Privacy Policy
Anneshy Royals Inc., doing business as OptimizePlus.
Effective date / last updated: August 14, 2026
DRAFT — PENDING LEGAL REVIEW
This document is an unreviewed first draft prepared for evaluation by a licensed attorney. It has not been reviewed, approved, or adopted, it is not legal advice, and it does not yet describe a policy you may rely on. Items marked [REVIEW] are open questions for counsel.
1Scope
This policy explains what personal information Anneshy Royals Inc., doing business as OptimizePlus ("we," "us"), collects through optimizeplus.agency, the client dashboard, and our services, what we do with it, who processes it on our behalf, where it is stored, and what choices you have.
It covers three groups of people: visitors to our website, clients and their users, and individuals whose business contact details appear in our prospect research (see section 11).
2Categories of personal information we collect
We collect the following categories of personally identifiable information, mostly because you give it to us:
- Account information. Your email address, a password (stored only as a cryptographic hash, never in readable form), your role, and the tokens used to verify your email or reset your password.
- Business profile. Business name, website address, contact email, phone number, brand details you provide, your credit balance, and a customer reference from our payment processor.
- Content you upload. Photographs and other media you supply — which in practice often include images of your premises, equipment, treatment or service areas, and before-and-after results, and can therefore depict identifiable people — plus logos, brand guidelines, and product information.
- Onboarding and questionnaire answers. Including commercially sensitive answers such as your stated monthly advertising budget.
- Audit and deliverable records. Audit scores, findings, generated reports and their PDF files, generated copy, images, video, and audio, and the records of the jobs that produced them (including internal file locations).
- Website lead information. If you submit our website lead form: your email address, optionally your phone number, whether you separately opted in to marketing calls or texts, the exact wording of the consent you were shown, the time you gave it, and your browser's user-agent string.
- Prospect records. Business contact records obtained from a third-party data provider, including names, business email addresses, and phone numbers. See section 11.
- Usage and cost records. Per-request records of which AI provider was called, how many tokens were used, and what it cost.
- Connected-account credentials. Where you connect a social scheduling account, the API credential for that connection.
- Server logs. Our web server records each request, including the visitor's IP address, the URL requested, and the user agent. See section 5 and section 8.
We do not collect payment card numbers. Card details are entered into and held by Stripe; we hold only a customer reference and the resulting billing records.
We do not intentionally collect sensitive categories such as government identifiers, precise geolocation, biometric identifiers, or health records. Note, however, that images you upload may incidentally contain information about identifiable individuals, and that clinical or before-and-after imagery may be regulated in your industry. You are responsible for the consents behind anything you upload.
3How we use personal information
- to create and operate your account and authenticate you;
- to produce the audits, content, and deliverables you request;
- to schedule or publish content to accounts you have connected;
- to take payment, meter credit usage, and issue invoices;
- to send transactional email such as verification, receipts, and job notifications;
- to provide support, troubleshoot, and investigate abuse or security incidents;
- to send marketing email or, where you separately consented, marketing calls or texts;
- to conduct business-to-business outreach (see section 11); and
- to comply with law and enforce our terms.
4Who we share it with
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We share it with the service providers below, who process it on our behalf so that we can deliver the service, and with professional advisors, or where required by law, or in connection with a merger or sale of the business.
Deliverables you ask us to publish are, by design, transmitted to the platform you connect.
| Provider | Purpose | What it receives |
|---|---|---|
| Anthropic | AI generation of all written deliverables, audits, and analysis | Prompts, your business profile, audit inputs, and up to roughly 3,000 characters of text read from your public website |
| OpenAI | AI image generation | Image prompts and, where you supply one, a reference image |
| AI video generation, business information lookup (Places), and publishing to a connected YouTube channel | Video prompts, business name and location queries, and video files and metadata you publish | |
| Higgsfield | AI image and video generation | Prompts and any source media used for the generation |
| Replicate | AI video and music generation | Prompts and any source media used for the generation |
| ElevenLabs | Synthetic voiceover and sound effects (we do not use voice cloning) | Script text to be voiced |
| Stripe | Payment processing and invoicing | Your name, email, billing details, and card details, which you provide to Stripe directly; we store a Stripe customer reference, not your card number |
| Resend | Sending email | Recipient email address and message content |
| Postfast | Scheduling and publishing social posts on your behalf | Post copy, media files, and the client email address associated with the connection |
| Hetzner Object Storage | File storage (bucket in Nuremberg, Germany) | Photographs you upload, audio, generated images and video, and generated PDF reports |
| Apollo.io | Business prospect research | Search criteria; returns business contact records including names, business email addresses, and phone numbers |
| Pixabay | Stock footage and image search | Search terms only |
| Telegram | Internal operational alerts to our own staff (for example, a job awaiting approval) | Job and approval details, which may include your business name |
| xAI (Grok) | Trend and topic research | Research queries |
| Reddit (public data) | Trend and topic research | Public content is retrieved; no personal information about you is sent |
This list reflects the providers actually in use as of the date above. We will update it here as it changes. [REVIEW: whether written data processing agreements are in place with each provider, and whether any of them require standard contractual clauses]
5Cookies, analytics, and tracking
This is unusually short, because there is unusually little to disclose.
- We use exactly one cookie. It is a session cookie named
mh_sessionthat keeps you signed in. It is set to be inaccessible to JavaScript, transmitted only over HTTPS, restricted to same-site requests, and it lasts up to 30 days. - We run no analytics. There is no Google Analytics, no Tag Manager, no Plausible, no PostHog, no Segment, and no comparable product on this site.
- We run no advertising or social pixels and set no third-party or cross-site tracking cookies. Nothing on this site profiles you for advertising.
Our web server does keep standard access logs, described in section 8. Those are server-side logs, not tracking technology, and they are not used to build a profile of you.
6Do Not Track
Some browsers send a "Do Not Track" (DNT) signal. There is no accepted standard for how a site must respond to it.
We do not track you across third-party websites or services for any purpose, including advertising, and we do not permit third parties to do so on our site. Because we perform no cross-site tracking to begin with, our behavior is the same whether or not your browser sends a DNT signal, and we therefore do not respond differently to it.
7Where your data is stored
Our application and database run on servers we operate. Files — the photographs you upload, audio you provide, media we generate, and the PDF reports we produce — are stored in an object-storage bucket physically located in Nuremberg, Germany. That means those files are stored in the European Union, even though we are a California company and you may be in the United States.
The service providers listed in section 4 process data in the locations described in their own terms, which may include the United States and other countries.
[REVIEW: cross-border transfer analysis in both directions — EU-stored content belonging to U.S. clients, and any EU-resident data subject whose data reaches this system]
8Security: what is protected, and how
We describe our security measures accurately rather than generically, so you can make your own judgment about what to upload.
What we do:
- All traffic to and from the service is encrypted in transit using TLS.
- Passwords are never stored in readable form. They are stored as Argon2 hashes, a memory-hard password hashing algorithm.
- API keys are stored only as a SHA-256 hash. The key itself is shown to you once at creation and cannot be recovered from us afterwards.
- The credential for a connected social scheduling account is encrypted at rest using AES-256-GCM with a per-record random initialization vector and an authentication tag.
- The session cookie is HTTP-only, secure, and same-site restricted, and sessions stop working after 30 days.
- Access to production systems is limited to our own personnel.
What we want you to know we do not do:
- The encryption described above covers one specific credential field, not your data generally. Other information — including email addresses, phone numbers, consent records, business information, invoices, the photographs you upload, and the media we generate — is stored without additional application-level or disk-level encryption at rest, protected instead by access controls on the systems that hold it.
- We do not currently offer multi-factor authentication. Account security depends on your password and on your control of your email account.
- We do not hold any security certification such as SOC 2 or ISO 27001, and we make no claim to one.
No system is perfectly secure, and we cannot guarantee absolute security. If you would prefer not to store a particular photograph or document on our systems, do not upload it.
[REVIEW: data-breach notification obligations (Cal. Civ. Code § 1798.82) and whether an incident response plan must exist before this policy is published]
9How long we keep it
We are being direct about this because it matters. We do not currently operate any automatic deletion of application data. Information in our system — accounts, client records, uploaded photographs, generated media, audit results, lead records, prospect records, invoices, and usage history — is retained indefinitely until it is deleted manually in response to a request or on our own initiative.
Specifically:
- Server access logs (which include IP addresses) are rotated daily and kept for 14 days, then discarded. This is the one retention period our systems enforce automatically. IP addresses are not stored in our application database at all.
- Sessions stop working 30 days after sign-in, but the session record itself is not automatically removed.
- Email verification and password reset tokens stop being usable after they expire, but the records are not automatically removed.
- Deleting a generated media job deletes the underlying files. The job record and its cost history are kept for billing and accounting purposes.
- Opting out of marketing records a suppression flag so that we stop contacting you. It does not, by itself, delete the underlying contact record, including a phone number. To have the record removed, ask us to delete it (section 10).
[REVIEW: a defensible retention schedule — how long each category should actually be kept, which records must be retained for tax or accounting purposes, and whether an enforced deletion mechanism must be built before this policy is published]
10Reviewing, correcting, and deleting your information
You can review and change most of your account and business information yourself by signing in to the dashboard and editing your profile.
For anything you cannot change yourself — including a copy of the information we hold about you, a correction, or deletion — email legal@optimizeplus.agency from the address on your account, tell us what you want, and we will handle it. These requests are processed manually by our team; there is no self-service export or deletion control in the product today, so please allow us time to complete them, and expect us to verify your identity first.
We may need to retain some information after a deletion request where we are required to keep it — for example, transaction records needed for tax and accounting, or records needed to resolve a dispute or enforce our agreements.
You can opt out of marketing email using the unsubscribe link in any marketing message, or by emailing us. Transactional messages about your account cannot be opted out of while your account is open. If you consented to marketing calls or texts, you can withdraw that consent at any time by replying STOP or by emailing us.
[REVIEW: whether the CCPA/CPRA applies to this business at its current size, and if so, which additional disclosures, response deadlines, verification standards, and a "Notice at Collection" are required; also whether any authorized-agent process is needed]
11Prospect and business contact data
Part of our business involves identifying businesses that may want our services. To do that, we obtain business contact records — names, business email addresses, and phone numbers — from a third-party data provider, Apollo.io. We did not collect that information from the individual directly, and the individual did not provide it to us.
We use it to send business-to-business outreach about our services. If you received a message from us and want it to stop, use the unsubscribe link or email legal@optimizeplus.agency, and we will record your opt-out. If you want your record deleted rather than suppressed, say so and we will delete it — as explained in section 9, an opt-out alone suppresses contact but does not by itself remove the record.
[REVIEW: legal basis and compliance posture for purchased prospect data, including CAN-SPAM, state anti-spam law, TCPA exposure for any phone use, and whether a "collected from another source" notice is required]
12Marketing consent for calls and texts
Where our website lead form offers marketing calls or texts, that consent is asked for separately and is never inferred from the fact that you gave us a phone number. The checkbox is not pre-selected. When you check it, we store the exact wording you agreed to and the time you agreed, so that the basis for contacting you is always auditable. If you do not check it, we do not treat your phone number as consent to be called or texted.
Message and data rates may apply. Reply STOP to opt out of texts at any time.
13Children
The service is intended for businesses and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us information, contact us and we will delete it.
14Third-party links
Our site and our reports link to third-party websites and platforms. We are not responsible for their privacy practices; read their policies.
15Changes to this policy
We may update this policy. When we do, we will post the revised policy at this URL and update the effective date at the top. We encourage you to review it periodically. If a change is material, we will take reasonable steps to notify you, which may include emailing the address on your account or displaying a notice in the dashboard.
16Contact us
Anneshy Royals Inc. (dba OptimizePlus)
28 Geary St., Suite 650
San Francisco, CA 94108
legal@optimizeplus.agency [REVIEW: confirm this mailbox is provisioned and monitored before publication]
See also our Terms of Service and our AI Content Disclosure.