Legal

Privacy Policy

What data we collect, why we process it and how long we keep it.

Effective date: 2026-09-22

Data we collect

CategoryExampleSource
Account dataname, email, password hashfrom you
Brand datawebsite content, product images, logo, positioningfrom you / your site
Production dataprompts, generated images and videos, quality scoresfrom the system
Ad datacampaign, ad set, spend and performance metricsfrom your connected ad account
Technical dataIP, browser, session, error logsautomatic
  • Performance of contract — account management, creative production, publishing
  • Legitimate interest — security, abuse detection, product improvement
  • Consent — marketing communication, non-essential cookies
  • Legal obligation — invoicing and retention requirements

Model training

We do not use your brand data, product images or generated output to train foundation models, and we do not share them with our subprocessors for that purpose. Data is processed for inference on your account only.

Sharing

Data is shared with subprocessors only as needed to provide the service. It is never sold or rented to third parties. A current list of the subprocessors we use is available on request.

Requests from public authorities

We disclose personal data to public authorities only when legally required. For every request:

  • Legal review: we verify that the request is valid, issued by a competent authority and has a proper legal basis before responding.
  • Challenge: we challenge requests that are overly broad, lack a legal basis or are otherwise unlawful, including through available legal remedies.
  • Data minimisation: where disclosure is required, we disclose only the minimum data necessary to comply.
  • Record-keeping: we document each request, our response, the legal reasoning and the people involved.
  • Notice: where the law permits, we notify the affected user before disclosure.

In the past 12 months we have received no national security requests.

Data from connected ad platforms (Google, Meta, TikTok)

When you connect an advertising account, you authorise Adropic through that platform's own sign-in screen. Nothing is accessed before you do, and only the account you choose is used.

Google user data. When you connect Google Ads, Adropic requests a single permission: https://www.googleapis.com/auth/adwords (manage your Google Ads accounts and data). With it we:

  • list the Google Ads accounts you can access, so you can pick one;
  • create the campaign budgets, Search campaigns, ad groups, keywords, locations and responsive search ads you configure in Adropic — always created paused, so spending starts only when you start it;
  • read performance metrics (impressions, clicks, cost, conversions) to show your reporting;
  • change budgets and pause or resume campaigns when you ask us to, or when you have switched on an optimisation rule that does so.

We do not request any other Google permission and do not access Gmail, Drive, Contacts, Calendar or any other Google data.

How it is stored and protected. The refresh token Google issues is stored encrypted at rest and used only to carry out the actions above. Google Ads data is visible only to the members of your Adropic workspace.

Sharing. We do not sell Google user data, do not transfer it to third parties, do not use it for advertising of our own, and do not use it to train AI models. It is processed by our infrastructure subprocessors only as needed to run the service.

Deletion. Disconnecting Google Ads in Settings → Integrations deletes the stored token immediately; deleting your Adropic account deletes the token and all Google Ads data we hold. You can also revoke access at any time from your Google Account's security settings.

Adropic's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Retention

  • Billing and invoice records: 10 years after account closure (statutory)
  • Account, brand and production data: deleted immediately when you delete your account; removed from backups within 90 days
  • Technical logs: 12 months

Your rights

Your rights under Turkish data protection law (KVKK) and how to exercise them are described in the KVKK notice.

You can delete your account and its data at any time from Settings → Account. Step-by-step instructions, including data received from Meta, Google and TikTok, are on the Data Deletion page.

Security

Data is encrypted in transit and at rest; access is restricted by role. In the event of a breach, affected individuals and the supervisory authority are notified within the statutory period.

Children's data

The service is not directed at persons under 18 and we do not knowingly collect personal data from children. If we learn that data belonging to a child has been collected, we delete it without delay.

Limits of security

No system can provide absolute security. Adropic applies reasonable and industry-accepted measures, but does not undertake that unauthorised access will never occur. You are responsible for the confidentiality of your password and for the access you grant to team members.

Breach notification

In the event of a data breach, affected users and the competent authorities are notified within the period required by law. Giving notice does not constitute an admission of fault by Adropic.

Automated decision-making

Autonomous optimisation features produce automated decisions about advertising campaigns. These decisions do not have legal effects on individuals. You can turn autonomous mode off at any time and review the decision history.

Updates to this policy

This policy may be updated. Material changes are announced by email or in-app notice at least 15 days before they take effect.

Contact

Adropic Inc. 8 The Green, Suite B, Dover, DE 19901, USA support@adropic.com

Privacy Policy — Adropic