Skip to content

Legal

Privacy policy

What AdFace collects, why, who processes it on our behalf, and how you get your data out or deleted.

Last updated September 15, 2026

1. Who is responsible

The AdFace operating entity is the controller for the personal data described here. Insert its registered name, address and data protection contact before publishing.

For anything in this policy, write to privacy@adface.ai.

2. What we collect

  • Account data: name, email address, password hash, interface language, workspace membership and role.
  • Content you bring: product URLs, imported product pages and images, briefs, scripts, presenter and voice choices, and the ads we render for you.
  • Usage data: credit ledger entries, generation jobs and their provider costs, and technical logs with IP address and user agent.
  • Billing data: plan, subscription status, invoices and the customer identifier held at our payment provider. Card details never reach our servers.
  • Messages you send us by email.

3. Why we use it

We use your data to run the service: authenticate you, ingest product pages, generate briefs, scripts and media, keep the credit ledger honest, send transactional email, prevent abuse, and meet our accounting duties.

We do not sell personal data, we do not use your product content or renders to train our own models, and we do not send you marketing email you did not ask for.

4. Processors and AI providers

Running the pipeline means sending parts of your content to specialised providers, each under a data processing agreement and only for the task at hand:

  • Text model provider: product briefs, scripts and moderation checks.
  • Speech, lip-sync and video providers: the voice line and the presenter video for a variation.
  • Object storage and hosting: your uploads, work files and renders.
  • Email provider: verification, password reset and batch notification email.
  • Payment provider: subscriptions, top-ups and invoices.

The current list of sub-processors is available on request from privacy@adface.ai.

5. Legal bases

Where the GDPR applies we rely on: performance of a contract for account, generation and billing data; legitimate interests for security, abuse prevention and product analytics; legal obligation for invoices and tax records; and consent where we ask for it, which you can withdraw at any time.

6. How long we keep it

Intermediate work files, such as voice tracks and presenter clips, are deleted about 30 days after a variation completes. Renders, products and scripts stay until you delete them or close the workspace.

Credit ledger entries and invoices are kept for the period our accounting and tax rules require, even after an account is closed. Technical logs are kept for a short retention window.

7. Your rights

You can access and correct your profile in settings, export your data as JSON, and delete your account, which deletes its personal workspace and content.

Depending on where you live you may also have the right to restrict or object to processing, to portability, and to complain to your data protection authority. Write to privacy@adface.ai and we answer within one month.

8. International transfers

Our infrastructure and several model providers are located outside the European Economic Area. Where we transfer personal data we rely on the European Commission's standard contractual clauses or another valid transfer mechanism, and we assess each provider before we route content to it.

9. Security

Traffic is encrypted in transit, secrets are held outside the code base, access to production data is limited to the people who need it, and passwords are stored hashed. Media is served from storage with signed, expiring URLs, and share links can be revoked.

No service is perfectly secure. If a breach affects you we notify you and the relevant authority as the law requires.

10. Children

AdFace is a business tool and is not intended for anyone under 16. We do not knowingly collect their data; write to privacy@adface.ai if you believe a child has created an account.

11. Changes

We update this policy when the service changes. The date at the top of this page always reflects the current version, and material changes are announced by email or in the app.