B
Baymonk

Privacy Policy

Última actualización: August 28, 2026

Esta política también está disponible en español.

Baymonk is a platform operated by Wiper Agency that agency teams use to monitor the community, content and paid media — their own and their competitors' — of the brands they manage. This policy explains what data Baymonk processes, where it comes from and who it is shared with.

1. Who processes the data

Wiper Agency is the data controller for the data Baymonk processes. For any question about this policy, or to exercise the rights described in section 6, write to braian.greno@wiperagency.com.

2. What data we collect

From people who use Baymonk (agency teams): name, email, password (stored hashed, never in plain text), and role within their team.

From the social media accounts being monitored — the client's own and its competitors' —: account name, follower count, and the content they publish (text, format, date, public engagement metrics).

From people who comment on those posts. People who comment on a post of a brand monitored in Baymonk are not users of the platform and never registered anywhere. For those comments we process the text, the publicly visible name or handle, the like count, and an AI-inferred sentiment (Positive, Neutral or Negative) for that specific comment. This processing is based on our client's legitimate interest in managing its community and on the fact that the information was published publicly by the person themselves. We do not use this data to profile those people outside that context, nor do we cross-reference it with other sources.

Credentials for third-party services. When someone connects a Google or Meta account to Baymonk, we store the access token those platforms issue — encrypted at rest with AES-256-GCM, never in plain text — so we can read (and, only if explicitly authorized, moderate) the connected accounts.

Advertising data: spend, impressions and reach of the ad accounts the client connects.

3. Who we share data with

We do not sell data to anyone. We share it only with the providers that make the service work, under their own confidentiality terms:

4. Google user data

Baymonk lets users optionally connect a Google account through Google's OAuth flow. The connection is per-account, always read-only, and only reaches the data the person authorizes on Google's consent screen. These are the permissions (scopes) Baymonk requests, the data each one accesses, and the user-facing feature it powers:

What we do — and do not do — with that data. Data obtained from Google APIs is used exclusively for the features described above: displaying it in the dashboards of the team that connected the account, and including it in the reports that team generates. We do not use it for advertising, we do not sell or transfer it to third parties, we do not use it to determine creditworthiness or for lending purposes, and we do not use it to train generalized artificial intelligence models. When an AI-generated report includes metrics that came from Google, only the aggregates needed to write that user-requested report are sent to our AI provider (Anthropic); Anthropic does not train its models on that data. No one at Wiper Agency accesses Google user data except with the client's consent for support, for security purposes (investigating abuse or an incident), or to comply with applicable law.

How we protect that data. All communication — between your browser and Baymonk, and between Baymonk and Google's APIs — is encrypted in transit over HTTPS/TLS. Google refresh tokens are encrypted at rest with AES-256-GCM; the encryption key lives only on the production server, outside the database and the source code. Access tokens are short-lived (1 hour), exist only in server memory and are never persisted. Every scope we request is read-only — Baymonk cannot modify, create or delete anything in your Google account. Access within the platform is limited by team and by role: data from a connected account is only visible to members of the team that connected it. Each connection records its last use and its errors so anomalous access can be detected.

Revocation and deletion. You can disconnect your Google account from Baymonk's settings — doing so deletes the stored token from our database — or revoke access from your Google Account permissions. Derived data (metrics already incorporated into historical reports) is deleted on request within 30 days at most, following the process on the data deletion page.

Baymonk's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5. How long we keep data

Baymonk accumulates history by design: for example, an ad from the public ad library that a competitor takes down is not deleted — it is marked inactive to preserve the archive. We keep the data while the client has a contracted service, and delete it on request — see the data deletion page — or when the relationship with the agency ends.

6. Your rights

You can request access to, rectification or deletion of your data, and object to its processing, by writing to braian.greno@wiperagency.com. If you are a person who commented on a post of a Baymonk client (not a registered user), the same channel applies.

7. Cookies

Baymonk uses a single technical cookie, required to keep the session signed in (httpOnly; not used for advertising or cross-site tracking). We do not use analytics cookies or third-party tracking cookies.

8. Changes to this policy

If we update this policy, we will change the "last updated" date at the top of this page. Substantial changes will be announced by email to registered users.