Trust
Security at Magneety
Last updated: 13 September 2026 · Magneety EU Ltd.
Magneety holds the keys to accounts that can spend your money and read your customers' orders. This page says plainly how we protect them, what we do not do, and how to reach us if you find a problem.
1. Where your data lives
Magneety EU Ltd. is a Bulgarian company. The application and database run on Railway and Neon, files on Cloudflare R2. Where a sub-processor is outside the EU (AI models, error monitoring), transfers rely on the EU-US Data Privacy Framework or Standard Contractual Clauses. The full, dated list is in our Privacy Policy, section 8.
2. How connected accounts are protected
- Encrypted tokens. The access tokens for your ad accounts and store are encrypted at rest with a key that is not stored in the database. They are never shown in the app, never sent to your browser, and never included in exports.
- Least permission. We ask each platform only for the permissions the features you use need. You can disconnect any account in Settings, which deletes its token.
- Every write is logged. Every change Magneety makes on a connected account is recorded with the time, the change and the values before and after. Admins can view and export the log.
- Nothing spends without you. Budget changes, pauses and publishing happen because you scheduled, approved or enabled them. Read-only integrations, including the assistant connector for AI tools, cannot change anything on your accounts.
3. Your workspace
- Every request is scoped to your workspace. Access reviews of cross-workspace and unauthenticated access were carried out in June and September 2026 with no confirmed findings.
- Passwords are hashed, never stored. Sign-in with Google is available. Sessions can be revoked from every device at once in Settings.
- Shared report links can be revoked at any time. Client logins in agency workspaces are view-only.
- You can export everything in your workspace from Settings, and delete the workspace yourself.
4. Operations
- The database is backed up continuously with point-in-time restore, plus a nightly encrypted copy stored with a separate provider and login.
- All traffic is encrypted in transit. Security headers, rate limits and a content security policy are in place on the site and the app.
- Errors are monitored around the clock. If we confirm a breach affecting your data we notify you within 72 hours, as GDPR requires.
5. What we do not do
- We do not sell or share your data with advertisers or data brokers.
- We do not use your content or your customers' data to train AI models, and our AI providers are contractually barred from doing so.
- We do not move budget or publish on your accounts on our own initiative.
6. Report a vulnerability
If you believe you have found a security issue, email [email protected]. We acknowledge reports within two business days and will not take legal action against good-faith research that avoids privacy violations, data destruction and service disruption. A machine-readable version of this policy is at /.well-known/security.txt.
7. Questions
Anything else about security or data: [email protected].
Magneety EU Ltd. · 5 Ekzarh Yosif I Str., 2nd floor, Office 1, 9300 Dobrich, Bulgaria