Privacy Policy
This Privacy Policy explains what information Boostad ("we", "our", "us") processes, how and why we process it, who we share it with, how long we keep it, and how you can have it deleted. Boostad is operated by SOLE PROPRIETOR SAMAR ANTON, who is responsible for the information described here.
Want your data deleted? See Section 9 — How to Delete Your Data.
1. What Boostad Is
Boostad is a web tool for advertisers and marketing teams. It lets you create advertising campaigns in your own Meta (Facebook and Instagram) and Snapchat ad accounts by reusing an existing campaign as a template, upload ad creatives from your computer, Google Drive or Dropbox, and manage the Facebook Pages you administer. Access to Boostad requires a registration that is approved by us.
In short:
- –We only access the ad accounts, Pages, Instagram accounts and files that you connect or select yourself.
- –We act on your advertising accounts only when you start an action in Boostad (for example, press “Launch” or “Upload”).
- –We do not sell your data, use it for advertising, or build profiles of people.
- –We do not collect data about your customers or ad audiences: no lead form submissions, no Messenger or Instagram conversations, no personal data of people who see or interact with your ads.
2. Information We Collect
2.1 Your Boostad account
- –Name and email address.
- –Password, stored only as a bcrypt hash (we never store your plain-text password). If you sign in with Google, we receive your name and email address from Google.
- –Interface language, time zone and your role in Boostad.
- –Registration requests: name, email address, hashed password (if any), team name and sign-in method. We keep a record of each request, including rejected ones.
2.2 Meta (Facebook and Instagram) connection
When you connect a Facebook account using Facebook Login, we store:
- –Your Facebook user ID and display name. We do not request access to your email address.
- –Your Facebook access token, encrypted with AES-256-GCM before it is written to our database, and its expiry date.
Using that token, and only when you use the corresponding feature, Boostad reads and writes the following through the Meta Marketing API and Graph API:
- ads_management
- Reading your ad accounts and their campaigns, ad sets, ads, creatives, pixels, apps and media library, so you can pick a template; creating campaigns, ad sets, creatives and ads and uploading images and videos to your ad accounts when you launch; reading performance statistics (spend, impressions, reach, clicks and results) of the campaigns in your Boostad launch history, to show them on your dashboard.
- business_management
- Reading business assets available to your ad accounts, such as the Instagram accounts of the business that owns an ad account, so they can be used as the identity of your ads.
- pages_show_list
- Showing the list of Facebook Pages you manage, so you can choose the Page your ads run from.
- pages_read_engagement
- Reading your Page and its posts when you reuse an existing ad or post (for example, its call-to-action button), checking which Instagram account is linked to the Page, and listing your Page’s own posts and photos in the Facebook Pages module.
- pages_manage_posts, pages_manage_metadata, pages_read_user_content
- Facebook Pages module only, requested separately when you grant access from that module: updating your Pages’ profile picture, cover and details, publishing and scheduling posts, and removing posts and content from your Pages at your request.
Page access tokens are requested from Meta when needed for an action and are not stored in our database. Campaign performance statistics are read from Meta when you open your dashboard, are aggregated across your campaigns, and are not stored (they are kept in server memory for up to a few minutes to avoid repeated requests).
2.3 Snapchat connection
When you connect a Snapchat account, we store:
- –Your Snap member ID, display name and email address, as provided by Snap, and the organization you selected.
- –Your Snapchat access and refresh tokens, encrypted with AES-256-GCM, and their expiry date.
Using those tokens, and only when you use the corresponding feature, Boostad reads your Snapchat organizations, ad accounts, Public Profiles, campaigns, ad squads, ads, creatives and media (to use them as templates), uploads your media, and creates campaigns, ad squads, creatives and ads in your ad accounts when you launch.
2.4 Google connection
- –Sign in with Google: your Google account ID, name and email address.
- –Google Drive (optional): your Google account ID, name, email address and encrypted access and refresh tokens. We use the drive.file scope, which only gives us access to the files you choose in the Google Picker — not to the rest of your Drive.
- –Links to public Google Drive folders and public Google Sheets that you paste are read without your Google account.
2.5 Dropbox connection
If you connect Dropbox, we store your Dropbox account ID, name, email address and encrypted access and refresh tokens, and use them to list and download the files and shared links you choose.
2.6 Creatives and upload history
- –File name and type, the media identifiers returned by Meta or Snap (image hash, video ID, Snap media ID), a preview image URL provided by Meta, and the ad account ID. This lets you reuse previously uploaded creatives.
- –We do not keep copies of your images or videos. Files you upload from your computer to Meta go directly from your browser to Meta. Files from Google Drive, Dropbox or links, and all files uploaded to Snapchat, pass through our servers only while they are being transferred and are not stored.
2.7 Launches, settings and templates
- –Launch history: campaign name, platform campaign ID, ad account ID and name, campaign objective, launch type, number of ad sets and ads created, status, progress and error messages. This is the history shown in your dashboard.
- –Saved launch presets: the settings of a launch (including a copy of the template campaign’s settings) that you choose to save for reuse.
- –Technical launch logs: for each launch, the names of created objects, platform error codes and the names of settings that a platform rejected. We use them to diagnose failures and improve reliability.
- –Launch snapshots: if a launch fails, a copy of the settings that were being sent (campaign, ad set, creative and ad settings, including targeting, ad texts and links), so we can find the cause.
- –Background job records used to run launches after you start them.
- –Facebook Pages module: design templates, post text templates and the history of publications (Page IDs, Page names and results).
2.8 Feedback
When you send feedback through the in-app form, we store your message and its type. If you leave the “attach diagnostics” option on, we also store the page address, your browser’s user agent, screen size and the most recent JavaScript errors from that page, together with the app version.
2.9 Technical data
Our servers keep standard logs (such as IP address, requested address, time and errors) for security and troubleshooting. IP addresses are also used, in memory only, to limit repeated registration attempts.
3. How We Use Information
We use the information described above only to:
- –Authenticate you and keep your account secure.
- –Perform the actions you start in Boostad on your Meta, Snapchat, Google and Dropbox accounts.
- –Show your launch history, the performance statistics of your campaigns, saved presets, templates and upload history.
- –Diagnose failed launches and improve the reliability of the service.
- –Respond to your feedback and support requests.
- –Detect and prevent abuse and unauthorized access, and comply with legal obligations.
We do not use data received from Meta, Snap, Google or Dropbox for advertising, to build profiles, segments or audiences, or to track people, and we do not sell it. We may create aggregated, de-identified statistics (for example, how often a particular platform error occurs) to improve Boostad.
5. Data Security
- –All access and refresh tokens (Meta, Snapchat, Google, Dropbox) are encrypted with AES-256-GCM before being stored.
- –Passwords are stored only as bcrypt hashes.
- –All data in transit is protected by TLS (HTTPS).
- –Every request is checked against your account: you can only use the connections, ad accounts and records that belong to you (or that are shared with your team, if you work in a team).
- –Database credentials and encryption keys are kept in the hosting environment, never in source code.
- –To upload files from your computer directly to Meta, your own Facebook access token is made available to your browser session. It is never shown to other users.
No system is completely secure. Please connect only accounts that you control or are authorized to use with Boostad.
6. Data Retention
- Account data
- For as long as your account exists.
- Connected accounts and tokens
- Until you disconnect the account in Settings or delete your Boostad account. Disconnecting deletes the stored tokens and account identifiers immediately.
- Launch history, presets, templates, upload history
- For as long as your account exists, or until you ask us to delete them.
- Technical launch logs
- Deleted automatically after 90 days.
- Launch snapshots (failed launches only)
- Deleted automatically after 30 days.
- Background job records
- Deleted automatically 7 days after the job finishes.
- Feedback
- Until it is resolved and no longer needed, or until you ask us to delete it.
- Registration requests
- Kept as a record of applications until you ask us to delete them.
- Server logs
- For a limited period, according to our hosting provider’s log retention.
We also delete data when it is no longer needed to provide Boostad, when we stop operating Boostad, or when Meta, Snap or applicable law requires it.
8. Your Choices and Rights
You can:
- –Ask for a copy of the personal data we hold about you, or ask us to correct it.
- –Ask us to delete your data (see Section 9).
- –Disconnect Meta, Snapchat, Google or Dropbox at any time in Settings → Accounts.
- –Remove Boostad’s access from Facebook in Settings & privacy → Settings → Apps and websites.
- –Revoke Boostad’s access from your Snapchat account, your Google Account permissions or your Dropbox connected apps.
- –Object to or ask us to restrict processing, and lodge a complaint with your local data protection authority.
To make a request, email [email protected] from the email address of your Boostad account. We respond within 30 days.
9. How to Delete Your Data
Anyone who uses Boostad can have their data deleted:
- –To delete a single connection: open Settings → Accounts and click “Disconnect” next to the Meta, Snapchat, Google or Dropbox account. Its tokens and account identifiers are deleted immediately.
- –To delete everything: email [email protected] with the subject “Delete my data” from the email address of your Boostad account. We will delete your account and all associated data — connections and tokens, launch history, presets, templates, upload history, logs, feedback and registration records — within 30 days and confirm by email.
- –If you removed Boostad in your Facebook or Snapchat settings, please also email us so we can delete the data we already hold.
Campaigns, ads, media and posts that you created through Boostad exist in your Meta and Snapchat ad accounts and Pages. We cannot delete them for you; you can manage or delete them in Meta Ads Manager, on your Pages, or in Snapchat Ads Manager.
10. Where Data Is Processed
Your information is stored and processed on servers operated by our hosting provider, Railway, and may be processed in a country other than yours, which may have different data protection laws. We apply the protections described in this policy wherever the data is processed.
11. Children
Boostad is intended for professional use and is not directed at anyone under 18. We do not knowingly collect data from minors.
12. Changes to This Policy
When we change this Privacy Policy, we will update the "Last updated" date above. If a change materially affects how we process your data, we may also notify you in the app or by email.
13. Contact
If you have any questions about this Privacy Policy or your data, please contact us. See also our Terms of Service.