Fire Pixel

Confidentiality, NDAs and AI disclosure

Fire Pixel works inside advertising accounts, analytics, call records and CRMs. That access can reveal commercially sensitive and personal data. This page explains the default safeguards and where AI is involved.

This page is a public commitment, not a signed standalone non-disclosure agreement. Our terms include mutual confidentiality. We will also sign a reasonable mutual NDA before account access where a client requires one. The signed proposal, NDA and data processing terms for an engagement take precedence over this summary.

Confidentiality by default

We treat non-public account data, credentials, CRM records, call recordings and transcripts, pricing, customer data, strategies, reports and business plans as confidential.

Access is limited to people and providers who need it for the agreed work. We do not publish a client's name, account screenshots, results or case study without prior written permission. We use account-level access and password managers where the platform supports them rather than asking a client to send passwords in email or chat.

Information may be disclosed where the client authorises it, where a provider needs it to deliver the agreed service under appropriate terms, or where disclosure is required by law. At the end of an engagement, access is removed and client data is returned or deleted according to the contract, applicable retention duties and the client's instructions.

How we use AI

AI is used as an assistant, not as the accountable decision-maker. Typical uses include drafting and checking code, proposing bulk account changes, producing a first-pass analysis, classifying calls or leads against an agreed rubric, and helping draft or illustrate website content.

Material client deliverables and proposed advertising-account changes are reviewed by a person before they are delivered or applied. Advertising account changes are not left to a general-purpose AI agent to approve for itself. Lead or call classification is tested against later CRM outcomes and can be overridden. We document the model, data fields, retention position and human review step for any client workflow that processes personal or confidential data.

We minimise what is sent to an AI provider. Credentials and secrets are not placed in prompts. Client data is not used for an unrelated case study or marketing example. If a project needs an external model to process client data, that use and the relevant provider are agreed as part of the implementation and covered by the appropriate controller, processor and transfer terms.

How data is routed

The route depends on the work and the data involved. The implementation record names the actual systems, region, retention and access controls rather than relying on a general claim that everything is either local or in the cloud.

Data or workDefault boundaryExternal processingHuman control
Public research, website code and public page evidenceLocal tools or a bounded public scanner where practicalOnly where the task requires an external providerPublished or delivered output is reviewed
Aggregated advertising and analytics metricsClient account, client-owned BigQuery project or the agreed reporting systemProject-specific and documentedI approve account decisions
CRM rows and customer dataMinimum fields needed for the agreed workflowNamed provider only where agreedOverrides and reconciliation remain available
Call audio and transcriptsAgreed call provider and classification routeProvider, retention and transfer position documented per projectA labelled sample and later CRM outcomes are used for QA
Credentials and secretsAccount-level access and password managementNever placed in promptsAccess is revoked when it is no longer needed

Predictive ecommerce models are treated as a separate documented data use. The training table, target, features, outcome window, validation result, model version and every outbound destination are recorded. Where BigQuery ML is used, training and batch scoring remain in the client-owned BigQuery project. Customer-level scores are not sent to Klaviyo or an advertising platform without the agreed purpose, required consent, platform eligibility and client approval.

Clients can ask for the current provider and subprocessor list, request an alternative route, or decline a proposed external model. If that changes what can be delivered, the effect is agreed before the workflow is built.

AI on this website

The text, code and some abstract illustrations on this website were produced with AI assistance. The current release received automated tests, visual checks, an AI-assisted primary-source fact-check and Ben Luong's editorial review. Fire Pixel remains the publisher and responsible for the version kept live. AI-assisted checking does not make the content infallible, so dated platform claims link to primary sources and corrections are welcome.

Any customer-facing chatbot supplied by Fire Pixel identifies itself as AI at the start of the interaction. A person remains available for handoff. This supports the transparency duty for systems that interact directly with people under Article 50 of the EU AI Act, which applies from 2 August 2026.

Data protection and project documents

Our privacy policy covers this website. For client work involving personal data, roles and instructions are recorded in the proposal or a data processing agreement. The implementation record identifies the systems used, data sent, purpose, retention, access and any international transfer safeguards. A client can request an NDA, data processing agreement or current subprocessor list before sharing account data.

Primary sources

Questions, corrections or an NDA request: [email protected].

Last updated: 30 August 2026.

Ask an AI about this page: ChatGPTClaudeGoogle AI ModePerplexity