Legal

Privacy Policy

Last updated:

RoasBrain is a web application that reads data from your advertising accounts (Meta, Google Ads, TikTok) and, optionally, from your online store, analyses it with artificial intelligence and helps you write copy, generate images and prepare campaigns.

This policy explains in plain language what personal data we process, for what purpose, on what legal basis, who we share it with and what rights you have under Regulation (EU) 2016/679 (GDPR) and Romanian Law no. 190/2018.

Contents

01Who the controller is

The controller of your personal data is {company}, registered office [Registered address], Trade Register no. [Trade Register no.], tax ID [Tax ID] (“we”, “us”).

You can reach us about anything related to your data at contact@roasbrain.com or by phone at [Phone].

For your customers’ data that you send us through store integrations (for example orders used for the Meta Conversions API), you are the controller and we act as your processor (Art. 28 GDPR): we process it only for the features you enable and only according to your settings. On request, we will sign a written data processing agreement with you.

02What data we process

Account data

Your name, email address, password (stored only as a bcrypt hash, never in plain text), preferred language, account creation and email verification dates. The brand profile you fill in: name, website, industry, offer, target audience, tone, differentiators, markets, currency and monthly budget.

Advertising platform data

When you connect a Meta, Google Ads or TikTok account through the official authorisation flow (OAuth), we read through the platforms’ official APIs: the ad account ID and name, currency and time zone, the structure of campaigns, ad sets and ads, ad copy and images, budgets, targeting settings and performance metrics (impressions, clicks, spend, conversions, conversion value). For Meta we also read the list of Pages you manage, so you can choose the Page your ads run under, and your app-scoped user ID, which we need to honour deletion requests sent by Meta.

We do not read personal data about the people who see or interact with your ads. The platforms only give us aggregated figures.

Access tokens received from the platforms are stored encrypted and used only to read the data above and to carry out the actions you trigger.

Online store and Google Analytics 4 data

If you connect a store (Shopify, WooCommerce, Gomag, MerchantPro) or a GA4 property, we read daily aggregated figures: order count, revenue, taxes, discounts, shipping, refunds and, where available, cost of goods. We use these figures to calculate the real profit of your advertising. Store credentials are stored encrypted.

Meta Conversions API (only if you enable it)

If you explicitly enable sending orders to the Meta Conversions API for a store, for every new order we receive the order data from your store, including the customer’s contact details. Before sending, email, phone, first name, last name, city, postal code and country are normalised and irreversibly hashed with SHA-256; IP address, browser user agent and Meta click identifiers (fbc, fbp) are sent as Meta requires. We do not store customer contact details: we keep only a short log of the last 25 events (order ID, value, currency, delivery status, date).

AI content

The instructions you write, the texts you give us to proofread or analyse, the generated results (audits, copy, strategies, campaign plans) and their history, so you can find them again.

Uploaded creatives and generated images

Images you upload or generate in the app, together with the instructions used to generate them.

Competitor monitoring

The names, Pages and keywords of the competitors you choose to follow, and their public ads obtained from the Meta Ad Library (copy, run dates, platforms, reported EU reach).

Notifications

The email address for alerts and reports, your notification preferences and, if you enable Telegram, the chat ID of your conversation with our bot.

Automations

The rules you define and the history of proposed, approved, rejected or executed actions.

Technical data

Server logs (IP address, date and time, requested URL, browser user agent, error codes), used for operation and security, and the strictly necessary cookies described in the Cookie Policy.

AI usage metering

For every call to an AI model we record the type of operation, the model, the number of tokens or images and the estimated cost, to enforce monthly usage limits.

03Purposes and legal bases

PurposeData usedLegal basis (Art. 6 GDPR)
Creating and managing your account, signing inAccount dataPerformance of a contract – Art. 6(1)(b)
Showing reports, audits and profitPlatform, store and GA4 dataPerformance of a contract – (b)
Generating copy, images, analyses and plans with AIBrand profile, instructions, platform dataPerformance of a contract – (b)
Creating or changing campaigns at your requestPlatform data, access tokensPerformance of a contract – (b)
Sending orders to the Meta Conversions APIOrder data, hashedYour instructions, as controller of your customers’ data (Art. 28)
Alerts, weekly reports, Telegram notificationsEmail, Telegram chat ID, platform dataPerformance of a contract – (b); consent for Telegram – (a)
Security, abuse prevention, troubleshootingTechnical dataLegitimate interest – (f)
Enforcing AI usage limits and controlling costsAI usage meteringLegitimate interest – (f)
Service emails (verification, password reset)EmailPerformance of a contract – (b)
Keeping records required by lawBilling data, if paid plans are introducedLegal obligation – (c)

Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of earlier processing. Where we rely on legitimate interest, we have assessed that the processing is necessary, proportionate and does not override your rights; you can object at any time.

We do not send marketing emails and we do not sell data.

04Google user data

This section describes how RoasBrain accesses, uses, stores and shares data received through Google APIs.

What Google data we access

  • Google Ads (adwords scope, https://www.googleapis.com/auth/adwords): the list of ad accounts you can access, the structure of campaigns, ad groups and ads, budgets, ad copy and performance metrics.
  • Google Analytics 4 (analytics.readonly scope, https://www.googleapis.com/auth/analytics.readonly): the list of your GA4 properties and daily aggregated reports on purchases and revenue. Access is read-only.

How we use it

  • to show you reports and dashboards;
  • to generate audits, recommendations and profit calculations;
  • only on your explicit action, to create campaigns (always created paused) or to change the status or budget of an existing campaign.

To produce an analysis you request, extracts of this data (mainly aggregated metrics and ad copy) are sent to our AI provider, Anthropic, solely to generate the response shown to you.

What we don’t do

  • we do not sell Google user data;
  • we do not use or transfer it for advertising, including personalised, retargeted or interest-based advertising;
  • we do not use it to develop, improve or train generalised artificial intelligence or machine learning models;
  • we do not transfer it to third parties except as necessary to provide user-facing features, to comply with the law, or as part of a merger or acquisition with prior notice;
  • no one on our team reads this data except with your explicit consent (for example when you ask us to help with a specific issue), to investigate security incidents or abuse, or when required by law.
RoasBrain's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

You can revoke access at any time in the app (Integrations → Disconnect) or in your Google Account at myaccount.google.com/permissions. When you disconnect, we delete the tokens and the data synced from that account.

05Meta Platform Data

For Meta (Facebook and Instagram) accounts we request the ads_read, ads_management, business_management, pages_show_list and pages_read_engagement permissions. We use them to read the advertising data described above, to select the Page and pixel for your campaigns and, only on your explicit action, to create campaigns (paused) or change their status or budget.

Data received from Meta is used only to provide the app’s features to you. We do not sell it, use it for advertising or profiling, use it to train AI models, or share it with third parties other than the providers that help us run the service (hosting, AI), under this policy and the Meta Platform Terms.

For competitor monitoring we use the Meta Ad Library, which contains public ads.

You can remove the app at any time in Facebook: Settings → Business Integrations. When you do, Meta notifies us automatically and we delete the connections and synced data. Details and request status lookup: Data deletion.

06TikTok data

For TikTok for Business accounts we use the TikTok API for Business, with the authorisation you grant for the selected advertiser accounts. We read the structure of campaigns, ad groups and ads, budgets and performance metrics and, only on your explicit action, create campaigns (paused) or change their status or budget.

TikTok data is used only to provide the app’s features to you; we do not sell it, use it for advertising or use it to train AI models. You can revoke access in the app or in TikTok Business Center.

07Artificial intelligence and automated decisions

Copy, analyses and recommendations are generated by AI models (Anthropic Claude for text and analysis; OpenAI or Replicate for images). For each request we send the provider only what is needed: your brand profile, your instruction and, where relevant, aggregated metrics, ad copy or the uploaded image.

Anthropic and OpenAI state in their commercial API terms that, by default, they do not use data received through the API to train their models. We do not use your data to train AI models.

AI results are suggestions. We make no decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR). Changes to your ad accounts happen only when you approve them; an automation rule acts without approval only if you have explicitly set it to automatic mode, within safety limits.

08Who we share data with

We use the following service providers (processors), bound by data protection terms:

RecipientRoleLocation
Web hosting providerApplication server and databaseEuropean Union
Anthropic PBCAI models for text and analysisUSA
OpenAI or Replicate, Inc. (depending on configuration)Image generationUSA
Email provider (SMTP)Service emails, alerts and reportsAs per the configured provider
Telegram (only if you enable it)Delivering notifications in TelegramOutside the EU

Meta, Google and TikTok, as well as your store platform, are not our providers: they are services you choose to connect, and they act as independent controllers for the data they hold. When you create a campaign or send conversion events through the app, the data reaches that platform and is subject to its policies.

We disclose data to authorities only when legally required, on the basis of a lawful request.

09Transfers outside the European Economic Area

Some providers (Anthropic, OpenAI, Replicate, Telegram) process data outside the EEA, notably in the USA. For these transfers we rely on the adequacy decision for the EU-US Data Privacy Framework, for certified providers, and/or on the Standard Contractual Clauses adopted by the European Commission, with supplementary measures where needed. You can ask for a copy of the applicable safeguards at contact@roasbrain.com.

10How long we keep data

  • Account data and brand profile: for as long as you have an account. Deleted immediately when you delete your account.
  • Data synced from platforms and stores: for as long as the connection is active. Deleted when you disconnect the account or store, or delete your RoasBrain account.
  • AI history, creatives, rules and alerts: until you delete them or your account.
  • Conversions API log: only the last 25 events per store; older entries are replaced automatically.
  • Records of deletion requests received from Meta (confirmation code, app-scoped ID, date, number of connections removed): up to 3 years, so we can demonstrate that we honoured the request.
  • Server logs: usually no longer than 30 days.
  • Backups: deleted data also disappears from backups at the end of the rotation cycle, within 30 days at most.
  • Accounting records, if paid plans are introduced: for the period required by accounting law.

11How we protect data

  • platform access tokens and store credentials are encrypted with AES-256-GCM before being stored;
  • passwords are stored only as bcrypt hashes;
  • all traffic uses HTTPS; the session uses a signed cookie that JavaScript cannot read (httpOnly);
  • we request only the permissions needed for the features we offer (Google Analytics is read-only);
  • campaigns created through the app always start paused, and budget and status changes require your approval;
  • OAuth authorisation requests are protected with a unique state parameter checked on return;
  • access to the server and database is restricted to the people who operate the service.

No system is completely secure. If a personal data breach occurs that is likely to affect your rights, we notify the supervisory authority within 72 hours and inform you without undue delay, as required by Articles 33–34 GDPR.

12Your rights

Under the GDPR you have the right:

  • of access – to know what data we hold and receive a copy;
  • to rectification – to correct inaccurate data;
  • to erasure (“right to be forgotten”);
  • to restriction of processing;
  • to data portability – to receive your data in a structured, machine-readable format;
  • to object – to processing based on legitimate interest;
  • to withdraw consent at any time;
  • not to be subject to a decision based solely on automated processing.

How to exercise them

Directly in the app, under Settings, “Your data”: Download data gives you a JSON file with all of your account data straight away, and Delete account permanently removes the account and all associated data. You can edit your brand profile and connections in the app at any time.

For any other request, email us at contact@roasbrain.com from the address linked to your account. We reply within one month; this may be extended by two further months for complex requests, in which case we will let you know.

Complaints

If you believe we are infringing your rights, you can lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), 28–30 G-ral. Gheorghe Magheru Blvd., District 1, Bucharest, www.dataprotection.ro, or with the authority in the country where you live or work. Please contact us first; we can usually sort things out quickly.

13Children

RoasBrain is intended for businesses and professionals. It is not directed at anyone under 16 and we do not knowingly collect data about them. If you learn that a minor has given us data, contact us and we will delete it.

14Cookies and local storage

We use only strictly necessary cookies: the mg_session session cookie, short-lived cookies that protect platform connections (OAuth) and the language preference cookie. Your theme and a few display preferences are kept in your browser’s local storage. We do not use analytics or advertising cookies, which is why we don’t ask for consent with a banner. Full list with lifetimes: Cookie Policy.

15Changes to this policy

We may update this policy when the service or the law changes. The date of the last update is shown at the top. For material changes we will notify you by email or in the app before they take effect.

16Contact

[Company name], [Registered address]. Email: contact@roasbrain.com. Phone: [Phone].

Back to top