Privacy
What Ad Geek collects, why, and how to have it removed.
This policy describes what Ad Geek actually does today. Where a feature is not built yet, it says so rather than describing it in advance. It has not been reviewed by a lawyer and is not legal advice.
Who we are
Ad Geek is advertising software for insurance agents. It connects to a Meta (Facebook and Instagram) advertising account that you already own, reads performance data from it, and reports on which advertising produced actual business outcomes.
Ad Geek is an independent product. It is not affiliated with, endorsed by, or operated by Meta Platforms, Inc. “Facebook”, “Instagram”, and “Meta” are their trademarks, used here only to describe what Ad Geek connects to.
What Ad Geek stores about you
- Your email address, display name, and a hashed password. Passwords are hashed with argon2id and are never stored or transmitted in a readable form.
- When you signed in most recently, and failed sign-in attempts, so we can rate-limit password guessing.
- A record of consequential actions you take in Ad Geek, so account activity can be audited.
What Ad Geek reads from Meta when you connect an account
Connecting is entirely your choice, and you choose which ad accounts to share on Facebook’s own screen. Ad Geek requests read-only advertising permissions:
- Your Facebook name and user ID, so Ad Geek can show you which account is connected.
- The list of Business portfolios and ad accounts you choose to share.
- Campaign, ad set, ad, and creative structure in those ad accounts — names, status, budgets, and settings.
- Daily advertising performance — spend, impressions, clicks, reach, and conversion counts.
Ad Geek stores an encrypted copy of the access token Facebook issues, so it can refresh this data. The token is encrypted with AES-256-GCM before it is written to the database.
What Ad Geek cannot do
Ad Geek does not request permission to manage your advertising, and the software currently contains no capability to do so. It cannot create, edit, pause, or delete campaigns, cannot change budgets, and cannot spend money. Those are separate Meta permissions that Ad Geek does not ask for.
Ad Geek does not read your personal Facebook profile beyond your name and user ID, your friends, your messages, or your posts.
Not built yet
Ad Geek does not currently capture sales leads, use AI to analyse your account, or make automated changes on your behalf. If those features are added, this policy will be updated before they are switched on — not after.
Who your data is shared with
Ad Geek does not sell your data or share it for advertising purposes.
Data is processed by the services Ad Geek runs on:
- Vercel — application hosting.
- Neon — the database where your data is stored.
- Meta — the source of the advertising data, when you connect an account.
Other Ad Geek customers cannot see your data. Access is enforced by the server on every request, not by hiding things in the interface.
How long data is kept
Your account data and advertising history are kept while your account exists, because they are your business records — what you spent and what it produced.
If you disconnect Meta, or remove Ad Geek from your Facebook account, the stored access token is deleted immediately and syncing stops. Advertising history already in your Ad Geek account is retained, because it describes your own business activity and remains available to you.
Deleting your data
You can remove Ad Geek at any time from Facebook → Settings & Privacy → Settings → Apps and Websites. Facebook notifies Ad Geek, which deletes the stored access token, the list of accounts shared with it, and your Facebook profile details.
Facebook gives you a confirmation code. You can check what happened at /data-deletion.
To delete your Ad Geek account entirely, including advertising history, contact us and we will remove it.
Security
Passwords are hashed with argon2id. Stored Meta access tokens are encrypted with AES-256-GCM. Traffic is served over HTTPS. Sessions expire after 12 hours.
No system is perfectly secure, and Ad Geek does not claim to hold any security certification.
Changes
If this policy changes materially, the change will be described here rather than replaced silently.