Privacy Policy

Last updated: September 15, 2026

This Privacy Policy describes Our policies and procedures on the collection, use, and disclosure of Your information when You use the Service and informs You about Your privacy rights and how the law protects You.

We use Your Personal Data to provide and improve the Service. By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy.

Interpretation and Definitions

Interpretation

The words with capitalized initial letters have meanings defined under the following conditions.

Definitions

  • Account: A unique account created for You to access our Service.
  • Advertising Data: The data We retrieve, on a Customer's behalf and with that Customer's authorisation, from the advertising platforms the Customer connects to the Platform (Google Ads, Meta). Advertising Data is a subset of Customer Data.
  • Affiliate: An entity that controls, is controlled by, or is under common control with a party.
  • Company: Historian ApS, Strandvejen 157 1 th, 2900 Hellerup.
  • Cookies: Small files placed on Your device containing browsing details.
  • Country: Denmark
  • Customer: A business that has entered into an agreement with the Company for the use of the Platform.
  • Customer Data: The data We process on behalf of a Customer, on that Customer's instructions, in order to provide the Platform. It includes data collected from visitors to the Customer's own website and Advertising Data.
  • Device: Any device that can access the Service, such as a computer, cellphone, or tablet.
  • Personal Data: Any information that relates to an identified or identifiable individual.
  • Platform: The Historian application made available to Customers at https://app.historian.ai, including the analyses, reports and AI-generated insights provided through it.
  • Service: The Website and the Platform, taken together.
  • Website: Historian.ai, accessible from https://historian.ai
  • You: The individual accessing or using the Service.

Collecting and Using Your Personal Data

Types of Data Collected

Personal Data

While using Our Service, We may ask You to provide personally identifiable information, including but not limited to:

  • Email address
  • First name and last name
  • Company name
  • Usage Data

Usage Data

Usage Data is collected automatically and may include:

  • IP address
  • Browser type and version
  • Pages visited, time and date of visit
  • Device information

Tracking Technologies and Cookies

We use Cookies and similar tracking technologies to analyze and improve Our Service. These include:

  • Browser Cookies: Small files stored on Your Device.
  • Web Beacons: Small electronic files used for statistics.

The cookies and similar technologies We use on Our own Website, and the purposes they serve, are described in this section. You can set Your browser to refuse cookies; some parts of the Website may then not function as intended.

Use of Your Personal Data

The Company may use Personal Data for various purposes including:

  • To provide and maintain our Service
  • To manage Your Account
  • To contact You
  • To manage Your requests

Data We Process on Behalf of Our Customers

Most of the data handled through the Platform is not our own. Our Customers are businesses that use Historian to understand how their websites and their advertising perform. For that data, the Customer decides why and how it is processed, and We process it only on the Customer's documented instructions.

Our roles. We act as a data processor for Customer Data, including Advertising Data. We act as a data controller only for personal data We collect about visitors to Our own Website at historian.ai, and about the individuals who represent Our Customers. The terms governing Our processing on a Customer's behalf — including confidentiality, security, sub-processors and assistance with data subject requests — are set out in the data processing agreement that forms part of the Customer's contract with Us.

Website interaction data

Where a Customer installs Our recording script on its website, We collect and process, on that Customer's behalf, information about how visitors interact with that website: the pages viewed and their full URLs, clicks and other on-page interactions, movement between pages, and e-commerce events such as items added to a cart and completed purchases. We also process technical information sent by the visitor's browser: IP address, user agent, referring URL, device type and screen dimensions.

Because We record the full URL of the pages a visitor views, that URL may contain click identifiers that an advertising platform appended when the visitor clicked an ad — for example gclid (Google) or fbclid (Meta). We use these identifiers solely to attribute a visit to the advertising that led to it.

Advertising Data

Where a Customer connects an advertising account to the Platform, We retrieve and store, on that Customer's behalf, the data needed to relate the Customer's advertising to what happens on its website. From the advertising platforms Our Customers connect (Google Ads, Meta) this includes:

  • the structure of the advertising account: campaigns, ad groups, ads, keywords, asset groups and the assets used in ads;
  • the creative content of the ads themselves, including ad text, final URLs, image assets and video thumbnails, which We download and store so that reports remain accurate after the advertising changes;
  • daily performance figures per ad group: impressions, clicks, cost, conversions and conversion value;
  • click identifiers (such as gclid) provided by the advertising platform, together with the ad, keyword, campaign and date they belong to, which We use to attribute website visits to specific advertising;
  • a raw copy of each day's retrieved data, stored as a single JSON snapshot per Customer website per day, so that reporting can be rebuilt without querying the advertising platform again.

We also store the authorisation credentials (access and refresh tokens) that allow Us to retrieve this data. They are stored so that the connection can keep working, are never shared with third parties, and are deleted when the connection is removed.

Advertising Data is business data about a Customer's advertising. It is not used to profile individual visitors, is not combined across Customers, and is never sold. We do not use Customer Data to train publicly available AI models.

Google User Data

When a Customer connects a Google Ads account, Historian requests read access to that account through Google's OAuth (scope https://www.googleapis.com/auth/adwords). Historian never creates, edits, pauses or deletes anything in Google Ads.

How We protect it

  • In transit: all traffic to historian.ai and app.historian.ai uses HTTPS (TLS). HTTP is redirected to HTTPS.
  • At rest: Google Ads data and the OAuth credentials that give access to it are stored in Microsoft Azure SQL Database and Azure Storage in the North Europe (Ireland) region, where all data is encrypted at rest.
  • Access: data from a Google Ads account is shown only to users of the Customer that connected it. Only the Customer's owners and administrators can connect or disconnect an account. Historian staff access it only to operate and support the service.
  • Credentials: OAuth credentials are kept on Our servers, are used only to read the account the Customer selected, and are never shared with third parties.
  • Retention: Google user data is deleted within 30 days after the account is disconnected, the Customer relationship ends, or the Customer asks Us to delete it (see Data deletion).

AI processing. Historian uses the Google Gemini API (Google LLC) to analyse a Customer's own data, including Google Ads data, and present the results to that Customer. We use Gemini's paid service, under which Google does not use prompts or responses to improve its products. We use no other AI provider, no AI gateway or aggregator, and no self-hosted models. Data from one Customer is never used to produce output for another.

Limited Use. Historian's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data — raw, aggregated, anonymized or derived — to develop, improve or train generalized or foundational AI or machine learning models.

Retention, Deletion and Transfer

Data We hold as a controller. We retain personal data We collect through Our own Website for as long as it is needed for the purpose it was collected for, and to comply with Our legal obligations.

Customer Data and Advertising Data. We keep Customer Data, including Advertising Data, for as long as the Customer relationship lasts. The history is the product: We do not delete it on a rolling schedule, and We prefer to say so plainly rather than state a shorter period than We keep.

We delete Customer Data within 30 days:

  • when the Customer relationship ends;
  • when the Customer, or a data subject through the Customer, asks Us to delete it;
  • when an advertising connection is disconnected — even if the Customer relationship continues. Withdrawn consent means the platform data goes.

Deletion covers both places the data is held: Our databases and Our file storage, including the raw daily snapshots and the ad creatives We have downloaded.

Reconnecting does not restore the history. We build the record of a Customer's advertising day by day, as We capture it. Where an advertising platform still makes past figures available, We may retrieve those figures again — but the detailed history We keep, including how the advertising account changed over time and the click-level attribution, starts again from the day of reconnection. That is a real cost of disconnecting, and We state it here so that it is not a surprise.

Transfer. The Company is established in Denmark and processes data within the European Union. Where a service provider processes data on Our behalf, it does so under a written agreement that imposes the same obligations on that provider. The sub-processors We use, and the locations in which they process data, are identified in the data processing agreement that forms part of Our Customer contracts.

Delete Your Personal Data

You have the right to ask Us to delete personal data We hold about You.

Deletion requests are handled by Us directly. Write to contact@historian.ai and We will carry out the deletion and confirm when it is done. There is no self-service deletion in the Platform: a request reaches a person at Historian, who performs the deletion.

Step-by-step instructions — what to write, what is deleted, how long it takes, and how a Customer disconnects an advertising account — are set out on Our data deletion page: https://historian.ai/data-deletion.

If You are a visitor to a website operated by one of Our Customers, that Customer is the data controller for the data collected there. You may contact Us at the address above, and We will forward Your request to that Customer and act on their instructions.

Disclosure of Your Personal Data

Your Personal Data may be disclosed:

  • During business transactions
  • To comply with legal obligations
  • To protect against legal liability

Security of Your Personal Data

While We strive to protect Your data, no method of transmission over the Internet is 100% secure.

Children's Privacy

Our Service does not address individuals under 13. If We discover that We have collected data from a child under 13, We will delete it.

Links to Other Websites

Our Service may contain links to third-party websites. We advise reviewing their Privacy Policy.

Changes to this Privacy Policy

We may update Our Privacy Policy from time to time. Changes will be posted on this page.

Contact Us

If you have any questions about this Privacy Policy, you can contact us: