations
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use the information we process for our customers to build profiles for anyone else, and one customer's data is never used to benefit another.
Who we share information with
We use a small number of service providers. All are United States entities, and all data stays in the United States.
- Google Cloud, for all hosting, storage, and computing
- Cloudflare, which sits in front of our data collection endpoint to provide encryption, denial-of-service protection, and rate limiting. Traffic passes through Cloudflare; it is not stored there.
- Clerk, for account authentication
- Anthropic and Amazon Web Services, for the AI features that generate campaign plans and reports
- OpenAI, the advertising platform we manage campaigns on. Where a customer enables it, we forward their conversion data to OpenAI so their advertising can be measured.
- Sentry, for error monitoring on our own application
- Amplitude, for product analytics on our own application
- Slack, for internal operations
- Stripe, for invoicing our customers
We may also disclose information where the law requires it, or in connection with a merger or acquisition, in which case this policy continues to apply until you are told otherwise.
How long we keep it
- Website behavioral events: at least 90 days. These are deleted in monthly batches rather than individually, so depending on when an event occurred it may be held up to roughly 120 days.
- Conversion and attribution records: for as long as we work with the customer, then deleted when their account is closed
- Platform account information: for as long as the account is active
When a customer leaves, their data is deleted on a defined schedule, including a short recovery window in case the closure was a mistake. Deleted information can persist in our encrypted backups for up to 14 days before those backups expire.
How we protect it
Information is encrypted in transit and at rest. Access is limited to the small number of our staff whose role requires it, with multi-factor authentication required. Our databases are not reachable from the public internet. We maintain a written security program covering access control, change management, incident response, backups, and vendor review.
No system is perfectly secure. We maintain a written incident response plan, and if a security incident affects information we hold, we notify the affected customer promptly so they can take their own steps.
Your choices and rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, and to object to or restrict certain uses. Texas, California, and several other states provide these rights. We will not discriminate against you for exercising them.
If you use the aematic platform or visited aematic.ai, contact us at info@aematic.ai. We acknowledge requests within 5 business days and respond within 30 days. We verify your identity through the email address on your account, and we will not ask you for additional documents.
If you visited a brand's website that uses our measurement script, contact that brand. They control the information and we act on their instructions. If you contact us instead, we will point you to them and, where we can identify them, let them know you reached out.
One practical note. The information we hold on behalf of brands is keyed to a device identifier and to hashed identifiers, not to names or email addresses. We can locate records from an email address by hashing it, but we cannot search by name.
Cookies and similar technologies
Our measurement script sets a first-party identifier on the website of the brand that installed it. That brand controls whether and when the script loads, including through any cookie banner or consent tool they use. If you want to prevent it, use that brand's consent controls or your browser's cookie settings.
Our script does not currently respond to browser Do Not Track headers or Global Privacy Control signals. Consent is managed by the brand whose site you are on.
Children
aematic is a business product and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.
Where we operate
We are a United States company. Our staff, our infrastructure, and our service providers are all in the United States, and we do not transfer personal information outside it. We do not currently offer our services outside the United States.
Changes
If we make a material change to this policy, we will update the effective date above and notify customers by email. Continued use after a change means you accept the updated policy.
Contact
Privacy questions and rights requests: info@aematic.ai
Security matters: security@aematic.ai
Lifeguard Technology, Inc.
924 E 7th Street, Suite 200
Austin, TX 78702