Security

Nimblet handles connected advertising accounts and creative data for paid teams. Security is built into how the product is architected, not bolted on. This page summarizes the measures in place; for a data processing agreement or a security questionnaire, contact info@yoyaba.com.

EU data residency

Application data - your account, connected ad-account data, and creative media - is stored in the European Union (Google Cloud region europe-west1).

Encryption

All traffic is served over TLS. Connected ad-account OAuth tokens are encrypted at rest, and secrets are held in Google Secret Manager rather than in code or configuration.

Tenant isolation

Every request is scoped to a workspace and verified against the requesting user’s membership, so one customer cannot access another’s data. This is enforced at the data-access layer on each request, not just in the UI.

Authentication

Sign-in is via Google OAuth or a password stored with Argon2id. There is no public self-registration; access is provisioned. OAuth connection flows are protected against cross-site request forgery.

Least-privilege access

Production access is limited to authorized personnel. The service runs under a dedicated, scoped service account.

Data minimization

Conversion and pixel data is processed in aggregate only. We do not ingest lead-level identifiers (names or emails of ad audiences), and we set no advertising or analytics tracking cookies.

Bring-your-own-key AI

AI analysis and generation run only when your workspace supplies its own model-provider key. Your key is encrypted at rest and used only for your requests.

Responsible disclosure

Found a security issue? Email info@yoyaba.com and we’ll respond promptly. Please give us reasonable time to fix before public disclosure.

Data processing & privacy

See our Privacy Policy, sub-processor list, and Data Processing Agreement.

Last updated: 2026-07-08