Sign in

Last updated: April 24, 2026

Privacy Policy

1. Who we are

AdBrief is operated by Novaleads SASU, a French company registered in France (SIRET 92378335100011), headquartered in Nanterre, France. You can reach us at contact@novaleads.eu for any question about this policy or your data.

This policy explains how we collect, use, and protect your personal data when you use our service at adbrief.io.

2. Data We Collect

  • Account data: email address, name (collected via Supabase Auth or Google OAuth)
  • Usage data: tools used, generations created, platform selected, timestamps
  • Payment data: handled entirely by Stripe. We do NOT store credit card numbers, CVVs, or banking details.
  • Analytics: anonymized usage via Google Analytics (page views, click events, session duration)

3. Lawful basis for processing (GDPR Article 6)

We process your personal data on the following legal grounds:

  • Performance of a contract — Article 6(1)(b) GDPR. Account creation, login, ad-account connections, and delivery of the AdBrief service to you.
  • Legitimate interests — Article 6(1)(f) GDPR. Service analytics, fraud prevention, security monitoring, and aggregated, anonymous usage telemetry. We balance these interests against your rights and freedoms.
  • Consent — Article 6(1)(a) GDPR. Optional cookies, marketing emails, and any data processing where we explicitly ask you to opt in. You can withdraw consent at any time.
  • Legal obligation — Article 6(1)(c) GDPR. Billing record retention required by French tax law (10 years), and response to lawful requests from authorities.

4. Third-Party Data Sources

When you connect your Meta Ad Account via OAuth, AdBrief accesses campaign performance data via the Meta Marketing API using the ads_read scope only.

Meta data we read:

  • Ad account name, currency, timezone, and account status
  • Campaign IDs and names
  • Performance metrics: spend, impressions, clicks, CTR, CPC, CPM, reach, frequency
  • Conversion actions and cost-per-action breakdowns reported by your Meta Pixel or CAPI events

We do NOT read: ad creative content, ad copy, audience targeting definitions, lookalike sources, ad placements, comments, messages, or any data outside the campaign-insights endpoint.

We also do NOT access or store:

  • Personal profile data of your ad account's end viewers
  • Private messages, comments, or user-generated content
  • Payment method details or billing information

All Meta data is stored encrypted (AES-256) in our EU-based Supabase database (Frankfurt region). Access tokens are encrypted at rest and never exposed client-side.

You can revoke AdBrief's access at any time:

  • From AdBrief: Dashboard → Connections → Disconnect Meta
  • From Facebook: Business Settings → Business Integrations → Remove AdBrief

Upon revocation, all associated Meta data is permanently deleted from our systems within 7 days.

5. How We Use Your Data

  • Provide, maintain, and improve AdBrief services
  • Process payments and manage subscriptions via Stripe
  • Send transactional emails (account creation, subscription changes)
  • Analyze usage patterns to improve the product
  • We do NOT sell your data to third parties.

6. AI & Data Processing

  • Your inputs are sent to Anthropic’s API (Claude) for AI generation
  • Generated outputs are stored in your account for history and export
  • We do not use your data to train AI models. Anthropic’s API usage policy applies.
  • Data transfer: Your inputs are processed by Anthropic (Claude AI) in the United States to generate content. By using AdBrief, you consent to this data transfer.
  • Approximate Location Data: When you log in, we derive your approximate location (country and city) from your IP address to improve our service and understand our user distribution. Your IP address is not stored. Location coordinates are rounded to ~11km precision. This processing is based on our legitimate interest (GDPR Art. 6.1.f).

7. Cookies

  • Essential cookies: authentication session (Supabase). Required for the service to function.
  • Analytics cookies: Google Analytics. Can be declined via your browser settings.

8. Data Retention

We retain your data only as long as necessary:

  • Account data: duration of your subscription + 3 years after cancellation
  • Usage data: 12 months rolling
  • Billing data: 10 years (French commercial law obligation)
  • Meta Ads data: duration of connection, deleted within 7 days of disconnection
  • Uploaded files (CSV, screenshots): 30 days maximum, automatically deleted
  • Anonymized analytics: indefinite (no personal data)

Upon account deletion, all identifiable data is permanently erased within 30 days, except data we are legally required to retain.

9. Your Rights under GDPR

Under the EU General Data Protection Regulation (GDPR), you have the following rights regarding your personal data:

  • Right of access — request a copy of the personal data we hold about you
  • Right to rectification — request correction of inaccurate or incomplete data
  • Right to erasure — request deletion of your data (“right to be forgotten”)
  • Right to restrict processing — request limitation of how we use your data
  • Right to data portability — receive your data in a structured, machine-readable format
  • Right to object — oppose processing based on legitimate interests
  • Right to withdraw consent — at any time, where processing is based on consent

To exercise these rights, contact us at contact@novaleads.eu. We respond within 30 days as required by GDPR.

You also have the right to lodge a complaint with the French Data Protection Authority (CNIL) if you believe your rights have been violated.

10. Security Measures

AdBrief implements technical and organizational measures to protect your data:

  • Encryption in transit: TLS 1.3 on all connections
  • Encryption at rest: AES-256 for sensitive data (Meta tokens, personal info)
  • Access control: Row-Level Security (RLS) in Supabase with deny-by-default policies
  • Authentication: Supabase Auth with bcrypt password hashing, Google OAuth 2.0
  • Infrastructure: EU data centers only (Vercel Frankfurt + Supabase Frankfurt)
  • Monitoring: anomaly detection, rate limiting, CSRF protection
  • Backups: daily encrypted backups with 30-day retention
  • Auto-deletion: uploaded files purged after 30 days

In case of a data breach likely to result in high risk to your rights, we will notify affected users and the CNIL within 72 hours as required by GDPR Article 33.

11. Sub-processors

AdBrief relies on the following sub-processors. All are bound by Data Processing Agreements (DPA) with appropriate safeguards (Standard Contractual Clauses for non-EU transfers):

  • Vercel Inc. — application hosting — EU (Frankfurt)
  • Supabase Inc. — database, authentication — EU (Frankfurt)
  • Anthropic PBC — AI API (Claude) — USA with SCC
  • Stripe Inc. — payment processing — USA with SCC
  • Meta Platforms Inc. — Marketing API source (user-authorized) — Global
  • Google LLC — OAuth sign-in, anonymized analytics — USA with SCC
  • Ionos SE — domain and transactional email — EU (Germany)

Request a copy of our sub-processor DPA at contact@novaleads.eu.

12. Data Deletion Request

To request deletion of your personal data:

Option 1 — From your AdBrief account:
Log in to adbrief.io → Settings → Account → Delete Account

Option 2 — By email:
Send a request to contact@novaleads.eu with the subject “Data Deletion Request” and your registered email address.

We process deletion requests within 30 days and send a confirmation once your data has been permanently removed (except data legally required to be retained).

For Meta Platform Data specifically:
Revoke AdBrief's access via Facebook Business Settings → Business Integrations → AdBrief → Remove. All Meta-sourced data is deleted from our systems within 7 days of revocation.

Tracking Your Deletion Request

When you submit a deletion request through Facebook Business Settings, we return a confirmation code (UUID) that you can use to track the status of your request at any time.

Status page: https://adbrief.io/data-deletion-status?code=<your_confirmation_code> — replace <your_confirmation_code> with the UUID you received after submitting the request.

The page displays:

  • Request type (deauthorize or data deletion)
  • Submission timestamp
  • Completion status and timestamp

This page is publicly accessible (no login required) so you can verify compliance even after your account is deleted.

13. Changes to This Policy

We may update this privacy policy from time to time. Changes will be posted on this page with an updated “Last updated” date.

14. Contact

Data Controller:
AdBrief (operated by Novaleads)
Nanterre, France
SIRET: 92378335100011
Email: contact@novaleads.eu

Data Protection Authority:
If you believe your data protection rights have been violated, you may lodge a complaint with the CNIL (Commission nationale de l'informatique et des libertés):

  • Online: cnil.fr
  • Mail: CNIL, 3 Place de Fontenoy – TSA 80715, 75334 Paris Cedex 07