Legal
Last updated: 9 August 2026 · Maesto
Maesto (“Maesto”, “we”, “us”, “our”) is an Australian-based provider of an AI-assisted marketing platform. This policy describes what information we collect, how we use it, and the choices you have. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles; where the GDPR (EEA/UK) or CCPA (California) applies to you, we honour the rights those laws provide.
Account information — your name, email address and password (stored only as a salted hash by our authentication provider). Workspace information — your website address, brand context and files you add to your knowledge base, and workspace settings. Connected-platform data — when you connect an advertising account (currently Meta), we store the OAuth access token (encrypted at rest) and read campaign and performance data; we never see or store your platform password. Billing — payments are handled by Stripe; we store subscription identifiers and plan state, never card numbers. Usage and technical data — aggregate, privacy-friendly analytics about how the product is used, plus standard technical data such as browser type.
Lead and conversion events your systems send to Maesto, and contact lists you import, may contain personal information about your customers and prospects — names, email addresses, phone numbers. For that data, you are the data controller: you are responsible for having a lawful basis to collect and use it, including consent requirements under the Spam Act 2003 (Cth) for commercial electronic messages. We process it solely to provide the service to you, keep it isolated to your workspace, never sell it or use it for our own marketing, and delete it with your workspace.
Content you provide — your website content, knowledge-base items, campaign data — may be processed by our AI provider, Anthropic, to generate the analyses and recommendations the product shows you. Under our API agreement, this data is not used to train their models.
We use your data to provide and improve the Maesto platform, send transactional communications (e.g. approval notifications), respond to support requests, and analyse aggregate usage. We do not sell your personal data, and we do not use your data or your customers' data for our own advertising.
Our database and file storage (Supabase), hosting (Vercel), email delivery (Resend), payment processing (Stripe) and AI processing (Anthropic) are provided by companies that store and process data in the United States. By using Maesto you acknowledge that your information is stored and processed there. We take reasonable steps to ensure each provider protects your information consistently with Australian privacy law, and each is bound by its own contractual and security obligations.
We retain your data for as long as your account is active or as needed to provide services. You may request deletion of your account and associated data at any time by contacting privacy@maesto.ai. We will fulfil deletion requests within 30 days, subject to legal obligations such as billing and tax records.
You may request access to, or correction of, the personal information we hold about you at any time via privacy@maesto.ai. If you have a privacy complaint, contact us first and we will respond within 30 days; if you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (oaic.gov.au). Where the GDPR or CCPA applies to you, you may additionally have rights to deletion, portability and objection, which we honour on request.
We use Supabase (database, authentication and file storage), Vercel (hosting and aggregate analytics), Anthropic (AI inference), Stripe (payments), Resend (email delivery) and the advertising platforms you choose to connect (currently Meta). Each processes data only as needed to provide its service to us and is bound by its own privacy and security commitments.
By accessing or using Maesto, you agree to these Terms of Service. If you do not agree, do not use the platform.
Maesto grants you a limited, non-exclusive, non-transferable licence to use the platform for your internal business purposes. You may not resell, sublicence, or reverse-engineer any part of the service. You are responsible for all activity that occurs under your account.
You agree not to use Maesto to generate content that is illegal, deceptive, harassing, or in violation of any platform's terms (including Meta, TikTok, and Google). You are solely responsible for the advertising content and campaigns you create or publish using our platform, and for ensuring any electronic messages you send comply with applicable law, including the Spam Act 2003 (Cth).
Paid plans are billed monthly in advance. Fees are non-refundable except where required by law. We reserve the right to change pricing with 30 days' notice. Free trials do not require a credit card and convert to a paid plan only with your explicit consent.
Either party may terminate the agreement at any time. On termination, your access to the platform ceases and your data will be deleted within 90 days, unless you request earlier deletion.
Maesto is provided “as is.” To the maximum extent permitted by law — and without excluding any consumer guarantees under the Australian Consumer Law that cannot be excluded — we are not liable for indirect, incidental, or consequential damages arising from your use of the platform. Our aggregate liability shall not exceed the fees you paid in the 12 months preceding the claim.
These terms are governed by the laws of Australia, and you submit to the non-exclusive jurisdiction of the Australian courts.
We take the security of your data seriously. Below are the measures we implement to protect your information.
Maesto runs on Vercel and Supabase (PostgreSQL), both of which are SOC 2 Type II certified. Data is encrypted at rest (AES-256) and in transit (TLS).
We use Supabase Auth with email-and-password authentication. Passwords are stored only as salted hashes, never in plaintext, and password resets are performed through secure emailed links.
All database tables implement Row-Level Security (RLS) enforced at the database layer — not just in application code — so users can only access data belonging to their own workspace.
API keys are stored as encrypted environment variables and are never exposed in client-side code or logs. Connected ad platforms are authorised via OAuth; the resulting access tokens are encrypted at rest with AES-256-GCM. We never handle your platform passwords.
If you discover a security vulnerability, please report it responsibly to security@maesto.ai. We will acknowledge receipt within 48 hours and aim to resolve confirmed vulnerabilities within 30 days.
Questions about this policy? Contact us at privacy@maesto.ai.