Last updated: 18 August 2026
This policy describes how Ultrads collects, uses and protects your personal information when you use our platform.
To provide the platform's services we collect the following kinds of information:
Information you provide: full name, email, phone number and contact details.
Business information: data about competitor sites you enter into the system, and content you upload for processing.
AI output: images, videos and text you generate through the platform.
Technical information: IP address, browser type, session times and usage data.
Payment details: card processing is carried out by external payment providers certified to the PCI-DSS standard. The Company does not store full card details on its servers.
The site uses cookies for its ongoing operation, to improve the user experience and for security. The types used are: essential cookies (to keep you signed in), analytics cookies (Google Analytics) and advertising cookies.
Consent. Using the site constitutes consent to the use of cookies. You can block cookies through your browser settings, but doing so may impair how the platform works.
Your information is stored on Google Firebase servers (Google LLC) — Google Cloud Firestore for operational data and Cloud Functions for server-side processing. Google has a valid Data Processing Addendum, available at cloud.google.com/terms/data-processing-addendum. Although we take accepted security measures, the Company cannot guarantee absolute immunity from cyber breaches or unauthorised access.
We use Facebook Login. Users choose to connect their Facebook and Instagram assets to Ultrads through the Facebook Login permissions dialog. The connection is initiated by the user only, and all actions are performed solely on assets owned by the connected user.
The permissions we request and what they are used for: public_profile — basic identification; pages_show_list — listing the pages you hold so you can choose one; pages_read_engagement — reading the connected page's content and metadata; pages_manage_posts — publishing posts you created to your page; instagram_basic — identifying the linked Instagram business account; instagram_content_publish — publishing to your Instagram account; business_management — reading Business Manager assets (pages and ad accounts) in order to connect them; ads_read — reading ad account and campaign performance; ads_management — creating, activating, pausing and updating campaigns and ads in your ad account, according to the actions you take in the system.
What we store in this context: the Facebook user ID, a long-lived user access token and a page access token, the ad account ID and name, its currency and time zone, the connected page's ID and name, the linked Instagram account's ID and name, and the connection date. Tokens are stored encrypted on Ultrads servers and are used solely for actions the user initiates.
Publishing. Publishing to Facebook and Instagram happens only on the user's initiative (pressing "publish") and only to assets they own. Paid campaigns are always created in PAUSED state — Ultrads never un-pauses ads automatically; activation requires an explicit action by the user.
Disconnecting and deletion. You can disconnect at any time from the Ultrads dashboard, or through your Facebook settings (Settings → Apps and Websites → remove Ultrads). Removing the app triggers our Deauthorize Callback, which immediately deletes the access tokens and connection data from our servers.
Content privacy. Content you upload or create is processed by AI models supplied by external providers acting as data processors on our behalf: OpenAI, L.L.C. (United States) — text and image generation, audio transcription and content analysis; and Cloudflare, Inc. (United States) — video generation.
Data originating from Meta. When you connect an Instagram business account, data received from Meta — including the profile description (bio), post captions and images from the feed — may be sent to OpenAI in order to analyse the account and produce content recommendations. OpenAI's data processing terms are available at openai.com/policies/data-processing-addendum.
Use for improving the system. The user agrees that the Company may use uploaded information and content, anonymously, to improve the performance of its algorithms and system.
Public content. Content you choose to share in the public gallery will be visible to all users, and the Company is not responsible for how third parties use it.
The Company will not sell or rent your personal information. We share information only in the following cases: to provide the service (hosting providers such as Google Firebase, AI providers, and Meta Platforms for users who connected through the Marketing API); to comply with a court order or a lawful demand from state authorities; and in the event of legal proceedings between the user and the Company.
Requests from government authorities. For any request for personal information from a government authority, the Company will first examine the legal validity of the request (for example, whether a court order or an appropriate legal basis exists) before disclosing anything. Where information is disclosed, only the minimum needed to answer that specific request will be provided — no more. The Company keeps an internal record of every such request, including its substance, its legal basis and the response given. Where the Company believes a request does not meet legal requirements, it reserves the right to consider objecting to it in consultation with legal counsel.
By law you are entitled to inspect the information held about you in our database and to request its correction or deletion. There are four ways to request deletion:
(a) Delete it yourself from the dashboard. On the settings screen, press "delete account" — this deletes your data from the platform and automatically disconnects the Meta connection if one exists.
(b) Ask by email. Send a request to [email protected] with the subject line "Data Deletion Request" and your registered email address. We will complete the deletion within 30 days and send written confirmation.
(c) Disconnect Meta only, without deleting the account. Through the dashboard → Automation → "disconnect". This deletes all Meta-related data (tokens, ad account IDs, page IDs) from Ultrads servers.
(d) Automatic deletion through Facebook. Removing the app in your Facebook settings (Settings → Apps and Websites) causes Facebook to send a deletion request to our Data Deletion Callback at https://ultrads.ai/api/fb/data-deletion, and we permanently delete all Facebook and Instagram connection data and provide a confirmation code for tracking.
The Company may update this privacy policy from time to time. Continued use of the site after an update constitutes acceptance of the new terms.
This English text is a translation provided for convenience. In the event of any discrepancy, the Hebrew version at ultrads.ai/privacy prevails.
Contact. For any question about privacy, information security or a data deletion request: [email protected] · Ultrads, Nim Boulevard 2, Rishon LeZion, Israel.