Privacy Policy
Last updated: July 12, 2026
1. The short version
We collect what we need to run an ad-generation service and nothing more. We don't sell your data, we don't run third-party ad trackers, and your API keys are encrypted and never shown to anyone — including you — after you save them.
2. What we collect
- Account data: your email address and, if you sign in with Google, your Google account email. Passwords are handled by Supabase Auth; we never see them.
- Brand data: what you enter in the setup wizard or we extract from your public website at your request — brand name, logo, colors, products, tone, disclaimers.
- Content: your briefs, generated scripts, uploaded product photos, and rendered videos.
- Your API keys (Anthropic and WaveSpeed AI): encrypted with AES-256-GCM before storage. They are decrypted only server-side, only to run script or render jobs you queue.
- Billing: handled by Stripe. We store your Stripe customer ID and subscription status — never card numbers.
- Product analytics: basic first-party events (like “ad created”) stored in our own database to understand usage. No third-party analytics scripts.
3. Who processes it
We use a small set of processors, each for one job:
- Supabase — authentication, database, and file storage.
- Stripe — payments and subscription management.
- Anthropic — script generation, using your own key. Your brand profile and brief are sent to produce scripts; we use API terms under which inputs are not used to train models.
- WaveSpeed AI — video and image generation, using your own key. Script text, brand assets, and style choices are sent there when a render runs. Their processing is governed by your agreement with them.
- Resend — transactional email (welcome, ad-ready, render-failed, trial reminders).
- Vercel — application hosting.
4. What we don't do
- We don't sell or rent your data to anyone.
- We don't use your content to train AI models.
- We don't use your API keys for anything except the jobs you queue.
- We don't send marketing email without your consent.
5. Website scraping
The setup wizard fetches your website only when you submit its URL, reads publicly available information (title, logo, colors, product names), and shows you everything it extracted for editing before anything is saved. We don't crawl beyond the page you give us.
6. Retention and deletion
Your data is retained while your account is active. Delete your account and we remove your profile, brands, briefs, scripts, keys, and rendered videos within 30 days. Stripe retains billing records as required by financial regulations.
7. Security
All traffic is encrypted in transit (TLS). API keys are encrypted at rest with a key held only in our server environment. Database access is scoped with row-level security so accounts can only ever read their own rows. No system is perfectly secure — if we learn of a breach affecting your data, we will notify you promptly.
8. Your rights
You can access, correct, export, or delete your data at any time — most of it directly in the app, or by emailing us. If you are in the EU/UK or California, you have additional statutory rights (access, portability, erasure, objection); email us and we'll honor them.
9. Changes and contact
If this policy changes materially, we'll email you first. Questions: use the support address listed on the site.