BoostadLast updated: September 23, 2026

Privacy Policy

This Privacy Policy explains what information Boostad ("we", "our", "us") processes, how and why we process it, who we share it with, how long we keep it, and how you can have it deleted. Boostad is operated by SOLE PROPRIETOR SAMAR ANTON, who is responsible for the information described here.

Want your data deleted? See Section 9 — How to Delete Your Data.

1. What Boostad Is

Boostad is a web tool for advertisers and marketing teams. It lets you create advertising campaigns in your own Meta (Facebook and Instagram) and Snapchat ad accounts by reusing an existing campaign as a template, upload ad creatives from your computer, Google Drive or Dropbox, and manage the Facebook Pages you administer. Access to Boostad requires a registration that is approved by us.

In short:

  • We only access the ad accounts, Pages, Instagram accounts and files that you connect or select yourself.
  • We act on your advertising accounts only when you start an action in Boostad (for example, press “Launch” or “Upload”).
  • We do not sell your data, use it for advertising, or build profiles of people.
  • We do not collect data about your customers or ad audiences: no lead form submissions, no Messenger or Instagram conversations, no personal data of people who see or interact with your ads.

2. Information We Collect

2.1 Your Boostad account

  • Name and email address.
  • Password, stored only as a bcrypt hash (we never store your plain-text password). If you sign in with Google, we receive your name and email address from Google.
  • Interface language, time zone and your role in Boostad.
  • Registration requests: name, email address, hashed password (if any), team name and sign-in method. We keep a record of each request, including rejected ones.

2.2 Meta (Facebook and Instagram) connection

When you connect a Facebook account using Facebook Login, we store:

  • Your Facebook user ID and display name. We do not request access to your email address.
  • Your Facebook access token, encrypted with AES-256-GCM before it is written to our database, and its expiry date.

Using that token, and only when you use the corresponding feature, Boostad reads and writes the following through the Meta Marketing API and Graph API:

ads_management
Reading your ad accounts and their campaigns, ad sets, ads, creatives, pixels, apps and media library, so you can pick a template; creating campaigns, ad sets, creatives and ads and uploading images and videos to your ad accounts when you launch; reading performance statistics (spend, impressions, reach, clicks and results) of the campaigns in your Boostad launch history, to show them on your dashboard.
business_management
Reading business assets available to your ad accounts, such as the Instagram accounts of the business that owns an ad account, so they can be used as the identity of your ads.
pages_show_list
Showing the list of Facebook Pages you manage, so you can choose the Page your ads run from.
pages_read_engagement
Reading your Page and its posts when you reuse an existing ad or post (for example, its call-to-action button), checking which Instagram account is linked to the Page, and listing your Page’s own posts and photos in the Facebook Pages module.
pages_manage_posts, pages_manage_metadata, pages_read_user_content
Facebook Pages module only, requested separately when you grant access from that module: updating your Pages’ profile picture, cover and details, publishing and scheduling posts, and removing posts and content from your Pages at your request.

Page access tokens are requested from Meta when needed for an action and are not stored in our database. Campaign performance statistics are read from Meta when you open your dashboard, are aggregated across your campaigns, and are not stored (they are kept in server memory for up to a few minutes to avoid repeated requests).

2.3 Snapchat connection

When you connect a Snapchat account, we store:

  • Your Snap member ID, display name and email address, as provided by Snap, and the organization you selected.
  • Your Snapchat access and refresh tokens, encrypted with AES-256-GCM, and their expiry date.

Using those tokens, and only when you use the corresponding feature, Boostad reads your Snapchat organizations, ad accounts, Public Profiles, campaigns, ad squads, ads, creatives and media (to use them as templates), uploads your media, and creates campaigns, ad squads, creatives and ads in your ad accounts when you launch.

2.4 Google connection

  • Sign in with Google: your Google account ID, name and email address.
  • Google Drive (optional): your Google account ID, name, email address and encrypted access and refresh tokens. We use the drive.file scope, which only gives us access to the files you choose in the Google Picker — not to the rest of your Drive.
  • Links to public Google Drive folders and public Google Sheets that you paste are read without your Google account.

2.5 Dropbox connection

If you connect Dropbox, we store your Dropbox account ID, name, email address and encrypted access and refresh tokens, and use them to list and download the files and shared links you choose.

2.6 Creatives and upload history

  • File name and type, the media identifiers returned by Meta or Snap (image hash, video ID, Snap media ID), a preview image URL provided by Meta, and the ad account ID. This lets you reuse previously uploaded creatives.
  • We do not keep copies of your images or videos. Files you upload from your computer to Meta go directly from your browser to Meta. Files from Google Drive, Dropbox or links, and all files uploaded to Snapchat, pass through our servers only while they are being transferred and are not stored.

2.7 Launches, settings and templates

  • Launch history: campaign name, platform campaign ID, ad account ID and name, campaign objective, launch type, number of ad sets and ads created, status, progress and error messages. This is the history shown in your dashboard.
  • Saved launch presets: the settings of a launch (including a copy of the template campaign’s settings) that you choose to save for reuse.
  • Technical launch logs: for each launch, the names of created objects, platform error codes and the names of settings that a platform rejected. We use them to diagnose failures and improve reliability.
  • Launch snapshots: if a launch fails, a copy of the settings that were being sent (campaign, ad set, creative and ad settings, including targeting, ad texts and links), so we can find the cause.
  • Background job records used to run launches after you start them.
  • Facebook Pages module: design templates, post text templates and the history of publications (Page IDs, Page names and results).

2.8 Feedback

When you send feedback through the in-app form, we store your message and its type. If you leave the “attach diagnostics” option on, we also store the page address, your browser’s user agent, screen size and the most recent JavaScript errors from that page, together with the app version.

2.9 Technical data

Our servers keep standard logs (such as IP address, requested address, time and errors) for security and troubleshooting. IP addresses are also used, in memory only, to limit repeated registration attempts.

3. How We Use Information

We use the information described above only to:

  • Authenticate you and keep your account secure.
  • Perform the actions you start in Boostad on your Meta, Snapchat, Google and Dropbox accounts.
  • Show your launch history, the performance statistics of your campaigns, saved presets, templates and upload history.
  • Diagnose failed launches and improve the reliability of the service.
  • Respond to your feedback and support requests.
  • Detect and prevent abuse and unauthorized access, and comply with legal obligations.

We do not use data received from Meta, Snap, Google or Dropbox for advertising, to build profiles, segments or audiences, or to track people, and we do not sell it. We may create aggregated, de-identified statistics (for example, how often a particular platform error occurs) to improve Boostad.

4. How We Share Information

We do not sell, rent or trade your information. We share it only as follows:

Meta

When you launch campaigns, upload creatives or manage Pages, we send the advertising content and settings you create (campaigns, ad sets, creatives, ads, media, Page posts and Page details) to Meta on your behalf. Meta processes this data under the Meta Privacy Policy.

Snap

When you launch campaigns or upload creatives to Snapchat, we send the advertising content and settings you create (campaigns, ad squads, creatives, ads and media) to Snap Inc. on your behalf. We do not provide Snap with personal data about our users beyond what is needed to act on your connected account. The Snap Privacy Policy is incorporated into this Privacy Policy by reference and applies to data processed by Snap.

Google and Dropbox

We communicate with Google and Dropbox only to sign you in (Google) and to read the files you select. See the Google Privacy Policy and the Dropbox Privacy Policy. Boostad’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Service providers

Our application and database are hosted by Railway, which stores and processes data on our behalf only to operate the infrastructure. No other service provider has access to the data we receive from Meta or Snap.

Legal requirements

We may disclose information if required by applicable law, regulation or a valid legal request.

5. Data Security

  • All access and refresh tokens (Meta, Snapchat, Google, Dropbox) are encrypted with AES-256-GCM before being stored.
  • Passwords are stored only as bcrypt hashes.
  • All data in transit is protected by TLS (HTTPS).
  • Every request is checked against your account: you can only use the connections, ad accounts and records that belong to you (or that are shared with your team, if you work in a team).
  • Database credentials and encryption keys are kept in the hosting environment, never in source code.
  • To upload files from your computer directly to Meta, your own Facebook access token is made available to your browser session. It is never shown to other users.

No system is completely secure. Please connect only accounts that you control or are authorized to use with Boostad.

6. Data Retention

Account data
For as long as your account exists.
Connected accounts and tokens
Until you disconnect the account in Settings or delete your Boostad account. Disconnecting deletes the stored tokens and account identifiers immediately.
Launch history, presets, templates, upload history
For as long as your account exists, or until you ask us to delete them.
Technical launch logs
Deleted automatically after 90 days.
Launch snapshots (failed launches only)
Deleted automatically after 30 days.
Background job records
Deleted automatically 7 days after the job finishes.
Feedback
Until it is resolved and no longer needed, or until you ask us to delete it.
Registration requests
Kept as a record of applications until you ask us to delete them.
Server logs
For a limited period, according to our hosting provider’s log retention.

We also delete data when it is no longer needed to provide Boostad, when we stop operating Boostad, or when Meta, Snap or applicable law requires it.

7. Cookies and Browser Storage

  • Cookies set by our sign-in system that keep you signed in and protect the sign-in forms.
  • Short-lived security cookies (up to 10 minutes) that protect the account-connection flows with Meta, Snapchat, Google and Dropbox.
  • Your browser’s local storage for interface preferences, for following a launch that is still running if you reload the page (up to 2 hours), and for the Facebook Pages module’s recent publication history.

We do not use analytics, tracking or advertising cookies. The Google Picker and Dropbox Chooser are loaded from Google and Dropbox only when you use them and are governed by their own policies.

8. Your Choices and Rights

You can:

  • Ask for a copy of the personal data we hold about you, or ask us to correct it.
  • Ask us to delete your data (see Section 9).
  • Disconnect Meta, Snapchat, Google or Dropbox at any time in Settings → Accounts.
  • Remove Boostad’s access from Facebook in Settings & privacy → Settings → Apps and websites.
  • Revoke Boostad’s access from your Snapchat account, your Google Account permissions or your Dropbox connected apps.
  • Object to or ask us to restrict processing, and lodge a complaint with your local data protection authority.

To make a request, email [email protected] from the email address of your Boostad account. We respond within 30 days.

9. How to Delete Your Data

Anyone who uses Boostad can have their data deleted:

  • To delete a single connection: open Settings → Accounts and click “Disconnect” next to the Meta, Snapchat, Google or Dropbox account. Its tokens and account identifiers are deleted immediately.
  • To delete everything: email [email protected] with the subject “Delete my data” from the email address of your Boostad account. We will delete your account and all associated data — connections and tokens, launch history, presets, templates, upload history, logs, feedback and registration records — within 30 days and confirm by email.
  • If you removed Boostad in your Facebook or Snapchat settings, please also email us so we can delete the data we already hold.

Campaigns, ads, media and posts that you created through Boostad exist in your Meta and Snapchat ad accounts and Pages. We cannot delete them for you; you can manage or delete them in Meta Ads Manager, on your Pages, or in Snapchat Ads Manager.

10. Where Data Is Processed

Your information is stored and processed on servers operated by our hosting provider, Railway, and may be processed in a country other than yours, which may have different data protection laws. We apply the protections described in this policy wherever the data is processed.

11. Children

Boostad is intended for professional use and is not directed at anyone under 18. We do not knowingly collect data from minors.

12. Changes to This Policy

When we change this Privacy Policy, we will update the "Last updated" date above. If a change materially affects how we process your data, we may also notify you in the app or by email.

13. Contact

If you have any questions about this Privacy Policy or your data, please contact us. See also our Terms of Service.

Operator
SOLE PROPRIETOR SAMAR ANTON (Boostad)
Email
[email protected]