Last updated: July 24, 2026

Privacy Policy

Controller: AdsCaffeine LLP, 5307 Victoria Drive #485, Vancouver, BC V5P 3V6, Canada. Privacy contact: hello@raw2ads.com. We have not appointed a Data Protection Officer or an EEA/UK representative; contact us by email for all privacy matters.

1. Scope and roles

This Policy explains how raw2ads collects, uses, discloses, and retains personal data when you use app.raw2ads.com, raw2ads.com, and the Service. It applies alongside the Terms of Service, Acceptable Use Policy, and Refund Policy.

For account, billing, security, support, and product operations, raw2ads is generally the controller (or equivalent business) of the data described here. If an organization instructs raw2ads to process personal data contained in its workspace, raw2ads may act as its processor/service provider; a data-processing agreement is available on request at hello@raw2ads.com. A user uploading someone else's data is responsible for having a lawful basis, notices, and instructions for that upload.

2. Data we collect and sources

We may receive data from authentication, hosting, AI, email, analytics, payment, and other providers used to operate the Service. We do not intentionally request government identifiers, health data, or other sensitive data. Do not upload such data unless the feature requires it and you have a documented lawful basis.

3. How we use data and legal bases

Where consent is the basis, you may withdraw it at any time; withdrawal does not affect earlier processing. We do not use your data to make solely automated decisions that produce legal or similarly significant effects.

4. Content, faces, voices, and biometric processing

Uploads containing a face or voice are personal data where a person is identifiable. raw2ads does not use uploads to uniquely identify people, authenticate them, or create biometric templates. A face image or voice recording can nevertheless be subject to additional biometric or sensitive-data rules depending on the technical processing and purpose. If a future feature would create or use biometric identifiers, we will complete a separate legal and risk assessment, provide the required notice, and obtain any required consent before enabling it.

You must obtain the necessary permissions and notices from people appearing in content. You must not upload content that you are not entitled to process or that violates the Acceptable Use Policy.

5. AI and service providers

We share the minimum data needed for the feature and route you select. Providers currently used to operate the Service:

ProviderWhat it doesData involved
SupabaseSign-in (email magic links) and authentication recordsEmail address, authentication events
ResendTransactional and onboarding emailEmail address, message content
OpenRouter, routing to the model provider for the requested feature (for example Google Gemini)AI analysis of clips and reference ads, tagging, suggestions, translationThe clips, frames, text, or prompts needed for the requested feature
Higgsfield, fal.ai, ElevenLabs (optional)AI clip, image, or voice generation, only when you enable the feature or connect your own key (BYOK)Content needed for the requested generation; with BYOK, your own agreement with the provider applies
Contabo (data centres in the European Union)Application hosting and storage of uploaded content, Outputs, and workspace dataAll workspace content and account data
CloudflareDNS, CDN/security proxy, hosting of the marketing site, and encrypted backup storage (R2)Technical request data; encrypted backup archives
Umami (self-hosted on our own infrastructure)Cookieless, privacy-focused usage statisticsAnonymized usage events; nothing is shared with a third-party analytics company
Creem (creem.io), our Merchant of RecordPayment, tax, invoicing, subscriptions, refunds, fraud, and chargebacksBilling details and transaction data; full card data never touches raw2ads servers

We do not use Your Content to train our own machine-learning models. AI providers process content to deliver the result you request, under their API terms; where a provider offers API terms or settings that exclude API content from model training, we rely on those. With BYOK, your own agreement with that provider applies. Provider names, routes, and settings can change; we will keep this table current or provide any legally required notice.

6. Sharing and disclosure

We disclose data to the providers above, our professional advisers, auditors, insurers, payment/fraud partners, and authorities or other parties where required by law, to protect rights and safety, or as part of a merger, financing, or sale of assets. We do not sell personal data for money, and we do not share personal data for cross-context behavioural advertising.

7. International transfers

Uploaded content and workspace data are primarily hosted in the European Union. Some providers process data in the United States or other countries. Where required, we rely on an adequacy decision or another lawful transfer mechanism, such as the applicable EU/UK Standard Contractual Clauses or equivalent safeguards. Contact us for current transfer information.

8. Retention and deletion

Deletion from raw2ads does not necessarily cause immediate deletion from a provider that has already received data; we apply our provider deletion processes and disclose relevant limits where required. You may request deletion at any time, subject to lawful exceptions.

9. Your rights

Depending on your location, you may have rights to access, correct, delete, restrict, object, portability, withdraw consent, and complain to a supervisory authority. Email hello@raw2ads.com; we may verify your identity and will respond within the period required by law. If you use the Service through an organization, send content-data requests to that organization first where it is the controller.

EU/EEA/UK: you can lodge a complaint with your local data-protection supervisory authority.

California and other US states: rights to know/access, delete, correct, opt out of sale/sharing, limit sensitive-data use, or appeal may apply. We do not sell personal data for money and do not share it for cross-context behavioural advertising. To exercise a right or appeal a decision, email hello@raw2ads.com.

10. Security

We use measures appropriate to the risk, such as HTTPS, access controls, magic-link authentication, per-user workspace isolation, provider permissions, logging, and encrypted backups. No system is completely secure. Report suspected unauthorized access to hello@raw2ads.com promptly. We will handle and notify qualifying incidents as required by law.

11. Cookies and similar technologies

We use strictly necessary cookies and local storage for sign-in, security, session continuity, and preferences. Analytics is self-hosted Umami and is cookieless: it sets no cookies, uses no advertising identifiers, and shares nothing with third-party analytics companies. We do not use advertising cookies. Because only strictly necessary cookies and cookieless analytics are used, no cookie banner is shown; if this ever changes, we will update this Policy and add any required consent mechanism first.

12. Children

The Service is not directed to, and may not be used by, anyone under 18. If we learn that we collected a child's personal data contrary to applicable law, we will take reasonable steps to delete it. Contact hello@raw2ads.com.

13. Changes and contact

We may update this Policy and will post the new effective date. For material changes, we will provide notice through the Service or by email where required. Questions, rights requests, and complaints: hello@raw2ads.com - AdsCaffeine LLP, 5307 Victoria Drive #485, Vancouver, BC V5P 3V6, Canada.