Skip to main content

Privacy Policy

Last updated: September 23, 2026

This Privacy Policy explains how AdPredictor ("we", "us", "our") collects, uses, stores, and protects your personal data when you use adpredictor.ai (the "Service"). We are committed to protecting your privacy in compliance with the General Data Protection Regulation (GDPR), the Spanish Organic Law 3/2018 on Data Protection (LOPDGDD), and other applicable privacy legislation.

1. Data Controller & Data Protection Officer

The data controller responsible for the processing of your personal data is AdPredictor, contactable at hello@adpredictor.ai.

Data Protection Officer (DPO): Daniel Benitez, hello@adpredictor.ai. Our DPO oversees data protection compliance and is your point of contact for any privacy-related questions, concerns, or data subject requests.

If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us at the email address above or directly to our DPO.

2. Data We Collect

Account Information: When you register, we collect your name, email address, and authentication credentials (managed via Supabase Auth). If you sign in with Google, we receive your Google profile information (name, email, profile picture).

Google Ads Data: If you connect your Google Ads account, we access campaign data, keyword performance, search terms, daily metrics, and account metadata via the Google Ads API. This data is used exclusively to provide you with insights, predictions, and optimization recommendations.

Payment Information: When you subscribe to a paid plan, payment processing is handled entirely by Stripe. We store your Stripe customer ID and subscription status, but never your credit card number or full payment details.

Usage Data: We collect information about how you use the Service, including pages visited, features used, tool inputs/outputs, and interaction patterns. This helps us improve the product.

Contact & Lead Data: If you submit a contact form or use our free tools, we collect the information you provide (name, email, company, message content, tool inputs).

Technical Data: We automatically collect IP addresses, browser type, device information, and access timestamps for security, rate limiting, and analytics purposes.

3. Legal Basis for Processing

We process your personal data based on the following legal grounds under GDPR Article 6:

Contract Performance (Art. 6(1)(b)): Processing necessary to provide the Service you requested, including account management, Google Ads data analysis, and subscription handling.

Legitimate Interest (Art. 6(1)(f)): Processing for security (rate limiting, fraud prevention), product improvement (analytics), and customer support. We have assessed that these interests do not override your fundamental rights.

Legitimate Interest (Art. 6(1)(f)), ad measurement: when you leave your email for an audit, start a trial or pay, we tell the ad platforms we advertise on that it happened, so we know which of our ads bring in customers. The platforms we work with are listed in section 5. We send your email encrypted (SHA-256), your IP address, your browser and, if you arrived from an ad, the identifier of that click. Those platforms' cookies are only read if you accepted marketing cookies. If your browser sends Global Privacy Control or Do Not Track when you leave your email and you have not accepted them, we do not send that step. You can object at any time by writing to hello@adpredictor.ai.

Consent (Art. 6(1)(a)): Where required, such as for marketing communications and non-essential cookies. You can withdraw consent at any time.

Legal Obligation (Art. 6(1)(c)): Processing necessary to comply with tax, accounting, or other legal requirements.

4. How We Use Your Data

Service Delivery: To audit your Google Ads account without changing anything in it (free audit and Live audit) and generate its verdicts and recommendations. We never change anything in your account.

Account Management: To create and manage your account, authenticate your identity, and handle billing.

Communication: To send essential service emails (welcome, password reset, account notifications). We use Brevo as our email service provider.

Security: To protect against unauthorized access, detect anomalies, and enforce rate limits.

Product Improvement: To analyze aggregated, anonymized usage patterns and improve the Service.

Ad Measurement: To know which of our ads on Meta, Google and ChatGPT bring in customers (see section 3).

AI Processing: Tool inputs and campaign data may be processed by third-party AI providers to generate insights. This data is not used to train AI systems.

5. Third-Party Processors

We share your data with the following third-party processors, each of which maintains their own privacy policies and data processing agreements:

Supabase (EU/US), Authentication and database hosting. Data stored in AWS eu-west-1 (Ireland).

Stripe (US), Payment processing. PCI DSS Level 1 certified.

Vercel (US), Application hosting and serverless functions. SOC 2 Type 2 certified.

Google (US), Google Ads API access for campaign data synchronization. Subject to Google API Services User Data Policy.

Brevo (EU/US), Transactional email delivery and CRM.

Upstash (EU), Rate limiting via Redis. Data processed in EU region.

Cloudflare (US), Turnstile CAPTCHA for spam protection on forms.

AI processing service (US), AI-powered insight generation. Campaign data is processed to generate optimization recommendations: campaign names, keywords, search terms, the texts of your ads, what you write in the chat and, from the change history, whether each change was made by you, by someone else, by an automated rule or by Google. Data is not used for model training.

Google Analytics (US), Website analytics with Consent Mode v2 for GDPR compliance.

Microsoft Clarity (US), Anonymous session recordings and heatmaps to improve the website. Only with analytics consent.

Meta Platforms Ireland (EU/US), Ad measurement: Meta pixel (only with marketing consent) and Conversions API (legitimate interest, see section 3).

Google Ads (US), Ad conversion measurement. Only with marketing consent.

OpenAI (US), ChatGPT Ads conversion measurement. Only with marketing consent.

We ensure all processors provide adequate data protection guarantees. Where data is transferred outside the EEA, we rely on Standard Contractual Clauses (SCCs) or adequacy decisions.

6. Cookies and Tracking

Essential Cookies: Required for authentication and session management. These cannot be disabled.

Analytics Cookies: Google Analytics (GA4) with Consent Mode v2. These are only activated with your consent.

Security Cookies: Cloudflare Turnstile uses cookies for bot detection on forms.

Marketing Cookies: Google Ads, Meta and ChatGPT Ads, only with your consent, to measure which of our ads bring in customers. We do not sell your data. Details and the full list are in our Cookie Policy.

You can manage your cookie preferences from the cookie banner or through your browser settings.

7. Data Retention

Account Data: Retained for the duration of your account. Deleted within 30 days of account deletion.

Free audit (Google Ads data): If you do not start the trial, after 48 hours we delete the detail of your account pulled for the free audit: campaigns, keywords and search terms. The audit session (the access key to your account, your health score, the email address and identifier of the Google account you connected with, and the IP address you connected from) is kept for 9 more days after those 48 hours so we can send you the follow-up emails, and then we delete it. We keep a daily summary of the account with its totals and its health score, without campaign names, keywords or search terms; this summary has no deletion date. If you give us your email, we also keep it as a contact to write to you with tips and offers until you unsubscribe with the link in each email.

Paid audit (Google Ads data): Kept for as long as you have access to the report you bought. We promise the audit is yours permanently, and we cannot honour that while deleting the data it is built on. You can delete it at any time from your account settings, or by writing to us.

Live audit subscribers (Google Ads data): Kept on a rolling 90 day window while your subscription is active. Performance data older than 90 days is deleted automatically. Nightly monitoring works by comparing the previous day against the recent past, so keeping that window is not a side effect, it is the service you contracted. When you cancel we stop pulling new data immediately. Within 30 days we delete the stored access credential for your Google Ads account, so we can no longer reach it, and we delete your alert history. Within 90 days we remove the account link and delete the performance data we had downloaded (daily metrics, search terms, keywords, quality score history, baselines, and the geographic, device and time of day breakdowns). If you want it done sooner, ask us from your account settings or at hello@adpredictor.ai; we action it within 30 days.

Watchdog Monitoring: Your Google Ads data is accessed nightly (via a stored OAuth refresh token; we only read) to detect anomalies. Alert history is retained for 30 days. Weekly summaries are sent every Monday.

Contact Form Submissions: Retained for up to 24 months for follow-up purposes.

Server Logs & Security Data: Retained for up to 90 days for security and debugging purposes.

Payment Records: Retained as required by tax and accounting legislation (typically 5-7 years).

8. Your Rights (GDPR Articles 15-22)

You have the following rights regarding your personal data:

Right of Access (Art. 15): Request a copy of all personal data we hold about you. You can do this instantly via Settings > Export Data, which downloads a JSON file with all your data.

Right to Rectification (Art. 16): Request correction of inaccurate personal data.

Right to Erasure (Art. 17): Request deletion of your personal data. You can do this via Settings > Delete Account, which triggers deletion (or anonymisation) of your data and your authentication account, subject to any retention required by law, security, or billing.

Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format (JSON). Available via the export feature.

Right to Restrict Processing (Art. 18): Request that we limit how we use your data.

Right to Object (Art. 21): Object to processing based on legitimate interest.

Right to Withdraw Consent: Where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of prior processing.

Automated Decision-Making (Art. 22): Our service uses AI (Google Gemini) to generate audit insights and optimization recommendations about your Google Ads campaigns. These insights are INFORMATIONAL ONLY and do not automatically execute changes to your campaigns. You always review and approve any actions. You have the right to request human review of any AI-generated recommendation by contacting us at hello@adpredictor.ai.

CCPA Rights: If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to delete it, and the right to opt-out of the sale of personal information. We do not sell personal information.

To exercise any of these rights, contact us at hello@adpredictor.ai. We will respond within 30 days as required by GDPR. You also have the right to lodge a complaint with your local supervisory authority (in Spain: Agencia Española de Protección de Datos, www.aepd.es).

9. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including: encryption in transit (TLS 1.3) and at rest, secure authentication via Supabase Auth with OAuth 2.0, rate limiting to prevent abuse, regular security reviews, and access controls limiting data access to authorized personnel only.

In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay, as required by GDPR Article 33-34.

10. Children's Privacy

The Service is not intended for individuals under 13 years of age. We do not knowingly collect personal data from children under 13. If we become aware that we have collected data from a child under 13, we will delete it promptly. Users between 13 and 16 require parental or guardian consent.

11. International Data Transfers

Your data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States. Where this occurs, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, or reliance on the EU-US Data Privacy Framework where applicable.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or an in-app notification at least 30 days before they take effect. The "Last updated" date at the top of this page indicates the most recent revision.

13. Contact

For any privacy-related inquiries, data subject requests, or complaints: Email: hello@adpredictor.ai

Supervisory Authority: If you are in the EU/EEA and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection authority. In Spain: Agencia Española de Protección de Datos (AEPD), www.aepd.es.