AI Policy
Last Updated: July 17, 2026
This AI Policy (“Policy”) explains how Comet LLC d/b/a Cometly (“Cometly,” “we,” “us,” or “our”) builds, operates, and governs the artificial intelligence (“AI”) features in our platform, including Agent, AI Ads Manager, AI Slack Reports, and the Cometly MCP server. It describes what data our AI features can access, which model providers we use, how data is protected and retained, your responsibilities, and our compliance posture under applicable laws (e.g., GDPR, CCPA, EU AI Act). By using Cometly’s AI-powered features, you agree to this Policy. This Policy supplements our Terms of Service, Privacy Policy, and Data Processing Addendum.
1. Overview
Cometly’s AI features are grounded in the attribution data already in your Cometly workspace. Rather than requiring you to manually copy data into a chat window, our AI uses secure, read-only tools to look up the data relevant to your question—campaign performance, attribution reports, customer journeys, contacts, and companies—and sends only the retrieved results to a large language model (“LLM”) to generate a response.
We are transparent about three things that matter most: (1) our AI features do process customer data from your workspace, including personal data, to answer your questions; (2) that data is sent to our AI model providers only to generate your response and, per our agreements with them, is never used to train their models; and (3) every AI feature operates read-only—AI can look up and analyze your data, but decisions and changes remain with you.
2. Our AI Features
Agent
A natural-language interface for your live attribution data. You ask a question (e.g., “which campaigns produced the highest LTV customers last quarter?”); Agent queries your workspace data using read-only tools and returns an answer grounded in that data.
AI Ads Manager
Surfaces suggestions on what to pause, scale, or rebalance across your connected ad platforms based on attributed revenue performance. Suggestions are recommendations only—AI Ads Manager does not autonomously change your campaigns.
AI Slack Reports
Scheduled daily and weekly performance summaries generated from your workspace data and delivered to Slack channels you configure.
Cometly MCP Server
A remote Model Context Protocol (“MCP”) server that lets AI clients you choose (e.g., Claude, ChatGPT, Cursor) securely query your Cometly workspace. See Section 5 for how the MCP server handles authorization and data, and docs.cometly.com/mcp/overview for technical documentation.
3. What Data Our AI Can Access
Tool-Based, Read-Only Access
- Our AI features do not receive a copy of your database and are not connected to raw data stores. They access data exclusively through scoped, read-only tools that query your workspace—the same data you can already see in Cometly.
- Accessible data includes advertising performance metrics (spend, impressions, clicks, conversions, cost metrics), attribution reports and models, events, dashboards, and—because Cometly is an attribution platform—customer data such as contacts, companies, and customer journey timelines, which may include personal data.
- No AI feature can write, modify, or delete data in your workspace.
Permissions Are Honored
- AI access is scoped to a single workspace (Space). Data from different customers is never mixed in AI processing, and AI cannot reach data outside the workspace it is operating in.
- AI features operate under the access of the user invoking them. A user cannot use AI to reach data they could not otherwise access in Cometly.
Data Minimization
- For each request, only the data needed to answer the question is retrieved and sent to the model provider, consistent with data minimization principles under GDPR and applicable U.S. privacy laws. Responses are size-limited by design.
4. AI Model Providers
Who We Use
Cometly’s AI features are powered by frontier models from the following providers, acting as our sub-processors:
- Anthropic (Claude Opus 4.8) — anthropic.com/privacy
- xAI (Grok 4.5) — x.ai/privacy
We may update the specific models or providers as newer versions are released; material changes will be reflected in this Policy and our sub-processor list.
How Providers Handle Your Data
When an AI feature runs, your prompt and the workspace data retrieved to answer it are transmitted to one of the providers above. Under our agreements with them:
- Your data is processed only to generate the response—not for the provider’s own purposes.
- Your data is not used to train or improve their models. Cometly does not opt in to any training programs, and Cometly does not train its own models on your data.
- Providers may temporarily retain request data (typically up to 30 days) for security, abuse monitoring, and legal compliance, after which it is deleted per their retention policies.
- Providers may rely on infrastructure subcontractors (e.g., cloud providers) under data protection agreements consistent with GDPR and other applicable laws.
5. The Cometly MCP Server
The Cometly MCP server lets you connect third-party AI clients— such as Claude, ChatGPT, or Cursor—directly to your workspace data. Because you choose the client, the security model differs from our in-platform AI features in one important way, described below.
Authorization & Access Controls
- Every connection is authorized via OAuth 2.1 with PKCE. You approve access in your browser and select exactly which workspace (Space) to grant; tokens are scoped to that single Space with no “all-spaces” scope available.
- All MCP tools are read-only. No tool can create, modify, or delete data in your workspace.
- Tokens can be revoked at any time in Settings → API Tokens. Removing a user from a Space immediately revokes their MCP tokens.
- Every MCP tool call is recorded in an immutable audit log, including the user, tool, and request metadata.
Your AI Client, Your Provider Terms
- When you query Cometly through a third-party AI client, the data returned by our MCP tools is processed by that client’s model provider under youragreement with that vendor (e.g., your Anthropic or OpenAI plan). The provider commitments in Section 4 apply to Cometly’s in-platform AI features; they do not extend to AI clients you connect via MCP.
- Workspace administrators control who can use the MCP server via the “Use Public API” permission.
6. Retention & Deletion
AI Conversations
- AI conversation history (e.g., Agent chats) is stored in your Cometly account, encrypted at rest with AES-256, and retained until you delete it.
- You can delete a conversation directly in the product (hover the chat, click the three dots, select “Delete,” and confirm) or by emailing privacy@cometly.com.
- Upon a deletion request, Cometly permanently removes the transcript from our systems within 30 days, unless retention is required for legal reasons. Where retention is legally required, we will notify you by email within 72 hours with an explanation.
- Conversations flagged for security or compliance review (e.g., suspected abuse) may be retained for up to 90 days for investigation, then deleted unless legal obligations require longer retention.
Provider Retention
- Model providers may retain request data for up to 30 days for abuse monitoring (see Section 4), after which it is deleted per their policies. Deletion from Cometly does not accelerate provider-side deletion, though we will pass deletion requests to providers where supported.
Logs
- Encrypted metadata logs of AI requests (and the MCP audit log) are retained for security, debugging, and abuse prevention, accessible only to authorized Cometly personnel under strict controls. You may request a data processing summary at privacy@cometly.com.
7. Your Responsibilities
- Data already in Cometly. Personal data your workspace lawfully collects (e.g., contacts and journey data from your CRM and pixel) is processed by AI features under this Policy and our Data Processing Addendum. You are responsible for having a lawful basis to process that data in Cometly in the first place.
- Data you type into prompts.Do not paste data into AI prompts that does not belong in Cometly at all—for example, credentials, payment card numbers, health records, or other special categories of data. Anything you include in a prompt will be transmitted to our model providers as described in Section 4.
- Acting on outputs. You are responsible for ensuring that actions you take based on AI outputs comply with ad platform terms, industry regulations (e.g., GDPR, CCPA, EU AI Act), and local laws.
- MCP clients.If you connect a third-party AI client via MCP, you are responsible for that client’s configuration and for your agreement with its model provider (see Section 5).
8. Accuracy & Limitations of AI Outputs
- AI outputs may contain inaccuracies, hallucinations, or outdated insights due to the inherent limitations of AI models. Review AI outputs before relying on them or sharing them.
- AI features are designed to augment your analysis and decision-making, not replace it. Recommendations (e.g., from AI Ads Manager) are suggestions; humans make the changes.
- Where practical, outputs include the key metrics and reasoning behind a recommendation to support transparency, consistent with the EU AI Act.
- We periodically review AI outputs for quality and bias (e.g., in audience or budget recommendations) to mitigate risks of unfair or discriminatory results.
- AI outputs are not financial, legal, or professional marketing advice. Consult qualified professionals before making significant business decisions.
- To report inaccurate or problematic outputs, email privacy@cometly.com.
9. Credit Consumption & Billing
Credit Usage
- Certain AI features consume credits based on dataset size and question complexity. This includes AI analyses triggered via the MCP server (e.g., report analysis tools).
- View your credit balance in real time on the Billing page.
Free Trial Credits
- New teams receive 10 free AI credits upon sign-up to test the feature.
Purchasing Credits
- Purchase additional credit bundles ($25, $50, $100, or $250) when credits are depleted. All sales are final, except in cases of billing errors.
- For billing disputes, email billing@cometly.com within 30 days for review and resolution.
Credit Expiry & Account Closure
- Credits do not expire while your account is active.
- Upon account cancellation, unused credits are forfeited but can be restored within 90 days of reactivation by emailing billing@cometly.com.
10. Security
- All AI data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
- AI access is protected by the same role-based access controls, audit logging, and workspace isolation as the rest of the Cometly platform. Our full security posture—including SOC 2 status—is documented at cometly.com/security.
- Model providers are vetted as sub-processors and listed with our other third-party sub-processors.
11. Limitation of Liability & Indemnification
Limitation of Liability
- Cometly’s aggregate liability for claims arising from AI features—including credit consumption and AI outputs—is capped at the greater of (a) the amount paid for AI credits in the six months preceding a claim or (b) USD 10,000, to the fullest extent permitted by law.
- Cometly is not liable for indirect, incidental, consequential, or punitive damages (e.g., lost budget, revenue, or reputation).
- For issues caused by AI provider errors, users may contact privacy@cometly.com to explore recourse under our provider agreements.
Indemnification by Customer
- You agree to indemnify and hold Cometly harmless from third-party claims arising from your use of AI outputs, except where such claims result from Cometly’s or our AI providers’ negligence or system errors.
12. Policy Updates
- We may update this Policy at any time. Material changes will be posted on this page and communicated via email at least 30 days in advance.
- Continued use of AI features after updates constitutes acceptance. To discontinue AI feature use, visit your account settings or email privacy@cometly.com.
13. Contact Us
For questions about this Policy, please email privacy@cometly.com or support@cometly.com
Comet LLC d/b/a Cometly41 University Drive, Suite 400
Newtown, PA 18940
USA