AI Policy
Last updated: August 13, 2026
This Policy supplements the CriterionIQ Terms of Service, Privacy Policy, and Data Processing Agreement. It covers CritiQue, the feature that sends precomputed, aggregated account-level metrics to Anthropic's Claude API and returns AI-generated narrative prose inside your CiQ dashboard. It does not cover CiQ Identity Spine's cross-device identity resolution, or CiQ's use of de-identified/aggregated data for its own internal benchmarking under DPA Section 2.3(d); those use a different mechanism (deterministic/probabilistic matching and internal analytics, not a third-party LLM) and are addressed in the DPA.
1. What data is sent to the AI provider
Two distinct features send data to an AI provider, and they send different things.
Narrative interpretation (CritiQue). Only precomputed, aggregated metrics already computed by CiQ, the kind of summary numbers that would appear on a dashboard chart (e.g., conversion counts, spend, attribution rollups).
Creative analysis. Your own advertising creative, as published by you on an advertising platform: the creative image or a contact sheet of video frames, the ad copy that accompanies it, and the audio track of a video creative, which is transcribed to text. This is used to describe creative attributes: hook, format, emotional register, production quality, so performance can be compared across creative rather than only across placements.
Neither feature sends: raw event-level data (pipeline_events), identity or identity-graph data (ciqid, person_id, household_id, hashed emails or phone numbers, or any other identifier from Annex I of the DPA), IP addresses or user-agent strings, message content, lead records, or special-category/sensitive data of any kind.
A note on people in creative. Advertising creative frequently depicts identifiable individuals: presenters, creators, partnership and testimonial talent. Where your creative does, their image and recorded speech are part of what is analyzed. CiQ does not perform facial recognition, does not attempt to identify anyone appearing in a creative, and does not match creative content against any identity data. You are responsible for holding the rights and releases necessary for the creative you run, which is the same responsibility you already carry to the advertising platform itself.
If CriterionIQ introduces a feature that sends a category of data not described above, this Policy will be updated before that feature launches, and the boundary reaffirmed: no raw event-level data, no identity data, no message or lead content.
2. The AI providers
CiQ uses Anthropic (Claude) for narrative interpretation and for creative image and copy analysis, and OpenAI (Whisper) for speech-to-text transcription of the audio track of video creative. Both are listed in the DPA's Sub-processor Annex (Annex III, Part A) alongside CiQ's other infrastructure vendors; unlike Recipient Platforms (Annex III, Part B), both process data on CiQ's behalf to deliver the Services, so they are genuine Sub-processors under DPA Section 6, not independent controllers.
Adding or replacing an AI provider is a Sub-processor change and carries the 30-day notice and objection right in DPA Section 6.3.
3. Model training
CiQ does not use Client data to train or fine-tune its own AI models, and does not direct any provider to train on data submitted through these features. Under both providers' commercial API terms, data submitted via the API is not used to train their models.
4. Retention
CiQ retains generated narratives, creative attribute analyses, and transcripts as part of your account records while your account is active, consistent with the account-data retention described in our Privacy Policy. Following the end of your engagement with CiQ, they are deleted or de-identified within 90 days, consistent with the Data Processing Agreement's post-termination deletion commitment (DPA Section 11.2). Where any such output is connected to an identifiable Data Subject's personal data, that individual may request deletion of it at any time, independent of the 90-day timeline; see Section 6 below. Each provider may retain API request data for a limited period for safety and abuse-monitoring purposes before deletion, per its own commercial terms.
5. Accuracy and human oversight
Narratives generated by this feature are AI-generated interpretations of your own aggregated data. They may contain inaccuracies, omissions, or misleading framing, and are not a substitute for your own review of the underlying metrics. They are not financial, legal, marketing, or other professional advice. You're responsible for verifying any narrative output before relying on it for a material business decision.
6. Your controls
Where a generated narrative is connected to an identifiable Data Subject's personal data, that individual may request its deletion at any time by contacting [email protected] or through the process described in Privacy Policy Section 9 and DPA Section 7. CiQ will honor that request within the same timeframes that apply to other data subject requests.
Separately, and regardless of any individual request, all account data, including any narratives generated by this feature, is deleted or de-identified within 90 days of the end of your engagement with CiQ, per DPA Section 11.2.
7. Relationship to other CriterionIQ policies
This Policy supplements the CriterionIQ Terms of Service, Privacy Policy, and Data Processing Agreement. Personal data already present in CiQ (to the extent any flows into this feature) continues to be governed by the DPA; this Policy addresses the AI-specific data flow and provider relationship on top of that. If there's a conflict between this Policy and the DPA regarding the Processing of Client Personal Data, the DPA controls, consistent with DPA Section 15.1.
8. Liability
Claims arising from this feature are subject to the same liability cap as the rest of the Agreement (see DPA Section 14.1 / Terms of Service Section 11).
9. Changes to this policy
We'll update this Policy as the underlying feature, data flows, or AI provider change, using the same notice mechanism as the DPA (Section 15.4).
10. Contact
Questions about this policy: [email protected].