Privacy Policy
adup.com turns a product page into finished ad creatives and publishes them to your own advertising accounts. Doing that means handling three sensitive things: access to your ad accounts, information taken from your website, and the performance data your ads produce. This policy describes each of them specifically rather than in general terms.
1. Who we are
Societatea cu Răspundere Limitată “NICKTIM SOLUTIONS” (IDNO 1024600084676), bd. Traian 1/1, ap. 110, MD-2060, Chișinău, Republic of Moldova (“adup”, “we”) is the controller of the personal data described here. Contact us at privacy@tryadup.com.
2. What we collect
Account information
Your email address, name and profile picture, and — depending on how you sign in — an identifier from Google or Facebook, or a hashed password. We never store a password in readable form.
Advertising-platform credentials
When you connect Meta or Google Ads we store the OAuth access and refresh tokens that authorise us to act on your behalf. These are the most sensitive items we hold: they permit reading and writing in your advertising account, including creating ads that spend your money. We store one token per connected platform, plus the Meta token issued when you sign in with Facebook.
Advertising-account metadata
The account's name, time zone, currency, whether it is a test or manager account, and its minimum daily budget. Reporting days belong to your ad account's time zone, so we need it to report your numbers correctly.
Performance data
For each ad you publish through us, one record per reporting day: impressions, clicks, spend, conversions, revenue, reach and the rates derived from them. Both platforms restate this data for weeks after the fact, so we refresh a trailing window rather than storing it once.
Brand and product information from your website
If you give us your website address, we fetch that site and use an AI model to extract your brand identity (colour palette, description) and a catalogue of your products, including product names and image URLs. We only fetch pages that are publicly accessible.
Creatives you generate
Generated images, the editable text layers on them, and the flattened exports. These are held in a private storage bucket and are readable only through short-lived signed links.
Technical records of AI usage
For each call we make to an AI provider we record the provider, model, timing, token counts and cost. These records currently include the request and response content sent to the model, which can contain material extracted from your website and the creative brief you wrote.
3. Why we use it, and on what basis
| Purpose | Data | Lawful basis |
|---|---|---|
| Provide the service — generate, edit and publish creatives | Account, brand and product data, creatives, platform credentials | Performance of our contract with you |
| Report on your ads without you logging into each ad platform | Performance data, ad-account metadata | Performance of our contract with you |
| Bill you and maintain an auditable record of charges | Credit movements, plan | Contract, and our legal obligation to keep accounting records |
| Operate, debug and improve the generation pipeline | Technical AI-usage records | Our legitimate interest in a service that works |
| Security, abuse prevention and fraud | Account and technical records | Our legitimate interest in protecting the service |
4. Who we share it with
We do not sell your personal data and we do not use it for advertising of our own. We share it with the processors below, each of which acts on our instructions:
| Processor | What they receive |
|---|---|
| Anthropic — brand and product extraction, ad copy | Content from your website, your creative brief |
| Google (Gemini image models) | Image-generation prompts and reference images |
| OpenAI (image models) | Image-generation prompts and reference images |
| Amazon Web Services | Stored images and exports |
| DigitalOcean | Hosting for our API and database |
| Cloudflare | Hosting for our web application |
We also send data to Meta and Google Ads — but as your agents, at your instruction, to publish into your own advertising accounts. What those platforms then do with it is governed by their own terms and privacy policies, not ours.
International transfers
Several of our processors operate outside the European Economic Area, in the United States. Transfers to them rely on the Standard Contractual Clauses approved by the European Commission, incorporated into each processor’s data processing agreement, or — where that processor is certified under it — the EU–US Data Privacy Framework. The UK Addendum to those clauses covers transfers subject to United Kingdom law.
5. Google Ads data
If you connect Google Ads, you grant us the
https://www.googleapis.com/auth/adwords scope. We use it for exactly two
things: creating and managing the ads you ask us to publish, and reading back their
performance so we can show it to you in adup. We do not use Google user data to train
any model, we do not transfer it to third parties for their own purposes, and we do not
allow humans to read it except where you ask us for support, where the law requires it,
or to investigate abuse or a security incident.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can revoke our access at any time in adup's Connections screen or from your Google account permissions.
6. Meta data
If you connect Meta, we request the permissions needed to list your ad accounts and Pages, publish ads and read their performance. You can disconnect in adup at any time, which revokes our authorisation with Meta, or remove the app from your Facebook settings. Removing it there tells us to delete your data, and we act on that automatically.
7. How long we keep it
While your account is open, we keep your data for as long as you use the service. Advertising performance data is refreshed on a rolling window and retained so that your historical reporting remains available.
When you delete your account, we delete your personal and content data — see Deleting your data for exactly what that covers. We retain de-identified advertising-performance and billing records: the account reference is replaced with a random value that is not stored anywhere alongside your identity, so the remaining rows cannot be traced back to you. We keep them to understand which creative formats perform, what our costs are, and to maintain the accounting records we are legally required to keep.
We should be straightforward about the limit of that: de-identification is strong but not absolute. An account with a very distinctive advertising history could in principle be recognised by someone who already holds matching records from an ad platform. We remove every direct identifier, every ad and campaign identifier, your website address and all ad copy specifically to make that as difficult as possible.
8. Your rights
Depending on where you live, you may have the right to access, correct, export, restrict or object to our processing of your personal data, and to erase it. You can delete your account and data yourself from your profile page in adup, or ask us at privacy@tryadup.com. You may also complain to your local data protection authority.
9. Security
Data is transmitted over TLS, our storage bucket is private and served only through short-lived signed links, and access to production systems is restricted.
In the interest of accuracy: advertising-platform tokens are currently stored without additional encryption at rest beyond the protections provided by our database host. We are working to change this. We mention it because a policy that claims more than the system does is worse than one that is candid.
10. Children
adup is a business tool and is not directed at anyone under 18.
11. Changes
We will update this page when our practices change and revise the date at the top. If a change materially affects you, we will tell you directly.