Legal
Privacy Policy
The short version
Adease is a desktop application backed by our secure cloud service. When you connect an advertising account, our backend holds the connection tokens and a synced copy of your campaign data, scoped to your workspace, so the app and its assistant can do their job. We do not sell that data, we do not share it with advertisers or data brokers, and we never use it to train models. Disconnecting an account or deleting your Adease account deletes it.
Who we are
Adease LTD ("Adease", "we", "us") is the data controller for the personal data described here. You can reach us at support@adease.io.
- Company
- Adease LTD
- Company number
- 14743980 — England and Wales
- Registered office
- 124 City Road, London, EC1V 2NX, United Kingdom
- Contact
- support@adease.io
Your advertising data
When you connect an advertising account (Google Ads, Meta, TikTok, Pinterest, LinkedIn or Shopify), the following is processed and stored on our backend, which runs on Google Cloud / Firebase, scoped to your workspace:
- Connection tokens — the OAuth tokens that let Adease act on the accounts you authorised. These are stored server-side in our database and are never placed in the desktop application or exposed to other users.
- Campaign data — a synced copy of the campaign, ad group, ad and keyword structure of your connected accounts, together with performance metrics such as spend, impressions, clicks and conversions.
- Your work in the app — assistant conversations, generated reports, and the knowledge cards you record for each client.
The desktop application additionally keeps a local cache and any files you export; those stay on your machine until you delete them.
Your account data
To run your account and licence we process a small amount of personal data on our own systems:
- Account details — your name, email address and organisation membership.
- Billing records — subscription status, plan and invoices. Card details are handled by our payment processor and are never stored by us.
- Diagnostics — crash reports and error traces used to fix faults. These are scrubbed of ad account content.
Why we are allowed to process it
- Performance of a contract — account details and billing records are needed to give you access to the software.
- Legitimate interests — diagnostics, to keep the application working and secure.
- Legal obligation — retaining invoices and tax records for the period the law requires.
Who else is involved
We use a small number of service providers, each receiving only what is needed for its role:
- Google Cloud / Firebase — hosts our backend and database, where connection tokens, synced campaign data and your work in the app are stored.
- The model providers that power the agent — Anthropic and/or Hugging Face. When you ask the agent something, your request and the campaign context needed to answer it are processed by the model to generate the response, and for nothing else. See "The agent" below.
- Payment processing — billing details only, to take subscription payments.
- Error reporting — crash diagnostics only, scrubbed of ad account content.
- Google Analytics — on this website only, to count visits and downloads. It is not part of the desktop app and never sees your ad accounts. See below.
- Google Ads — on this website only, to measure which adverts lead to a download or a subscription. It is not part of the desktop app and never sees your ad accounts. See below.
- Meta — on this website only, for the same purpose on Facebook and Instagram adverts. It is not part of the desktop app and never sees your ad accounts. See below.
None of them are permitted to use your data for their own purposes. Your ad account data, campaign data and client names are never sold and never shared with advertisers or data brokers by anyone, including us. The website measurement described below is separate: it concerns visits to these web pages, and never touches the data in your connected accounts.
Analytics on this website
These web pages use Google Analytics to measure how many people visit, which pages they read, and which downloads they start. It records page addresses, referrer, approximate location derived from IP address, device and browser type, and the download events described above. It sets cookies in your browser.
This applies to the website only. The Adease desktop application does not contain Google Analytics, Google Ads or Meta tags, and no advertising account data, campaign data or client name is ever sent to it. You can opt out with Google's browser add-on, or by blocking analytics cookies in your browser.
Advertising measurement on this website
We advertise Adease on Google Search, and on Facebook and Instagram. When you arrive from one of those adverts, the address carries a click identifier that we store in your browser, and Google Ads and Meta each set their own cookies. If you go on to create an account or start a subscription, that identifier tells us which advert brought you — so we can tell which adverts are worth paying for.
What is shared with Google and Meta is the fact that a click led to a signup or a subscription, and its value. Where an email address is used to match a conversion it is hashed first, and the address itself is not transmitted. Some of these measurements are sent from our servers rather than from your browser; they carry the same information, and are sent from our systems so that they are not lost when a browser blocks the request. No campaign data, client name or connected ad account is involved at any point — this measures visits to these web pages and nothing else.
The click identifier is kept for 90 days and then discarded. You can refuse these cookies in your browser, use Google's ad settings or Meta's ad preferences to turn off personalised advertising.
The agent
When you ask the agent to do something, the request and the context needed to answer it — which can include campaign structure and performance data from your connected accounts — are processed by a hosted language model operated by Anthropic and/or Hugging Face. The model's output is returned to you and the exchange is stored in your workspace as chat history. Ad account credentials and OAuth tokens are never included in what is sent to the model, and nothing you send is used to train models.
Model training
Your ad accounts, campaigns, knowledge cards and reports are never used to train machine learning models — ours or anyone else's. There is no setting that turns this on.
Google user data
Adease connects to your Google Ads account through Google's OAuth 2.0
flow, requesting a single scope:
https://www.googleapis.com/auth/adwords (the Google Ads
API). This section sets out, specifically for Google user data, what
we access, how we use it, who we share it with, how we protect it,
and how long we keep it. Adease's use of information received from
Google APIs adheres to the
Google API Services User Data Policy, including the Limited Use requirements.
What Google user data we access
- OAuth tokens for the Google account you authorise, used solely to call the Google Ads API on your behalf.
- Your accessible Google Ads accounts — the customer IDs and descriptive names of the Google Ads accounts you can manage, so you can choose which to connect.
- Campaign structure and settings — campaigns, budgets, ad groups, ads, keywords, and their status and targeting.
- Performance metrics — impressions, clicks, cost and conversions for those campaigns.
- Keyword ideas returned by Google's keyword planning service when you research keywords.
We request no other Google scope and access no other Google service — no Gmail, Drive, Contacts, Calendar or profile data beyond the above.
How we use Google user data
Only to provide the features you see in the application:
- showing your campaigns and their performance in your dashboard and in reports you generate;
- answering questions you ask the agent about your campaigns and their performance;
- suggesting keywords while you plan a campaign;
- creating or changing campaigns, ad groups, keywords and budgets, or pausing campaigns — and only after you have reviewed and approved the specific change in the app. No change is made to your Google Ads account automatically.
We do not use Google user data for our own advertising or marketing, we do not aggregate it across customers, we do not sell it, and we do not use it to train AI or machine-learning models.
Who we share Google user data with
We do not sell, rent or trade Google user data, and we do not share it with advertisers, data brokers or other third parties for their own purposes. It is disclosed only to the processors required to run the service:
- Google Cloud / Firebase — our backend and database run there; tokens and synced campaign data are stored on this infrastructure.
- Our AI model providers (Anthropic and/or Hugging Face) — when you ask the agent a question, the campaign context needed to answer it is processed by the hosted model solely to generate the response. Tokens and credentials are never sent to the model, and the data is not used for model training.
Beyond that, we would disclose data only if required by law, or as part of a merger or acquisition in which the receiving party remains bound by this policy. Humans at Adease do not read your Google Ads data except with your permission for support, where required for security or abuse investigation, or where the law requires it.
How we protect Google user data
- All data is encrypted in transit using TLS, and encrypted at rest on Google Cloud infrastructure.
- OAuth tokens are stored server-side only — never in the desktop application, never in exports, and never visible to other users. The OAuth client secret is held server-side as a managed secret.
- Access is scoped to your workspace: every request is authenticated and authorised against your user account and organisation membership before any Google Ads data is returned.
- Internal access follows the principle of least privilege, and sensitive operations are logged for audit.
How long we keep Google user data, and how to delete it
- OAuth tokens are kept while your Google Ads connection is active and deleted immediately when you disconnect the integration in the app, when the project they belong to is deleted, or when you delete your Adease account.
- Synced campaign data and metrics are kept while the connection is active and deleted with the workspace or account they belong to.
- Agent conversations and reports that reference Google Ads data are kept until you delete them or delete your account.
You can delete everything yourself: disconnect Google Ads from the integrations screen, or use Settings › Privacy & legal › Delete account, which permanently removes your profile, workspaces, stored tokens and synced data. You can also email support@adease.io to request deletion, and you can revoke Adease's access to your Google account at any time at myaccount.google.com/permissions.
How long we keep things
Account details are kept while your account is open and deleted after it is closed. Ad platform tokens and synced campaign data follow the rules described in the Google section above, which apply equally to every connected platform. Billing records are kept for as long as tax law requires. Diagnostics are kept for a limited period and then removed. Anything held only on your machine is deleted when you delete it.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or object to our using it. You can also complain to your data protection regulator.
Two of these you can do yourself, without asking: Settings › Privacy & legal › Export my data writes everything out as JSON, and Delete account removes your profile, memberships and stored tokens. For anything else, email support@adease.io.
Changes
If we change this policy we will update the date at the top of the page, and tell you in the app if the change is significant.
Contact
Questions about any of this go to support@adease.io.