Skip to content
AngryBoss — AngryBoss home
ProductsPricingFeaturesSign in
Get started

AngryBoss

AI-powered marketing observability across every channel.

Product

  • Products
  • Pricing
  • Features
  • FAQ

Company

  • About
  • Contact
  • alert@angryboss.io

Legal

  • Privacy Policy
  • Terms of Service
  • Refund Policy

© 2026 AngryBoss. Sole Proprietor Tserkovnyi Daniil Albertovych · Individual Tax ID (RNOKPP / ІПН) 333414951.

Hvardiitsiv-Shyronintsiv St., bldg. 63a, apt. 21, Kharkiv, Ukraine · Hosted in European Union (Ireland).

Privacy Policy

Effective date: 27 July 2026.

This Privacy Policy explains how AngryBoss ("we", "us", or "our") collects, uses, discloses, and protects personal data when you visit our marketing website and use our software-as-a-service platform (the "Service"). It also describes your rights and choices.

We provide the Service globally; our primary data hosting location is in the European Union (Ireland). We use encryption in transit and at rest for our primary production systems.

If any translated version of this Policy conflicts with the English version, the English version controls.

Table of Contents

  1. Who we are and how to contact us
  2. Scope
  3. Personal data we collect
  4. How we use personal data
  5. Payment processing
  6. Where your data is processed
  7. How we share personal data
  8. Security
  9. Data retention and deletion
  10. Cookies, pixels, and analytics
  11. Your rights, choices, and data exports
  12. Roles and responsibilities (Controller vs. Processor)
  13. Third-party services and links
  14. Children
  15. Changes to this Policy
  16. How to delete your account
  17. Contact

1. Who we are and how to contact us

Data controller: Sole Proprietor (Individual Entrepreneur / ФОП) Tserkovnyi Daniil Albertovych (Ukrainian: ФОП Церковний Данііл Альбертович), operating under the trade name "AngryBoss".

Registered address: Hvardiitsiv-Shyronintsiv St., bldg. 63a, apt. 21, Kharkiv, Ukraine (Ukrainian: вул. Гвардійців-Широнінців, буд. 63а, кв. 21, м. Харків, Україна).

Tax identifier: Individual Tax ID (RNOKPP / ІПН) 333414951. Not registered as a VAT payer.

Contact:

  • Email: alert@angryboss.io — single mailbox during MVP for privacy requests, legal correspondence, abuse reports, and DPO inquiries. We may add specialized addresses (e.g., dpo@, legal@) later; this Policy will be updated when that happens.
  • Phone: +380 50 164-1157 (Ukrainian business hours).

If we act as a processor on your behalf (see Section 12), your organization is the controller for those datasets.

2. Scope

This Policy covers:

(a) our marketing website (including contact forms, newsletters, and public marketing pages described in BLOCK-14); (b) our web application where customers register, create projects, connect advertising / analytics / messaging accounts, and receive notifications and analytics; (c) optional public marketer-profile pages and any future aggregate-analytics features, if and when those features are activated (see Sections 3 H and 3 I).

Certain features analyze advertising campaigns, web analytics, Facebook Page and Instagram messaging and comments that you choose to connect. Authorized users can also initiate supported actions through the Service, such as replying to a message or comment, or pausing and restoring a Meta advertising campaign. We send alerts through channels you configure, such as email or Telegram.

3. Personal data we collect

We collect the following categories of data, depending on how you interact with the Service:

A. Account & profile data

Identifiers (name, email, password hash), language and timezone, organization / company name, roles, and preferences.

B. Subscription, billing, and tax data

Plan tier, status, invoices, tax country, currency, and limited payment metadata. Card details are processed by our payment processors (see Section 5); we do not store full card numbers.

C. Service content you connect or submit

When you connect external platforms, we process the data categories you authorize. Today this typically includes (list may evolve as we add platforms — see integrations.md for the live list):

  • Meta (Facebook Ads, Facebook Pages, Instagram Business / Creator accounts, Page Messenger, Instagram Direct, Facebook Page comments, and Instagram comments);
  • Google Ads, Google Analytics 4;
  • Microsoft Clarity;
  • TikTok Ads Manager (post-MVP);
  • Telegram Business (post-MVP);
  • Pinterest / Amazon / LinkedIn / Microsoft Ads / Shopify (Phase 2, when added).

For each connected platform we may process account, Page, Instagram-account, campaign, ad, post, media, message, comment, and thread identifiers; performance metrics; creative assets (images, video frames, and captions); conversation or comment content and metadata; sender information made available by the platform; and audience or attribution data. We limit this processing to the permissions you grant and the features you use.

When an authorized AngryBoss user initiates or confirms an action, we may use the connected platform's official API to send a message reply, a private reply, or a supported comment action, or to pause or restore a Meta advertising campaign. These actions are not performed as independent advertising decisions by AngryBoss. Access can be revoked in the connected platform's settings or in AngryBoss, although disconnecting a platform does not by itself erase historical data already stored in the Service; see Section 9 for deletion options.

D. Analytics inputs

Text and media content (including conversation transcripts, comments, ad creatives, web pages, and similar material) that you ask us to analyze with automated tools, including AI-based classifiers, embeddings, and language models. Retention depends on the feature and the reason the data is needed. We do not represent that every input is automatically deleted immediately after an analysis or that every derived result is already anonymous. See Section 9.

E. Usage, device, and log data

IP address, device / browser information, pages viewed, timestamps, referring / exit URLs, diagnostic logs, and security / performance events.

F. Cookies and similar technologies

We use cookies and similar technologies to remember settings and measure performance. See Section 10.

G. Communications

Your messages to us (support, feedback) and the channels you configure for alerts (e.g., email or messaging bots).

H. Optional public profile (Phase 2 feature)

If you choose to publish a public marketer profile page (planned post-MVP), you control which honest, real-data aggregates from your workspaces are made publicly visible (e.g., "managed >$100K in Meta Ads spend over the last 12 months"). Each dimension is opt-in and independently toggleable. The profile is an identity artifact, not a marketplace. Data shown on the profile is derived from your own workspace data — we do not expose your customers' or competitors' raw data.

I. Future aggregate analytics

We may introduce market benchmarks or forecasts based on data that has been de-identified and combined across a sufficient number of sources. This capability is not currently active as a generally available market dataset. Before activating it, we will validate safeguards designed to prevent identification of an individual, customer, or workspace and will update this Policy where required. We do not currently treat customer-derived aggregates as exempt from a valid deletion request merely by asserting that they are anonymous.

We do not intentionally collect special categories of data (e.g., health, religion) through the Service.

4. How we use personal data

We use personal data for the following purposes and on the following legal bases (EEA / UK):

  • Provide and secure the Service — create and manage accounts, authenticate users, operate features, provide customer support, prevent abuse, and ensure continuity (contract, legitimate interests, legal obligations).
  • Process connected-platform data on your behalf — ingest, analyze, and present metrics, messages, comments, deviations, and alerts from data sources you connect (contract; we typically act as processor for this item — see Section 12).
  • Carry out user-initiated platform actions — after an authorized user initiates or confirms the action, send supported Facebook Page or Instagram message and comment replies, carry out supported comment actions, and pause or restore a Meta advertising campaign through Meta's official APIs (contract; we typically act as processor for this item).
  • AI-assisted insights — transform your authorized inputs into analytics, classifications, and summaries; identify anomalies; surface notifications (contract, legitimate interests, or consent where required). AI outputs are accompanied by source citations and confidence indicators (see Terms §6).
  • Customer-owned AI agent foundation — structure the data flowing through your workspaces so that you, the customer, can later export it for training your own AI agents and assistants (see Section 11). We do not use your raw customer data to train AngryBoss-owned production models. We may use de-identified or aggregated data to improve the Service.
  • Future aggregate analytics — if this capability is activated, produce de-identified and sufficiently aggregated benchmarks or forecasts only after the safeguards and legal basis described in Section 3 I have been validated.
  • Billing and subscription management — process payments, detect fraud, handle taxes (contract, legal obligations, legitimate interests).
  • Lifecycle communications — use SendPulse to send activation, onboarding, billing, and product-update emails, and use Telegram Messenger to deliver bot notifications only when you configure that channel (contract for transactional communications; legitimate interests or consent where required for other communications). Non-transactional email includes an unsubscribe option where required.

We do not make decisions that produce legal or similarly significant effects based solely on automated processing. Alerts, severity scores, and AI-generated insights are for operational guidance and remain subject to human oversight.

5. Payment processing

Payments are processed by one or more independent payment processors, currently including WayForPay, WesternBid, and Hutko (the specific processor depends on your billing currency, region, and the plan you select). Each payment processor acts as an independent controller for payment card data. We receive only limited billing metadata from them (e.g., card brand, last four digits, transaction status, billing country) to manage your subscription, invoices, and refunds.

For details on how each processor handles personal data, please refer to their respective privacy documentation. Links are surfaced at checkout time.

6. Where your data is processed

Hosting: Primary application and database storage is located in the European Union (Ireland, AWS eu-west-1, via Supabase). Background workers run in the European Union (Germany / Falkenstein, Hetzner). Static frontend assets and edge functions are served globally via Vercel's CDN.

International transfers: Some service providers, payment processors, or support personnel may be located outside your country. Where we transfer personal data from the EEA / UK / Switzerland to countries without an adequacy decision, we rely on Standard Contractual Clauses (SCCs) and additional safeguards.

7. How we share personal data

We share personal data only as needed for the purposes described in this Policy. Our current core service providers and processors include:

  • Vercel Inc. for application hosting and content delivery;
  • Supabase Pte. Ltd. for database, authentication, and storage services;
  • Hetzner Online GmbH for background processing infrastructure;
  • Anthropic, PBC and OpenAI OpCo, LLC for AI-assisted analysis when you use an AI-enabled feature;
  • SendPulse Inc. for account, service, and lifecycle email communications; and
  • Telegram Messenger Inc. for bot and notification delivery when you choose to connect Telegram.

We also share personal data with:

  • Payment processors (WayForPay, WesternBid, Hutko, and any successor / additional provider we add) for billing and fraud prevention.
  • Analytics and measurement tools on our marketing site and app (see Section 10) where permitted by law.
  • Third-party platforms you connect — we access and process data from those platforms based on your authorization and their terms; we are not affiliated with them.
  • Future aggregate analytics recipients — only if the capability described in Section 3 I is activated and the released information has passed the validated safeguards described there.
  • Public marketing artifacts — when you (a) choose to publish a public marketer profile (Section 3 H) or (b) generate and share a shareable notification card or achievement artifact, the content you choose to share becomes publicly accessible at the URL you share. You control what is shared and can revoke each share at any time from your account.
  • Legal and compliance recipients — if required by law, court order, or to protect rights, safety, and integrity.
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets. We will continue to protect data consistent with this Policy and provide notice of any material changes.

We do not sell personal information, and we do not share it for cross-context behavioral advertising where prohibited by law. Where applicable (e.g., in certain U.S. states), you may opt out of "sharing" via the controls described in Section 11 and your cookie preferences in Section 10.

8. Security

We use administrative, technical, and organizational measures designed to protect personal data, including:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256); secrets management; network isolation.
  • Access controls (least privilege, multi-factor authentication for internal staff, logging and monitoring).
  • Row-level security on the database such that each workspace's data is logically isolated and access is gated by authenticated workspace membership.
  • Data minimization and separation of environments (development / staging / production).
  • Vulnerability management and periodic risk assessments.
  • Automated dependency scanning and infrastructure-as-code reviews.

No system is 100% secure; if we learn of a breach, we will inform affected users and regulators as required by law (within the statutory time limits set by GDPR Art. 33–34 and equivalent regimes).

9. Data retention and deletion

We retain personal data only for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements.

Retention depends on the data category, the feature you use, the duration of the customer relationship, and any legal or security requirement. Where a retention or deletion lifecycle is not yet automated, a trained operator completes the required steps using restricted access and a review checklist. We do not claim that a generic automated cleanup or permanent-deletion process is already active for every data category.

Connected-platform data and analytics inputs are retained while needed to provide the feature, investigate reliability or security issues, meet a valid legal requirement, or respond to your instructions. You can disconnect a platform to stop future access. To request erasure of stored data, use the account-deletion process below, the Meta-specific process below, or contact us.

Verified Meta data-deletion requests

Meta may send AngryBoss a signed data-deletion request when a Facebook user removes the app or asks Meta to delete data associated with it. We cryptographically verify the request before acting on it. For a verified request, we erase the Meta Platform Data attributable to that Facebook identity and the affected Facebook Page or Instagram resources that can be safely traced to it, disarm and unlink those resources, and destroy recoverable credential material associated with Meta and related platform identifiers. We do not guess when ownership or credential lineage is ambiguous, and we do not delete unrelated workspace data or another customer's assets.

When you enable email or Telegram alerts, AngryBoss sends selected alert content, at your direction, to the mailbox or Telegram destination you configured. A verified Meta deletion request erases AngryBoss's local notification records and delivery logs for the attributable Meta data. It cannot recall an email already delivered to a recipient-controlled mailbox and does not delete an entire mailbox, Telegram account, chat, or unrelated messages. Copies already delivered may remain at that destination under its provider and account controls. We do not currently claim callback-triggered deletion of provider-side transmission logs where the provider offers no exact deletion mechanism that we have implemented.

This Meta process does not delete the person's entire AngryBoss account or unrelated data from other connected services. Meta receives a confirmation code and status URL after the verified request has been processed. A request for which we hold no attributable Meta Platform Data is recorded as having no data to erase.

Account deletion

You can request deletion in Settings → Account → Delete account. The request signs you out, removes your workspace access immediately, and places the account into a 30-day soft-deletion grace period. During that period, recovery is available only through verified support at alert@angryboss.io.

After the grace period, permanent deletion is completed through an operator-reviewed process. We are working toward an automated lifecycle, but we do not represent it as active until it has been implemented and verified. The operator reviews the request, the affected records, and any applicable legal hold before completing the purge.

Some limited records may be retained for longer where required or permitted by law, including invoices, tax and transaction records, security or fraud-prevention records, and information needed to establish or defend legal claims. Access to retained records is restricted and they are used only for those purposes. Some residual copies may also remain temporarily in restricted backups until those backups expire; they are not returned to ordinary product use.

10. Cookies, pixels, and analytics

We use cookies and similar technologies to run the Service and measure performance. Our marketing site is designed to favor privacy-respecting, first-party analytics by default. Third-party measurement is only enabled where it materially helps us serve you (e.g., conversion attribution for paid acquisition campaigns) and, where required by law, only with your consent.

The current list of cookies and similar technologies in use, with their purposes and durations, is available at the Cookie Settings link on our site. The list may evolve over time.

Where required by law, we obtain your consent before setting non-essential cookies. Consent is collected through our own self-hosted cookie consent component built into the marketing site — we do not rely on a third-party consent management platform, so your consent data never leaves our infrastructure. You can manage preferences via the Cookie Settings link in the site footer at any time, and through your browser settings (e.g., blocking third-party cookies or using Global Privacy Control, where supported). Disabling certain cookies may impact functionality.

11. Your rights, choices, and data exports

Your rights depend on your location but may include:

EEA / UK / Switzerland (under GDPR / UK GDPR): the rights to access, rectify, erase, restrict, object, and data portability; and to withdraw consent at any time (without affecting prior lawful processing). You may also lodge a complaint with your supervisory authority.

Certain U.S. states (e.g., California / CPRA): the rights to know / access, delete, correct, and to opt out of sale / sharing (including cross-context behavioral advertising). We do not sell your personal information. To exercise rights or opt out, use the in-product controls, your cookie preferences (Section 10), or email alert@angryboss.io. We do not discriminate against you for exercising your rights.

Brazil (LGPD) and other jurisdictions: similar rights may apply. Contact us to exercise them.

Data exports

AngryBoss is being designed to support structured, machine-readable exports for portability, customer analytics, and customer-owned AI tools. Self-service export availability currently varies by data type and feature. If the export you need is not available in the product, contact alert@angryboss.io. After verifying your identity and authority, we will provide an appropriate commonly used machine-readable format where required by law and technically feasible.

How to make a request

To make a rights request, contact alert@angryboss.io from the email associated with your account. We may ask for information to verify your identity and respond within the time limits set by law (typically one month under GDPR).

12. Roles and responsibilities (Controller vs. Processor)

For account, billing, product telemetry, our own marketing data, and any aggregate service analytics that we may lawfully create for our own purposes, we act as a data controller.

For data ingested from third-party platforms you connect (e.g., business pages, ad accounts, messaging data) and customer content you submit for analysis, we generally act as a data processor and process such data solely on your documented instructions, to provide the Service.

A Data Processing Addendum (DPA) incorporating the applicable Standard Contractual Clauses is available upon request. If you require a signed DPA, contact alert@angryboss.io.

13. Third-party services and links

The Service integrates with third-party platforms at your request. Your use of those platforms is governed by their own terms and privacy policies. We are not responsible for their practices. You can revoke our access to those platforms at any time in their settings or in our app.

14. Children

Our Service is not directed to children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided personal data to us, contact alert@angryboss.io and we will take appropriate steps to delete it.

15. Changes to this Policy

We may update this Policy from time to time. We will post the updated version with a new effective date and, if changes are material, notify you via the Service or by email. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy. A running list of material changes is maintained in our public _changelog.md.

16. How to delete your account

At any time, go to Settings → Account → Delete account. This immediately signs you out and removes workspace access, starts the 30-day grace period, and schedules the account for the operator-reviewed permanent-deletion process described in Section 9. You may also email alert@angryboss.io for assistance, including if you cannot sign in or need to recover an account during the grace period.

17. Contact

If you have questions about this Policy or our data practices, contact alert@angryboss.io.


Summary of key points (non-contractual)

  • Global service, EU hosting (Ireland), encryption at rest and in transit.
  • Multi-payment-provider model (WayForPay / WesternBid / Hutko depending on currency and region); we never store full card numbers.
  • Privacy-respecting first-party analytics by default; third-party measurement only with consent.
  • We do not train AngryBoss-owned production AI models on your raw customer data.
  • Facebook Page and Instagram messages and comments are processed only for connected features; replies, comment actions, and Meta campaign pause / restore actions require an authorized user to initiate or confirm them.
  • Verified Meta deletion callbacks erase attributable Meta Platform Data and destroy recoverable Meta credential material without deleting unrelated customer data.
  • Account deletion removes access immediately, includes a 30-day grace period, and is completed through an operator-reviewed permanent-deletion process until the automated lifecycle is active.
  • Future aggregate analytics are not represented as active today; safeguards will be validated before any such capability is launched.
  • Product analytics and improvement — understand feature usage, fix issues, improve user experience (legitimate interests; de-identification / aggregation wherever possible).
  • Marketing (limited) — measure campaign performance on our site and reach audiences in permitted regions (consent where required; opt-out options in Section 11 and Section 10).
  • Compliance — comply with applicable laws, requests from authorities, and enforce our terms (legal obligations, legitimate interests).