Privacy Policy

Last updated: August 26, 2026

This policy explains what personal data upload.ad collects, why, and what rights you have. It applies to everyone who uses the Service, wherever you are in the world. The data controller is CROapps Oy ("we"), a limited company registered in Finland, Business ID 3550932-5, VAT number FI35509325, Pohjoinen Rautatiekatu 29B, 00100 Helsinki, Finland. You can reach us for privacy and legal matters through our contact form.

1. Data we collect

  • Account data: your name and email address, collected when you sign up. Sign-in uses one-time codes sent to your email, so we store no password.
  • Content you upload: the images and videos you submit for delivery to your ad account, plus related metadata such as file names, sizes, and upload status.
  • Ad account connection data: identifiers and access credentials for the Meta and TikTok ad accounts you connect, and the ads and performance data we fetch from them to show you insights.
  • Lead data: if you use lead forms on a connected ad account, the form submissions (such as names, email addresses, and phone numbers of people who filled in your forms) that we fetch from the platform so you can view and export them. See section 5 for how this data is handled.
  • Team and activity data: workspace membership, comments, and activity history. These are visible to the other members of your workspace, along with your name and email.
  • Reviewer data: if someone shares a creative with you for review through a share link, the name you enter and the comments and approvals you leave. These are visible to the workspace that shared the link.
  • Import and export connections: if you import files from Google Drive or Dropbox, or export data to Google Sheets, the access credentials for that connection and the files you choose to import or the data you choose to export. We do not access other files in those accounts. See section 4 for how Google user data is handled.
  • Billing data: your plan, invoices, and payment history. Card details are collected and stored by Stripe, our payment processor, not by us.
  • Affiliate data: if you join the affiliate program, the billing details you provide for payouts and your referral and commission history. Identity verification for payouts is handled by Stripe.
  • AI assistant messages: the messages you exchange with the in-app assistant, kept as part of your workspace history.
  • Technical data: IP address, browser information, and server logs generated when you use the Service, kept for security and troubleshooting. The desktop app also checks our servers for updates automatically; these checks carry no personal data beyond the standard technical data above.

We do not use advertising trackers, and we do not sell personal data or share it for cross-context behavioral advertising (as those terms are defined in US state privacy laws such as the California Consumer Privacy Act).

2. How we use data

  • To provide the Service: authenticate you, store your creatives, and deliver them to your ad account (performance of contract).
  • To send transactional email such as account and security notices (performance of contract).
  • To send occasional product emails about your trial or how to get more out of the Service (legitimate interest). Every such email includes an unsubscribe link, and opting out never affects transactional email.
  • To keep the Service secure, prevent abuse, and debug problems (legitimate interest).
  • To comply with legal obligations.

3. Where data is processed

We use the following service providers as processors:

  • Cloudflare for application hosting, file storage, and caching.
  • Neon for our database.
  • Amazon Web Services (SES) for sending transactional email.
  • Stripe for payment processing and affiliate payouts. Stripe collects your payment details directly; we never see your full card number.
  • OpenRouter routes requests you make to the in-app AI assistant (chat messages, copy generation, and tagging, including any creatives you attach) to the AI model that generates the response. The models behind it are provided by Anthropic and Z.ai. Every request is sent with OpenRouter's no-data-collection setting, so it is routed only to providers that do not retain or train on it, and nothing you send is used to train or improve any AI model.
  • Meta Platforms and TikTok receive your creatives when we deliver them to the ad account you connected on each platform, acting on your instruction, and provide the ads, performance, and lead data we fetch for you.
  • Google and Dropbox, when you connect them, provide the files you import and receive the data you export to Google Sheets, acting on your instruction.

If you configure webhooks or chat notifications, event data (such as upload statuses and review comments, including the names of the people involved) is sent to the endpoints and channels you choose, acting on your instruction.

These providers process data in the United States and other countries outside the EU/EEA. Where they do, transfers are protected by the EU Standard Contractual Clauses or an adequacy decision such as the EU-US Data Privacy Framework. Wherever you are, your data may be processed in a country other than your own; we apply the protections in this policy to all of it.

4. Google user data

If you connect Google Drive or Google Sheets, we ask Google for permission to read only the files you pick in Google's file picker, to write the spreadsheets you export, and to see your name and email address so we can show which Google account is connected. If you choose to watch a Drive folder, you share that folder with an address we give you, and we read that folder alone until you unshare it or stop watching. We use that access for one purpose only: providing the import and export features you asked for. In particular, we:

  • copy only the images and videos you select (or that appear in a folder you shared with us to keep in sync) into your creative library, and write only the export sheets you request;
  • never use Google user data for advertising, never sell it, and never share it with anyone except as needed to provide the import or export you requested, as required by law, or with your explicit consent;
  • never let a person read Google user data, except with your consent, for security or abuse investigations, to comply with the law, or in internal operations where the data has been aggregated and anonymized;
  • never use Google user data, in raw, aggregated, or derived form, to create, train, or improve any machine learning or AI model, ours or anyone else's. A file you imported from Drive is only sent to an AI model when you ask the assistant to work with it (for example to write copy or tags for that creative), it goes through OpenRouter with the no-data-collection setting described in section 3, and the model providers do not retain or train on it.

The use of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

You can disconnect Google at any time from your workspace settings, or revoke our access from your Google account's security settings, and you can stop watching a folder from settings or by unsharing it. Either way we delete the stored credentials and stop reading from or writing to your Google account. Files you already imported stay in your library until you delete them.

5. Lead data belongs to your workspace

Lead form submissions are the personal data of the people who filled in your forms, not ours. For this data we act on your workspace's instructions: we fetch it from the connected platform, store it so your team can work with it, and delete it when you delete it or disconnect the account. You are responsible for having a lawful basis to collect and use your leads' data and for honoring their privacy requests; if a lead contacts us directly, we will refer them to you and assist as needed.

6. Connected Shopify stores

If you connect a Shopify store, we read your orders, products and inventory costs so your advertising can be reported on profit rather than platform-estimated revenue. We ask only for read access, and nothing is ever written back to your store.

We deliberately do not read or store your customers' personal details. No names, email addresses, phone numbers or addresses are requested or kept. For each order we store the amounts (subtotal, discounts, shipping, tax, refunds), the product variants and quantities so cost of goods can be worked out, the order's identifier, and which of your ads it came from. The address a visitor landed on is reduced to the two parameters our ad builder adds before it is saved, so anything else your own links carry is discarded rather than stored.

This data is used only to produce your own profit reporting. It is not sold, not shared with Meta, TikTok or any other advertising platform, and not used to build audiences or target anybody. Order records are kept for 25 months and then deleted automatically. Disconnecting the store, uninstalling the app in Shopify, or deleting your account removes them sooner.

7. Retention

  • Account data is kept while your account exists and deleted within 30 days of account deletion, except records we must keep longer by law (for example, invoices and related billing records, which Finnish accounting law requires us to keep for six years).
  • Uploaded creatives are kept while needed to complete delivery and for your upload history, and are deleted when you delete them or your account.
  • Lead data is kept until you delete it, disconnect the ad account it came from, or delete your account.
  • AI assistant messages are kept as part of your workspace history while your account exists and are deleted with it.
  • Server logs are kept for up to 90 days.

If you disconnect your Meta, TikTok, Google, or Dropbox account, or remove upload.ad from your account on those platforms, we delete the connection credentials and stop fetching data from that account.

8. Cookies

We use only essential and functional first-party cookies: a session cookie to keep you signed in, short-lived cookies that secure sign-in and account connection flows, a cookie that remembers that you unlocked a password-protected share link, and, if you arrive through an affiliate's referral link, a referral cookie that remembers the referring affiliate for up to 90 days so we can credit them if you sign up. We do not use analytics or advertising cookies, so there is no cookie banner to click.

9. Your rights

Wherever you live, you can ask us to access, correct, delete, or export the personal data we hold about you, and to object to or restrict certain processing. You can delete your account yourself at any time from your account settings, which permanently removes your data as described in section 6. For other requests, send a message through our contact form, and we will respond within one month; for particularly complex requests we may extend this by up to two further months, and will tell you if we do. We never discriminate against you for exercising a privacy right.

If you are in the EU/EEA or UK, these are your rights under the GDPR, and you can also lodge a complaint with your supervisory authority; in Finland this is the Office of the Data Protection Ombudsman (tietosuoja.fi). If you are a resident of California or another US state with a privacy law, the same request channel covers your rights to know, delete, correct, and port your data; we do not sell or share personal data, so there is nothing to opt out of. If your request is denied, you may appeal by replying to our decision and we will review it again. Residents of other countries with data protection laws (such as Brazil's LGPD or Canada's PIPEDA) can use the same channel and have the same rights honored.

10. Children

The Service is for businesses and requires users to be at least 18 years old. We do not knowingly collect personal data from children; if you believe a child has created an account, tell us through the contact form and we will delete it.

11. Security

Data is encrypted in transit and at rest, sign-in uses short-lived one-time codes instead of stored passwords, and access to production systems is restricted. No system is perfectly secure; if a breach affects your personal data, we will notify you and the relevant authority as required by law.

12. Requests from public authorities

If a public authority requests personal data we hold, we review the request's legal validity under Finnish law and the GDPR before responding, challenge requests we consider unlawful or overbroad, disclose only the minimum information a valid request legally requires, and document every request together with our response and the legal reasoning applied. To date we have received no such requests.

13. Changes

We may update this policy from time to time. Material changes will be announced by email or in the Service before they take effect.