Effective September 21, 2026

Privacy policy

This document explains what data the Aevin platform collects, why it needs it, who it shares it with, and how to delete it. It is written in plain language, because a policy nobody can read protects nobody.

1Who processes the data

The Aevin platform is hosted at aevin.dev. The data controller is AFM Digital LLC, 1100 Cleveland Street, Apt 1403, Clearwater, Florida 33755, United States. Contact for any questions about data: office@afmdigital.com.

This policy covers the platform itself and its interfaces. The website afmdigital.com and the company's other products operate under their own rules.

2What data we collect

The data falls into three groups, and each one reaches us differently and is protected differently. A fourth part stands apart: what the site keeps inside your own browser.

2.1 Your account

  • the email address you sign in with;
  • your name and profile picture, if you provided them;
  • the organization you belong to and your role in it;
  • your training progress: lessons completed, quiz answers, submitted work.

2.2 Data from connected ad accounts

When you connect your Meta account, the platform reads and stores operating metrics to build reports and suggestions:

  • the list of accounts, their name, currency, and time zone;
  • campaigns, ad sets, ads, and creatives together with their settings and budgets;
  • daily metrics: spend, impressions, reach, clicks, leads, revenue;
  • the assets your token grants access to: pages, pixels, Instagram accounts.

This is your business's data, not your customers' personal data. Meta does not give us information about specific people who saw the ads, and we do not request it.

2.3 Leads you collect yourself

If you use the leads module, the platform receives data from people who submitted a lead on your landing pages and forms: name, email, phone, company, campaign tracking tags, source URL, IP address and browser information, plus consent-to-contact markers.

In this part, you are the data controller, and the platform acts as a processor: we store and display this data on your instructions and do not use it for our own purposes. Responsibility for the lawfulness of collection and for obtaining consent rests with you.

2.4 Cookies and browser storage

The site keeps a few entries in your browser. They are there so that signing in, signing up and connecting an ad account work at all, and so that the interface remembers how you set it up. None of them follows you to other sites:

  • the sign-in session: the cookie that keeps you inside your account. It appears when you sign in, page scripts cannot read it, and it lives up to 400 days unless you sign out earlier;
  • short-lived service entries: the email address awaiting confirmation while you sign up, and the one-time key that protects the connection to Meta and Google from being hijacked. They expire on their own within minutes;
  • interface preferences and drafts: the light or dark theme, whether the sidebar is expanded, which metrics your chart shows, which hints you have dismissed, whether you allowed cloud transcription for voice input, and the unfinished creative drafts the ad studio holds on your own device and does not upload to us. They stay in your browser, they are not tied to any profile, and no picture of you is built from them.

A visitor who has not signed in receives none of these. Counting visits is separate and is off until you say otherwise: if we run a visit counter, we ask first, and until you agree nothing from the analytics provider is loaded, no script, no request, no cookie. Decline and the counter never appears. Your answer is kept in your own browser rather than on our servers, and the link in the footer changes it at any time. You can also clear this storage through your browser settings: you will simply be signed out and these preferences will go back to their defaults.

2.5 Ad tracking on your own sites

The platform gives you a tracking script to put on your own site. It answers one question: which ad brought the person who left you a lead. Without it a lead from a form is a name and a phone number and nothing else, and neither you nor the ad platform can tell which ad paid for it.

When a visitor opens a page carrying your script, we record:

  • the ad markup in the link they arrived by: the Meta click identifier, UTM tags, and the campaign, ad set and ad numbers;
  • the address of the page they landed on and the site they came from;
  • their IP address and the browser they use;
  • an identifier we generate for that visit and keep for 90 days in a cookie set on your own domain, so that a lead submitted an hour or a month later can still be matched to the visit.

The script reads nothing your visitor types, records no clicks and sets no third-party cookies. It adds one hidden field to your forms, the visit identifier, and does nothing else.

Here too you are the data controller, and the platform is a processor: the script runs on your site, on your instruction, and obtaining the visitor's consent where the law requires it is your responsibility. We do not use these records for our own purposes and never join them across customers.

3Access to your ad account and what happens to the token

The connection goes through Meta's official login. We never ask for or receive your Facebook password: you sign in on Meta's side and choose yourself which accounts to grant access to.

  • the access token we receive is stored in the database's encrypted secrets store , not in a regular table, and only the server-side sync code can read it;
  • the token never reaches the browser and is never shared with third parties;
  • every request to Meta is signed with a separate app signature, so a stolen token is useless on its own;
  • you can revoke access at any time with the "Disconnect" button in the "Accounts" section, or in your Facebook account settings. The token is deleted on our side when you do.

The platform makes changes to your ads (launching, pausing, budget) only after you confirm the specific action on screen. Consent for automations is a separate toggle, it has a daily spend cap, and it can be revoked at any time.

4Why we need this data

  • to give you access to the platform and manage your subscription;
  • to show your ad statistics and calculate suggestions from them;
  • to carry out the ad actions you confirmed;
  • to run the training and track your progress;
  • to respond to your requests;
  • to keep the platform secure: detecting password-guessing attempts, abuse, and failures.
  • build an anonymised summary across all ad accounts on the platform, so that the advice does not rest on your experience alone.

Legal bases for processing: performance of our contract with you (platform access), your consent (connecting an account, automations, emails), and our legitimate interest in the security of the service.

We do not sell data , and we do not share it with ad networks or data brokers. We do not train any models on your account data, and we do not show that data to other customers. It does reach a language model, because otherwise the agent could not answer your question: who exactly receives it, what they see, and what happens to it next are listed in section 5.

What anonymised means here. What goes into the shared summary is not your rows but proportions: a feature of an ad or of the way a campaign is set up (the objective, the audience type, the placement, the country, the age range, the creative format), taken on its own or in pairs, the size of the sample, and how much cheaper a lead is with that feature. No company name, no ad account number, no ad copy and no spend figures. A line appears there only if the feature occurred in at least five different companies and ten ad accounts, at least fifty leads were collected on each side of the comparison, and no single company contributed more than forty percent of the sample. Below those thresholds there is no line at all: it could be traced back to one account.

5Who we share data with

The vendors the platform cannot work without, and exactly what they see:

  • Supabase: the database, sign-in, and file storage. All the data listed above lives there.
  • Vercel: hosting for the application itself. It processes network requests and system logs.
  • Meta Platforms: the source of your ad account data, and the recipient of the conversions you choose to send back. We read metrics and send the changes you have confirmed. If you turn conversion sending on, each event also carries: the person's email address, phone number and name, hashed, so that Meta can match them without ever receiving the values themselves; the identifiers Meta issued on its own side (the click identifier, its own cookie, the lead form's number); the value and currency of the deal, when it is known; and, for an event that happened on your website, the visitor's IP address and browser, which Meta requires before it will match a website event at all. Contact details never leave in readable form.
  • Google Ads: the source of your Google Ads account data, if you connect one. The exchange runs both ways: we read metrics and the campaign structure, and send the changes you have confirmed.
  • TikTok for Business: the source of your TikTok Ads account data, if you connect one. The exchange runs both ways: we read metrics and the campaign structure, and send the changes you have confirmed.
  • Anthropic: the language model behind the AI advertising agent. It receives the analysis the platform prepares for your question: the names of accounts, campaigns, ad sets and creatives, spend, leads, cost per lead, click-through rate, fatigue signals, your working rules, and your conversation with the agent. The model has no access to the database; it only sees the text we assemble.
  • Google: the language model behind the support chat. It receives your questions to the assistant, your conversation with it, and the excerpts from our own help articles it answers from. Ad account metrics never reach that chat.
  • OpenAI: the model that draws images for ads and looks at the photos in the studio. It receives the description you wrote yourself, the product photos you attached yourself, and, when the platform suggests ideas, the previews of a couple of your own ads with the cheapest lead: that is how it learns what works for you. No leads, no client names and no spend figures go into that request.

About the language models specifically. Data reaches them only at the moment you ask a question, and only so that it can be answered. Neither Anthropic, nor Google, nor OpenAI trains its models on it: for Anthropic this is a commercial agreement term that applies by default, for Google it applies on the paid tier, which is the one we are on, and for OpenAI training on API data is off by default. Anthropic deletes what we send within 30 days on its side. Voice input in the agent chat is transcribed by your own browser: the audio reaches neither us nor them.

The automation builder has "send an email" and "send a Telegram message" steps. They are not connected yet: no keys are configured for them, and attempting to run such a step honestly stops with an error. Once they are connected, Resend and Telegram will start receiving the content of whatever messages you configure yourself, and this section will be updated before that happens.

Data received from Google APIs. Aevin's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use that information to serve advertising, do not sell it, and do not let a person read it, except with your explicit permission, for security, where the law requires it, or on data that has been aggregated and anonymised.

Data may be disclosed if the law requires it, or in the event of a sale or reorganization of the business, which we will announce in advance.

What the platform does not have. It has no traffic counters, no ad pixels, and no third-party behavioral analytics installed. We do not track you across sites and do not build advertising profiles. The tracking script in section 2.5 is a different thing and does not contradict this: it runs on your own sites, at your instruction, and sees only the visits to them. It is never present on this site, and it never follows anyone from one customer's site to another's.

6How long we keep data

  • account and organization data: for as long as your account exists;
  • ad account metrics: while the connection is active, and up to 12 months after disconnection, to preserve your report history if you come back;
  • the access token: deleted immediately when the account is disconnected;
  • leads in the CRM module: until you delete them or delete your account;
  • system logs: up to 90 days;
  • ad tracking visits on your sites: 90 days from the visit, then deleted automatically. The markup a lead needs is copied into the lead itself the moment it arrives, so a deleted visit never costs you the source of a lead;
  • the log of conversions sent to Meta: 180 days from sending. It is kept that long so that a dispute over a sent event can be settled, and no longer: Meta itself stops accepting an event a week after it happened.

After account deletion, data is removed within 30 days, except for what the law requires us to keep longer (payment records, for example).

7How we protect data

  • all traffic runs over an encrypted connection;
  • access control is built into the database at the row level: one organization's query cannot physically return another organization's rows;
  • ad account tokens live in a separate encrypted store;
  • the service key that bypasses row-level access is available only to the server, never to the browser;
  • database schema changes go through review and automated security checks.

There is no such thing as absolute security, and promising it would be a lie. If a breach affects your data, we will notify you and, where required, the relevant authority.

8Your rights

You can:

  • get a copy of your data;
  • correct inaccurate data;
  • delete your account and all associated data;
  • withdraw consent: disconnect an account, turn off automations, unsubscribe from emails;
  • object to processing or ask us to restrict it;
  • file a complaint with your country's supervisory authority.

Send your request to office@afmdigital.com. We reply within 30 days. To avoid handing your data to a stranger, we ask that you send the request from the address you use to sign in to the platform.

If you are in California. The CCPA and CPRA give you the right to know what personal information we collect and why, to have it deleted, to correct it, to opt out of its sale and sharing, to limit the use of sensitive personal information, and not to be treated worse for exercising any of these rights. We do not sell personal information and we do not share it for cross-context behavioral advertising, and we have not done so in the preceding 12 months. That is why there is no "Do Not Sell or Share My Personal Information" link on this site: it would have nothing to switch off. Requests go to the same address, we confirm your identity by matching it against the email you sign in with, and an authorized agent may submit a request on your behalf.

9Data deletion

A separate page with step-by-step instructions: how to delete your data. It also covers what happens to your ad account data when you disconnect.

10Children

The platform is built for business owners and advertising professionals and is not intended for anyone under 18. We do not knowingly collect children's data. If such data reaches us by mistake, write to us and we will delete it.

11Cross-border data transfers

Our vendors are based in the United States and the European Union, and data is processed on servers in those jurisdictions. We have data processing agreements with our vendors that include standard contractual clauses for cross-border transfers.

12Changes to this policy

We may update this document. The effective date is shown at the top of the page. We announce material changes by email to your account address and with a notice in the interface, we do not silently change the text.

13Contact

Questions about data, and access or deletion requests: office@afmdigital.com.

The terms of using the platform are described separately: terms of use.