Privacy Policy
Last updated:
RoasBrain is a web application that reads data from your advertising accounts (Meta, Google Ads, TikTok) and, optionally, from your online store, analyses it with artificial intelligence and helps you write copy, generate images and prepare campaigns.
This policy explains in plain language what personal data we process, for what purpose, on what legal basis, who we share it with and what rights you have under Regulation (EU) 2016/679 (GDPR) and Romanian Law no. 190/2018.
Contents
- 01Who the controller is
- 02What data we process
- 03Purposes and legal bases
- 04Google user data
- 05Meta Platform Data
- 06TikTok data
- 07Artificial intelligence and automated decisions
- 08Who we share data with
- 09Transfers outside the European Economic Area
- 10How long we keep data
- 11How we protect data
- 12Your rights
- 13Children
- 14Cookies and local storage
- 15Changes to this policy
- 16Contact
01Who the controller is
The controller of your personal data is {company}, registered office [Registered address], Trade Register no. [Trade Register no.], tax ID [Tax ID] (“we”, “us”).
You can reach us about anything related to your data at contact@roasbrain.com or by phone at [Phone].
For your customers’ data that you send us through store integrations (for example orders used for the Meta Conversions API), you are the controller and we act as your processor (Art. 28 GDPR): we process it only for the features you enable and only according to your settings. On request, we will sign a written data processing agreement with you.
02What data we process
Account data
Your name, email address, password (stored only as a bcrypt hash, never in plain text), preferred language, account creation and email verification dates. The brand profile you fill in: name, website, industry, offer, target audience, tone, differentiators, markets, currency and monthly budget.
Advertising platform data
When you connect a Meta, Google Ads or TikTok account through the official authorisation flow (OAuth), we read through the platforms’ official APIs: the ad account ID and name, currency and time zone, the structure of campaigns, ad sets and ads, ad copy and images, budgets, targeting settings and performance metrics (impressions, clicks, spend, conversions, conversion value). For Meta we also read the list of Pages you manage, so you can choose the Page your ads run under, and your app-scoped user ID, which we need to honour deletion requests sent by Meta.
We do not read personal data about the people who see or interact with your ads. The platforms only give us aggregated figures.
Access tokens received from the platforms are stored encrypted and used only to read the data above and to carry out the actions you trigger.
Online store and Google Analytics 4 data
If you connect a store (Shopify, WooCommerce, Gomag, MerchantPro) or a GA4 property, we read daily aggregated figures: order count, revenue, taxes, discounts, shipping, refunds and, where available, cost of goods. We use these figures to calculate the real profit of your advertising. Store credentials are stored encrypted.
Meta Conversions API (only if you enable it)
If you explicitly enable sending orders to the Meta Conversions API for a store, for every new order we receive the order data from your store, including the customer’s contact details. Before sending, email, phone, first name, last name, city, postal code and country are normalised and irreversibly hashed with SHA-256; IP address, browser user agent and Meta click identifiers (fbc, fbp) are sent as Meta requires. We do not store customer contact details: we keep only a short log of the last 25 events (order ID, value, currency, delivery status, date).
AI content
The instructions you write, the texts you give us to proofread or analyse, the generated results (audits, copy, strategies, campaign plans) and their history, so you can find them again.
Uploaded creatives and generated images
Images you upload or generate in the app, together with the instructions used to generate them.
Competitor monitoring
The names, Pages and keywords of the competitors you choose to follow, and their public ads obtained from the Meta Ad Library (copy, run dates, platforms, reported EU reach).
Notifications
The email address for alerts and reports, your notification preferences and, if you enable Telegram, the chat ID of your conversation with our bot.
Automations
The rules you define and the history of proposed, approved, rejected or executed actions.
Technical data
Server logs (IP address, date and time, requested URL, browser user agent, error codes), used for operation and security, and the strictly necessary cookies described in the Cookie Policy.
AI usage metering
For every call to an AI model we record the type of operation, the model, the number of tokens or images and the estimated cost, to enforce monthly usage limits.
03Purposes and legal bases
| Purpose | Data used | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Creating and managing your account, signing in | Account data | Performance of a contract – Art. 6(1)(b) |
| Showing reports, audits and profit | Platform, store and GA4 data | Performance of a contract – (b) |
| Generating copy, images, analyses and plans with AI | Brand profile, instructions, platform data | Performance of a contract – (b) |
| Creating or changing campaigns at your request | Platform data, access tokens | Performance of a contract – (b) |
| Sending orders to the Meta Conversions API | Order data, hashed | Your instructions, as controller of your customers’ data (Art. 28) |
| Alerts, weekly reports, Telegram notifications | Email, Telegram chat ID, platform data | Performance of a contract – (b); consent for Telegram – (a) |
| Security, abuse prevention, troubleshooting | Technical data | Legitimate interest – (f) |
| Enforcing AI usage limits and controlling costs | AI usage metering | Legitimate interest – (f) |
| Service emails (verification, password reset) | Performance of a contract – (b) | |
| Keeping records required by law | Billing data, if paid plans are introduced | Legal obligation – (c) |
Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of earlier processing. Where we rely on legitimate interest, we have assessed that the processing is necessary, proportionate and does not override your rights; you can object at any time.
We do not send marketing emails and we do not sell data.
04Google user data
This section describes how RoasBrain accesses, uses, stores and shares data received through Google APIs.
What Google data we access
- Google Ads (
adwordsscope, https://www.googleapis.com/auth/adwords): the list of ad accounts you can access, the structure of campaigns, ad groups and ads, budgets, ad copy and performance metrics. - Google Analytics 4 (
analytics.readonlyscope, https://www.googleapis.com/auth/analytics.readonly): the list of your GA4 properties and daily aggregated reports on purchases and revenue. Access is read-only.
How we use it
- to show you reports and dashboards;
- to generate audits, recommendations and profit calculations;
- only on your explicit action, to create campaigns (always created paused) or to change the status or budget of an existing campaign.
To produce an analysis you request, extracts of this data (mainly aggregated metrics and ad copy) are sent to our AI provider, Anthropic, solely to generate the response shown to you.
What we don’t do
- we do not sell Google user data;
- we do not use or transfer it for advertising, including personalised, retargeted or interest-based advertising;
- we do not use it to develop, improve or train generalised artificial intelligence or machine learning models;
- we do not transfer it to third parties except as necessary to provide user-facing features, to comply with the law, or as part of a merger or acquisition with prior notice;
- no one on our team reads this data except with your explicit consent (for example when you ask us to help with a specific issue), to investigate security incidents or abuse, or when required by law.
RoasBrain's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can revoke access at any time in the app (Integrations → Disconnect) or in your Google Account at myaccount.google.com/permissions. When you disconnect, we delete the tokens and the data synced from that account.
05Meta Platform Data
For Meta (Facebook and Instagram) accounts we request the ads_read, ads_management, business_management, pages_show_list and pages_read_engagement permissions. We use them to read the advertising data described above, to select the Page and pixel for your campaigns and, only on your explicit action, to create campaigns (paused) or change their status or budget.
Data received from Meta is used only to provide the app’s features to you. We do not sell it, use it for advertising or profiling, use it to train AI models, or share it with third parties other than the providers that help us run the service (hosting, AI), under this policy and the Meta Platform Terms.
For competitor monitoring we use the Meta Ad Library, which contains public ads.
You can remove the app at any time in Facebook: Settings → Business Integrations. When you do, Meta notifies us automatically and we delete the connections and synced data. Details and request status lookup: Data deletion.
06TikTok data
For TikTok for Business accounts we use the TikTok API for Business, with the authorisation you grant for the selected advertiser accounts. We read the structure of campaigns, ad groups and ads, budgets and performance metrics and, only on your explicit action, create campaigns (paused) or change their status or budget.
TikTok data is used only to provide the app’s features to you; we do not sell it, use it for advertising or use it to train AI models. You can revoke access in the app or in TikTok Business Center.
07Artificial intelligence and automated decisions
Copy, analyses and recommendations are generated by AI models (Anthropic Claude for text and analysis; OpenAI or Replicate for images). For each request we send the provider only what is needed: your brand profile, your instruction and, where relevant, aggregated metrics, ad copy or the uploaded image.
Anthropic and OpenAI state in their commercial API terms that, by default, they do not use data received through the API to train their models. We do not use your data to train AI models.
AI results are suggestions. We make no decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR). Changes to your ad accounts happen only when you approve them; an automation rule acts without approval only if you have explicitly set it to automatic mode, within safety limits.
08Who we share data with
We use the following service providers (processors), bound by data protection terms:
| Recipient | Role | Location |
|---|---|---|
| Web hosting provider | Application server and database | European Union |
| Anthropic PBC | AI models for text and analysis | USA |
| OpenAI or Replicate, Inc. (depending on configuration) | Image generation | USA |
| Email provider (SMTP) | Service emails, alerts and reports | As per the configured provider |
| Telegram (only if you enable it) | Delivering notifications in Telegram | Outside the EU |
Meta, Google and TikTok, as well as your store platform, are not our providers: they are services you choose to connect, and they act as independent controllers for the data they hold. When you create a campaign or send conversion events through the app, the data reaches that platform and is subject to its policies.
We disclose data to authorities only when legally required, on the basis of a lawful request.
09Transfers outside the European Economic Area
Some providers (Anthropic, OpenAI, Replicate, Telegram) process data outside the EEA, notably in the USA. For these transfers we rely on the adequacy decision for the EU-US Data Privacy Framework, for certified providers, and/or on the Standard Contractual Clauses adopted by the European Commission, with supplementary measures where needed. You can ask for a copy of the applicable safeguards at contact@roasbrain.com.
10How long we keep data
- Account data and brand profile: for as long as you have an account. Deleted immediately when you delete your account.
- Data synced from platforms and stores: for as long as the connection is active. Deleted when you disconnect the account or store, or delete your RoasBrain account.
- AI history, creatives, rules and alerts: until you delete them or your account.
- Conversions API log: only the last 25 events per store; older entries are replaced automatically.
- Records of deletion requests received from Meta (confirmation code, app-scoped ID, date, number of connections removed): up to 3 years, so we can demonstrate that we honoured the request.
- Server logs: usually no longer than 30 days.
- Backups: deleted data also disappears from backups at the end of the rotation cycle, within 30 days at most.
- Accounting records, if paid plans are introduced: for the period required by accounting law.
11How we protect data
- platform access tokens and store credentials are encrypted with AES-256-GCM before being stored;
- passwords are stored only as bcrypt hashes;
- all traffic uses HTTPS; the session uses a signed cookie that JavaScript cannot read (httpOnly);
- we request only the permissions needed for the features we offer (Google Analytics is read-only);
- campaigns created through the app always start paused, and budget and status changes require your approval;
- OAuth authorisation requests are protected with a unique state parameter checked on return;
- access to the server and database is restricted to the people who operate the service.
No system is completely secure. If a personal data breach occurs that is likely to affect your rights, we notify the supervisory authority within 72 hours and inform you without undue delay, as required by Articles 33–34 GDPR.
12Your rights
Under the GDPR you have the right:
- of access – to know what data we hold and receive a copy;
- to rectification – to correct inaccurate data;
- to erasure (“right to be forgotten”);
- to restriction of processing;
- to data portability – to receive your data in a structured, machine-readable format;
- to object – to processing based on legitimate interest;
- to withdraw consent at any time;
- not to be subject to a decision based solely on automated processing.
How to exercise them
Directly in the app, under Settings, “Your data”: Download data gives you a JSON file with all of your account data straight away, and Delete account permanently removes the account and all associated data. You can edit your brand profile and connections in the app at any time.
For any other request, email us at contact@roasbrain.com from the address linked to your account. We reply within one month; this may be extended by two further months for complex requests, in which case we will let you know.
Complaints
If you believe we are infringing your rights, you can lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), 28–30 G-ral. Gheorghe Magheru Blvd., District 1, Bucharest, www.dataprotection.ro, or with the authority in the country where you live or work. Please contact us first; we can usually sort things out quickly.
13Children
RoasBrain is intended for businesses and professionals. It is not directed at anyone under 16 and we do not knowingly collect data about them. If you learn that a minor has given us data, contact us and we will delete it.
15Changes to this policy
We may update this policy when the service or the law changes. The date of the last update is shown at the top. For material changes we will notify you by email or in the app before they take effect.
16Contact
[Company name], [Registered address]. Email: contact@roasbrain.com. Phone: [Phone].