1. Who we are
AskAds ("AskAds", "we", "us") provides an AI assistant for managing paid advertising. This policy covers the AskAds web application at askads.ai and everything connected to it.
For the purposes of the EU General Data Protection Regulation, HOOTCODES LTD is the data controller for your account data, and acts as a data processor in respect of the advertising data we access on your instruction from your connected ad accounts.
Operator details. AskAds is operated by HOOTCODES LTD, a company registered in Bulgaria, European Union. Registered office: Aleksandar Stamboliyski Blvd 55, fl. 4, 1000 Sofia, Bulgaria. Company (UIC) number 208188022. VAT number BG208188022. Data protection questions go to [email protected].
2. What we collect
We collect only what the product needs to work. Specifically:
- Your email address. Used to sign you in and to contact you about your account. We do not use passwords — sign-in is by emailed magic link or six-digit code.
- Your projects and settings. Project names, the website address you supply, and your currency, timezone and language preferences.
- Your conversations. The messages you send the assistant, its replies, and a record of which tools it ran to answer you.
- Notes the assistant keeps. Facts you tell it, or that it derives during onboarding, so it does not have to ask twice.
- Access tokens. The credentials your ad platform issues when you connect an account, stored encrypted (see section 9).
- Basic technical data. Requests to our servers produce ordinary logs containing IP address, browser type and timestamps.
We do not collect payment card details directly, and we do not buy personal data from third parties or enrich your profile from external sources.
3. Data from your ad accounts
When you connect Meta (Facebook and Instagram), you grant AskAds permission to read your advertising data. We request the minimum scopes required to do the job:
- Campaign, ad set and ad structure — names, status, budgets, objectives and settings.
- Performance figures — spend, impressions, clicks, conversions, revenue and derived metrics.
- Ad creative — headlines, body copy, calls to action, destination links, images and videos.
- Business and account details — the ad accounts and businesses you have access to, so you can choose which one to use.
We read this data. We do not change anything in your ad account unless you explicitly approve a specific proposed change, shown to you in full beforehand. We never post content on your behalf, never contact your customers, and never access your audience lists or customer files.
When you ask the assistant to review a creative, we download that image or video temporarily to sample frames and transcribe its audio. The file itself is deleted as soon as the analysis finishes.
4. Why we process it, and our lawful basis
| Purpose | Data | Lawful basis |
|---|---|---|
| Providing the service you asked for | Account, projects, conversations, ad data | Performance of a contract |
| Signing you in and keeping your account secure | Email, tokens, technical logs | Performance of a contract |
| Reading your ad accounts | Advertising data | Your consent, given at connection and withdrawable at any time |
| Diagnosing faults and preventing abuse | Technical logs | Legitimate interests in a working, secure service |
| Improving the product | Aggregate usage counts | Legitimate interests, balanced against your privacy |
| Meeting legal and accounting obligations | Account records | Legal obligation |
5. How AI models are used
AskAds is built on large language models. To answer your questions, we send relevant context to a model provider — this can include your messages, the advertising figures retrieved for that question, your ad copy, the content of a landing page you asked us to inspect, and frames or audio from a creative under review.
Two commitments that matter here:
- We do not train models on your data. Neither we nor, under our agreements, our model providers use your content to train or fine-tune models.
- We send only what the question requires. Context is assembled per request rather than by handing over your whole account.
Model providers are listed in section 6. AI output can be wrong; see the Terms of Service for what that means for decisions you take.
6. Who we share it with
We do not sell your data, and we do not share it for advertising. We use the following processors, each under a contract restricting them to our instructions:
| Processor | Purpose | Data involved |
|---|---|---|
| MongoDB Atlas | Database hosting | All stored account and conversation data |
| OpenRouter | Routing requests to AI models | Message context, ad figures, creative under review |
| Meta Platforms | Reading your Meta ad account | OAuth token, API requests |
| Postmark | Sending sign-in and account emails | Email address, message content |
| Umami | Privacy-focused website analytics | Aggregate page views; no cookies, no cross-site tracking |
We may also disclose data where we are legally required to, or to establish or defend legal claims. If AskAds is ever acquired or merged, your data may transfer to the acquirer, who would remain bound by this policy until you are told otherwise.
7. International transfers
Some processors above operate outside the European Economic Area, including in the United States. Where data leaves the EEA we rely on the European Commission's Standard Contractual Clauses, or on an adequacy decision where one applies to that provider.
8. How long we keep it
- Account and project data — for as long as your account is open.
- Conversations and assistant notes — until you delete the conversation, or until your account is deleted.
- Access tokens — until you disconnect the account or the platform expires them.
- Cached advertising data — short-lived, typically minutes to hours, to avoid re-requesting the same figures. Creative analyses are cached for up to 30 days.
- Downloaded creative files — deleted immediately after analysis.
- Technical logs — up to 90 days.
After account deletion we remove your data within 30 days, except where law requires us to keep records longer.
9. How we protect it
- Ad platform access tokens are encrypted at rest with AES-256-GCM. They are never displayed back to you and never sent to your browser.
- All traffic runs over HTTPS.
- Every request is scoped to your own account and project, so one customer's data cannot be reached from another's session.
- Access to production systems is limited to those who need it.
No system is perfectly secure. If a breach affects your data we will notify you and the relevant supervisory authority as the law requires.
10. Your rights
If you are in the UK or EEA, you have the right to:
- Access the personal data we hold about you.
- Rectify anything inaccurate.
- Erase your data — see section 11.
- Restrict or object to processing based on legitimate interests.
- Port your data to another provider in a machine-readable format.
- Withdraw consent at any time, by disconnecting an ad account. This does not affect processing already carried out.
Write to [email protected] and we will respond within 30 days. You also have the right to complain to your local data protection authority.
11. Deleting your data
You can disconnect an ad account at any time from Connections, which revokes our access and removes the stored token. To delete your account and everything in it, follow the instructions on our Data Deletion page.
12. Cookies and analytics
We use a small number of cookies, all of them necessary for the app to function:
- Session cookie — keeps you signed in.
- Active project cookie — remembers which project you are working in.
- OAuth state cookie — a short-lived security token that protects the ad account connection flow.
We use no advertising cookies and no cross-site trackers. Our analytics (Umami) is cookieless and does not build a profile of you across sites, which is why you are not asked to consent to it.
13. Children
AskAds is a business tool and is not directed at anyone under 16. We do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.
14. Changes to this policy
If we change this policy we will update the date at the top. Where a change materially affects your rights, we will tell you by email or in the app before it takes effect.
15. Contact us
Privacy questions, requests and complaints: [email protected]. Anything else: [email protected].