What is collected
From you
- Your email address and a password. They are how you sign in. The address has to be verified, by a link sent to it, before the account can be used. The password is never stored: what is kept is a one-way hash of it, which cannot be turned back into the password by anyone, the operator included.
- Your first and last name, date of birth, phone number and country. Asked for when you create your account, and yours to correct afterwards under Settings. The date of birth is used to check that you are at least 18.
- That you accepted the terms and this notice, and when.
- Marketing consent, if you give it. Recorded separately from signing in, and withdrawable at any time from Settings without affecting your ability to sign in.
- API keys, if you choose to add them. An OpenAI or Anthropic key for the assistant, and a Higgsfield key if you want it to create images and videos. All are optional; the dashboard works fully without them.
- What you put into the assistant. Your questions and its answers are kept as conversations so you can come back to them. An image you attach to a message is kept as a plain picture; the file you uploaded is not kept.
- How you set the app up. The ad accounts you chose to report on, your dashboard layouts, your saved views and the AI models you picked.
From Meta, with your authorization
- An access token for the ad accounts you select, and Meta’s ID for the identity that authorized it.
- For each ad account: its name, ID, currency, time zone and status.
- Your campaigns, ad sets and ads as Ads Manager shows them: their names, statuses and objectives, and their settings, such as budgets, bidding, schedules and targeting.
- Your ads’ creatives: their text, links and call to action, which Page or Instagram account they run under, and where Meta keeps their images and videos. The images and videos themselves are not stored here. When the app shows you a preview of an ad, your browser loads it directly from Meta.
- Daily performance figures: spend, impressions, reach, clicks, video and engagement figures, and the conversions and conversion values Meta attributes to your ads.
The app requests only Meta’s ads_read permission. It cannot create, edit, pause or re-budget anything in your ad account, and does not read your personal profile, your messages or your contacts, or anything on your Pages beyond what an ad itself carries. Meta adds its basic “public profile” permission to every app login; this app uses it for nothing, and takes from the connection only Meta’s ID for it, not your name or picture.
Recorded when you use the app
- Sign-in sessions. Each session records the internet address (IP) and the browser it was started from. They are kept with the session and removed with it: when you sign out, when it has not been used for 30 days (sessions that have run out are cleared every night), or when you delete your account.
- Attempts. Attempts to sign in, to create an account and to have an email sent are counted for a short time, by internet address and by email address, so that nobody can guess at a password or fill an inbox without end. The counters are cleared within a few days.
- Operational events. A record that something happened and when: a connection made or lost, an import, an export, a key saved or removed, a question answered (with which model and how much it used, never what was asked or answered). It is there to work out why something stopped working.
What is not collected
- No tracking of your website visitors. This app has no pixel and no tag of its own.
- No advertising or analytics trackers on these pages.
- No payment details — the service is free and takes no payment.
Cookies
The app sets three, all its own, and none of them for advertising or analytics:
- one that keeps you signed in;
- one that remembers the date range and comparison you last chose;
- one that remembers whether the sidebar is open or closed.
How it is used
Your reporting data is used to show you your reporting data and, if you use the assistant, to answer your questions and make what you ask it for. It is not sold, this app does not use it to train any model, and it is not pooled with other users’ data for any purpose. Two people who connect the same Meta ad account get two separate copies that never mix. Your email address is used to send you the emails about your account (to verify the address, to choose a new password, to tell you your password was changed), and product news only if you asked for it.
Who it is shared with
Meta, because the data comes from there — requests are made on your behalf using the authorization you granted.
Your chosen AI provider, only if you enable the assistant. When you ask the assistant a question, what is needed to answer it is sent to OpenAI or Anthropic using your own API key, and billed to your own account there: your question and the conversation so far, the figures and the names of the campaigns, ad sets and ads involved and, when you ask about your creatives, their ad text, their images, and frames of their videos. An image you attach to a message is sent with it, and so is an image the assistant has had made for you, so that it can check how it came out. Your Meta access token is never sent. The assistant is off until you add a key, and you are shown this before you turn it on.
To follow what is said in a video, its sound track is sent to OpenAI’s speech-to-text service with your own OpenAI key, if you have saved one, whichever provider you chat with. The video file is downloaded to this app’s server only for the moment it takes to do that, and is then deleted.
Higgsfield, only if you add a Higgsfield key and ask for an image or a video. When you ask the assistant to create one, the instruction for it and the pictures it is based on (the image of an ad you named, an image you attached, or an image made earlier) are sent to Higgsfield using your own key, and charged to your own Higgsfield credits. A finished image is copied back and kept in this app for you to download. A finished video is not kept here: it is fetched once to take a single frame from it, and otherwise stays in Higgsfield’s storage. This app keeps the link to it and that frame, and when you play it your browser loads it from Higgsfield. Nothing is uploaded to Meta.
Resend, to deliver email. The emails about your account are sent through Resend, an email delivery service. It receives your email address and what the email says: your first name and a link to verify your address or to choose a new password. It is given nothing else about you or your advertising.
Each of these handles what it receives under its own terms and your agreement with it. This app cannot see or delete what a provider keeps; for that, use the controls of your account with that provider.
Nothing else. There are no advertising networks and no data brokers involved.
How long it is kept
- Reporting data: a rolling 730 days. Older data is deleted automatically, and is not recoverable from the app.
- Your Meta token and any API key: until you disconnect, remove them, or delete your account.
- AI conversations: until you delete them, remove the ad account they are about, or delete your account.
- Images attached to or made in a conversation: 7 days from when they were attached or made. After that the pictures are removed and cannot be recovered; the conversation keeps the line saying what was there. An attached file is kept as a plain picture; the file itself is not kept. An image you attach and never send is removed after a day.
- Videos made in a conversation: 7 days from when they were asked for, which is as long as Higgsfield keeps its copy. After that this app removes the link and the frame; the conversation keeps the line saying what was there.
- What the assistant prepares in order to look at your ads: the pictures and video frames for up to 20 minutes and a video’s transcript for up to six hours, in the server’s memory only, so that a follow-up question does not repeat the work. They are never written to the database.
- Your account details (name, date of birth, phone, country): until you delete your account. An account whose email address is never verified is removed, with everything given for it, after 7 days.
- Links sent by email: the one that verifies your address works for 1 day; the one for a new password works once, for 1 hour. Sign-in sessions, with the address and browser each was started from: until you sign out, or 30 days after you last used them.
- Operational events: kept after the data they are about has gone, but not with anything that says whose it was. When you delete your account, remove an ad account or have Meta ask for your data to be deleted, the events about it are reduced to what kind of event it was and when: their wording and details are removed, and with them any name, Meta ID or address. The operator keeps evidence that an action occurred without keeping a record of who took it.
How it is protected
- Your Meta access token and your OpenAI, Anthropic and Higgsfield keys are encrypted with AES-256-GCM using a key held outside the database. There is no endpoint that returns a stored key — not to you, not to the operator.
- Every query is scoped to your own account at the database level, using the identity from your session rather than anything sent by your browser. Images you attached or had made are served only to you, signed in.
- A video made for you lies in Higgsfield’s storage at a long address that cannot be guessed. This app gives that address only to you, signed in. Like any such link, it would open for anyone it was passed on to, until the video is removed.
- Your password is kept only as a one-way hash (scrypt). Signing in is limited to a number of attempts per email address and per internet address. Choosing a new password by an emailed link, or changing it while signed in, signs out every other session, and you are told by email that it changed.
- An account cannot be used until its email address is verified, and the forms that create an account, sign in or send a link never say whether an address already has one.
- Sessions use secure cookies.
- Secrets are kept out of logs, error reports and exports.
No system is immune to compromise, and this page does not claim otherwise or carry a certification it does not hold.
Deleting your data
You can do any of the following yourself, at any time:
- Delete a conversation, from the assistant. It goes with the images attached to it and the images and videos made in it.
- Remove one ad account’s data. Stops syncing it and deletes the reporting imported for it, together with the dashboards, saved views and conversations that belong to it.
- Disconnect Meta. Revokes this app’s access and stops all syncing. You choose whether to delete the reporting already imported.
- Remove a saved API key. Deleted immediately.
- Delete your account. Removes your account and the details you gave for it, your password, connections, reporting, saved views, dashboards, stored keys, and conversations with their images and videos, and signs you out everywhere. Any sync in progress is cancelled and cannot write data back afterwards.
You can also remove the app from your Meta settings. Meta then notifies this app, which revokes the connection and stops syncing. If you additionally ask Meta to delete your data, the app deletes everything held for that Meta identity and gives you a confirmation code you can use to check the status. A record of that request is kept as evidence that it was carried out: the Meta ID it was for, when it arrived and was completed, and its code.
Deleting here does not reach what a provider holds. What was sent to OpenAI, Anthropic or Higgsfield while you used the assistant, and a video Higgsfield made for you, stay with that provider until it removes them under its own rules.
Deletion removes records from the live database immediately. Encrypted database backups may still contain them until those backups expire on their normal schedule, which the operator must state above before publication.
Your rights
Depending on where you live, you may have rights to access, correct, export or erase your personal data, and to object to its processing. You can see and correct the details of your account under Settings, and the self-service controls above cover erasure. For anything else, write to [email protected].
Changes
If this notice changes in a way that affects what is collected or who it is shared with, signed-in users will be told before the change takes effect.
