Privacy Policy

Last updated 3 September 2026

This policy describes what DadADS collects, why, who else sees it, and what you can ask us to do about it. It describes the service as it is actually built — the processors named below are the ones the application really sends data to.

Who we are

DadADS is a paid-media auditing tool. You connect an advertising account, we read it, and we report on how it is set up and performing. With your explicit confirmation, we can also make specific changes to that account on your behalf. We are the data controller for the account you hold with us, and a processor acting on your instructions for the advertising data we read.

What we collect

Your account

Your name, email address, and either a hashed password or an identifier from the provider you signed in with. We never store a password in a form we can read.

Your advertising data

When you connect an advertising account we read campaigns, ad groups, ads, keywords, search terms, budgets and performance metrics from it. We store the results of each audit, which contain that data. We do not read anything from your advertising account that is not needed to produce the report you asked for, and we never read from an account you have not connected.

Credentials

Where you connect through OAuth, we do not hold the access token — our broker does, and we ask it for a short-lived token each time we read. Revoking the connection on the advertising platform stops our access immediately. Where a provider issues an API key instead, we store it encrypted with AES-256-GCM, because it has to be replayed to that provider; it is never stored in plain text and never shown back to you in full.

What you type

Projects you create, instructions you give the assistant, and the conversations that result.

Payment

Handled entirely by Stripe. Card details never reach our servers. We store a customer identifier and your credit balance.

Who else sees your data

These are the services DadADS sends data to, and what each one receives. We do not sell your data, and we do not share it for advertising.

ServiceWhat it receivesWhy
Advertising platforms (Google, Meta, TikTok)Requests for your own account data; any change you confirmReading the account and applying changes you approve
OAuth broker and API gatewaysYour authorisation to read the connected accountHolding the connection so we do not have to store your tokens
AI providerAccount data from the audit, the page content of a landing page you submit, and your assistant messagesProducing the verdicts, copy and analysis you asked for
Page rendering and speed servicesThe public URL of a landing page you ask us to auditFetching and measuring that page
StripeYour email and payment details, entered on Stripe's own formTaking payment
ResendYour email address and the contents of the messagePassword resets and notifications that a job has finished

The AI provider matters most and is worth stating plainly: producing an audit means sending your advertising account data to a third-party model. If that is unacceptable for your account, do not connect it.

Changes we make to your advertising account

DadADS can pause a campaign, change a budget, add a negative keyword and create a paused ad. Every one of those requires you to confirm that specific change; nothing is applied automatically, and there is no bulk action. We keep a record of every change we make, including the value it replaced, so it can be undone and so you can see what was done and when. Ads we create are always created paused.

How long we keep it

Your account data and audit history stay until you delete them. Deleting a project deletes its jobs, audits, findings and change history. Deleting your account removes your profile, your projects and everything attached to them, and revokes the credentials we hold for you. Records we are required to keep for accounting are retained by Stripe under their own policy.

Your rights

Depending on where you live you may have the right to access a copy of your data, correct it, delete it, object to how we use it, or take it elsewhere. You can delete your projects and account from the settings page at any time. For anything else, write to us and we will respond.

Cookies

We set a cookie to keep you signed in. That is the only cookie we set. We do not run advertising or analytics trackers on this application.

Security

Traffic is encrypted in transit. Passwords are hashed, and provider API keys are encrypted at rest. Access to your data is scoped to your own account: a request for a project you do not own is answered as though it does not exist. No system is perfectly secure, and we will tell you promptly if something happens that affects you.

Changes

If we change this policy in a way that affects you, we will say so before it takes effect. The date at the top always reflects the current version.

Contact

Questions about any of this, or a request about your data, go to [email protected].