Legal
Privacy Policy
Effective date: 18 May 2026
1. Who we are
EverAds (the “Service”) is operated by Sentient Mind Ltd, a company registered in England & Wales (company number 16234530) with its registered office at 20 Wenlock Road, London, England, N1 7GU (“EverAds”, “we”, “us”, “our”).
For the purposes of UK GDPR, EU GDPR and the California Consumer Privacy Act (“CCPA”), Sentient Mind Ltd is the data controller for personal data processed through the Service.
You can contact us at any time about this policy or your personal data at team@ever-ads.com.
2. Scope
This policy describes how we collect, use, store, share and protect personal data when you visit ever-ads.com, sign up for an account, generate ad creatives, or otherwise interact with the Service.
3. Personal data we collect
We collect the following categories of personal data:
- Account data - name, email address, password (hashed), and authentication identifiers from Google if you sign in with Google OAuth.
- Profile and offer data - brand name, brand colours, product or service descriptions, target audiences, callouts and any other content you enter into the Service.
- Generated content - the prompts you submit and the images and text the Service generates for you.
- Billing data - subscription plan, billing status, customer ID and invoice history. Card details are collected and stored by Stripe; we never see or store your full card number.
- Usage and device data - IP address, browser type, device identifiers, pages viewed, features used, referrer URL and timestamps.
- Cookies and similar technologies - see Section 9.
- Communications - messages you send us through the contact form, email or support channels.
4. How we use your personal data
We process your personal data for the following purposes and on the following legal bases (UK/EU GDPR Article 6):
- To provide the Service - creating and managing your account, generating ad creatives, storing your brands and offers, enforcing plan limits. Legal basis: performance of a contract.
- To take payments - processing subscriptions, credit purchases and refunds via Stripe. Legal basis: performance of a contract; legal obligation (tax and accounting records).
- To communicate with you - sending transactional emails (sign-up confirmation, password resets, billing notices, generation results) and responding to support requests. Legal basis: performance of a contract; legitimate interests (responding to enquiries).
- To improve and secure the Service - monitoring usage, debugging, preventing abuse and fraud, enforcing our Terms. Legal basis: legitimate interests; legal obligation.
- Marketing and attribution - measuring the effectiveness of our advertising via the Meta Pixel and Meta Conversions API. Legal basis: legitimate interests, or your consent where required by law.
- To comply with the law - responding to lawful requests from regulators, courts and law enforcement. Legal basis: legal obligation.
5. Service providers
We use third-party service providers to operate EverAds. Service categories include:
- Hosting and database
- Payments
- Email delivery
- Error monitoring
- AI text generation
- AI image generation
- Authentication
- Advertising attribution and Meta integration
A current named list of these providers, including the role each plays and the categories of data they process, is maintained at ever-ads.com/subprocessors. We update it when the list changes. Each provider is bound by a written agreement to protect your data and process it only on our instructions.
We do not sell your personal data, and we do not share it for cross-context behavioural advertising for the benefit of unrelated third parties.
6. Meta integration data
If you connect a Meta account to EverAds, we access and process additional personal data through Meta's Marketing API.
What we access. Basic Meta profile information (your Meta user ID and name), business portfolio and ad account metadata, Facebook Page metadata, Meta Pixel metadata, and campaign and performance data for the ad accounts, Pages and Pixels you explicitly select during onboarding. We only access data for the entities you authorise; we never request access to anything outside those.
What we store. OAuth access tokens (encrypted at rest in Supabase Vault), the Meta IDs of the entities you select, campaign metadata for campaigns you create through EverAds, and snapshots of performance insights so we can display them in your dashboard.
How we use it. To let you publish AI-generated ad creatives to your Meta ad accounts, to display campaign performance, and to keep status indicators accurate. We do not sell Meta data, do not share it with third parties other than the service providers required to operate EverAds (see ever-ads.com/subprocessors), do not use it to train AI models, and do not access ad accounts you have not authorised.
Retention. We keep Meta data while your connection is active. When you disconnect Meta in EverAds, we revoke our access with Meta and invalidate the stored authorisation immediately. Disconnecting Meta removes our access but keeps your historical campaign records in EverAds: campaign metadata stays in your EverAds account until you delete your account or request its deletion. When you delete your account or request data deletion, we delete everything - including the encrypted token record - within 30 days.
How to revoke our access. You can disconnect at any time:
- In EverAds, go to Settings → Meta and click Disconnect Meta.
- Or in Facebook, go to Settings → Apps and Websites and remove EverAds.
Either path produces the same outcome.
How to request deletion. See our Data Deletion Instructions for the specific email procedure.
7. International data transfers
Your personal data is primarily stored in the European Economic Area (Ireland). Some of our sub-processors are based in, or operate infrastructure in, the United States and other jurisdictions outside the UK and EEA. Where personal data is transferred outside the UK or EEA, we rely on appropriate safeguards under UK GDPR and EU GDPR, including:
- the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum; and
- recipient certification under the EU–US Data Privacy Framework and UK Extension where applicable.
8. Retention
We keep your personal data only for as long as we need it for the purposes set out in this policy.
- Active accounts - we retain your account, offers and generations for as long as your account is open.
- Account deletion - when you delete your account, we delete or irreversibly anonymise your account data, offers and generations within 30 days, except where we are required by law to keep records longer (for example, billing records retained for tax purposes).
- Billing records - invoices and payment records are retained for at least six years to meet UK accounting and tax obligations.
- Backups - data may persist in encrypted backups for a short additional period after deletion before backups roll over.
9. Your rights
Depending on where you live, you have some or all of the following rights in relation to your personal data:
- access a copy of the personal data we hold about you;
- correct inaccurate or incomplete data;
- delete your data (the “right to be forgotten”);
- restrict or object to certain processing;
- receive a portable copy of data you provided to us (data portability);
- withdraw any consent you gave us, at any time, without affecting the lawfulness of processing before the withdrawal;
- opt out of the sale or sharing of personal data, and limit the use of sensitive personal information (CCPA);
- not be subject to discrimination for exercising your privacy rights.
To exercise any of these rights, email team@ever-ads.com. We will respond within the timeframes required by applicable law. You also have the right to complain to a supervisory authority - in the UK, the Information Commissioner's Office (ico.org.uk).
For specific deletion instructions, including how to delete data EverAds holds from your Meta connection, see our Data Deletion Instructions.
10. Cookies and tracking
We use cookies and similar technologies to:
- keep you signed in and remember your session (strictly necessary);
- remember preferences such as your template library filters (functional);
- measure and attribute the effectiveness of our advertising via the Meta Pixel and Conversions API (analytics / advertising).
You can control cookies through your browser settings. Blocking strictly necessary cookies will prevent the Service from functioning correctly.
11. Security
We take reasonable and appropriate technical and organisational measures to protect personal data, including encryption in transit (HTTPS/TLS), encryption at rest for stored data, role-based access controls, row-level security in our database, hashed passwords, and audit logging. No system is perfectly secure, and we cannot guarantee absolute security.
12. Children
The Service is not directed at children under 16, and we do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.
13. AI processing of your content
When you generate ad creatives, the prompts and structured offer data you submit are sent to our AI generation providers (see ever-ads.com/subprocessors for the current list and their roles) so they can produce the requested output.
Our text-generation routing is configured to use only upstream model providers whose API terms prohibit training on customer prompts.
Our image-generation providers process prompts and generated images under their own published privacy terms; we do not separately use your prompts or generated content to train any models we control.
Prompts may be retained briefly by upstream providers for service operation and abuse monitoring.
14. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you by email or through the Service before the changes take effect. Continued use of the Service after a change constitutes acceptance of the updated policy.
15. Contact us
Questions, requests or complaints about this policy or your data can be sent to:
Sentient Mind Ltd
20 Wenlock Road
London, England, N1 7GU
United Kingdom
team@ever-ads.com