Privacy Policy
Updated 2026-08-17
This Policy explains how AdDecide processes personal data when you use the product. For account and billing data we act as controller. For Customer Content and uploaded event data, you act as controller and we act as processor.
Data we process
Account data (such as email, name, and locale), session cookies, billing metadata through our payment providers, creatives and prompts you submit, UTM and unit metadata, uploaded event data, security logs, and limited product analytics used to understand activation.
Purposes
Provide the SaaS, bill correctly, secure the service, support you, and improve onboarding. We do not train ML models on Customer Content by default.
Retention
Raw ingest: 30 days. Aggregated facts: 24 months. Invoices: 10 years (legal hold — not erased with workspace delete). Account data: until deletion request, subject to legal holds.
Your rights
Depending on jurisdiction you may request access, correction, erasure, restriction, or portability. Invoice legal-hold records may be retained even after erase requests.
International transfers and subprocessors
We use subprocessors for hosting (VPS and Postgres backups), email, Cloudflare tunnel when used for public HTTPS, and payments (e.g. Paddle when billing is configured). See the Data Processing Agreement for the current list. Transfers use appropriate safeguards.
First-party product events
We record a small set of server-side, first-party product events to understand activation and improve onboarding — without third-party trackers such as Mixpanel or Google Analytics. Event names include guest_wow (demo engagement), signup (account created), sample_or_csv (first data on board), decision (Stop/Archive/Resume recorded), and checkout_start (billing checkout opened). Events contain minimal metadata (timestamps, workspace/plan codes where applicable) and are not used for cross-site advertising.
Cookies
We use a minimal set of cookies required to run the product.
addecide_session — httpOnly session cookie to keep you signed in.
addecide_locale — remembers your language preference.
See First-party product events above for how we measure activation without third-party marketing trackers.
Last updated 2026-08-17. Questions: [email protected]. This document is not legal advice.