Security
Nimblet handles connected advertising accounts and creative data for paid teams. Security is built into how the product is architected, not bolted on. This page summarizes the measures in place; for a data processing agreement or a security questionnaire, contact info@yoyaba.com.
EU data residency
Application data - your account, connected ad-account data, and creative media - is stored in the European Union (Google Cloud region europe-west1).
Encryption
All traffic is served over TLS. Connected ad-account OAuth tokens are encrypted at rest, and secrets are held in Google Secret Manager rather than in code or configuration.
Tenant isolation
Every request is scoped to a workspace and verified against the requesting user’s membership, so one customer cannot access another’s data. This is enforced at the data-access layer on each request, not just in the UI.
Authentication
Sign-in is via Google OAuth or a password stored with Argon2id. There is no public self-registration; access is provisioned. OAuth connection flows are protected against cross-site request forgery.
Least-privilege access
Production access is limited to authorized personnel. The service runs under a dedicated, scoped service account.
Data minimization
Conversion and pixel data is processed in aggregate only. We do not ingest lead-level identifiers (names or emails of ad audiences), and we set no advertising or analytics tracking cookies.
Bring-your-own-key AI
AI analysis and generation run only when your workspace supplies its own model-provider key. Your key is encrypted at rest and used only for your requests.
Responsible disclosure
Found a security issue? Email info@yoyaba.com and we’ll respond promptly. Please give us reasonable time to fix before public disclosure.
Data processing & privacy
See our Privacy Policy, sub-processor list, and Data Processing Agreement.
Last updated: 2026-07-08