Legal
Privacy Policy
Effective 26 June 2026 · Last updated 26 June 2026
Contact: jani@sansatech.com
1. Who this applies to
This policy applies to anyone who authenticates with the App and grants it access to a Meta Business / advertising account via Facebook Login. By connecting your account, you agree to this policy.
2. Information we collect
We collect only what is needed to run the advertising features you ask for.
a) Account & authentication data
- Your basic Meta profile (the public profile returned at login).
- Email and password for your Otto account (authentication is handled by Supabase Auth; passwords are stored salted and hashed by Supabase, never by us in plain text).
b) Meta advertising data (read)
- Ad accounts, Pages, pixels/datasets, and business portfolio identifiers you authorize.
- Campaigns, ad sets, ads, creatives, and their performance insights (spend, impressions, clicks, conversions, etc.).
c) Meta access tokens
- The long-lived access token Meta issues when you connect. It is encrypted at rest (XChaCha20-Poly1305) and is used only to make API calls on your behalf. It is never shown in the interface, never placed in prompts, and never shared.
d) Content you create in the App
- Chat conversations with Otto.
- Business-profile information and a knowledge base built from public information about your business (e.g., your website).
- Ad creative concepts and the images/videos generated for you.
e) Technical data
- Standard server logs (timestamps, request metadata) used for security and debugging.
We do not collect payment-card data, and we do not knowingly collect data about anyone under the age required by Meta’s platform terms.
3. How we use information
- To connect your Meta account and read your advertising data.
- To analyze performance, surface waste, and suggest improvements.
- To draft ad copy and generate creative images/videos at your request.
- To propose advertising changes for your review. Every money-affecting action requires your explicit approval before it is sent to Meta, and is bounded by a spend cap you control.
- To operate, secure, and improve the App.
We do not sell your data, and we do not use your advertising data to train our own models.
4. Third-party processors
To provide the service, your data may be processed by these subprocessors, each only for the purpose listed:
| Provider | Purpose |
|---|---|
| Meta Platforms (Graph API) | Read your ad data; execute changes you approve |
| Supabase | Database, authentication, and file storage (encrypted) |
| Railway | Application hosting (web + background worker) |
| OpenAI | Language understanding and image generation |
| fal.ai | Video generation |
| Firecrawl | Researching public information about your business |
| Resend | Sending transactional emails (e.g., alerts, daily briefs) |
We share with these providers only the minimum data needed for each task. When we send content for AI generation or research, we send the relevant prompt and context — not your Meta access token.
5. Use of Meta Platform data
Our use of data obtained through Meta’s APIs complies with the Meta Platform Terms and Developer Policies. We request only the permissions needed for the features you use (for example: reading ad performance, and — with your approval — managing campaigns). We retain Meta data only as long as needed to provide the service and delete it on request.
6. Data storage, security, and location
- Data is stored in managed Postgres and object storage (Supabase) with row-level security, so each account can access only its own data.
- Access tokens and other secrets are encrypted at rest.
- Transport is encrypted via HTTPS/TLS.
- Access to production systems is restricted to the operator.
No method of storage or transmission is 100% secure, but we take reasonable measures to protect your information.
7. Data retention and deletion
You can request deletion of your data at any time:
- Disconnect your Meta account in the App to remove the stored connection and its encrypted access token.
- Request full deletion by emailing jani@sansatech.com. We will delete your account, conversations, generated creatives, and any stored Meta data within 30 days, except where retention is required by law.
- You may also remove the App’s access at any time from your Facebook settings: Settings & Privacy → Settings → Business Integrations.
8. Your rights
Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data, and to withdraw consent. To exercise these rights, contact us at the address above.
9. Cookies
We use only essential cookies required for authentication and session management. We do not use third-party advertising or tracking cookies in the App itself.
10. Changes to this policy
We may update this policy as the App evolves. Material changes will be reflected by updating the “Last updated” date above and, where appropriate, by notice within the App.
11. Contact
Questions about this policy or your data: Sansa Technologies, Inc. — jani@sansatech.com.