AdBreeze Brain
FeaturesPricingSolutionsBlogAbout
Log inSign up
FeaturesPricingSolutionsBlogAbout
Start free trialLog in

Privacy Policy

Last updated: April 25, 2025

1. Introduction

Welcome to AdBreeze Brain ("we", "our", or "us"). We are an AI-powered advertising performance platform that helps brands and media buyers analyse campaign data, generate insights, and optimise their advertising spend across Meta, Google, and TikTok.

This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have. By using AdBreeze Brain, you agree to the practices described here. If you do not agree, please discontinue use of the platform.

2. Information We Collect

2.1 Account & Profile Information

  • Name and email address (provided by the account administrator when creating your user account)
  • Hashed password (we never store your password in plain text)
  • Role (Admin or User)

2.2 Brand Card Data

  • Brand name, website, industry, and logo
  • Social media profile URLs
  • Business goals: monthly ad budget, target ROAS, KPIs, campaign objectives
  • Audience description, naming conventions, and any files you choose to upload (e.g. brand briefs, product catalogues)

2.3 Advertising Platform Data

When you connect your Meta, Google, or TikTok ad accounts via OAuth, we access campaign data on your behalf using the permissions you grant. This includes:

  • Campaign names, budgets, statuses, and objectives
  • Performance metrics: spend, impressions, clicks, conversions, ROAS, CPA, CTR, CPM
  • Ad set and ad-level data within your accounts
  • Country and regional breakdown of ad performance

We store OAuth access tokens and refresh tokens encrypted at rest (AES-256) in our database. We only access your ad accounts when you request data within the platform.

2.4 E-Commerce Data

If you connect a Shopify or WooCommerce store, we access order and revenue data to enrich your performance reports. This includes:

  • Total orders, revenue, and average order value for selected date ranges
  • Top-selling products and their revenue contribution
  • Country and regional sales breakdown

Store credentials (API tokens, consumer keys) are stored encrypted and never exposed in plaintext.

2.5 AI Interaction Data

When you use the AI Chat or run an AI Analysis, we send your brand context and campaign data to Anthropic's Claude API to generate insights. Chat messages and analysis results are stored in our database and associated with your brand.

2.6 Usage & Technical Data

  • Session tokens (stored as httpOnly cookies)
  • Server-side logs (request timestamps, errors) — retained for up to 30 days
  • IP address (used for security and fraud prevention, not for tracking or profiling)

3. How We Use Your Information

  • Provide the service — display dashboards, generate AI analyses, power the AI chat, and build performance reports
  • Token management — automatically refresh OAuth tokens before they expire so your data connections stay active
  • AI context — inject your brand card and live campaign data into every AI call so responses are specific to your business
  • Shared reports — generate publicly shareable report links containing your chosen date range of data
  • Security — detect and prevent unauthorised access, verify admin permissions, and protect your data
  • Service improvement — fix bugs and improve performance based on error logs and usage patterns

We do not use your data for advertising, sell it to third parties, or use it to train AI models beyond what is required to process your individual requests.

4. How We Share Your Information

We share your data only in the following limited circumstances:

4.1 Anthropic (AI Processing)

Your brand context and campaign data is sent to Anthropic's API (Claude) to generate AI analyses and chat responses. Anthropic processes this data in accordance with their Privacy Policy. Anthropic does not use API data to train their models by default.

4.2 Ad Platforms

We communicate directly with Meta, Google, and TikTok APIs using your OAuth tokens. Data flows from their APIs to us — we do not send your data back to these platforms beyond normal OAuth token operations.

4.3 Infrastructure Providers

  • Vercel — application hosting and serverless functions
  • Neon — PostgreSQL database hosting

These providers process data solely to deliver the service and are bound by their own privacy commitments.

4.4 Legal Requirements

We may disclose data if required by law, court order, or to protect the rights, property, or safety of AdBreeze Brain, our users, or the public.

4.5 Shared Report Links

If you generate a shareable report link, anyone with that link can view the report data for the configured date range. You control who receives the link. Links can be set to expire.

5. Data Security

We take security seriously and implement the following measures:

  • AES-256 encryption for all OAuth tokens and API credentials stored in our database
  • Bcrypt password hashing — passwords are never stored in plaintext
  • httpOnly session cookies — session tokens are inaccessible to client-side JavaScript
  • HTTPS everywhere — all data in transit is encrypted via TLS
  • Role-based access control — admin routes are separately protected; users cannot access other brands' data
  • Cron endpoint protection — automated jobs require a secret header to prevent unauthorised triggering

No system is perfectly secure. If you believe your account has been compromised, contact us immediately at the address below.

6. Data Retention

  • Account data — retained for as long as your account is active
  • Campaign data — fetched live on demand and not permanently cached; aggregated analysis results are stored until you delete them
  • Chat history — retained indefinitely per brand unless you request deletion
  • Analysis results — retained indefinitely per brand unless you request deletion
  • Server logs — retained for up to 30 days, then automatically purged
  • Shared report links — expire according to the expiry you set (if any); data is not independently stored, it is fetched live when the link is accessed

7. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access — request a copy of the personal data we hold about you
  • Correction — request correction of inaccurate data
  • Deletion — request deletion of your account and associated data
  • Portability — request your data in a machine-readable format
  • Objection — object to processing based on legitimate interests
  • Revoke OAuth — you can revoke AdBreeze Brain's access to your ad accounts directly through Meta, Google, or TikTok at any time

To exercise any of these rights, contact us at the address in Section 10.

8. Cookies

We use a single httpOnly session cookie (adbreeze_session) to keep you logged in. This cookie:

  • Contains a signed JWT token (not readable by client-side JavaScript)
  • Is not used for tracking or advertising
  • Expires when you log out or after the session lifetime

We do not use third-party tracking cookies, analytics cookies, or advertising pixels.

9. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For significant changes, we will notify active users via the platform or by email. Continued use of AdBreeze Brain after changes constitutes acceptance of the updated policy.

10. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us:

AdBreeze Brain

Email: privacy@adbreeze.com

Website: https://brain.adbreeze.com

AdBreeze Brain

The AI media performance platform for agencies and brands. Meta, Google, TikTok, Shopify and GA4 — one brain, every client.

Product

  • Features
  • Pricing
  • Solutions
  • Help center

Resources

  • Blog
  • FAQ
  • Getting started

Company

  • About
  • Talk to sales

Legal

  • Privacy Policy
  • Terms of Service

© 2026 AdBreeze Brain. All rights reserved.

Built for performance teams who ship results.