1.Who we are
Autonomic is operated by Autonomic, the entity responsible for deciding how and why your personal data is processed when you use the platform at threezinc.ai (the “Service”).
For any question about this policy, or to exercise any of the rights described in section 12, write to api@threezinc.ai. We answer privacy requests within 30 days.
2.Data we collect
We collect three kinds of data, and each has a different origin.
| Category | What it includes | Where it comes from |
|---|---|---|
| Data you give us | Name, work email, organisation and role, brand details, product data, and billing details for paid plans. | You, at sign-up and while using the Service. |
| Data we collect automatically | Pages visited, features used, actions taken, approximate location from IP, browser and device type, and error diagnostics. | Your browser, as you use the Service. |
| Data the Service generates | Generated images and copy, listing audits, competitor and review analyses, credit usage and job history. | Produced for you by the platform. |
Payment card details are never seen or stored by us — card data is handled entirely by our payment processor.
Together with sections 3, 7 and 10, this table is our record of processing activities: what each category of data is, why we process it, who processes it on our behalf, and how long it is kept.
3.How we use your data, and on what basis
We use data only for the purposes below, each with the basis that makes it lawful.
| Purpose | Basis |
|---|---|
| Operating the Service: generating creatives, running audits, publishing listings you approve | Performance of our contract with you |
| Authenticating you and keeping accounts secure | Performance of our contract; our legitimate interest in preventing abuse |
| Billing, credits and invoicing | Performance of our contract; legal obligation |
| Service and security emails (job finished, publish failed, password changed) | Performance of our contract |
| Product analytics and diagnostics to improve reliability | Our legitimate interest in improving the Service |
| Marketing emails about new features | Your consent — withdrawable at any time from any such email |
| Responding to legal requests and keeping tax records | Legal obligation |
We do not sell personal data, and we do not use your data to target advertising to you or to anyone else.
4.AI processing
Generating a creative pack sends the inputs required for that job — your product data, brand guidelines, uploaded reference images and the instructions you write — to third-party AI model providers acting as our processors. Only what a job needs is sent.
- Your content is not used to train models. We use these providers under business or enterprise terms that exclude training on submitted data.
- Outputs are stored in your workspace so you can return to them, and are deleted with your account or on request.
- AI output is probabilistic and can be wrong. You review every asset before it is published anywhere — the Service never publishes anything you have not approved.
- Where you publish AI-generated content, any disclosure or labelling required by the destination platform or by law is your responsibility as the publisher.
The current list of model providers behind these features is available on request to api@threezinc.ai.
5.Meta platform data
When you connect a Meta Ads account, we request these permissions:
ads_read, ads_management, business_managementThey are used only to read your ad account data and display it inside your Autonomic dashboard, and to send outreach messages that you have explicitly triggered. We do not sell, share or use Meta data for advertising, and we do not use it for any purpose beyond providing the Service to you.
Your access token is stored encrypted and is used only to make authorised API calls on your behalf. Disconnecting the account from the platform revokes and deletes the token.
6.Amazon Selling Partner data
Commerce Studio can connect to a seller’s Amazon account in order to improve and publish their product listings. When you connect it, we request a single role:
Product ListingWith that role we read your listing attributes, images and the relevant Amazon product type definitions, and we write listing updates back only after you have reviewed and confirmed them.
We do not request, receive or store any customer personally identifiable information. No buyer names, addresses, phone numbers, email addresses or order data are accessed by our application. The Product Listing role does not grant access to that data, and we do not request any role that would.
Your Amazon refresh token is encrypted with AES-256-GCM before it is stored, using a key held in an isolated secret store that is never committed to source control or written to logs. Short-lived access tokens exist only in memory for the duration of a request. Each connected seller is served by an isolated runtime instance holding only that seller’s credentials, so one seller’s data is unreachable from another’s session.
You can revoke our application at any time from Amazon Seller Central. Our system detects the revoked grant, marks the connection revoked and stops all API calls for that account immediately. On request we delete the stored listing content and credentials associated with your account.
7.Service providers
We use a small set of providers to run the platform. Each processes data only on our instructions, under a contract that restricts what they may do with it.
| Provider | Purpose | Data involved |
|---|---|---|
| Cloudflare | Application hosting, database, object storage, CDN | All Service data |
| Clerk | Authentication and session management | Account identity, session metadata |
| Stripe | Payments and subscription billing | Billing identity, transactions (card data never reaches us) |
| AI model providers | Creative generation, audits and analysis | Job inputs and outputs (see section 4) |
| Email delivery | Transactional and service email | Email address, message content |
We do not sell or rent personal data. We disclose it outside this list only where the law requires it, or to protect the rights and safety of our users.
9.International transfers
The Service runs on globally distributed infrastructure, so your data may be processed in countries other than your own. Where data leaves its region of origin, the transfer is covered by an appropriate safeguard with the provider concerned — such as Standard Contractual Clauses — and the same protections described in this policy continue to apply.
10.How long we keep data
| Data | Retention |
|---|---|
| Account and workspace content | While your account is active, then deleted on account deletion or request |
| Generated creatives and job history | While your account is active, then deleted with the account |
| Connected-account tokens (Meta, Amazon) | Until you disconnect or revoke — deleted immediately on revocation |
| Invoices and financial records | As long as tax and accounting law requires |
| Product analytics | Up to 24 months, in aggregate form |
| Security and access logs | At least 90 days |
| Application error logs | Up to 90 days |
11.Security
We maintain a documented internal policy covering how data is classified, handled, retained and disposed of, and the technical controls that protect it. The measures below are the parts of it that affect you directly.
- All traffic is encrypted in transit with TLS; stored data is encrypted at rest.
- Third-party credentials are additionally encrypted with AES-256-GCM using keys held in an isolated secret store, never in source control and never written to logs.
- Data is scoped to your organisation, and every request is checked against your organisation before any record is returned.
- Access to production systems is restricted to the engineers who need it.
- Security and access events are logged and monitored, and those logs are retained for at least 90 days.
Incident response. We maintain an incident response plan. If a security incident affects data belonging to a connected marketplace account, we notify the marketplace operator within 24 hours of becoming aware of it, and we notify affected customers and any relevant authority as required by law. Our response includes rotating the affected credentials and encryption keys, which invalidates stored tokens and requires the connection to be re-authorised.
No system can be guaranteed perfectly secure, and we do not claim otherwise.
12.Your rights
Subject to your local law, you can ask us to:
- confirm what personal data we hold about you, and give you a copy;
- correct data that is wrong or incomplete;
- delete your data;
- restrict or object to a particular use;
- export your data in a portable format;
- withdraw consent you previously gave, with no effect on prior processing.
Email api@threezinc.ai and we will respond within 30 days. If you are unhappy with our response, you may complain to the data protection authority in your country.
13.Account deletion
You can request deletion of your account at any time, from within the platform or by emailing us. Deletion removes your profile, workspace content, generated creatives, remaining credits and connected-account credentials.
Invoices and financial records are retained where tax law requires. Deletion cannot be undone, so export anything you want to keep first.
14.Children's privacy
The Service is built for businesses and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us data, write to api@threezinc.ai and we will delete it.
15.Changes to this policy
We may update this policy as the Service changes. For material changes we will give notice in the product or by email before they take effect, and the “last updated” date above will change. The current version always lives at this URL.
