Legal
Privacy Policy
This policy describes how Adstrai processes personal data, cookies, third-party processors, retention, and your choices.
- Document version
public-beta-legal-101-privacy-v1- Effective date
- 19 July 2026
Data controller
Semawork (Adstrai) is the data controller for personal data processed through Adstrai.
Registered address: 9 rue Dunoyer de Segonzac, 06200 Nice, France. Company registration: SIREN 932 099 393.
Privacy contact: [email protected]. Data protection contact: [email protected].
What this policy covers
This Privacy Policy explains how we collect, use, store, and share information when you use the Adstrai web application, create an account, connect third-party services, submit feedback, or subscribe to a paid plan.
Adstrai is a Meta campaign preparation and review workspace. Publishing and live activation remain approval-controlled.
Information we process
- Account data: name, email, authentication identifiers, and workspace membership (via Clerk).
- Workspace data: campaign drafts, uploads, media metadata, approval history, and operational notes (via Supabase).
- Billing data: subscription status and billing portal references (via Stripe; we do not store full payment card numbers).
- Meta connection data: OAuth tokens, ad account identifiers, and synced structure or performance metrics when you connect Meta.
- Support and feedback: messages you submit, optional contact email, and technical context needed to investigate issues.
- Technical data: request logs, device/browser metadata, and anonymized analytics when enabled (via Vercel Analytics).
How we use information
- Provide, secure, and improve the Adstrai workspace.
- Authenticate users and enforce workspace access controls.
- Process subscriptions, invoices, and entitlement changes.
- Operate Meta connection, draft review, and approval-controlled publishing workflows you initiate.
- Respond to support requests and beta feedback.
- Detect abuse, troubleshoot errors, and maintain audit records required for safety controls.
Third-party processors
We use the following categories of service providers to operate Adstrai. Each provider processes data under its own terms and privacy policy:
- Clerk — Authentication, session management, and account security. Privacy policy: https://clerk.com/legal/privacy.
- Supabase — Application database, file storage, and workspace persistence. Privacy policy: https://supabase.com/privacy.
- Vercel — Application hosting, edge delivery, and web analytics. Privacy policy: https://vercel.com/legal/privacy-policy.
- Stripe — Hosted checkout, subscription billing, and customer portal. Privacy policy: https://stripe.com/privacy.
- Meta Platforms — OAuth connection, ad account discovery, and approved ad operations. Privacy policy: https://www.facebook.com/privacy/policy/.
Retention
We retain account and workspace data while your account is active and as needed to provide the service, comply with law, resolve disputes, and enforce agreements.
Beta feedback and support messages are retained for triage and product improvement unless you request deletion, subject to legal hold or safety audit requirements.
Billing records follow tax and accounting retention requirements. Aggregated analytics may be retained in de-identified form.
Your choices, export, and deletion
Depending on your location, you may have rights to access, correct, delete, restrict, or port personal data, and to object to certain processing.
To request data export or deletion, email the privacy contact with the subject line "Adstrai data request". We may verify your identity before fulfilling requests.
You can disconnect Meta, cancel subscriptions through the Stripe customer portal when enabled, and revoke sessions by signing out of all devices in Clerk account settings where available.
Deleting your account may not immediately remove backups retained for disaster recovery for a limited period.
International transfers
Our processors may process data in the United States and other countries. Where required, we rely on appropriate safeguards such as standard contractual clauses offered by providers.
Age and eligibility
Adstrai is intended for business users who are at least 18 years old (or the age of majority in your jurisdiction). We do not knowingly collect personal data from children.
Changes to this policy
We may update this policy as the product or legal requirements change. Material updates will be reflected on this page with a revised effective date.
Contact and support
Questions about this policy: [email protected].
Product support is available through in-app feedback and the support email published on our marketing pages.
Processor details
Clerk
Authentication, session management, and account security
Processed per Clerk regional hosting and subprocessors disclosure.
Privacy policy: https://clerk.com/legal/privacy
- Account identifiers
- Email address
- Authentication events
- Device and session metadata
Supabase
Application database, file storage, and workspace persistence
Hosted in the project region configured for the beta data plane.
Privacy policy: https://supabase.com/privacy
- Workspace and campaign data
- Upload metadata
- Beta feedback records
- Operational audit logs
Vercel
Application hosting, edge delivery, and web analytics
Edge and serverless execution may route through global infrastructure.
Privacy policy: https://vercel.com/legal/privacy-policy
- Request logs
- Performance telemetry
- Anonymous page analytics when enabled
Stripe
Hosted checkout, subscription billing, and customer portal
Card data is collected by Stripe; Adstrai does not store full card numbers.
Privacy policy: https://stripe.com/privacy
- Billing contact details
- Payment method tokens
- Subscription status
- Invoice and tax metadata
Meta Platforms
OAuth connection, ad account discovery, and approved ad operations
Governed by Meta Platform Terms and your Meta Business Tools settings.
Privacy policy: https://www.facebook.com/privacy/policy/
- Meta user and business identifiers
- Ad account, page, and campaign structure
- OAuth tokens (encrypted at rest)
- Ad performance metrics when synced