Privacy Policy
Last updated: July 11, 2026
This policy explains what personal data FacelessAd ("we") collects, why, and what your rights are. We process personal data in accordance with the EU General Data Protection Regulation (GDPR).
1. Data we collect
- Account data: email address, hashed password, email-verification status, and — if you sign in with Google — your Google account identifier and email.
- Content data: the briefs, scripts, images, and other materials you provide, and the videos, images, audio, and text the Service generates for you. Generated files are stored for 90 days and then deleted.
- Billing data: subscription plan, payment status, and payment-card fingerprint (used to prevent abuse of the money-back guarantee). Full card details are handled by Stripe and never touch our servers.
- Usage data: generation events, per-request cost records, technical logs (IP address, timestamps), and session cookies required to keep you signed in.
2. Why we process it (legal bases)
- Providing the Service you subscribed to — account, content, and billing data (contract).
- Preventing fraud and abuse, including guarantee-abuse prevention and rate limiting (legitimate interest).
- Sending transactional emails: email verification, password resets, and file-expiry reminders. Reminders can be turned off with one click; verification and security emails cannot, as they are necessary to operate your account (contract / legitimate interest).
- Complying with bookkeeping and tax obligations (legal obligation).
We do not sell personal data and we do not send marketing email without your separate consent.
3. Processors and transfers
We use the following processors to run the Service. Some are located outside the EEA; transfers rely on EU adequacy decisions or Standard Contractual Clauses:
- Hetzner (Germany/Finland) — application hosting.
- Cloudflare R2 — storage of your uploaded and generated files.
- Stripe — payments and subscription management.
- Brevo — transactional email delivery.
- AI model providers (including Anthropic, OpenAI, Google, ElevenLabs, and video-generation providers accessed via WaveSpeed, and AWS for rendering) — receive the prompts and media needed to generate your content. We send them only what the generation requires; your account identity is not shared with them.
4. Retention
- Generated files: 90 days from creation, then permanently deleted.
- Account data: for as long as your account exists, and up to 90 days after deletion for backup rollover.
- Billing records: as required by accounting law (typically 6 years).
- Guarantee-abuse records (email and card fingerprint): retained to enforce the once-per-customer guarantee.
- Technical logs: up to 90 days.
5. Cookies
We use one strictly necessary cookie (fa_session) to keep you signed in. We do not use advertising or third-party analytics cookies.
6. Your rights
You have the right to access, rectify, and erase your personal data, to restrict or object to processing, and to data portability. You can delete your generated files at any time from My Files. To exercise any right or to delete your account, email [email protected]. You also have the right to lodge a complaint with your local supervisory authority (in Finland: the Office of the Data Protection Ombudsman).
7. Security
Passwords are stored as strong one-way hashes, sessions use random tokens, file access uses short-lived signed URLs, and provider-identifying metadata is stripped from generated files. No method of transmission or storage is 100% secure, but we work to protect your data with industry-standard measures.
8. Controller and contact
The data controller is FacelessAd. Contact: [email protected]. We will update this policy as the Service evolves; material changes are announced in the app or by email.
See also our Terms of Service.