Privacy Policy
Momentum, a product of Mostly Human, LLC · Effective date: [June 11, 2026] · Last updated: July 11, 2026
This Privacy Policy describes how Mostly Human, LLC (“Mostly Human,” “we,” “us”) collects, uses, and protects information in connection with the Momentum platform (the “Service”), a marketing analytics application provided to business customers under a license agreement. This policy covers the Momentum web application and the data connections it makes on your behalf.
1. Who we are
Momentum is operated by Mostly Human, LLC, 1117 Mclaughlin Place, Cincinnati, OH 45226. For privacy questions or requests, contact us at momentum@mostly-human.com.
2. Information we collect
- Account information. When your organization provisions your access, we receive your name, work email address, and organization identifier from your organization’s Microsoft Entra ID (Azure AD) sign-in. We do not store your password; authentication is handled by Microsoft.
- Marketing and advertising data. When you connect a third-party platform (such as Meta Ads, Google Ads, Google Analytics, Google BigQuery, TikTok Ads, Snapchat Ads, Viant, or Zoho Analytics), we retrieve advertising and analytics data — such as campaign names, spend, impressions, clicks, and conversions — that you authorize us to access. This data is used solely to provide the analytics features you request.
- Reporting connector query data. If you connect Google BigQuery, we read the project, dataset, table, and field metadata needed to discover the datasets you select and run bounded, read-only queries on your behalf. If you connect Viant, we read advertiser IDs, names, and limited account metadata from its read-only Trafficking API advertiser directory, and retrieve bounded Reporting API result rows for the report window and advertiser scope you request. Viant advertiser IDs and names may be stored in workspace-shared client mappings. Selected BigQuery results, Viant advertiser-directory metadata, and Viant report rows are processed by your workspace’s configured AI provider to generate the report and may be included in an immediate export. Raw connector result rows are not retained in background-job history, although the report text, source/cost statistics, shared client mappings, and exports you save may be retained like other Customer Data.
- Connected database content. If you connect your own SQL database (PostgreSQL, MySQL, or SQL Server), we run read-only queries — the ones you request, or those the assistant runs on your behalf to answer your request — and retrieve the resulting rows and the table and column names needed to query it. We never write to, modify, or delete from your database.
- Document library content. When you add documents to the Prior Learning feature — by upload, or from a cloud account you connect (OneDrive, SharePoint, Google Drive, Box, Dropbox) — we download and read those documents, extract their text, and build a private, per-workspace search index (including numeric representations of the text) so the assistant can answer questions and cite the sources.
- Uploaded data. Files and datasets you upload to the Service for modeling and analysis.
- Feedback and support submissions. When you send feedback or use an assistant’s “Report a Problem to Support” button, we receive your message and any file attachments you include, and — for support reports raised from an assistant — the relevant conversation transcript and the datasets in play, which we use to investigate and improve the Service.
- Usage information. We log basic usage events (sign-ins, feature invocations, AI assistant activity, errors) to operate, secure, and improve the Service.
3. Third-party platform connections
The Service lets you connect accounts you control on third-party platforms, including Meta (Facebook) Ads, Google (Ads, Analytics, BigQuery, and Drive), Microsoft (OneDrive and SharePoint), Box, Dropbox, Viant, Zoho Analytics, TikTok Ads, and Snapchat Ads, as well as your own SQL database. When you authorize a connection:
- We receive an access token and, where needed, a refresh token — or, for a database or Viant, the connection details — scoped to the permissions you approve. Viant users provide a username and password after Viant approves Reporting API access and, for advertiser discovery, read-only Trafficking API directory access. We use these connections on a read-only basis: we only read advertising, analytics, selected BigQuery data, and the documents you select, and a connected SQL database is queried read-only — we never modify campaigns or source data in your accounts. (For Meta we request ads_read and business_management; Google BigQuery uses only https://www.googleapis.com/auth/bigquery.readonly, separately from the Ads, Analytics, Drive, and Google-login scopes.)
- Tokens and credentials are stored encrypted and are used only to retrieve the data needed for the analyses you run.
- For ad and analytics platforms, we do not post to your accounts, modify your campaigns, or access personal profile content beyond what the platform requires to establish the connection. For BigQuery, you choose a billing project and a narrower dataset allowlist for direct query references; a selected Google-authorized view can expose underlying data according to its definition and Google IAM. Google may charge the billing project for queries. For cloud storage you connect (OneDrive, SharePoint, Google Drive, Box, Dropbox), we read the documents you choose to bring into the Service and may store files you ask the Service to save; for your own database, we only read.
- You can revoke a connection at any time within the Service, or from the platform’s own settings (for Meta: Settings & Privacy → Business Integrations). Revoking from either place stops further access. Disconnecting BigQuery deletes its stored Google grant and encrypted project/dataset configuration; disconnecting a SQL database or Viant removes its stored connection credentials. Disconnecting does not by itself delete reports already created from that source.
Data obtained from Meta platforms is handled in accordance with the Meta Platform Terms and applicable Developer Policies.
4. How we use information
- To provide, operate, and secure the Service, including marketing-mix modeling, attribution, optimization, and reporting features.
- To generate analyses, reports, and deliverables at your direction.
- To provide customer support and communicate about the Service.
- To comply with legal obligations.
We do not sell personal information, and we do not use data retrieved from connected advertising platforms for advertising of our own, for training generalized models across customers, or for any purpose other than providing the Service to you.
5. How information is shared
- Within your organization. Data in your workspace is visible to authorized users of the same customer workspace, per your organization’s configuration.
- Service providers. We use infrastructure subprocessors to host the Service (e.g., Microsoft Azure), third-party AI providers (such as Anthropic, OpenAI, or Google) to power the assistant features, and an AI provider (OpenAI or Google) to generate the search index used by Prior Learning. When you request a BigQuery or Viant report, selected query results are sent to the AI provider configured for your workspace. These providers process data only on our instructions to deliver the features you request.
- Legal. We may disclose information if required by law or to protect the rights, safety, or property of Mostly Human, our customers, or others.
6. Data retention and deletion
We retain your data for as long as your organization maintains an active license, and as needed to comply with legal obligations. You may request deletion of your data — including data retrieved from connected platforms such as Meta — at any time by emailing momentum@mostly-human.com from your account email. We will delete the requested data within 30 days and confirm in writing. Disconnecting a platform connection deletes its stored access/refresh token — or, for a SQL database or Viant, the stored connection credentials — for that connection; disconnecting BigQuery also deletes its selected project/dataset configuration. Reports already created remain until removed under the Service’s normal report-retention or deletion process. Removing a document from Prior Learning deletes it, and the text extracted from it, from your workspace’s search index.
7. Security
We use industry-standard safeguards, including encryption of data in transit (TLS) and at rest, encrypted credential storage, tenant isolation between customer workspaces, and role-based access controls. No method of transmission or storage is completely secure, but we work to protect your information against unauthorized access, alteration, and destruction.
8. International transfers
The Service is hosted in the United States. If you access the Service from elsewhere, you understand that your information will be processed in the hosting region.
9. Your rights
Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal information, or to object to or restrict certain processing. Because Momentum is provided to your organization under a business agreement, some requests may be fulfilled through your organization’s administrator. To exercise any right, contact momentum@mostly-human.com.
10. Children
The Service is a business tool and is not directed to children under 16. We do not knowingly collect personal information from children.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated policy at this URL and revise the “Last updated” date above. Material changes will be communicated to customer administrators.
12. Contact
Mostly Human, LLC
1117 Mclaughlin Place
Cincinnati, OH 45226
vince.ledney@mostly-human.com