Legal
Privacy Policy
Last updated 17 September 2026
This policy explains what Bigtam Console collects, why, and how to get rid of it. It is written for the product that exists today; where something is a limitation rather than a promise, it says so.
The service is operated by Bigtam Technologies Pvt Ltd, Pune, Maharashtra, India(“Bigtam”, “we”). Contact: privacy@gobigtam.com.
What we collect
Your account
When you sign in we store your email address and the sign-in identifier from your provider. We do not store a password — authentication is handled by Google or by a one-time email code.
Content you give us
Videos, images and product pages you upload or point us at, and everything the console produces from them: creative analyses, funnels, briefs and ad names. This is stored against your workspace and is visible only to members of your account.
Meta advertising data
If you connect a Meta ad account, we read — with the ads_read permission, and nothing else:
- the list of ad accounts your Meta login can access, so you can choose one;
- the ads in the account you chose, and their names;
- ad-level performance for those ads: spend, impressions, purchases, revenue, clicks and video views, by day.
What we do not read or receive: any personal information about people who saw or clicked your ads, your custom audiences or customer lists, your payment details, your Meta messages, or anything from a Page beyond the ads themselves. Meta does not give us individual-level data and we do not ask for it.
We never write. Bigtam cannot create, edit, pause, duplicate or delete a campaign, ad set or ad. We hold no permission that would allow it.
The waitlist
If you request access on this site we store the email address, and the brand, market and note you chose to give. We use it to contact you about access. It is not used for unrelated marketing and it is not sold or shared.
What we deliberately do not collect
We do not run third-party advertising or analytics trackers on this website, and we do not record your IP address or browser fingerprint when you join the waitlist.
How the Meta connection is secured
Connecting an ad account gives us an access token. How that token is stored is the most security-sensitive decision in this product, so it is worth being specific:
- The token is exchanged and stored entirely on our servers. It is never sent to your browser and never appears in a web page, a URL or a link.
- It is held in a separate database table that the application’s public key cannot read. Only privileged server-side code can reach it.
- Data is encrypted in transit, and encrypted at rest by our hosting provider at the storage layer. We do not claim application-level encryption of the token itself, because that is not what we have built.
- The token expires on Meta’s schedule, and you can revoke it at any time — see below.
Who else processes your data
| Provider | What it handles |
|---|---|
| Supabase | Database, authentication, file storage, server functions |
| Vercel | Hosting for this site and the console |
| Anthropic | The language model that writes analyses and briefs |
| Railway | Video processing (transcription and frame sampling) |
| Meta Platforms | The source of advertising data, when you connect an account |
Content you upload may be processed by these providers to produce the outputs you asked for. We do not sell your data, and we do not permit these providers to use it to train their own models on our behalf.
Where your data is held
Our infrastructure is hosted with the providers above, which operate internationally. Data may therefore be processed outside India and outside your own country. If you need to know the specific region for a deployment, ask us and we will tell you.
How long we keep it
- Account and workspace content: while your account is open.
- Meta tokens: until you disconnect, until you revoke access at Meta, or until they expire — whichever happens first.
- Imported performance figures: while the connection exists. They are aggregate numbers about your own ads, containing nothing about individual people.
- Waitlist entries: until you ask us to remove them.
After an account is deleted, backups roll off within 30 days. We may keep a minimal record of the fact of an account and its billing history where law requires it.
Your choices
Disconnect Meta
In the console, open Connections and press Disconnect. This asks Meta to revoke our access and deletes the stored token. You can also revoke it yourself in Facebook under Settings & Privacy → Settings → Business Integrations.
Delete your data
See Data deletion for what gets removed and how to ask. You can also request a copy of what we hold about you, ask us to correct it, or object to a particular use. Write to privacy@gobigtam.com and we will respond within 30 days.
Children
Bigtam Console is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children.
Changes
If we change this policy in a way that materially affects how your data is handled, we will email account holders rather than only updating the date at the top.
Contact
Bigtam Technologies Pvt Ltd, Pune, Maharashtra, India.
Privacy: privacy@gobigtam.com
Everything else: hello@gobigtam.com