Publisher & data controller
Company : LBF INITIATIVES LIMITED
Registration : Private Company Limited by Shares, registered in Ireland (CRO) under number 789791, incorporated on 29 May 2025
Registered office : Flat 5, 2 Richmond Row, Dublin 8, D08 T25Y, Ireland
Contact : contact@adsfellow.app
Hosting : Cloud infrastructure providers established in the United States and the European Union (details available on request)
Data we collect
We collect only what is needed to run the service:
- Account data — email address and authentication identifiers, managed by our authentication provider when you sign up or sign in.
- Billing data — subscription status and billing period, synchronized from Stripe, our payment provider. We never see or store your card number.
- Ad platform connections — OAuth access tokens for the ad accounts you choose to connect, stored encrypted (AES-256-GCM). We never know your platform passwords.
- Content you generate — briefs, Campaign Blueprints, ad copies and visuals you choose to save.
- Technical data — error logs and anti-abuse counters (rate limits, daily limits). Your email does not appear in our logs.
- Audience measurement — analytics statistics (Google Analytics), only if you accept it via the cookie banner.
We do not sell or rent any personal data, to anyone, ever.
Purposes & legal bases (GDPR art. 6)
Each processing activity relies on a legal basis:
- Providing the service (account, generation, pushing paused drafts, metrics) — performance of the contract.
- Billing and subscription management — performance of the contract and legal obligations.
- Security, fraud and abuse prevention (rate limits, encryption, monitoring) — legitimate interest.
- Audience measurement — your consent, which you can withdraw at any time via the cookie banner.
Processors (named sub-processors)
We share personal data only with the technical sub-processors required to run AdsFellow. All are bound by GDPR data processing agreements. No personal data is sold or rented, to anyone, ever.
- Clerk Inc. (USA) — account creation, sign-in and session management.
- Stripe Inc. (USA) and Stripe Payments Ireland Ltd. (Ireland) — subscription billing as merchant of record. We never see or store your card number.
- Vercel Inc. (USA) — application hosting and global delivery; transient processing of all incoming and outgoing requests.
- Neon Inc. (USA) — managed PostgreSQL database; persistent storage of your account data, encrypted OAuth tokens, Campaign Blueprints and saved assets.
- Upstash Inc. (USA / EU) — Redis cache, rate limiting and webhook idempotency. No persistent personal data.
- Functional Software Inc., dba Sentry (USA) — error monitoring. Personal identifiers are redacted before transmission.
- Google LLC (USA) — Gemini API for text and visual generation (your briefs only, never your ad platform data); Google Analytics for audience measurement, only with your consent.
How we use Google API user data
AdsFellow's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We only request the minimum scope required to deliver the feature you opt into (https://www.googleapis.com/auth/adwords). Google user data is used exclusively to provide and improve user-facing features of AdsFellow; no other use is permitted.
What Google user data we access
- OAuth access token and refresh token issued by Google when you connect your Google Ads account. Stored encrypted at rest (AES-256-GCM).
- Google Ads account identifiers (customer ID, account name, currency, time zone) that you choose to connect.
- Campaign performance metrics (impressions, clicks, spend, conversions) read from your connected ad accounts and displayed inside your AdsFellow dashboard.
- Draft campaigns we create on your explicit request. These are always created in PAUSED state and never started without your action inside Google Ads.
How we use Google user data
- Display your Google Ads campaign metrics inside your AdsFellow dashboard so you can monitor performance alongside your other ad platforms.
- Create PAUSED draft campaigns in your Google Ads account when you explicitly press the Push button in AdsFellow. We never start, modify, or delete existing live campaigns.
- Maintain the OAuth connection (refresh tokens as needed) so you do not have to reconnect at each session.
- Detect and prevent abuse, fraud and security incidents on our service (legitimate interest, GDPR art. 6.1.f).
With whom Google user data is shared
- Vercel Inc. (USA) — transient processing of API responses as they pass through our application server.
- Neon Inc. (USA) — encrypted storage of the OAuth tokens and the campaign metadata you save inside AdsFellow.
- Functional Software Inc., dba Sentry (USA) — only if an unhandled error occurs; personal identifiers and tokens are redacted before transmission.
- No other third party. We do NOT share Google user data with our AI generation provider (Gemini), with other connected ad platforms, with analytics, or with any advertising network.
How we protect Google user data
- OAuth access tokens and refresh tokens are encrypted at rest using AES-256-GCM before storage in our PostgreSQL database. Encryption keys are rotated and held in environment secrets, never in source code.
- All data is transmitted over HTTPS (TLS 1.2 or higher). Our domain is HSTS-protected.
- Access to production data is restricted to authorized employees of LBF Initiatives Limited and is logged and monitored. We require strong authentication for all administrative access.
- Our application enforces rate limiting, webhook idempotency and per-user authorization on every API route handling Google user data, to prevent unauthorized cross-account access.
- Errors transmitted to our monitoring provider are scrubbed of access tokens, refresh tokens and personal identifiers.
What we never do with Google user data
- We do not sell, rent or transfer Google user data to any third party.
- We do not use Google user data for advertising, retargeting, personalized ads, interest-based ads, or to build user profiles for advertising purposes.
- We do not use Google user data to train AI or machine-learning models, ours or anyone else's.
- We do not use Google user data for credit-worthiness assessment, lending, or to determine eligibility for any service unrelated to AdsFellow.
- We do not allow humans to read your Google user data, except (1) with your explicit consent for support, (2) to comply with applicable law, or (3) to investigate suspected abuse.
Google user data retention and deletion
- OAuth tokens are kept only as long as your Google Ads account is connected. When you click Disconnect in your AdsFellow dashboard, the access and refresh tokens are deleted from our database immediately.
- Saved campaign metadata (Campaign Blueprints, push deep links) is retained while your AdsFellow account exists. You can delete any individual campaign at any time from the dashboard.
- Account deletion permanently removes all Google user data we hold about you within 30 days, except for billing records that we are legally required to keep at Stripe.
- You can also revoke AdsFellow's access from your Google Account at any time at https://myaccount.google.com/permissions, independently of any action inside AdsFellow.
To request a copy or deletion of any Google user data we hold about you, contact us at contact@adsfellow.app. We respond within 30 days as required by GDPR.
International transfers
Some providers process data outside the European Economic Area, mainly in the United States. These transfers are governed by the European Commission's Standard Contractual Clauses and/or the EU-US Data Privacy Framework certifications of the providers concerned.
Data retention
Your data is kept for as long as your account exists. When you delete your account, your Stripe subscription is cancelled first, then your platform connections (tokens), Campaign Blueprints, saved assets and profile are permanently deleted from our database. Billing records are kept by Stripe for the duration required by accounting law. Error logs are retained for 90 days.
Your GDPR rights
Under the GDPR you have the following rights over your personal data:
- Access — obtain a copy of the data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — delete your account and all associated data (also available directly from your account settings).
- Restriction — limit the processing of your data in certain cases.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interest, and withdraw consent at any time.
To exercise any of these rights, write to us at contact@adsfellow.app
You also have the right to lodge a complaint with a supervisory authority: the Irish Data Protection Commission (dataprotection.ie), our lead authority, or your local authority such as the CNIL (cnil.fr) in France.
Cookies
We use two categories of cookies and similar technologies:
- Essential (no consent required) — authentication cookies from our sign-in provider (keeping you signed in), Stripe cookies during checkout (payment security), and the storage of your cookie choice itself.
- Audience measurement (consent required) — Google Analytics cookies (_ga, _ga_*), loaded ONLY if you click Accept in the banner. If you decline, nothing is sent to Google.
Your choice is stored for 6 months and can be changed at any time:
Payments
Subscriptions (€99/month after a 3-day free trial, card required) are processed by Stripe as merchant of record. Card data is entered exclusively on Stripe's secure pages and never transits through our servers. You can cancel at any time from the customer portal; access remains until the end of the paid period.
Security
Ad platform tokens are encrypted at rest (AES-256-GCM). All traffic is encrypted in transit (TLS). Access controls are fail-closed: if a security check cannot be performed, access is denied. Campaign drafts are always created PAUSED with a minimal placeholder budget — nothing can spend without your explicit activation in your own Ads Manager.
Artificial intelligence
Campaign Blueprints, ad copies and visuals are generated through the API of a leading AI provider. Your briefs are sent to this API solely to produce your content; under the provider's paid API terms, this data is not used to train its models. Generated content is yours; you remain responsible for reviewing it before any advertising use.
Applicable law & changes
This site and these terms are governed by Irish law and applicable EU regulations (GDPR, ePrivacy). We may update this page as the service evolves; the date below always reflects the latest version. Material changes will be announced in the app.
Last updated: 12 June 2026

