Privacy Policy
Last updated: 27 August 2026. This is a plain-language description, written in good faith to reflect what actually happens in the app today.
Who this is
AdArchitect is operated by an individual based in Cyprus, not a registered company. Because the operator is established in Cyprus, this policy is written to meet EU/GDPR standards regardless of where you, the customer, are located.
What this policy covers
What personal data AdArchitect collects when you use the site, why it's collected, who it's shared with, how long it's kept, and the rights you have over it.
What personal data we collect
- Your email address, used to log you in via a one-time magic link (there are no passwords).
- Your email address, if you take the free campaign structure check quiz, used to send you your result and, if you consent on the quiz form, further emails: a short automated follow-up sequence (4 emails over about 2 weeks), occasional one-off emails with PPC tips or product updates, and, only if you've gone quiet with no engagement for an extended period, a short automated check-in sequence (up to 3 emails). You can unsubscribe from any of these at any time with a one-click link in every email; this never affects your quiz result, any plan you've purchased, or your ability to log in.
- Your quiz answers (product relationship, rough product count, budget range, experience level) if you take the free structure check, kept as a record of what result you were given.
- Your email address, if you purchase a plan, used to send your order confirmation and onboarding emails and, if you haven't already purchased a second plan, an occasional follow-up about expanding it. You can unsubscribe from the optional follow-up at any time with a one-click link; core order/access emails (like your magic login link) aren't optional, since the product can't work without them.
- Payment and order records from Stripe: a checkout session ID and payment status. Your card details are entered directly into Stripe's own hosted checkout page and never reach AdArchitect's server.
- What you submit to generate a plan: your product ASINs and short descriptions, price points, monthly ad budget, experience level, and how your products relate to each other.
- The campaign structure generated for you, and any name you give the plan, stored so you can view your plan history later.
- Basic server logs (IP address, request timestamps) that any web server generates, used only for security and abuse prevention.
How and why we use it
- To create your account and log you in.
- To process your one-time payment through Stripe.
- To generate your campaign structure, which requires sending the product details you submit to Anthropic's Claude API.
- To email you your login link, order confirmation, onboarding emails, and (if applicable) an occasional follow-up about expanding your plan, sent through Resend.
- To email you your free campaign structure check result, if you take that quiz, and the optional emails described above (follow-up sequence, occasional updates, and a check-in if you go quiet) if you consent to it, all sent through Resend.
- To detect and prevent abuse of the refund policy (see the Terms of Service).
Who we share it with
We don't sell your data. It's shared only with the services that make AdArchitect work, and only to the extent each one needs:
- Stripe: processes your payment. AdArchitect never sees or stores your card details.
- Anthropic: receives the product details you submit, in order to generate your campaign structure.
- Resend: delivers your login and plan emails.
- Google Analytics: only if you accept analytics cookies via the cookie banner. Sees anonymized usage data (pages viewed, general location, device type) to help us understand how the site's used. If you're logged in and accept analytics cookies, Google Analytics also receives an internal account ID (not your email or name) so your visits from different devices can be recognized as the same person, rather than counted separately. See Cookies below.
- Meta (Facebook/Instagram): only if you accept via the cookie banner. We use the Meta Pixel, and a matching server-side integration called the Conversions API, to measure whether our ads on Facebook and Instagram actually lead to visits, leads, and purchases, and to build audiences of people who've visited the site. Meta receives the pages you viewed on this site, your IP address, and browser/device information. If you take the free quiz, start checkout, or complete a purchase while logged in, Meta also receives a one-way cryptographic hash of your email address and of your internal account ID (never the email address or ID itself, and never your name or the product details you submit to generate a plan) so that action can be matched to the same ad click across devices. If you reject, the pixel is loaded but blocked from sending anything, and this server-side matching doesn't happen either. See Cookies below.
We may also disclose data if legally required to.
How we protect your data
There's no password to leak, since login is passwordless. Card data is handled entirely by Stripe's hosted checkout, never by our own server. Database queries are parameterized against injection. Login attempts are rate-limited, and forms are protected against cross-site request forgery.
Cookies
AdArchitect sets one strictly-necessary session cookie to keep you logged in. This one is always set, since the site can't function without it, and doesn't require consent.
We also set a separate, first-party site-journey cookie to measure the sequence of pages visitors use to move through the site (for example, which page most people land on first, and which page they're most often on when they leave), so we can find and fix real navigation and content problems. This is not the same as the Google Analytics/Meta cookies described below: it's set by AdArchitect directly, is never shared with Google, Meta, or anyone else, is never linked to your account, email, or a purchase, and is automatically deleted after 30 days. It's set automatically on your first visit unless your browser sends a Global Privacy Control or Do Not Track signal, in which case nothing is set at all. You can also opt out manually, regardless of what your browser sends, by visiting this opt-out link — doing so clears the cookie immediately and stops a new one being set in this browser.
Separately, if you land on our homepage, we set a cookie to randomly place you into one of a few page-design variants, so we can measure which one performs better (this is standard, common practice known as A/B testing). Unlike the site-journey cookie above, this one is associated with your purchase if you buy a plan, so we can tell which design led to it.
We also use Google Analytics to understand how the site's used, and the Meta Pixel (plus its server-side counterpart, the Meta Conversions API) to measure our Facebook and Instagram advertising, but both only if you accept via the cookie banner shown on your first visit. If you accept, Google Analytics sets its own cookies (_ga, _ga_*) to measure visits, and Meta sets its own (_fbp) to recognize your browser across visits; that same cookie is also what tells our server you've consented, which is what allows the server-side Conversions API calls described below to fire at all. If you reject or don't respond, no analytics or advertising cookies are set: Google receives only anonymized, cookie-free usage pings, and neither the Meta Pixel nor the Conversions API sends anything. The banner's Accept and Reject buttons cover both together; we don't offer a separate choice per vendor. You can change your choice at any time by clearing your browser's local storage for this site and revisiting; the banner will show again.
If you're logged in when you accept analytics cookies, we also send Google Analytics your internal account ID (an internal number, not your email) so a purchase can be linked to the visit that led to it, even if the payment confirmation happens on our server rather than in your browser. Likewise, if you take the free quiz, start checkout, or complete a purchase while logged in and have accepted, our server sends Meta a one-way cryptographic hash of your email address and of that same internal account ID (never the raw email, ID, name, or plan details) through the Conversions API, so that action can be matched to the ad click that led to it even if your browser blocks the Pixel itself or the purchase confirmation happens after you've left the page.
Children's data
AdArchitect is not intended for anyone under 18.
How long we keep your data
We keep your account and plan history for as long as your account is active, since viewing past plans is a real feature of the product. Email us to request deletion of your account and data.
Your rights
Under GDPR, you have the right to access, correct, or delete your personal data, restrict or object to its processing, request a copy in a portable format, and withdraw consent at any time. To exercise any of these, contact us below.
Right to complain
If you're unhappy with how we've handled your data, you can lodge a complaint with Cyprus's Office of the Commissioner for Personal Data Protection, the relevant authority given AdArchitect operates from Cyprus.
Changes to this policy
We may update this policy as the product changes. The "last updated" date above will always reflect the most recent revision.
Contact us
Questions about this policy, or requests about your data, can be sent to [email protected].