Privacy Policy

Last updated: 3 October 2026

This policy explains how AdForge processes personal data when you visit our website or use the Service. We are based in the European Union and process personal data in accordance with the General Data Protection Regulation (GDPR).

1. Controller

The controller is Miha Vidakovič, operating AdForge, Slovenia, European Union. Contact: [email protected].

2. Data we process

Depending on how you use AdForge, we process:

  • Account data: name, email address, password hash, language, role, and — if you use Google sign-in — your Google account identifier and profile name.
  • Usage and security data: IP address, browser user agent, session records, audit logs of security-relevant actions, and rate-limiting counters.
  • Brand and content data: websites you submit, crawled page content and screenshots, brand profiles, angles, generated copy and images, and files you upload.
  • Billing data: plan, token balance and transaction history. Payment card details are processed directly by Stripe; we never see your full card number.
  • Communications: emails you send us and transactional emails we send you (verification, password reset).

3. Purposes and legal bases

  • Providing the Service, including AI generation and storage of your content — performance of a contract (Art. 6(1)(b) GDPR).
  • Account security, fraud and abuse prevention, rate limiting and bot protection — legitimate interests (Art. 6(1)(f)).
  • Billing, invoicing and tax records — legal obligation (Art. 6(1)(c)) and contract.
  • Service emails about your account — contract. We do not send marketing emails without your consent (Art. 6(1)(a)).

4. AI processing

To generate ads we send relevant parts of your brand data and instructions to AI providers: Anthropic (Claude) for text and Google (Gemini) for images. They process the data on our behalf under data processing terms and do not use it to train their models. Generation involves no decisions with legal or similarly significant effects on you.

5. Recipients and international transfers

We share data only with the sub-processors listed in our DPA & sub-processor list, and with authorities where required by law. Some sub-processors are located in the United States; transfers are based on the EU–US Data Privacy Framework and/or Standard Contractual Clauses with supplementary measures.

6. Retention

  • Account, brand and generated content: for as long as your account exists; deleted within 30 days after you delete your account.
  • Security and audit logs: up to 12 months.
  • Billing records: as long as required by tax law (currently up to 10 years in Slovenia).
  • Backups: overwritten on a rolling basis within 30 days.

7. Your rights

You have the right to access, rectify, erase, restrict and port your data, and to object to processing based on legitimate interests. You can export or delete your data yourself in Settings, or email [email protected]. Where processing is based on consent, you can withdraw it at any time.

You also have the right to lodge a complaint with a supervisory authority, in Slovenia the Information Commissioner (Informacijski pooblaščenec, www.ip-rs.si), or the authority in your country of residence.

8. Security

We use encryption in transit, hashed passwords, short-lived access tokens, role-based access, rate limiting, isolated crawling infrastructure and access-logged administration to protect your data.

9. Cookies

We use only strictly necessary cookies. See our Cookie Policy for details.

10. Changes

We will post updates to this policy here and notify registered users of material changes by email.

Questions about this document? Email [email protected].