Privacy Policy

This Privacy Policy explains how Sume, Inc. ("Sume", "we", "us", or "our") collects, uses, shares, and protects information when you use Sume websites and documentation, Sume Agents, Sume Studio and Formats, workspaces and organizations, the Sume dashboard, Sume APIs, API keys and webhooks, the Sume MCP server and CLI, media generation services, and related account, billing, or support services (together, the "Services").

Request data deletion, including data associated with your Meta Ads connection.

Last updated: September 13, 2026

Information we collect

  • Account and authentication information, such as name, email address, user identifiers, profile image, and sign-in method. Sume uses Clerk for authentication and currently offers Google and GitHub sign-in.
  • Workspace and organization information, such as workspace name and handle, organization membership and roles, invitations you send or accept, and the email addresses used to invite teammates. Sume uses Clerk Organizations for team accounts.
  • Google Sign-In information, if you choose Google OAuth, such as basic profile and email information needed to authenticate your account.
  • API, MCP, and developer information, such as API key metadata, key prefixes, scopes, authorized MCP clients and their grants, CLI session state, dashboard settings, request identifiers, job identifiers, webhook endpoints and delivery attempts, usage records, concurrency state, and rate-limit state.
  • Content you submit to the Services, such as prompts, scripts, product images, uploaded media and chat attachments, voice and text-to-speech input, reference files, URLs, avatar inputs, brand assets, Format inputs, and other materials used for agent and generation workflows.
  • Brand and product information, such as the website URL you connect and the product titles, descriptions, page URLs, and product images Sume retrieves from publicly reachable pages on that site, plus other public pages and public media you ask an agent to fetch or import.
  • Agent activity, such as chat threads and messages, agent tool calls and their results, spend approval decisions, scheduled runs, automation definitions and run history, and drafts of emails the agent prepares for your approval.
  • Generated outputs and related metadata, such as media artifacts, job status, result metadata, usage events, and public-safe URLs or asset records.
  • Technical and security information, such as IP address, user agent, device and browser information, log events, diagnostics, crash reports, abuse signals, and product analytics.
  • Billing information, such as plan and subscription status, generation and agent balances, prepaid credit top-ups, usage charges, invoices, payment status, and billing contact details. Payments are processed by Stripe; Sume does not receive or store full payment card numbers.
  • Cookies, session storage, local storage, and similar technologies used to keep you signed in, remember preferences, secure the Services, measure usage, and improve product experience.

How we use information

  • To authenticate users, maintain sessions, and secure accounts, workspaces, and organizations.
  • To create and manage API keys, webhook deliveries, MCP authorizations, workspaces, organization membership and invitations, brands, product catalogs, agent threads, Formats and their runs, scheduled runs, automations, jobs, generated outputs, usage records, support requests, and dashboard features.
  • To process agent requests and generation requests and deliver media outputs through the Sume dashboard, API, MCP server, and CLI.
  • To fetch the public web pages and public media you or your agent ask us to retrieve, and to keep the resulting product and reference material available in your workspace.
  • To send email you approve to the primary email address on your account, and to send administrative and service notices.
  • To apply your spend approval settings, estimate and record generation and agent spend, and keep balances accurate.
  • To operate, monitor, debug, secure, and improve Sume websites, agents, dashboard, APIs, MCP server, and media generation services.
  • To enforce rate limits and concurrency limits, prevent abuse, investigate security issues, and protect users and infrastructure.
  • To process payments, maintain balances, produce invoices, and administer billing or refunds where applicable.
  • To provide support, communicate service updates, and comply with legal obligations.

Agent activity and automated processing

Sume Agents run on your instructions and generate records as they work. We store chat threads, attachments, tool calls and results, spend approvals, and run history so you can review what an agent did, so scheduled runs and automations can continue on the schedule you set, and so we can debug failures, bill usage accurately, and investigate abuse. Scheduled runs and automations can process information and produce output when you are not present; you can review and remove them from the Agents surface. Agents may draft email for your approval and send it only to the primary email address on your Sume account.

Workspaces and organizations

Sume accounts can be personal or part of an organization. When you work inside an organization, the threads, Formats, brands, assets, API keys, jobs, usage records, and billing activity created in that workspace are visible to other members according to their role, and organization administrators can manage membership, access, and billing. Inviting a teammate means sharing their email address with Sume and our authentication provider so the invitation can be delivered and accepted. If you join an organization you did not create, an administrator controls that workspace and may retain or remove its content after you leave.

Google user data

Sume uses Google OAuth through Clerk for sign-in. The current sign-in flow requests only basic profile and email information as needed to identify you, secure your account, and operate your session. Sume does not request access to Gmail, Google Drive, Calendar, Contacts, Docs, Sheets, Slides, or other Google Workspace content. Sume does not sell Google user data or use it to train generalized AI models. Sume's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Service providers

We use service providers to operate the platform. By category these cover authentication and organization management (Clerk), web hosting and delivery (Vercel), application and database infrastructure, caching and queueing, object storage and media delivery, payments and invoicing (Stripe), product analytics (PostHog and Vercel Analytics), error and performance monitoring (Sentry), transactional email, customer support, sandboxed execution for agent tooling, and AI model providers for image, video, avatar, speech, and language generation. These providers may process information only as needed to provide services to Sume, comply with legal obligations, or as otherwise permitted by law. We do not disclose confidential model routing or workflow implementation details in public product responses.

Analytics, cookies, and operational logging

We use product analytics to understand how the Services are used and to improve them, including PostHog and Vercel Analytics. Analytics capture is explicit rather than broad page autocapture, and where session replay is enabled it is configured to mask text input. We also collect operational logs, traces, and error reports through monitoring tools such as Sentry so we can detect, debug, and fix failures; these records can include request and job identifiers, account or organization identifiers, IP address, and technical context attached to an error. Cookies, session storage, and local storage keep you signed in, remember preferences, secure the Services, and measure usage. You can control cookies through your browser, though blocking some cookies may break sign-in or other features.

Generation inputs and outputs

Agent and generation workflows may require Sume or its providers to process prompts, scripts, product images, uploaded files and attachments, voice input, media URLs, references, retrieved web content, generated outputs, and operational metadata. Do not submit sensitive personal information unless it is necessary for your authorized use of the Services. Inputs and outputs may be retained as needed to provide the Services, keep your asset library and threads available, reproduce or debug issues, enforce policies, maintain billing and usage records, and meet legal obligations.

When we share information

Sume does not sell personal information and does not share it for cross-context behavioral advertising. We share information in the following situations:

  • With service providers that help us operate, secure, bill, support, analyze, or improve the Services.
  • With your organization members or administrators, if you use the Services as part of an organization or team account.
  • With MCP clients and applications you authorize, within the access you grant them, until you revoke that access.
  • With payment processors and financial service providers for billing, invoices, tax, fraud prevention, and dispute handling.
  • When required by law, legal process, or to protect the rights, safety, security, and integrity of Sume, users, providers, or the public.
  • In connection with a merger, financing, acquisition, reorganization, or similar corporate transaction, subject to appropriate safeguards.

Security and retention

We use administrative, technical, and organizational safeguards designed to protect information, including access controls and encryption in transit. No method of transmission or storage is perfectly secure. We retain information for as long as needed to provide the Services, maintain account, thread, asset, and usage history, comply with legal obligations, resolve disputes, enforce agreements, investigate abuse, and maintain security. Retention periods may vary based on the type of data and the context in which it is processed.

Your choices

You may contact Sume to request access, correction, deletion, or export of personal information, subject to applicable law and security requirements. You can also manage account access from the dashboard, revoke API keys from the API keys page, revoke authorized MCP clients, change your spend approval settings, and pause or delete scheduled runs and automations from the Agents surface.

Data deletion

Request deletion of Sume or Meta-connected data

You can request deletion of personal data held by Sume, Inc., including data associated with your Meta Ads connection. A request about Meta-connected data is separate from closing your Sume account or deleting all content in a shared workspace.

How to request deletion

Email dev@sume.com with the subject “Meta data deletion request”. You can email us even if you no longer have access to Sume. Include:

  • Your Sume sign-in email.
  • Your workspace name or URL.
  • Whether your request concerns Meta-connected data or your wider Sume account, and the data you want deleted.
  • Relevant ad-account IDs, if helpful to locate the data (optional).

Do not send passwords, access tokens, one-time codes, or unnecessary identity documents. We may need to verify your identity and authority over the requested data before acting, particularly for a shared workspace.

What the request covers

Your request can concern connection credentials and identifiers, and Meta-derived data stored by Sume, including stored tool results and relevant thread content. Identify the records you want us to review. A request does not authorize deletion of other users’ data or all shared-workspace content.

This process concerns data held by Sume. It does not delete your original Meta ad account or campaigns, or copies held independently by Meta or other businesses. Our security and retention practices above also apply; deletion is not a promise of immediate removal from every backup or service provider’s systems.

Disconnect versus delete

In Integrations, Meta Ads → Disconnect stops Sume from using that connection. Disconnect does not delete historical chats or stored tool results. Request deletion of retained data separately using the email instructions above. Removing an app in Facebook or revoking an authorized Sume MCP client does not by itself delete historical Sume records.

What happens next and timing

We review your request and use the email conversation to acknowledge it, ask for any information needed to verify ownership and scope, and communicate completion or an update. Timing depends on the request and any verification needed. If there is a delay or data needs to be retained, we explain that in our response. Requests remain subject to applicable law and security requirements, as described above.

Contact and follow-up

For status questions, reply to your existing email conversation with dev@sume.com and refer to your original request.

International use

Sume may process and store information in the United States and other countries where Sume or its service providers operate. These countries may have data protection laws that differ from those in your location.

Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the date above and provide additional notice where required by law.

Contact

Questions about this policy can be sent to dev@sume.com. See also our About page and Terms of Service.