Privacy Policy
Effective Date: May 11, 2026
Data Collection
DREAMLABS ("we", "us", "our") operates TheLab, an AI-powered growth intelligence platform. We collect information you provide directly, including your name, email address, company name, and billing details when you create an account or request access. We also collect data automatically through your use of the platform, including usage analytics, device information, IP addresses, and browser type.
How We Use Your Data
We use your information to provide and improve TheLab's services, including generating performance insights, managing your account, communicating important updates, and ensuring platform security. We may also use anonymized, aggregated data to improve our AI models and product features.
Third-Party Services
TheLab integrates with the following third-party services to provide its core functionality. Each integration only accesses data you explicitly authorize:
- Meta (Facebook & Instagram) — Ad account data, campaign performance metrics, and spend data via the Meta Marketing API.
- Google Ads — Campaign performance, keyword data, ad creative metadata, and advertising spend metrics via the Google Ads API. Access is granted by you through Google OAuth using the
https://www.googleapis.com/auth/adwordsscope. We do not request write access; the integration is read-only. - TikTok Ads — Advertiser account data and campaign performance metrics via the TikTok Marketing API.
- Shopify — Order data, product information, and store analytics via the Shopify Admin API.
- Klaviyo — Email and SMS campaign performance data.
- Anthropic (Claude) — AI inference. To generate insights, recommendations, and creative analysis, we send relevant excerpts of your connected platform data — including Google Ads campaign metrics, keyword performance, and ad creative content — to Anthropic's Claude models. Anthropic processes this data under their commercial terms, does not use it to train their models, and retains inference inputs and outputs only for the period required to operate and abuse-monitor the API (currently up to 30 days, per Anthropic's published policy).
- Clerk — Authentication and user management services.
- Supabase — Database infrastructure and storage services.
Data Security
We implement industry-standard security measures to protect your data, including encryption in transit (TLS) and at rest, secure OAuth token storage, role-based access controls, and regular security audits. Access tokens for connected platforms are encrypted and stored securely. We do not sell your data to third parties.
Data Retention
We retain personal data and connected platform data for the duration of your active account. Upon account closure or a deletion request, we remove personal data and revoke connected platform tokens within 30 days. Anonymized, aggregated analytics may be retained indefinitely. Data we are legally required to retain (e.g., billing records) is kept for the period mandated by applicable law.
Your Rights
You have the right to:
- Access — Request a copy of the personal data we hold about you.
- Deletion — Request deletion of your account and associated data. Connected platform data will be removed from our systems.
- Export — Request an export of your data in a machine-readable format.
- Correction — Request corrections to inaccurate personal data.
- Disconnect — Revoke access to any connected third-party platform at any time from your dashboard, or by removing TheLab from your provider's permissions page (see "Revoking Google Access" below for the Google-specific flow).
Revoking Google Access
You can revoke TheLab's access to your Google Ads data at any time, either by disconnecting the integration from the TheLab dashboard or by visiting your Google Account permissions page and removing TheLab. When you revoke access, we immediately invalidate the stored OAuth refresh token and stop polling the Google Ads API for your account. Cached Google Ads data — campaign metrics, keyword performance, ad creative metadata — is deleted from our systems within 30 days. Aggregated, anonymized usage analytics that cannot be tied back to you or your Google account may be retained.
Cookies
We use essential cookies to maintain your session and authenticate your account. We also use functional cookies for OAuth state management during platform connections. We do not use third-party advertising or tracking cookies. You can manage cookie preferences through your browser settings.
Google API Services User Data Policy
TheLab's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, sell it, or transfer it for purposes unrelated to delivering and improving the features you have explicitly consented to.
Contact
If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at hello@dreamlabsagency.com.