Who we are
Senditor (“we”) is based in Lithuania. We decide how the data described here is used, so under data protection law we are its controller, except where this policy says we act for you. Write to support@senditor.ad about anything in this policy.
What Senditor does
Senditor helps people who run Meta ads for their clients (we call them operators) check finished ads, get the client’s yes or no on one approval link, and add the approved ads, paused, to an ad account the operator already owns. Operators use the app after we invite them; the software runs on a server we operate. This policy covers the app, our website senditor.ad and email with us.
What we hold, and why
Your account. When we invite you, we keep your email address and the invitation: when it was made, when it expires and whether it was used. When you accept it you choose a passcode, and we store only a salted scrypt hash of it, never the passcode itself. We also keep when your account was created and whether it is active. Signing in sets a cookie, described under “Cookies and storage”. We also keep when your access started and ends, and, if you fill in our feedback form, your answers, which we use only to improve Senditor.
Your Meta connection. When you press “Connect Meta” and approve our app, Meta issues us an access token for your account. We immediately exchange it for a longer-lived token, which lasts approximately 60 days, and store that token, together with your Meta user id (the number Meta gives your account, which tells us whose token it is), on our server, in a file only the server’s own account can read. You sign in once: that one token serves every client workspace you manage. For each workspace we also store, in a separate file with no token in it, your Meta user id and the ID and name of the one ad account, the one Facebook Page and the one ad set you select for it. When you add ad accounts as workspaces in one step, each new workspace is named after its ad account unless you rename it, and that name is stored with it.
“Unlink” on a workspace removes that workspace’s selection only. “Disconnect Meta” removes your stored token, including an older workspace token unless another active operator owns that workspace. Your bound workspaces then read as not connected until you sign in again. Neither one deletes anything on Meta: your ad accounts, Pages and ads stay exactly as they are.
We use the token only to perform the actions described in this policy on your behalf. We do not transmit it to any third party, we do not include it in any report, export or email the product produces, and it is never displayed in the product’s interface. It stops working on its own when it expires, and you can revoke it at any time from your Facebook account settings under Business Integrations, which ends our access immediately. A token that has stopped working stays in its file until you press “Disconnect Meta”.
Ad data we read from Meta. With your permission we read the list of ad accounts you can access, the list of Pages you manage, the names of the ad account and ad set you select, and performance figures for ads in your account: impressions, clicks, spend, click-through rate, cost per thousand impressions, frequency and reach. We use these only to show you and your client how your ads are performing, inside your own workspace. With those two lists we also read the ID and name of the business that owns each ad account and Page, only to show it beside them and to suggest the Page that belongs to the same business as an ad account; we do not store it. We do not combine your data with any other advertiser’s, we do not use it to train models, and we do not sell or share it.
Ad data we write to Meta. When you approve a creative and confirm publication, we upload that image to your ad account, create an ad creative attributed to your selected Page, and create an ad in the ad set you selected. Every ad we create is created PAUSED. We never create or modify campaigns, budgets, bids, schedules or audience targeting, and we never set an ad to active.
AI checks. When the AI checks or the folder sort are switched on for a workspace, we send the images and ad text being checked to OpenAI’s API, which returns a review. OpenAI does not use API data to train its models and may keep it in abuse-monitoring logs for up to 30 days. We never send your Meta token or your performance figures. The result is kept with that batch’s records. A workspace with AI switched off sends nothing.
Ad set suggestions. When AI ad set suggestions are switched on, and only for a folder our own rules could not match to an ad set, we send the folder’s name, plain words from its ad text and the names of your active campaigns and ad sets to TypeSafe AI, Inc. in the United States, whose model picks one of those ad sets or none. We exclude account and ad identifier fields, remove links and email addresses, and filter text that resembles a password or key; private information written into names or ad text may remain. We never send image files, your saved Meta token or performance records from Meta. TypeSafe processes this under its data processing agreement, which includes the EU Standard Contractual Clauses, does not use it to train models, and states no fixed retention period. You confirm every placement; the suggestion only pre-fills it.
AI text checks. When AI text checks are switched on, each ad’s headline and primary text go to TypeSafe AI, Inc. in the United States to flag a possible Meta policy risk. We exclude account and ad identifier fields, remove links and email addresses, and filter text that resembles a password or key; private information written into ad text may remain. We never send image files, your saved Meta token or performance records from Meta. TypeSafe processes this under its data processing agreement, which includes the EU Standard Contractual Clauses, does not use it to train models, and states no fixed retention period. This is an operator-only warning, not a policy approval; it never stops an ad from being sent for client approval.
Your ads and their records. Each time you add a batch of ads, we keep the images, the ad copy, the check results, a record of every call to an outside service and what it cost, and the plan for where each ad goes. These records are how you can see what Senditor did. They never contain your access token.
Approval records and receipts. When you send creatives to a client for approval, we create a link containing an unguessable token that expires. Anyone with that link can view those creatives and record a decision. We store each decision (approve or reject, any comment, the name typed by the person deciding, and the time) as an append-only record, and we generate a receipt page showing those decisions. We keep the full history rather than only the latest decision, so a changed mind remains visible. We do not record the IP address or the device of the person deciding. Do not enter personal information into an approval comment; the field exists to say why a creative was rejected.
Approval links. The app gives you each approval link to send to your client yourself; we do not email your clients. If we start sending these emails, we will name the email provider here first.
Email you send us. Mail to support@senditor.ad is forwarded by Cloudflare to our own mailbox, which our email provider hosts. We use it only to answer you, and keep it under “How long we keep it” below.
What we do not collect. We do not collect your Facebook profile beyond your Meta user id, which Meta returns during connection, we do not read your Page’s posts, comments, messages, reactions or followers, we do not use cookies for advertising, and we do not have analytics that track you.
Your clients’ data
The person who opens an approval link may type their name, a decision and a comment. For that data we act on the operator’s instructions: we store it so the operator and their client can see what was decided, show it on the receipt, and delete it when the operator asks. If a client writes to us, we pass the request to the operator and help them answer it.
Cookies and storage
Our website senditor.ad sets no cookies, stores nothing in your browser and has no
analytics. The app sets two cookies, which scripts on the page cannot read and which travel
only over HTTPS to the app: __Host-senditor_session keeps you signed in for up to 24
hours, and __Host-senditor_meta lasts 10 minutes, only while you press “Connect Meta” and
approve our app on Meta.
The app also keeps a few choices in your browser’s own storage: your theme, your font and your upload view (folders or a list). On an approval link, the browser keeps the typed name and the choices not yet sent, so a reload does not lose them. These cookies and this storage are not used for advertising or tracking, so there is no cookie banner.
Who receives data
We never sell your data or share it for advertising. These services receive it, each only for the job named here:
- Meta Platforms receives the images, ad copy and ad details you publish, on your instruction, and provides the accounts, Pages, ad sets and performance figures we read for you. Meta handles that data under its own policies.
- Cloudflare, Inc. carries all traffic to senditor.ad and the app, forwards mail sent to support@senditor.ad, and stores any backups we keep, encrypted. Request logging is switched off on our Cloudflare Workers.
- TypeSafe AI, Inc. receives the cleaned ad text described under “Ad set suggestions” and “AI text checks”, only while those are switched on.
- OpenAI receives the images and ad text described under “AI checks”, only for a workspace where AI checks are switched on.
We disclose data to a public authority only when the law requires it, and then only what it requires.
Transfers outside the EU
Cloudflare, TypeSafe and OpenAI may process data in the United States and other countries outside the EU. Cloudflare and TypeSafe do so under data processing terms that include the EU Standard Contractual Clauses. We switch on AI checks only once OpenAI’s data processing terms, with the same clauses, are in place.
Our legal bases
Under the GDPR we rely on the performance of our contract with you to run your account, your Meta connection, the checks, the approval links and the paused ads you confirm; on our legitimate interests to keep the service secure, prevent abuse and answer your messages; and on a legal obligation when the law requires us to keep or disclose data. For your clients’ data we act for you, as described under “Your clients’ data”.
Where it is stored, and how it is protected
Your data is kept on a server we operate, reached only through Cloudflare over HTTPS. Your Meta token and your passcode’s hash are in files only the server’s own account can read. Every write to Meta passes a rule that refuses anything but a paused ad before it leaves our server. No system is perfectly secure; if a breach affects your personal data, we will tell you, and the data protection authority, as the law requires.
How long we keep it
- Your access token and your Meta user id: until you press “Disconnect Meta”. The token stops working when it expires or when you revoke it, but its file stays until you press “Disconnect Meta”.
- Each workspace’s selection, with your Meta user id: until you press “Unlink” on it.
- When a workspace that kept its own token is moved onto your one sign-in, that old token file is kept, readable only by our server, so the move can be undone, until the first ad published through your one sign-in is confirmed paused or, once that token has expired, the next clean-up; “Unlink” on that workspace and “Disconnect Meta” delete it at once. A copy whose record cannot be read stays until “Unlink” or “Disconnect Meta”.
- Everything else about you and your workspaces, your account, ads, records, approvals, receipts and the email you send us: while your access runs. We delete it within 90 days after it ends, or within 30 days of your request to delete it, whichever comes first.
- A request for access you email us before you have an account: up to 12 months.
- Encrypted backups, where we keep them, age out within six months.
Your rights
Wherever you live, you can ask us to access, correct, delete or export the personal data we hold about you, and to restrict or object to how we use it. Email support@senditor.ad from the address your account uses, and we answer within one month. If you are in the EU or the UK, you can also complain to a data protection authority. Ours is Lithuania’s State Data Protection Inspectorate (VDAI).
How to delete your data
See “Deleting your data” at https://senditor.ad/data-deletion. In short: “Disconnect Meta” and “Unlink” in the app, removing Senditor in your Facebook settings, or an email to us.
Children
Senditor is for businesses and for people aged 18 or older. We do not knowingly collect data about children.
Changes
If we change this policy we will update the date above and tell everyone with an account directly.
Contact
support@senditor.ad. Our terms of service are at https://senditor.ad/terms.