R
Reads

Privacy Policy

Last updated: May 31, 2026

Reads("we", "our", "us") operates an AI-powered ad management platform that helps businesses manage their Meta and Google advertising campaigns from a single dashboard. This Privacy Policy explains what information we collect, how we use it, who we share it with, and how we protect it, with specific attention to data accessed through the Meta Marketing API and the Google Ads API.

Google API Services User Data Policy: Limited Use Disclosure

Reads's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms:

  • We use Google user data only to deliver the Reads features the user explicitly signed up for (campaign reporting, AI optimization, campaign / ad-group / ad management).
  • We do not transfer Google user data to anyone, except as necessary to provide or improve user-facing features, comply with applicable law, or as part of a merger / acquisition (in which case the receiving party will be bound by these same commitments).
  • We do not use Google user data to serve advertisements.
  • We do notallow humans to read Google user data unless we have the user's explicit consent for specific messages, it is necessary for security purposes (e.g., investigating abuse), to comply with applicable law, or the data is aggregated and anonymized.

1. Information We Collect

We collect the following categories of information:

  • Account information. Name, email, hashed password, language preference, timezone, and (if you sign in with Google) the Google profile information returned by the OpenID Connect email, profile, and openid scopes.
  • Ad platform data. When you connect your Meta or Google Ads accounts, we receive (through official APIs and on your behalf) your ad-account identifiers, campaign / ad-set / ad-group / ad / keyword metadata, performance metrics (impressions, clicks, conversions, spend), audience lists associated with your account, and search terms reports.
  • OAuth tokens. Encrypted refresh tokens from Meta and Google so we can sync your data on a recurring schedule. Tokens are encrypted at rest with AES-256-GCM.
  • Generated content. AI-generated ad copy, keyword suggestions, and ad creatives you produce through Reads features.
  • Usage data. Aggregated, non-identifying information about how the platform is used (pages visited, features triggered, error counts).
  • Payment information. Billing details processed by our payment provider (Epoint). We never see or store card numbers.

2. How We Use Your Information

  • Provide and operate the Reads platform: list campaigns, sync metrics every ~4 hours, display dashboards and reports.
  • Create, edit, pause, resume, and delete campaigns / ad groups / ads / keywords on Meta and Google on your behalf, when you explicitly trigger those actions in Reads.
  • Generate AI-powered recommendations and ad copy based on the performance data of your own ad accounts. Aggregate prompts containing only your own campaign context are sent to Google Vertex AI / Gemini. No data from other Reads users is ever mixed into your prompts.
  • Send transactional emails (account verification, password resets, billing receipts, high-severity AI optimization alerts).
  • Respond to support requests.
  • Detect and prevent abuse, fraud, or violations of our Terms of Service.

We do not use your information to train any AI models, to advertise to you outside the Reads platform, or for any purpose other than those listed above.

3. Google Ads API Data

When you connect your Google Ads account, you authorize Reads to access the Google Ads API on your behalf under the OAuth scope https://www.googleapis.com/auth/adwords.

  • We use this scope only to read and modify the data of the ad accounts you explicitly connect.
  • We do not sell Google user data to third parties.
  • We do not use Google user data to serve advertisements.
  • You can revoke access at any time from myaccount.google.com/connections or from within Reads (Settings → Integrations → Disconnect). When you revoke, we delete the corresponding encrypted refresh token from our database within 24 hours and stop syncing data.
  • We comply with the Google Ads API Terms of Service and the Google API Services User Data Policy.

4. Meta Platform Data

When you connect your Meta Ads account, we access data through the Meta Marketing API under the permissions ads_management, ads_read, and business_management.

  • We only access data necessary to display and manage your campaigns.
  • We do not sell your Meta data to third parties.
  • You can revoke access at any time from Facebook → Settings → Business Integrations, or from within Reads.
  • We comply with Meta Platform Terms and Developer Policies.

5. Data Storage and Security

Your data is stored in a managed PostgreSQL 16 database hosted on Dokploy infrastructure in the European Economic Area. OAuth refresh tokens from Meta and Google are encrypted at rest with AES-256-GCM. All connections (between your browser and our servers, and between our servers and Meta / Google / Vertex AI) use TLS 1.2 or higher.

Access to production data is restricted to authorized personnel under the principle of least privilege, requires multi-factor authentication, and is logged. We perform regular security reviews and apply security patches promptly.

6. Data Sharing

We do not sell your personal data. We share data only as follows:

  • Sub-processors. Infrastructure providers necessary to operate the service: Dokploy (hosting + PostgreSQL), Cloudflare R2 (image storage), Cloudflare (DNS + CDN), Resend (transactional email), Epoint (payment processing), Google Cloud Platform (Vertex AI / Gemini for AI features).
  • Google Vertex AI / Gemini.Campaign context (campaign names, budgets, aggregated performance metrics) is sent to Gemini to generate AI recommendations and ad copy. Google's Vertex AI service is contractually prohibited from using these prompts to train their models per Google's enterprise data-processing terms.
  • Meta and Google. When you trigger an action in Reads (create campaign, change budget, pause ad), we forward only the minimum data required to perform that action via the official Meta Marketing API or Google Ads API.
  • Legal requirements. If we are legally required by court order, subpoena, or applicable law, or to protect the rights, property, or safety of Reads, our users, or others.
  • Business transfer. In the event of a merger, acquisition, or asset sale, the receiving entity will be bound by this Privacy Policy or a successor policy that maintains equivalent protections.

We do not transfer Google user data to anyone other than these sub-processors, and only for the purposes described above.

7. Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your account and all associated data. See our Data Deletion page.
  • Disconnect your Meta or Google Ads accounts at any time from Settings → Integrations. When you disconnect, we delete the corresponding encrypted refresh tokens within 24 hours and stop syncing data for that ad account.
  • Export your data in machine-readable format on request.
  • Object to or restrict certain processing where applicable under your local data protection law (e.g. GDPR for users in the EEA).

To exercise these rights, email privacy@reads.az from the email address on your account. We respond within 30 days.

8. Cookies

We use essential cookies only: authentication (session JWT and refresh-token cookies) and language preference. We do not use third-party analytics, advertising, or tracking cookies on the Reads application.

9. Data Retention

We retain your data for as long as your account is active. Specifically:

  • Account information. Until you delete your account.
  • OAuth refresh tokens. Until you disconnect the integration, after which they are deleted within 24 hours.
  • Ad performance metric snapshots. Retained for the lifetime of the account so you can view historical reports and year-over-year comparisons. Deleted on account deletion.
  • Audit logs. Retained for 12 months for security and abuse-detection purposes, then automatically purged.

When you delete your account, your personal data, ad-platform tokens, and AI-generated content are permanently removed from our production systems within 30 days. Backups are retained for an additional 30 days before being purged.

10. International Transfers

Our primary infrastructure is hosted in the European Economic Area. Some sub-processors (Google Cloud Platform for Vertex AI, Cloudflare) may process data in other jurisdictions. Where applicable, transfers outside the EEA are protected by Standard Contractual Clauses or equivalent safeguards.

11. Children

Reads is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be announced via email to your account email address and via an in-app notice at least 14 days before they take effect.

13. Contact

For questions about this Privacy Policy, to exercise your data-protection rights, or to report a concern, email privacy@reads.az.