> legal

Privacy Policy

Effective Date: July 2026

This Privacy Policy (or simply “Policy”) governs the manner in which Pantana and Ferry, LLC d/b/a Ai Marketing Academy (“AiM,” “we,” “us,” or the “Company”) collects, uses, maintains, and discloses information collected from you as a user (“User”) of the Ai Marketing Academy website (“Site”), the Ai Marketing Academy (the “Academy”), and AiM Automations (“Automations”), and all related applications, features, integrations, and services (collectively, the “Services”). 

Please read this Privacy Policy carefully to understand our policies and practices regarding your information and how we treat it. By interacting with our Services or providing us with your information, you agree to the collection, use, and sharing of your information as described herein. This Privacy Policy may change from time to time (see Changes to this Privacy Policy). Your continued use of the Services after we make changes to this Policy is deemed to be acceptance of those changes, so please check back periodically for updates. 

Our Site and Services may contain links to third-party websites, applications, portals, or plug-ins. We do not control the privacy practices of those third parties, and this Policy does not apply to information collected or processed by them. We encourage you to review the privacy policies of each third party before providing any information. 

TABLE OF CONTENTS

I. Information We Collect and How We Collect It

II. How We Use Your Information

III. Disclosing Your Information

IV. Data Security, Retention, and Deletion

V. Your Rights

VI. Children’s Privacy

VII. International Users

VIII. Changes to this Privacy Policy

IX. Contact Us

I. Information We Collect and How We Collect It

We collect Personal Information (or “Information”) (1) directly from you, (2) automatically through your use of our Website and other online Services, and (3) from other sources. For purposes of this Privacy Policy, “Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to an identified or identifiable individual.

Information You Provide Directly to Us

Account and billing information. Your name, email address, phone number, and subscription details. Payments are processed by Stripe; we do not store your full card number. Free accounts provide name and email only.

Usage information. Records of training content you access, platform feature usage (searches, playlists, Prompt Studio activity), automation configurations and run history, and technical data such as device and log information.

Content you provide. Materials you submit to the Services — prompts, branding (logos, colors, headshots), listing photos and property information, voice and avatar references, and business profile details. If you use “magic” profile onboarding, we analyze the website you give us to pre-fill your profile; however, nothing is saved until you review and approve it.

Contact data you connect (paid Automations). If you connect a CRM or upload contact lists, we process a limited set of your contacts’ fields (e.g., name, email, phone, address, tags, and pipeline stage) on your behalf and at your direction to run the automations you configure. We do not import CRM notes, transaction history, or communication logs, and our CRM connections are read-only — we never modify your CRM. You are responsible for having the right to share contact information with us and for the communications you send.

Consent records. We record your acceptance of our Terms and this Policy (at sign up, checkout, and profile creation), automatic-sending authorizations, and per-project rights and review confirmations — each with document version and timestamp.

The Services are not designed for sensitive personally identifiable information, such as Social Security or government ID numbers, financial account information (other than through Stripe checkout), health information, or other types of statutorily protected information. 

Information Collected Automatically

We and our service providers use cookies, pixels, software development kits, local storage, session storage, embedded content, and similar technologies (“Tracking Technologies”) to operate the Site, authenticate members, maintain security, understand how visitors and members use our Site and Services, measure the effectiveness of our communications and marketing, improve our services, and personalize the user experience.

A cookie is a text file containing small amounts of information sent by a web server and placed on your computer. We generally refer to cookies, web beacons, and other tracking technologies collectively as “cookies” throughout this Policy.

Some Tracking Technologies are necessary for the Site and membership platform to function. Others are used for functionality, analytics, performance measurement, session replay, and marketing. The specific cookies and technologies used may vary depending on the pages you visit, the features you use, whether you are logged in, and the choices you make.

Cookies and Other Tracking Technologies

Strictly Necessary and Security Technologies. These technologies are used to provide essential Site functions, authenticate members, maintain user sessions, process transactions, prevent fraud and abuse, and protect the Site. Because these technologies are necessary to provide services you request, they generally cannot be disabled through our cookie-preference tools. You may be able to block them through your browser, but doing so may prevent portions of the Site from functioning properly.

Functional Technologies. These technologies remember choices and settings, such as login status, video-player preferences, and other features intended to provide a more convenient or personalized experience.

Analytics and Performance Technologies. These technologies help us understand how visitors and members use the Site and platform. They may collect information such as pages viewed, referring URLs, approximate location derived from an IP address, browser and device characteristics, session duration, feature usage, search activity, content accessed, video viewing, clicks, and interactions with Site elements. We use this information to measure performance, troubleshoot problems, and improve our services.

Session Replay and Interaction Analytics. We use technology that may record or reconstruct how users interact with the Site, including mouse movements, clicks, scrolling, navigation paths, and interactions with Site elements. This information helps us identify usability problems and improve Site and platform functionality. Where configured, sensitive fields and designated content are masked or excluded from recording. You should not enter sensitive personal information into fields that are not intended to collect that information.

Advertising and Attribution Technologies. These technologies may help us understand how visitors arrived at our Site, attribute visits or subscriptions to particular campaigns, measure the performance of advertising and communications, and, where enabled, support personalized or interest-based advertising. These technologies may collect campaign parameters, referring-domain information, advertising click identifiers, device identifiers, and information about interactions with our Site.

Cookies and Tracking Technologies In use

Our Tracking Technologies include technologies provided by the companies listed below. We reserve the right to update this list, so please check back periodically for changes.

Amplitude. We use Amplitude for product analytics, feature experimentation, automatic measurement of interactions with Site elements, and session replay. Amplitude may collect device and session identifiers, user or account identifiers when a member is logged in, timestamps, referring URLs, campaign information, pages and features used, clicks, scrolling, and other interaction information.

Google. We use the Google tag and related Google services to measure Site traffic, events, campaign performance, and other interactions. Depending on the Google services enabled, Google technologies may collect IP address, device and browser information, pages viewed, referring URLs, event information, advertising click identifiers, and information about interactions with the Site.

Vimeo. We embed videos hosted by Vimeo. When a page containing a Vimeo player loads, or when you interact with the player, Vimeo may receive information including your IP address, browser and device information, referring page, video-viewing activity, and player preferences.

Memberstack. We use Memberstack to provide member registration, login, account management, restricted-content access, and related membership functionality. Memberstack may use cookies or similar storage to authenticate members, maintain sessions, remember account-related choices, support security, and provide membership services. Blocking these technologies may prevent you from logging in or accessing member-only features.

ProfitWell/Paddle. We use ProfitWell or related Paddle services for subscription and revenue analytics. These services may receive subscription, account, device, and usage information. When a member is identified, this information may be associated with an email address, customer identifier, or subscription record for purposes such as subscription analysis, retention measurement, and business reporting.

Mailchimp. We use Mailchimp-related technologies to support email subscription forms, communications, and measurement of interactions associated with those forms or communications. Mailchimp may collect contact information that you voluntarily submit, together with technical, campaign, and interaction information.

Cloudflare. We use Cloudflare technologies, including Turnstile, to protect forms and the Site against fraudulent, malicious, or automated activity. Cloudflare may process IP address, browser and device information, security signals, and information about interactions with security features.

For additional information about the privacy practices of our service providers, please review the privacy materials published by Amplitude, Google, Vimeo, Memberstack, Paddle, Mailchimp/Intuit, and Cloudflare.

Your Choices

You can set your browser to refuse all or some browser cookies or other tracking technology files, or to alert you when these files are being sent. If you disable or refuse cookies or similar tracking files, some Services features may be inaccessible or not function properly. Some browsers include a “Do Not Track” (DNT) setting that can send a signal to the online services you visit indicating you do not wish to be tracked. Because there is not a common understanding of how to interpret the DNT signal, our Services may not respond to all browser DNT signals. Instead, you can use the range of other tools to control data collection and use, including the cookie controls and advertising controls described in this policy.

We do not control third parties’ collection or use of your information to serve interest-based advertising. However, these third parties may provide you with ways to choose not to have your information collected or used in this way. 

Some browsers and browser extensions support the Global Privacy Control (“GPC”) that can send a signal to process your request to opt out from certain types of data processing, including data “sales” as defined under certain laws. When we detect such a signal, we will make reasonable efforts to respect your choices indicated by a GPC setting as required by applicable law.

Information from Other Sources

We may receive Personal Information from  other sources, including our service providers, third parties, or public information sources, such as:

  • Through our customers.
  • Through marketing, sales generation, and recruiting partners.
  • Through social media networks.
  • From our vendors, service providers, and business partners.

II. How We Use Your Information

We use the information we collect to provide and operate the Services, run the automations you configure, personalize your experience, process payments and manage subscriptions, communicate with you about your account and about AiM training, features, and offers, provide support, secure the Services, improve platform functionality, comply generally with  all laws and applicable statutory requirements, fulfill the purposes for which you provided the information or that were described when it was collected, and for any other purpose with your consent.

III. Disclosing Your Information 

We do not sell Personal Information in exchange for monetary consideration or for cross-context behavioral advertising. We do not use your contact data to market to your clients or prospects on our own behalf. We may disclose Personal Information to the following categories of recipients, subject to applicable law and contractual restrictions:

AI Features and AI Providers

The Services include AI-powered features (e.g., content search, playlists, Prompt Studio, and the Automations apps) that generate blogs, videos, emails, and market reports.

We do not train our own AI models on your data. While we do not train the models with your data, your content, contact data, voice and likeness assets are processed by our AI model providers in order to fulfill requests you make. Therefore, your use of AI-powered features is subject to the applicable terms and privacy policies of those providers (currently including OpenAI and Anthropic, accessed directly or through OpenRouter), and AiM is not responsible for the data-handling practices of those providers. You are responsible for reviewing the applicable AI provider terms to understand how your data may be used, including whether a provider may use your data for model training.  

Human access. No one at AiM reads your content or contact data except with your permission, for security or abuse prevention, to comply with law, or as necessary to operate, maintain, and support the Services.

AI-generated content may be inaccurate, incomplete, or unsuitable for a particular purpose; you are solely responsible for reviewing, verifying, and approving all AI-generated outputs (“Outputs”) before you rely on, distribute, or publish them. 

Connected Services (Paid Automations)

Automations works by connecting to accounts you already own. You choose what to connect, and you can disconnect any integration at any time from your settings. Disconnecting deletes the stored credential, stops future access, and for CRM connections, deletes the contacts imported from that connection.

CRM platforms. With your authorization, we retrieve the limited contact fields described above to power features like neighborhood mapping and personalized campaigns from CRM platforms (e.g., FollowUpBoss, Lofty, Sierra Interactive, BoldTrail/kvCORE, CINC, Cloze, GoHighLevel, or CSV upload). We access your CRM exclusively in a read-only capacity and do not write, modify, or delete data in your CRM. However, the API token or credentials you provide may carry permissions beyond read-only access depending on your CRM’s configuration. Consequently, you are responsible for managing the scope of permissions granted by your token.

Email service providers (ESP). With your authorization, email service providers (e.g., Mailchimp, ActiveCampaign, SendGrid, Resend) create and send the campaigns you approve through your own sending account and under your name. Your ESP maintains your audience and unsubscribe records under its own policies; the Services enforce unsubscribe links and do not send to suppressed contacts.

HeyGen and ElevenLabs (Tours). Avatar and voice features run through your own accounts, using credits you purchase from those providers. We reference your existing assets (such as an avatar or voice ID) and retrieve media generated at your request. Please note your avatar and voice models remain in your provider accounts under their terms. We do not sell or profit from biometric identifiers or biometric information.

Website and publishing platforms. With your authorization, we publish the content you approve to your own website and publishing platforms (e.g., WordPress or webhook).

Credentials. API keys and OAuth tokens are encrypted (AES-256) and stored securely. 

Connected Services are governed by their own terms and privacy policies, and we do not control, and are not responsible for, their privacy or data-handling practices. Therefore, this Policy does not apply to information collected or processed by Connected Services. We encourage you to review the privacy policies of each Connected Service before providing access to your accounts or data.

Service Providers and Data Sharing

Your information is processed by AiM and the service providers that host and operate the Services on our behalf, including Memberstack (accounts and identity), Supabase (database and encrypted storage), Vercel (hosting), Stripe (payments), Trigger.dev (background job processing), Resend (platform transactional email), our AI model providers (including OpenAI and Anthropic, accessed directly or through OpenRouter), and mapping and market-data providers. Except as described under “AI Features and AI Providers,” these providers process data under contractual protections and only to provide services to us. We reserve the right to use additional service providers from time to time, and will update this Policy accordingly. 

We may disclose information if required by law or valid legal process, to protect the security of the Services, or in connection with a merger, acquisition, or sale of assets. We also may disclose your information for other purposes with your consent or at your direction.

User-Generated Content

Prompts and conversations you create in Prompt Studio are stored with your account and remain private unless you choose to publish or share them. Content you publish or share (such as public prompts or community posts) is visible to other AiM members. Do not share personal or sensitive information through these features.

IV. Data Security, Retention, and Deletion

We use commercially reasonable administrative, physical, and technical measures designed to protect your personal information from accidental loss or destruction and from unauthorized access, use, alteration, and disclosure. However, no website, application, system, electronic storage, or online service is completely secure, and we cannot guarantee the security of your personal data transmitted to, through, using, or in connection with the Services. Any transmission of personal data, either to AiM or third-party service providers, is at your own risk. Because we rely on third-party platforms, we also recommend reviewing their security practices.

The safety and security of your information also depends on you. You are responsible for taking steps to protect your personal data against unauthorized use, disclosure, and access.

We retain your information while your account is active and afterward as needed to comply with legal obligations, resolve disputes, and enforce agreements. Canceling your subscription does not automatically delete your data — this lets you resume where you left off if you return.

You may request deletion at any time by contacting support@aimarketingacademy.com. Upon a verified request, we will delete your profiles, imported contacts, stored credentials, and generated media within a reasonable time, subject to backup cycles and legal retention requirements. Disconnecting an individual integration deletes its credential and imported contacts immediately. Information held in your own Connected Services is controlled by you and those providers, not by AiM, and deletion of your data from the Services does not affect content previously transmitted to or published through Connected Services at your direction. 

V. Your Rights

You may cancel your account at any time. You may request access to, correction of, deletion of, or a copy of your personal data by contacting support@aimarketingacademy.com. We will respond within a reasonable time and may need to verify your identity. If your information appears in a member’s connected contact data, we act as that member’s service provider and may direct your request to them. You can opt out of marketing communications using the unsubscribe link in every email. Transactional emails about your account continue while your account is active.

VI. Children’s Privacy

Our Services are not intended for, and we do not knowingly collect any personal data from, children under the age of 18. If we learn we have collected or received personal data from a child under 18 years old without verification of parental consent, we will delete that information.

VII. International Users

The Services are operated from the United States, and information is processed in the United States. If you access the Services from outside the U.S. (including Canada), you consent to processing in the U.S.

VIII. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The date the privacy policy was last updated is identified at the top of the page. We will notify you of changes to this policy by updating the “last updated” date and posting the updated policy on the Services. We may email or otherwise communicate reminders about this policy, but you should check our Services periodically to see the current policy and any changes we have made to it. Your continued use of the Services after we post changes constitutes your acceptance of the updated Policy.

IX. Contact

To exercise your rights or ask questions or comment about this Privacy Policy or our privacy practices, contact us at: support@aimarketingacademy.com.

By Mail: 101 Creekside Crossing, Ste 1700 PMB 122, Brentwood, TN 37027.