Legal

SEMBL Privacy Policy.

Effective date  July 15, 2026 Last updated  July 31, 2026

1. Who we are

SEMBL is a brand standards, content creation, marketing analysis, and reporting platform operated by Between Pixels, LLC, doing business as Between Pixels (“Between Pixels,” “SEMBL,” “we,” “us,” or “our”).

Address 22 Trammell Street SW, Suite B
Marietta, Georgia 30064
United States
Privacy inquiries info@betweenpixels.com

2. Scope of this policy

This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you:

use the SEMBL application, its hosted pages, APIs, or related services;
visit a SEMBL or Between Pixels website that links to this policy;
connect a third-party account or advertising account to SEMBL;
communicate with Between Pixels about SEMBL; or
have business contact information processed through an authorized SEMBL client account.

This policy does not govern a client’s independent privacy practices. When a SEMBL client uses the platform to process information on its own behalf, that client may be the organization responsible for deciding why and how the information is processed. You should also review that client’s privacy notice.

3. Our role

Depending on the context, Between Pixels may act in different roles:

For SEMBL account, website, billing, security, and product-administration data, Between Pixels determines the purposes and means of processing.
For client brand materials, client-connected analytics, advertising data, content, landing-page data, and other information submitted or connected by a client, Between Pixels generally processes the information on the client’s instructions under our agreement with that client.
For public-web research, business contact information, and monitoring features, the applicable role depends on the feature, the client’s instructions, and applicable law.

If you submit a privacy request concerning information controlled by a SEMBL client, we may refer the request to that client and assist it in responding.

4. Information we collect

A. Account and administrative information

We may collect:

name, business email address, telephone number, job title, employer, and profile image;
login, authentication, invitation, membership, and role information;
client and workspace associations;
support requests, feedback, and communications;
contract, subscription, and billing-administration information; and
records of consent, authorizations, and account settings.

SEMBL uses role-based memberships such as owner, editor, and viewer. Between Pixels personnel with authorized super-administrator responsibilities may access client workspaces to configure, support, secure, and operate the service.

B. Client brand and content information

Clients and authorized users may provide:

brand standards, brand guides, messaging, vocabulary, personas, value propositions, differentiators, proof points, and prohibited claims;
business names, addresses, locations, hours, telephone numbers, products, services, and market information;
logos, fonts, colors, icons, photographs, videos, audio, templates, Figma frames, documents, and other media;
campaigns, briefs, drafts, articles, social posts, emails, advertising copy, landing pages, and generated content;
reviews, audit materials, source files, and revision history; and
instructions, prompts, chats, feedback, approvals, and other information entered into SEMBL.

Please do not upload personal information that is unnecessary for the requested service. Unless Between Pixels and the client have expressly agreed in writing to appropriate handling terms, SEMBL must not be used to upload protected health information, government identification numbers, financial-account credentials, precise consumer location histories, or other highly sensitive personal information.

C. Connected service and advertising information

When an authorized user connects or authorizes a third-party service, SEMBL may receive information made available by that service and permitted by the user’s account rights. Depending on enabled features, this may include:

Google Analytics metrics, properties, key-event configuration, traffic, engagement, device, channel, and conversion data;
Google Search Console query and page-performance data;
Google Ads copy and campaign information supplied through files or an authorized integration;
Google business-location information and public reviews;
LinkedIn advertising account, campaign group, campaign, creative, targeting, budget, spend, impression, click, conversion, lead-performance, and aggregate professional-demographic reporting data;
account identifiers, OAuth authorization information, access tokens, refresh tokens, and token-expiration information;
Figma file and frame information accessed through an agency-authorized read-only token;
WordPress or other publishing information when an export or connection is used; and
other information described at the time a user enables an integration.

SEMBL only accesses connected accounts that the authorizing user is entitled to access. The permissions available within a third-party service continue to be governed by that service and the account owner’s settings.

D. Public-web, monitoring, and business contact information

Certain SEMBL features research or monitor publicly available or commercially licensed information. We may process:

publicly searchable company websites, biographies, articles, press coverage, conference materials, and other open-web sources;
publicly available Google reviews and Reddit discussions;
search-engine result positions and publicly accessible web-page content;
business names, professional roles, company affiliations, work contact information, seniority, company size, and related B2B prospecting information licensed from Apollo or another approved provider; and
source URLs and research results used to support sales briefs, competitive research, monitoring, or marketing analysis.

SEMBL does not scrape private LinkedIn profiles, private posts, private groups, recommendations, or other nonpublic LinkedIn member information. A public search result that links to a publicly indexed LinkedIn page may be included as a research source.

E. Hosted-page and usage information

When a person visits a page hosted or measured through SEMBL, we may collect:

IP address, browser type, device type, operating system, referring URL, and timestamps;
page views, session events, scroll depth, section visibility, CTA clicks, outbound-link clicks, and form-interaction or form-submission events;
page and campaign identifiers; and
diagnostic, security, and performance information.

SEMBL’s optional measurement script is designed to record that a form field was interacted with, not the value typed into the field. If a client deploys a form that collects names, contact details, appointment requests, or other information, the form must provide an appropriate client privacy notice and route the submitted information only as disclosed at the point of collection.

F. API and technical information

We may collect:

API keys, token identifiers, scopes, connection status, and authorized client identifiers;
API requests, response status, timestamps, rate-limit information, and audit logs;
application events, errors, crash data, and security signals; and
data needed to maintain versions, restore content, prevent abuse, and troubleshoot the service.

Users and clients are responsible for safeguarding SEMBL API keys and for promptly revoking keys that are no longer needed or may have been compromised.

5. How we use information

We use information to:

provide, configure, authenticate, and support SEMBL;
maintain client workspaces and enforce role-based access;
structure and maintain brand standards and content libraries;
generate, revise, audit, render, export, and publish client-authorized content;
create sales briefs, campaign ideas, performance reports, landing pages, and marketing recommendations;
retrieve and display authorized analytics, search, advertising, and performance information;
monitor public reviews and discussions selected by a client;
provide B2B prospecting functions requested by an authorized client;
operate AI-assisted features described in this policy;
protect accounts, tokens, API keys, content, and infrastructure;
diagnose errors, measure service performance, and improve product reliability;
communicate about service changes, support, security, and client relationships;
enforce our agreements and comply with law; and
establish, exercise, or defend legal claims.

We do not use one client’s confidential brand materials, connected-account data, advertising data, or generated content to serve another client.

6. Artificial intelligence

SEMBL uses artificial intelligence to support features such as brand-guide extraction, chat, content generation, design assistance, media tagging, auditing, research, reporting, recommendations, and image or video generation.

Depending on the feature and administrator configuration, relevant prompts, client instructions, brand standards, source content, page content, analytics, or media may be sent to approved providers such as Anthropic, Google, OpenAI, xAI, or other providers identified in our current subprocessor list. Only information reasonably needed to perform the requested operation should be sent.

Between Pixels will:

use paid business or API services subject to written data-protection terms;
configure provider services so customer inputs and outputs are not used to train shared provider models where the provider offers and contractually supports that control;
not use client confidential information or LinkedIn Marketing Data to train a shared SEMBL model;
identify AI-generated or AI-assisted functionality where appropriate;
provide users an opportunity to review and edit generated content before external publication;
maintain human review for client-facing claims and content in regulated contexts; and
require users to verify AI-generated results because they may be incomplete or inaccurate.

AI features are not a substitute for legal, medical, financial, compliance, or other professional review.

7. LinkedIn Advertising and Marketing Data

This section applies when a user connects a LinkedIn advertising account or SEMBL accesses information through a LinkedIn Marketing API.

Authorization and information accessed

SEMBL uses LinkedIn’s OAuth authorization process. An authenticated LinkedIn member must grant permission and must have the necessary role on the relevant advertising account. For a reporting-only connection, SEMBL is expected to request only the permissions needed to retrieve advertising reporting and related campaign objects.

SEMBL may process:

LinkedIn advertising account, campaign-group, campaign, and creative identifiers and configuration;
aggregate impressions, clicks, spend, conversions, lead-performance metrics, and related reporting;
aggregate professional-demographic reporting when authorized;
account roles and access information needed to validate authorization; and
OAuth access tokens, refresh tokens, granted scopes, and expiration information.

The initial SEMBL LinkedIn integration is not intended to collect private LinkedIn member profiles, member posts, messages, reactions, or other member-level social data.

Permitted purposes

SEMBL uses LinkedIn Marketing Data only to provide the authorized client with LinkedIn advertising reporting, analysis, billing support where applicable, and approved campaign-management services. LinkedIn data is displayed so that the client can separately identify its LinkedIn performance from data relating to other advertising platforms.

SEMBL does not:

sell LinkedIn Marketing Data;
use LinkedIn Marketing Data to build or enrich member profiles;
disclose one client’s LinkedIn data to another client;
make LinkedIn Marketing Data available to data brokers or information resellers;
use LinkedIn member data to create prospect lists or targeting audiences;
access an advertising account after authorization or the client relationship ends; or
use LinkedIn Page data or member data to train AI or as AI input except where LinkedIn expressly permits the particular use and the user has provided any required consent.

If aggregate LinkedIn Ad Analytics Data is used to generate an authorized client’s performance report, it may be processed only for that reporting purpose, only by an approved provider subject to protective written terms, and never for model training.

Retention and deletion

LinkedIn advertising account administrative and reporting data is retained for no longer than one year unless a shorter period is required.

SEMBL will permanently delete stored LinkedIn Marketing Data within ten days after:

the relevant client ceases to receive the SEMBL service for which the data was stored and the data is no longer required for the client’s authorized business or legal-retention need;
the client or relevant LinkedIn Account Manager requests deletion; or
LinkedIn directs us to delete it.

LinkedIn member data, if ever received, is subject to the shorter retention periods and additional restrictions specified by LinkedIn. SEMBL will not retain Microsoft Bing Maps location data received through LinkedIn.

Disconnecting LinkedIn

An authorized user may disconnect LinkedIn in SEMBL or contact us at info@betweenpixels.com. Disconnecting stops future collection but does not by itself override a lawful, documented retention obligation. A LinkedIn member may also revoke application permissions through LinkedIn’s account settings.

8. How we disclose information

We may disclose information:

To the applicable client and its authorized users. Client data and reports are available according to workspace memberships and assigned roles.
To Between Pixels personnel and contractors. Access is limited to people who need it to operate, support, secure, or provide contracted agency services and who are subject to confidentiality obligations.
To service providers and subprocessors. These may include Supabase for database, authentication, and storage; Railway for hosting; Anthropic, Google, OpenAI, and xAI for configured AI functionality; Apollo for B2B prospecting; Figma for design import; Google services for analytics, search, reviews, locations, and performance; Serper or similar providers for search results; and providers used for monitoring, rendering, email, support, security, or diagnostics.
At a client’s direction. For example, an authorized user may export a report, publish content, call the Retrieve API, or send information to a downstream system using an API key.
For a business transaction. Information may be disclosed as part of a merger, financing, reorganization, acquisition, bankruptcy, or sale of assets, subject to appropriate confidentiality and legal safeguards.
For legal and safety reasons. We may disclose information when reasonably necessary to comply with law, respond to valid legal process, protect rights or safety, investigate fraud or abuse, or secure the service.

We do not sell personal information for money. We do not use personal information for cross-context behavioral advertising. SEMBL’s Prospector feature may display commercially licensed business contact information to an authorized business client for its requested B2B prospecting activity. Where applicable law grants an opt-out right concerning that activity, a person may exercise it using the contact information below.

A current subprocessor list is available on request by contacting info@betweenpixels.com.

9. Cookies and similar technologies

SEMBL and its service providers may use cookies, local storage, and similar technologies that are necessary to:

keep users signed in;
maintain security and prevent abuse;
remember workspace and interface settings;
operate requested integrations; and
understand application reliability and performance.

Hosted landing pages may use first-party measurement or client-configured analytics such as Google Analytics. Each client is responsible for configuring any legally required cookie notice or consent mechanism on its page. SEMBL must not activate nonessential analytics or advertising technologies where consent is legally required until the required consent has been obtained.

10. Retention

We retain information only for as long as reasonably necessary for the purposes described in this policy, to provide contracted services, and to satisfy legal, accounting, security, and dispute-resolution obligations.

The following specific rules apply:

LinkedIn advertising account administrative and reporting data: no longer than one year, subject to the earlier deletion events described in Section 7.
LinkedIn OAuth credentials: until the connection is revoked, expires without renewal, or is no longer necessary; then securely deleted.
Client brand standards, content, media, templates, and connected-service data: for the client relationship and the documented transition/deletion period in the applicable agreement.
Security and access logs: for the period documented in our internal retention schedule, unless longer retention is required to investigate an incident or comply with law.
Backups: removed through the ordinary backup-expiration cycle after data is deleted from active systems, subject to access restrictions and non-restoration except for disaster recovery.

Our internal data-retention schedule identifies the system of record, owner, retention trigger, deletion method, and backup treatment for each data category.

11. Security

SEMBL uses administrative, technical, and organizational safeguards designed to protect information. Based on the sensitivity and context, these safeguards include:

membership-gated, role-based access;
logical separation of client workspaces and client-namespaced storage;
authentication through Supabase Auth;
HTTPS for application and API traffic;
restricted administrative access;
separately controlled API keys for downstream Retrieve API access;
provider and contractor confidentiality requirements;
logging, monitoring, vulnerability management, and incident-response procedures; and
secure management of OAuth tokens, service-account credentials, AI-provider keys, Figma tokens, and other secrets.

No system is completely secure. Users must protect their credentials and API keys and notify us promptly at info@betweenpixels.com if they suspect unauthorized access.

12. Your choices and privacy rights

Depending on where you live and the law that applies, you may have the right to:

request access to personal information about you;
request correction of inaccurate information;
request deletion;
obtain a portable copy of certain information;
object to or restrict certain processing;
withdraw consent where processing is based on consent;
opt out of certain sales, sharing, targeted advertising, profiling, or business-contact uses;
appeal a decision concerning a privacy request; and
complain to an applicable privacy or data-protection authority.

To exercise a right, contact info@betweenpixels.com. Please identify your relationship with SEMBL and the information or client account involved. We may need to verify your identity and authority. Authorized agents may submit requests where permitted by law.

We will not discriminate against you for exercising a privacy right. If the relevant information is controlled by a SEMBL client, we may forward the request to that client and assist with its response.

You may:

change available account settings;
ask a workspace administrator to remove your membership;
revoke or rotate a SEMBL API key;
disconnect an integration;
revoke a third-party application’s permission through that provider; and
unsubscribe from nonessential marketing email using the link in the message.

13. International data transfers

SEMBL and its providers may process information in the United States and other countries. Where required, we use contractual and organizational safeguards intended to provide an appropriate level of protection for international transfers, such as applicable standard contractual clauses and transfer assessments.

Clients must notify Between Pixels before using SEMBL in a jurisdiction that requires additional localization, transfer, or contractual measures not already covered by the client’s agreement.

14. Children’s privacy

SEMBL is a business service and is not directed to children under 13 or intended for use by minors. We do not knowingly collect personal information directly from children through SEMBL. If you believe a child has provided personal information to us, contact info@betweenpixels.com.

Client content must not include a child’s personal information unless the client has confirmed a lawful basis, provided all required notices and consents, and entered any necessary written agreement with Between Pixels.

15. Changes to this policy

We may update this policy as SEMBL, our providers, or legal requirements change. We will post the revised policy with an updated date and provide additional notice when required. If a change materially affects how we use client-connected data, we will provide notice consistent with our client agreements and any applicable platform requirements.

Material changes to SEMBL’s use, storage, deletion, disclosure, or availability of LinkedIn Marketing Data may also require notice to or approval from LinkedIn before implementation.

16. Contact us.

Between Pixels, LLC
Attn: Privacy
22 Trammell Street SW, Suite B
Marietta, Georgia 30064
United States
Email: info@betweenpixels.com Or reach us via the contact form at betweenpixels.com/contact

If you are a client user, you may also contact the organization that provided your SEMBL access.