Privacy Policy

Effective date: March 9, 2026

1. Introduction

Ad Beast ("we," "our," or "us") operates the platform at adbeast.ai. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our AI-powered marketing platform.

2. Information We Collect

Account Information: When you create an account, we collect your name, email address, and password (stored securely using industry-standard hashing).

Business Information: To generate marketing materials, we collect information you provide about your business, including business name, category, description, target audience, unique selling propositions, website URL, and brand photos.

Brand Assets: We store AI-generated assets created for your account, including logos, color palettes, fonts, ad copy, and ad images.

Ad Platform Connections: When you connect your Facebook, Instagram, Google Ads, TikTok, or LinkedIn ad accounts, we store OAuth access tokens to manage campaigns on your behalf. All tokens are encrypted using AES-256-GCM before storage. We do not store your ad platform passwords.

Lead Form Data: When you use lead generation features on connected ad platforms (including TikTok Instant Forms, Meta Lead Ads, and Google Lead Form Extensions), we collect and store lead submissions which may include names, email addresses, phone numbers, and other information provided by prospective customers through your ad forms.

2a. TikTok Data Practices

When you connect a TikTok Ads account to Ad Beast, we access and process the following data through the TikTok Marketing API:

  • Advertiser Account Information: Your TikTok Ads account ID and name, used to identify and manage your ad account.
  • Campaign & Ad Data: Campaign structures, ad groups, ads, and creatives, used to create and manage advertising campaigns on your behalf.
  • Ad Performance Metrics: Impressions, clicks, spend, conversions, and other reporting data, used to display campaign analytics and optimize performance.
  • Lead Form Submissions: Names, email addresses, phone numbers, and other PII submitted by prospective customers through TikTok Instant Forms. This data is stored in our database and may be sent to you via email notification.
  • Audience Data: Custom and lookalike audience segments, used for ad targeting.

Token Storage: TikTok OAuth access tokens and refresh tokens are encrypted using AES-256-GCM with unique initialization vectors before being stored in our database. Tokens are automatically refreshed before expiration and marked as expired when refresh fails.

Data Retention: TikTok data is retained for as long as your account is active and your TikTok ad account is connected. When you disconnect your TikTok account or delete your Ad Beast account, all associated TikTok data (tokens, campaign data, lead submissions) is deleted within 30 days.

Disconnection & Revocation: You may disconnect your TikTok ad account at any time from the Campaign settings page. Upon disconnection, we immediately delete your stored access and refresh tokens. If you revoke access from within TikTok, we process TikTok's data deletion callback to remove all associated data.

2b. Google Ads Data Practices

When you connect a Google Ads account to Ad Beast, we access and process the following data through the Google Ads API:

  • Ad Account Information: Your Google Ads customer ID and account name, used to identify and manage your ad account. If you do not have an existing account, we may create a child account under our Manager Customer Account (MCC) on your behalf.
  • Campaign & Ad Data: Campaign structures, ad groups, keywords, responsive search ads, and budget configurations, used to create and manage advertising campaigns on your behalf.
  • Ad Performance Metrics: Impressions, clicks, conversions, spend, click-through rates, and cost-per-lead data, collected daily via automated background jobs and used to display campaign analytics and optimize performance through A/B testing.
  • Lead Form Submissions: Names, email addresses, phone numbers, and other information submitted by prospective customers through Google Lead Form Extensions. This data is stored in our database and displayed on your leads dashboard.

Token Storage: Google OAuth access tokens and refresh tokens are encrypted using AES-256-GCM with unique initialization vectors before being stored in our database. Tokens are automatically refreshed before expiration.

Data Retention: Google Ads data is retained for as long as your account is active and your Google Ads account is connected. When you disconnect your Google Ads account or delete your Ad Beast account, all associated Google Ads data (tokens, campaign data, performance metrics, lead submissions) is deleted within 30 days.

Disconnection & Revocation: You may disconnect your Google Ads account at any time from the Campaign settings page. Upon disconnection, we immediately delete your stored access and refresh tokens. You may also revoke access from your Google Account permissions page.

Limited Use Disclosure: Ad Beast's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We only use Google Ads data to provide and improve the user-facing features of Ad Beast (campaign management, analytics, optimization, and lead delivery).
  • We do not transfer Google Ads data to third parties except as necessary to provide core platform features, comply with applicable laws, or as part of a merger or acquisition with prior user consent.
  • We do not use Google Ads data for serving advertisements, retargeting, or interest-based advertising.
  • Human access to Google Ads data is limited to cases where you provide affirmative consent, it is necessary for security or abuse investigation, or as required by law.

3. How We Use Your Information

We use the information we collect to:

  • Generate brand assets, ad copy, and ad images using AI
  • Create, manage, and optimize advertising campaigns on your connected ad platforms
  • Provide analytics and performance reporting
  • Communicate with you about your account and our services
  • Improve and develop our platform

4. AI Processing

To generate marketing content, we send your business information to third-party AI providers, including OpenAI, Google AI, and Anthropic. This information is used solely for content generation and is subject to each provider's data processing agreements. We do not use your data to train AI models. Each AI provider processes data under their respective enterprise data policies, which prohibit using customer data for model training.

5. Third-Party Services

We use the following third-party services to operate our platform:

  • Vercel: Website hosting and serverless functions
  • Supabase: Database hosting (PostgreSQL)
  • Vercel Blob Storage: File and image storage
  • Resend: Transactional email delivery
  • Facebook, Instagram, Google, TikTok, LinkedIn: Ad platform integrations for campaign management

6. Cookies

We use essential cookies for authentication and session management. These cookies are necessary for the platform to function and cannot be disabled. We do not use third-party tracking cookies or advertising cookies on our platform.

7. Data Security

We implement industry-standard security measures to protect your information, including encryption in transit (TLS/SSL), encryption at rest, secure password hashing, and access controls. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.

8. Data Retention

We retain your information for as long as your account is active or as needed to provide services. When you delete your account, we will delete your personal information and business data within 30 days. Some information may be retained longer as required by law or for legitimate business purposes (e.g., resolving disputes).

9. Your Rights

You have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate or incomplete information
  • Delete your account and associated data
  • Export your data in a portable format
  • Opt out of non-essential data processing
  • Disconnect any linked ad platform accounts at any time

To exercise any of these rights, contact us at the email address below.

10. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act, including the right to know what personal information we collect, the right to request deletion, and the right to opt out of the sale of personal information. We do not sell your personal information.

11. International Users (GDPR)

If you are located in the European Economic Area (EEA), we process your data under the lawful basis of contract performance (to provide the services you requested) and legitimate interest (to improve our platform). You have the right to lodge a complaint with your local data protection authority.

12. Children's Privacy

Our platform is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected information from a child, we will take steps to delete it promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the effective date. Your continued use of the platform after changes constitutes acceptance of the updated policy.

14. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us at: info@adbeast.ai