Privacy policy
How attn:wise processes personal data, in accordance with the GDPR. This covers the public site at attnwise.com and the signed-in application.
Last updated: September 2026
1. Controller
The controller within the meaning of the GDPR is:
Attention Fox KG
Dominik Berger, MA MSc
Lindengasse 56/18-19
1070 Vienna, Austria
Phone AT: +43 670 3015063
Email: […@…]
2. What attn:wise does
attn:wise analyses advertising creatives. You upload an image, the service computes attention maps and quality signals with machine-learning models, and an AI model writes a report with recommendations. Optional features let you describe your brand and target audiences, simulate audience reactions, connect a Meta Ads account and share reports by link. This policy explains which personal data each of these steps touches and where it goes.
3. Hosting and server logs
The site and the application are hosted by Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. Vercel delivers content via data centers including EU locations; a transfer to the United States cannot be ruled out (see section 17).
When you access the service, technical data (IP address, timestamp, user agent, requested URL) is processed in server logs. This data is not combined with other data sources and is deleted after 30 days at the latest, unless there is a legitimate interest in longer retention, for example security analysis during an attack. The legal basis is Art. 6 (1)(f) GDPR (legitimate interest in providing and securing the service).
4. Early access waitlist
If you join the waitlist on the public site, we store the email address you enter, the company name if you provide one, and which form on the page you used. We use this to contact you when a place opens. The form is protected against automated submissions by a hidden field and a rate limit (section 13).
Joining the waitlist also records one product analytics event (section 11) that carries a one-way hash of your email address, never the address itself, so we can count sign-ups without identifying you in the analytics tool.
The legal basis is Art. 6 (1)(b) GDPR (steps taken at your request prior to entering into a contract). We keep the entry until you ask us to remove it or until the waitlist is retired.
5. Accounts and sign-in
To use the application you need an account. You can sign in with an email address and a password, or with a one-time sign-in link sent to your email address. Passwords are stored only as a salted hash by our authentication provider (Supabase, section 8) and are never visible to us. We process your email address to authenticate you, to send account emails such as sign-in links, password resets and workspace invitations, and to contact you about the service.
Account emails are sent by the authentication provider's mail service. The legal basis is Art. 6 (1)(b) GDPR (performance of a contract).
6. Workspaces, members and invitations
Every account receives a workspace and can be invited into others. Members of a workspace can see each other's email address and everything stored in that workspace. When an owner invites someone, we store the invited email address together with an invitation token, and the authentication provider sends the invitation email; the token expires and the invitation can be revoked at any time.
The legal basis is Art. 6 (1)(b) GDPR (performance of a contract) and Art. 6 (1)(f) GDPR (legitimate interest in collaboration features).
7. Creatives, context and the reports we produce
The creatives you upload, the context you enter about them (platform, format, goal, industry, audience, notes), your brand profile, brand knowledge documents and learned brand notes, your target-audience descriptions, and the results we produce (attention maps, overlays, scores, indicators, reports, recommendations, simulation outputs, PDF exports) are stored in your workspace so that you can return to them. The synthetic personas used in audience simulations are generated by an AI model from your audience descriptions; they do not represent real people.
We do not use your creatives or reports for advertising, and we do not train models on them. Anonymous aggregate statistics are described in section 14. Your content is technically accessible to the members of your workspace and, for support and troubleshooting, to the controller. If a creative contains personal data of third parties, you are responsible for being allowed to upload it.
The legal basis is Art. 6 (1)(b) GDPR (performance of a contract).
8. Processors involved in producing a report
Producing a report requires sending the creative and its context to specialised providers. Each acts as a processor under a data processing agreement:
- Supabase Inc. (authentication, database, file storage). The database and storage instance for this service is located in the European Union (Frankfurt am Main, Germany). Uploaded creatives, derived images and all workspace data are stored there. Supabase also delivers the account emails described in section 5.
- Modal Labs, Inc., USA (GPU model inference). Your creative is fetched via a short-lived signed link and run through attention, aesthetic, composition, object and emotion models. Modal receives the image and returns numeric results and derived images; it does not store your creatives beyond the computation.
- Anthropic, PBC, USA (AI report generation). The creative, the attention overlay, the context you entered and your brand context are sent to Anthropic's Claude API to produce the report, the recommendations, and, in the audience simulation, the synthetic personas and their reactions. Under Anthropic's commercial API terms this data is not used to train Anthropic's models.
- Inngest, Inc., USA (job orchestration). Inngest coordinates the steps above and stores the state of each step (identifiers, storage paths, scores and report text) for retries and troubleshooting. The image files themselves are not passed through Inngest.
- Vercel Inc., USA (hosting and application runtime), as described in section 3.
9. Ad platform connection (Meta Ads)
A workspace owner can connect a Meta Ads account. In that case we receive an access token from Meta, store it encrypted, and use it to list ad accounts and pull ad metadata (ad names and identifiers, the creative images, and delivery metrics such as impressions and click rates) so that ads can be imported into the library and their performance shown next to the analysis. Meta Platforms Ireland Limited processes your data under its own terms; the connection can be removed in the workspace settings at any time, which deletes the token.
The legal basis is Art. 6 (1)(b) GDPR (performance of a contract at the request of the workspace owner).
10. Share links
You can share a single analysis by a link that expires automatically and can be revoked at any time. For each such link we count how often it was opened and when it was last opened, without recording who opened it. A campaign report can be shared by a password-protected link; the password is stored only as a hash and is never returned to the browser. After a viewer enters the correct password, a signed cookie (section 15) keeps the report unlocked on that device for 24 hours.
Anyone holding a link can view the shared report without an account, which is the purpose of the feature. The legal basis is Art. 6 (1)(f) GDPR (legitimate interest in a functioning sharing feature).
11. Product analytics (PostHog, server-side only)
We use PostHog Cloud EU, a service of PostHog Inc., hosted in the European Union (Frankfurt am Main, Germany), to understand whether the product works: whether analyses start, complete or fail, how long they take and what they cost us, whether new workspaces reach their first completed report, how audience simulations run, and how many people join the waitlist.
These events are sent from our servers, not from your browser. There is no analytics script on any page, no analytics cookie, no session recording and no page-view tracking. Events are identified by internal identifiers (user, workspace and analysis IDs) or, for the waitlist, by a hash of the email address. The legal basis is Art. 6 (1)(f) GDPR (legitimate interest in operating and improving the service). No transfer to third countries takes place.
12. Error monitoring (Sentry)
To detect and fix failures we use Sentry, a service of Functional Software, Inc., USA. When an error occurs in the application, a report with the technical context of the request (stack trace, URL, browser type, the affected identifiers) is sent to Sentry. Request bodies larger than four kilobytes and fields that look like credentials are removed before sending. Sentry does not set cookies. The legal basis is Art. 6 (1)(f) GDPR (legitimate interest in a reliable service).
13. Abuse protection (rate limiting)
To protect the service against automated requests and abuse, we use Upstash Redis, operated by Upstash, Inc., USA. For the waitlist form and for share-link password attempts, your IP address is stored as a counter key for a few minutes; for signed-in actions, the counter is keyed by your user or workspace ID instead. These counters are not used for anything else and expire automatically. The legal basis is Art. 6 (1)(f) GDPR (legitimate interest in protecting our systems).
14. Benchmarks (aggregate statistics)
To tell you how a creative compares to others, we compute distribution statistics (percentiles) of scores across all analyses on the platform, optionally grouped by campaign goal or industry. A group is only published once it contains at least 30 analyses, and the statistics contain no creatives, no workspace identifiers and no personal data. The legal basis is Art. 6 (1)(f) GDPR (legitimate interest in providing reference values).
15. Cookies and local storage
This service uses only technically necessary cookies. There is no cookie banner because there is nothing to consent to: no tracking, advertising or profiling cookies are set at any point, and no analytics script runs in your browser.
- Authentication cookies set by our authentication provider (names beginning with "sb-"), which keep you signed in.
- A cookie named "share_verified", set only after you unlock a password-protected shared report, valid for 24 hours and scoped to that report.
- A local storage entry named "attnwise.campaigns.view", which remembers whether you prefer the card or the list view of your campaigns. It stays in your browser and is never transmitted to us.
16. No browser tracking, no advertising, no decisions about you
We do not use tracking pixels, session recording, heat mapping of our own pages, advertising networks or social media plugins. We do not sell or share personal data. The reports the service produces are analyses of advertising creatives; there is no automated decision-making or profiling of individuals within the meaning of Art. 22 GDPR.
17. Transfers to third countries
Vercel, Modal, Anthropic, Inngest, Sentry, Upstash and Supabase Inc. are based in the United States, although the database and storage used for this service are located in the European Union. To the extent that personal data is transferred to the US, this is done on the basis of the EU-US Data Privacy Framework, where the provider is certified, or otherwise on the basis of the EU Standard Contractual Clauses (Art. 46 (2)(c) GDPR). You have the right to request a copy of these safeguards.
18. Retention and deletion
We keep your account and its content for as long as your account exists. You can delete individual creatives together with their analyses, reports and share links yourself in the library. You can ask us to delete your account at any time by emailing the address in section 1; we then delete the account and the workspaces you solely own, including their creatives and reports, within 30 days. Server logs are deleted as described in section 3, waitlist entries as described in section 4, rate-limit counters after a few minutes, and share links when they expire or are revoked.
19. SSL/TLS encryption
For security reasons and to protect the transmission of confidential content, this service uses SSL/TLS encryption. You can recognize an encrypted connection by the fact that the browser's address bar starts with "https://".
20. Your rights
You have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR)
- Right to rectification or erasure (Art. 16, 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to object to processing (Art. 21 GDPR)
- Right to data portability (Art. 20 GDPR)
21. Right to lodge a complaint
To exercise your rights, an informal email to […@…] is sufficient. You also have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data. In Austria, this is the Austrian Data Protection Authority (https://www.dsb.gv.at).