Last updated: August 27, 2026
At DijiMagic ("DijiMagic", "we"), we take the security of your personal data seriously. This policy explains what data we collect when you use the DijiMagic platform, how we use it, how long we keep it, and your rights.
This policy applies to the services provided through the DijiMagic website and DijiMagic SaaS dashboard.
DijiMagic is a platform that helps users connect their ad accounts to view performance data, run reporting, and (where applicable) perform certain ad management actions.
3.1 Meta (Facebook, Instagram, WhatsApp) Integration
When a user connects their Meta account via Facebook Login, DijiMagic requests access to the following categories of data, each tied to a specific permission scope:
(a) Advertising Data (ads_read, ads_management, pages_manage_ads): Ad account identifiers, campaigns, ad sets, ads, budgets, bid strategies, targeting settings, and performance metrics (impressions, clicks, spend, conversions, ROAS).
(b) Page Data (pages_show_list, pages_read_engagement, pages_manage_posts): Facebook Page names, IDs, profile pictures, engagement metrics, published posts (text, images, videos, permalinks), and the ability to publish content (feed posts, Reels) to the user's own Facebook Page.
(c) Lead Data (leads_retrieval): Active lead generation forms associated with connected Pages, including form names, field configurations, and submitted lead entries (name, email, phone, and other fields defined by the advertiser).
(d) Business Data (business_management): Business Manager account identifiers and names, owned Pages, and owned WhatsApp Business Accounts; used to map organizational assets.
(e) Instagram Data (instagram_basic, instagram_content_publish): Instagram Business Account profile information (username, profile picture), published media (images, videos, captions, permalinks), and the ability to publish content (feed posts, Reels, Stories) to the user's Instagram Business Account.
(f) WhatsApp Data (whatsapp_business_management, whatsapp_business_messaging): WhatsApp Business Account identifiers, associated phone numbers (display number, verified name, quality rating), and the ability to create Click-to-WhatsApp (CTWA) ad destinations.
All Meta data is used exclusively to provide the ad management, reporting, and campaign creation features within the DijiMagic platform. Data is not transferred to third parties, sold, or used for purposes unrelated to the user's advertising operations.
3.2 Google Ads Integration
The user grants access to their Google Ads account via Google OAuth. Data accessed includes Google Ads customer account ID, ad entities such as campaigns/ad groups/ads, budget/settings, and performance metrics (e.g. impressions, clicks, cost, and related reporting fields). Access scope: Google Ads API (adwords scope).
3.3 Google Analytics Integration (GA4)
When a user connects their Google account, DijiMagic requests access to Google Analytics 4 data via the following OAuth scopes:
(a) analytics.readonly: Read access to GA4 account identifiers, property configurations, data streams, audiences, and report data (sessions, users, events, conversions, traffic sources).
(b) analytics.edit: Write access to create GA4 properties on behalf of the user, configure data streams, define custom event definitions, create audiences, and set up conversion goals; only when the user explicitly initiates these actions through DijiMagic's setup wizards.
All Google Analytics data is used exclusively to display analytics dashboards within DijiMagic and to perform user-initiated configuration actions. Data is never transferred to third parties, sold, or used for advertising purposes.
3.4 Google Tag Manager Integration
When a user connects their Google account, DijiMagic requests access to Google Tag Manager data via the following OAuth scopes:
(a) tagmanager.readonly: Read access to the user's GTM account identifiers, containers, workspaces, tags, triggers, variables, and version history; used to display the user's existing setup within DijiMagic's dashboard.
(b) tagmanager.edit.containers: Write access to create and modify tags (GA4 configuration, GA4 events, conversion tracking), triggers (page view, form submit, click events), and variables within the user's GTM container; only when the user explicitly initiates these actions through DijiMagic's setup wizards.
(c) tagmanager.publish: Permission to publish GTM container versions, only after the user reviews and approves DijiMagic-generated changes via in-app one-click action. Auto-publishing is never performed without explicit user action.
All Google Tag Manager data is used exclusively to display the user's GTM setup within DijiMagic and to deploy tags configured by the user. Data is never transferred to third parties or used for advertising purposes.
3.5 Gmail/Email Sending Integration
When a user connects their Gmail account in DijiMagic's Email Marketing module, DijiMagic requests access via the following OAuth scopes:
(a) gmail.send: Permission to send email messages (such as marketing campaigns, outreach sequences, reports, or notifications) that the user composes and explicitly initiates within DijiMagic, delivered from the user's own connected Gmail account.
(b) userinfo.email: Read access used only to display which Gmail account is connected.
DijiMagic uses the gmail.send scope exclusively to send user-initiated messages. DijiMagic does not read, access, store, modify, delete, or analyze the user's existing emails, inbox, drafts, labels, or contacts; the gmail.send scope only permits sending. Users can disconnect their Gmail account at any time, which revokes the stored authorization token and stops further sending. All Gmail data handling complies with the Google API Services User Data Policy, including the Limited Use requirements. Data is never transferred to third parties, sold, or used for advertising purposes.
4.1 Google API Services User Data Policy (Limited Use)
DijiMagic's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. Specifically: (a) Google user data is used only to provide and improve the reporting, monitoring, and campaign management features requested by the user within DijiMagic. (b) Google user data is not transferred to third parties except as necessary to provide or improve user-facing features, with the user's explicit consent, for security purposes, or to comply with applicable laws. (c) Google user data is not used for serving ads, including retargeting, personalized advertising, or interest-based advertising. (d) Google user data is not sold to any party. (e) Humans are not allowed to read Google user data unless the user has provided affirmative consent, it is necessary for security purposes, it is required to comply with applicable law, or the data is aggregated and anonymized for internal operations.
4.2 Meta Platform Policy Compliance
DijiMagic's use of data received from Meta Platform APIs (Facebook, Instagram, WhatsApp) complies with the Meta Platform Terms (https://developers.facebook.com/terms/) and Meta's Data Use Restrictions. Specifically:
(a) Meta user data is used solely to provide the advertising management, reporting, campaign creation, and analytics features that the user explicitly initiates within the DijiMagic platform.
(b) Meta user data is not sold, licensed, or transferred to any third party (including data brokers, ad networks, or analytics providers) for any purpose.
(c) Meta user data is not used for surveillance, profiling unrelated to advertising, credit or insurance eligibility decisions, employment screening, or any purpose unrelated to the user's own advertising operations.
(d) Lead form data retrieved via the leads_retrieval permission is accessed only on behalf of the Page owner who created the form and is displayed exclusively within the DijiMagic dashboard for that user's own use.
(e) Instagram account data is used only for campaign targeting (selecting Instagram accounts as ad destinations) and displaying published media for ad creative selection.
(f) WhatsApp Business Account data is used only to enable Click-to-WhatsApp ad creation and to verify phone number availability.
(g) Access tokens are stored securely in httpOnly cookies and server-side storage. Tokens are never exposed to client-side JavaScript or logged in plain text.
(h) When a user disconnects their Meta integration or deauthorizes the app, all stored tokens, account mappings, and cached data are revoked and queued for deletion within 90 days.
(i) Users may request immediate data deletion by contacting info@dijimagic.com or through the in-app data deletion flow.
4.3 Artificial Intelligence and Machine Learning
DijiMagic uses third-party AI services to turn the advertising performance data of the accounts a user connects into ad copy, creative suggestions and optimization recommendations. The following disclosures apply. (a) Google Workspace user data is never sent to an AI service. The gmail.send permission only allows DijiMagic to send messages the user has composed inside the product; DijiMagic cannot read, list or analyze the user's mailbox, and no mailbox content reaches any AI model. A file the user selects through the Google Drive picker is passed straight to that user's own Google Ads asset library and is not processed by any AI model. (b) No Google user data, whether raw, aggregated, anonymized or derived, is used to create, train, fine-tune or improve any foundational or generalized machine learning or artificial intelligence model, our own or a third party's. (c) Advertising performance records, for example campaign, ad group and metric data, may be sent to our AI providers for the single purpose of producing the recommendation the user has asked for inside the product. These providers are used under their commercial API terms, which state that data submitted through the API is not used to train their models. (d) DijiMagic runs no self-hosted or offline AI model; all AI processing takes place through the providers' hosted APIs.
Account linking and authentication; providing performance reports, KPI dashboards, and analytics; in-product debugging and support (sensitive information such as credit card, password, or tokens is not logged); security measures and prevention of misuse.
Google user data is kept only for as long as the feature the user asked for requires it. (a) Authorization data: OAuth refresh tokens are stored encrypted while an integration is connected. When the user disconnects an integration, the token is revoked with Google and erased from our database in the same operation, and further access stops immediately. (b) Reporting data: metrics retrieved from Google APIs are stored as a cache so that dashboards can be rendered without calling the API repeatedly; each refresh replaces the previous entry for the same report, and the cache is removed when the account is deleted. (c) Account data: the records a user creates in the product are kept while the account is open. (d) Deletion on request: a user may ask us to delete their data at any time at info@dijimagic.com, and we complete such requests within 30 days. Removing an integration or closing an account also stops any further collection.
We do not sell Google user data, and we do not share it with data brokers, advertising networks or any party for advertising purposes. Google user data is shared only in the following cases, and only to the extent needed to deliver a feature the user asked for. (a) Infrastructure providers that host the application and its database, acting as processors on our instructions. (b) AI providers, and only advertising performance records such as campaign, ad group and metric data, when the user asks the product to produce a recommendation or a creative; these providers operate under commercial API terms that prohibit the use of submitted data to train their models. Google Workspace data, such as Gmail or Drive content, is never included. (c) Where disclosure to a competent authority is required by law. No Google user data is transferred to any party for a purpose unrelated to the user's own advertising operations.
DijiMagic protects user data, including data obtained through Google APIs, with the following measures. (a) Encryption in transit: all traffic between the user's browser, DijiMagic servers and third-party APIs travels over HTTPS/TLS only; plain HTTP requests are permanently redirected to HTTPS and HTTP Strict Transport Security (HSTS) is enforced. (b) Encryption at rest: application data is held in a managed PostgreSQL database whose disks and backups are encrypted at rest with AES-256, and the encryption keys are protected by FIPS 140-2 compliant hardware security modules. (c) Additional encryption of credentials: OAuth refresh tokens and mail server passwords are encrypted again at the application layer with AES-256-GCM before they are written to the database; that key exists only in the server environment and is never kept in the database, in client-side code or in source control. (d) Access control: every table holding user data has row level security enabled with per-user policies, so a record can be read or changed only by the user who owns it. Administrative access to the production hosting, database and Google Cloud consoles requires two-step verification. (e) Server-side isolation: access tokens are handled only in server-side modules and httpOnly cookies. They are never exposed to client-side JavaScript, never placed in URLs and never written to logs in readable form. (f) Least privilege: DijiMagic requests the narrowest scope each feature needs. The Gmail integration, for example, holds the send permission only; the application contains no code path that can read, list, change or delete messages in a user's mailbox. (g) Revocation and deletion: when a user disconnects an integration, the stored authorization data is revoked and deleted and further access stops immediately. Users may request deletion of their remaining data at info@dijimagic.com.
You may submit requests regarding the processing of your personal data through the following channel: Email: info@dijimagic.com
This policy may be updated as needed. Updates will be published on this page.
E-posta: info@dijimagic.com