Privacy policy

Variafy is a service through which an AI assistant manages ad accounts on behalf of their owner.

Draft — not for publication. Not filled in: legal entity name, registered address, registration numbers, contact email address, phone number. While these are blank, this page must not be submitted to Meta and must not be shown to customers.

Who processes the data

[not filled in: legal entity name], [not filled in: registered address]. [not filled in: registration numbers]. Questions and requests: [not filled in: contact email address].

In what role we act

The role differs by category of data, and merging them into one label would be untrue.

Customer and billing data
Controller. Email address, company name, plan and subscription status are data about our counterparty under our own contract. We determine the purpose and the retention period.
The customer's staff
Processor on the customer's instructions. Who is invited to the console, what role they get and when they are removed is decided by the customer, not by us. We store an email address, a name and a role because the customer asked us to.
Audit log and usage
Controller. Records of sign-ins, approvals and service usage are processed for our own purposes: to establish who authorized spending on an ad account, to issue invoices, and to protect the service. This is declared in advance and is outside the customer's instructions.
Ad account data
Toward the customer — processor: we act only on their instructions and for their purposes, and data belonging to different customers is stored separately. Toward Meta — an independent controller, as Meta's platform terms require.

What we store

Legal bases

How long we keep it

1 month
revoked app connections (ChatGPT, Claude): kept while questions about recent access are resolved; the fact of connecting and revoking stays in the console audit log — live connections are kept until revoked or until they lapse after 60 idle days
3 years
sign-ins and approvals: evidence of who authorized spending on an ad account, should the question come up later — the period follows the limitation period for claims between businesses
2 years
payments and leads that a customer sends in to measure their advertising: kept while comparing this year with the last one still makes sense — no contacts of their customers are stored: a one-way hash at most, and anything that looks personal is dropped at the door
3 years
service usage records: the basis for billing and for resolving disputes about it
1 month
proposed changes: the preview and its arguments, while they can still be disputed — the fact of the approval outlives this cleanup: it is kept in the audit log as a self-contained entry, not as a pointer to this table
6 months
Stripe payment events: protection against processing the same event twice
1 month
sign-up requests: the email address, name and IP address are kept while they back the anti-abuse counter and while a disputed sign-up can be examined — an unaccepted request creates neither an account nor obligations: it expires in twenty minutes and is deleted outright
3 years
data deletion requests: proof that the request was carried out — no personal identifier is kept here, only a hash
1 day
Counts of calls to Meta, needed only to stay under Meta's 5-minute and hourly limits.
1 month
The last known Meta limit state of an ad account.
6 months
Which ad account a Meta object id belongs to, kept to avoid repeating the ownership check.
1 month
Counts of calls to the Google Ads API, needed to stay under the Google Cloud project's daily quota and to measure Google's limits. — no queries and no results: only counts, status, error code and the Google request id
1 day
Google Ads accounts found while a person chooses which of them to connect.
1 month
Lists of image identifiers checked before an upload, kept while a proposal that uses them can still be approved — only identifiers of images inside the ad account library, no files and no personal data
1 month
When the queue email was last sent to an account, kept only to space out those emails — one row per account: a timestamp, no addresses and no message contents
1 day
Counts of competitor research calls, needed only to keep the shared Ad Library access under its hourly limit. — only the account and the time of the call: no domains, no results
3 months
Problems the watchdog and monitors found in an ad account, kept after they stop so that a problem that comes back is recognised as returning — a problem that is still present is kept for as long as it lasts
6 months
Monitors that were deleted, kept so that the question of why their emails stopped has an answer — monitors that are not deleted, including paused ones, are kept until they are deleted
6 months
Scheduled briefs that were deleted, with their schedule and the address they went to, kept so that the question of why they stopped has an answer — briefs that are not deleted, including paused ones, are kept until they are deleted
3 months
Records of failures in the background work of the service and of server errors, kept to find and fix problems that come back — they hold the error text and a short reference such as an ad account connection or a page address, not the content of requests
1 month
unfinished campaigns: the answers a person gave while building one — the texts of the ad, the link, the audience and the budget — kept so that a build interrupted today can be continued tomorrow — a draft creates nothing in the ad account; it is deleted outright once a campaign is built from it and confirmed
3 months
Records of alerts about such failures sent to the service operator, kept to space alerts out

These periods are not a verbal promise: automated cleanup runs against exactly this list, and they cannot be changed without changing it.

Who we share it with

Meta Platforms
Everything you ask us to do in an ad account. The service does not work without this. Meta's policy.
Stripe
Subscription billing: email address and an internal customer reference. Ad account data is not sent there.
Railway
Hosting for the server and the database — our infrastructure provider.
Your assistant's vendor
The text of your conversation with the assistant goes to whoever provides it (for example Anthropic or OpenAI), under your agreement with them, not ours. We receive only the resulting tool calls.

We do not sell data and do not share it for anyone else's advertising.

Transfers outside the European Economic Area

Such transfers do occur, and we do not conceal them:

Pending legal review. The specific instrument for transfers to Ukraine — which standard contractual clauses and which module — is deliberately not named here: naming it by guesswork would be worse than leaving a marked gap.

Your rights

You may ask what we hold about you, correct inaccuracies, request erasure, restrict processing, receive your data in a portable form, and object to processing based on legitimate interest. Write to [not filled in: contact email address] and we will respond.

If you are a member of a customer's staff rather than the customer: for most of this data we act on their instructions, so contacting them will be faster. We will still accept your request and pass it on to them.

You have the right to lodge a complaint with a data protection authority.

Deletion

How to delete data obtained through Facebook is described separately: https://www.variafy.com/data-deletion.

Changes

If this policy changes materially, we will tell customers before the change takes effect.


Terms of use · Data deletion