This policy covers the CEO Hero client application (investments.ceohero.com and the CEO Hero iOS app), operated by CEO Hero. In it you can connect your business bank accounts so we can deliver bookkeeping and financial reporting, and your social media and advertising accounts so we can publish content for you and report on your marketing. It sits alongside CEO Hero's general privacy policy and takes precedence for anything concerning bank, social media or advertising data.
When you connect an account, we retrieve from your financial institution through Plaid:
We retrieve up to 24 months of history when you first connect, and new transactions afterwards.
Your bank username and password are never seen, transmitted or stored by this application. You enter them inside Plaid's own secure window, which communicates directly with your bank. We receive only an access token that permits reading the data listed above. We cannot move money, initiate payments, or make any change to your accounts — the access is read-only.
We do not use your data for lending, credit or underwriting decisions, for marketing, for training machine-learning models, or for any purpose other than delivering your bookkeeping service.
You can connect Facebook Pages, Instagram professional accounts, Threads, Google Business Profile, YouTube, LinkedIn, TikTok, Pinterest and Bluesky, and your Meta (Facebook & Instagram) and Google Ads accounts. Each connection is made by you, signing in on that platform's own page and approving the specific permissions listed there. Bluesky connects with an app password you create in Bluesky, which you can revoke there at any time.
What we receive and store
How we use it — only to (1) publish the posts you or your authorised CEO Hero team member create and approve, to the accounts you select, at the time you choose; (2) show you your accounts' and ads' performance; and (3) tell you when a connection has stopped working so you can reconnect it. We do not read or store your private messages, we do not post anything you have not created or approved in the app, we do not sell this data, and we do not use it for advertising profiles or to train machine-learning models.
Platform-specific terms
Disconnecting and deletion. Tap Remove on any account in Settings → Connections: we immediately delete its stored tokens and profile details. See Data deletion for the full process, including deleting everything we hold from your social and ad accounts.
Every client organisation on this application is a separate, walled-off sub-account. Within yours:
We record your explicit consent before any bank connection can begin. The wording you agreed to, and the date, are stored so both of us have a record. You can withdraw consent at any time in the application, which immediately prevents any new account being connected.
We do not sell your data, and we do not share it for advertising. It is handled only by the providers required to run the service:
| Provider | Purpose | What they handle |
|---|---|---|
| Plaid Inc. | Bank connectivity | Your bank authentication and the transaction data retrieved. See Plaid's privacy policy. |
| Cloudflare, Inc. | Hosting, database, security | Stores the application data, encrypted at rest. |
| The social and ad platforms you connect (Meta, Google, LinkedIn, TikTok, Pinterest, Bluesky) | Publishing and reporting | Receive the posts and media you choose to publish to them; we request your account's performance numbers from them. |
We will disclose data if legally compelled, and will tell you unless prohibited from doing so.
While you are a client, and for up to seven years afterwards where required for accounting records. Where you request deletion and no legal obligation requires us to keep it, we delete it on request instead.
When you delete, we retain only the record that consent was given and later revoked. That contains no transaction data, and exists so we can demonstrate we handled your data lawfully.
If we change how bank data is used, we will ask for your consent again rather than relying on the consent you gave to earlier wording.
Questions, access requests or deletion requests: support@ceohero.com.