Skip to content
ad2app

Privacy Policy

Last updated: 5 August 2026

1. Data Controller

The data controller of your personal data is Ad2app sp. z o.o., with its registered office at ul. Juliana Smulikowskiego 4A/21, 00-389 Warszawa, Poland, NIP: 5253042936, KRS: 0001168159 ("ad2app", "we", "us", "our").

You can contact us regarding any privacy matter at kontakt@ad2.app.

Data Protection Officer: We have assessed our processing activities against the criteria of Article 37 GDPR. Our current processing volume does not meet the mandatory threshold for DPO designation under Art. 37 GDPR. All privacy queries are handled by our designated privacy contact at kontakt@ad2.app. We will appoint a DPO if our processing activities reach the applicable threshold and will update this policy accordingly.

2. Scope of This Policy

This Privacy Policy explains how we collect, use, store, share, and protect personal data when you access or use the ad2app platform, including our website, web application, our MCP integration for third-party tools, and any related services (collectively, the "Service"). It applies to everyone who registers an account to schedule and publish social media content.

We process personal data in accordance with Regulation (EU) 2016/679 (GDPR) and the Polish Act of 10 May 2018 on the Protection of Personal Data.

In fulfilling our accountability obligations under Art. 5(2) GDPR, ad2app maintains a Record of Processing Activities (ROPA) as required by Art. 30 GDPR, available to supervisory authorities on request.

3. Personal Data We Collect

We collect the following categories of personal data:

  • Identity and contact data: first name, last name, email address, phone number (if provided).
  • Account credentials: hashed password. See "OAuth tokens and account connections" below for how connection credentials are handled.
  • Social platform data via OAuth: when you authorise a connection to one of the social media platforms you choose to connect (currently Instagram, TikTok, X (Twitter), YouTube, LinkedIn, Facebook, Threads, Pinterest, Reddit, and Bluesky), we receive data from that platform's API as permitted by your OAuth consent. Across all connected platforms this generally includes your account/profile data (such as user ID, username or handle, display name, avatar, and account statistics where the platform exposes them), the content and media of posts you compose, schedule, or publish through the Service, and performance/analytics data for your published posts. The specific data received depends on the platform and the permissions you grant. For some platforms we describe the data in more detail below:
    • TikTok: basic profile (user ID, display name, avatar, biography, profile URL), account statistics (follower count, following count, like count, video count), video list and metadata (titles, view counts, engagement metrics), and, where enabled for scheduling features, video upload and publish permissions. We request only the permissions required for the features you actively use.
    • Instagram: Instagram Business account data including username, biography, profile picture, account type, and associated business metrics.
    • Facebook: public profile information and, where you grant permission, your Facebook email address. Facebook is an independent OAuth provider separate from Instagram.
    • YouTube: YouTube channel data (read-only: videos, statistics, channel metadata) and your Google Account profile (name, profile picture URL, Google Account ID) via the Google identity scope used for authentication.
    • Other connected platforms (X (Twitter), LinkedIn, Threads, Pinterest, Reddit, Bluesky): account/profile data, the post content and media you publish through the Service, and published-post analytics, in each case as permitted by the OAuth permissions you grant on that platform.
  • OAuth tokens and account connections: publishing to your connected platforms is handled by our processor Zernio (see Section 6). For the platforms Zernio publishes to, we do not store your OAuth tokens ourselves; the tokens are held by Zernio on our behalf, and we hold only a reference to your connected account (platform name and username). For a small number of platforms where we read analytics directly (TikTok, Instagram, YouTube, Facebook), we may hold an access token ourselves. We are completing a technical review to confirm and, where needed, encrypt at rest every token we hold directly (see Section 10).
  • Audience data (aggregate only): demographic and engagement statistics about your social media audience, as provided by the connected platform's API. This data is processed exclusively in aggregate statistical form and is not linked to any identified individual within your audience. We have assessed whether this data could constitute special category data under Art. 9 GDPR and confirm that we do not process such special category data: audience data is processed solely as aggregate numeric metrics.
  • Inbox data: when you use the platform's inbox features, direct message conversations and post comments from your connected social media accounts are fetched and displayed. This includes content sent to you by your followers or other third parties on those platforms. See Section 11 for further detail.
  • Post content and scheduled posts: the content you compose, schedule, and publish through the Service, including post text, captions, hashtags, links, scheduling times, and the images, videos, and other media you upload for those posts, together with the publishing status and metadata of each post. Where we cache a thumbnail or media preview for display in the app, we store only a pointer (a URL) to the file hosted by Zernio; we do not copy the underlying media into our own storage.
  • Published-post analytics: performance and engagement metrics for posts you have published through the Service to your connected accounts (e.g. views, impressions, likes, comments, shares, reach, and other statistics), as provided by the connected platform's API.
  • Media and content: files you upload (images, videos, documents) for posts or your profile.
  • Technical & usage data: anonymised IP address, browser type and version, operating system, pages visited, referral URLs, timestamps, error and crash reports, and usage events (e.g. feature interactions such as button clicks and page views, tracked via PostHog, see Sections 6 and 9). Usage tracking starts only after you give consent via the cookie banner.
  • Session replay data: with your consent (see Section 9), we record replays of your interactions with the Service (mouse movement, scrolling, clicks, page navigation) to diagnose usability problems and errors. Values you type into form fields are masked before recording. We are extending this masking to also cover other user-authored text shown on screen during a recording (for example post captions or inbox messages displayed as read-only text); until that work is complete, such text may appear in a recording in readable form. Recordings are automatically deleted after 30 days.
  • Billing data: Stripe, our payment processor, collects and holds your billing address and payment details when you subscribe. We ourselves store only a reference to your Stripe customer and subscription records (not your card details or billing address).
  • Marketing email preference: whether you have opted in to marketing and lifecycle emails, and when (see Section 4). This preference is opt-in only, it is never pre-selected on your behalf, and you can withdraw it at any time via the unsubscribe link in any such email or by contacting us at kontakt@ad2.app.
  • Feedback data: free-text feedback submitted via the in-app feedback form. This may incidentally contain personal data you choose to include.

We do not knowingly collect personal data from individuals under 18 years of age.

For information on which data fields are mandatory versus optional, see Section 8.

4. Legal Bases and Purposes of Processing

PurposeLegal basis (GDPR Art. 6)
Creating and managing your accountArt. 6(1)(b), performance of contract
Providing platform features (scheduling and publishing posts to your connected accounts, post analytics, inbox, the MCP integration for tools you authorize)Art. 6(1)(b), performance of contract
Processing social media data received via OAuth connections (profile/account data, post content and media you publish, published-post analytics, audience metrics, engagement data, video metadata, inbox messages)Art. 6(1)(b), performance of contract: necessary to deliver post scheduling and publishing, post analytics, and inbox features as contracted. Audience data is processed in aggregate and anonymised form only. No Art. 9 special category data is processed.
Temporary retention of account data for 30 days following account deletion (account recovery window)Art. 6(1)(f), legitimate interests: ad2app's and the user's shared interest in preventing irreversible accidental data loss, balanced against the minimal additional retention period. You may waive the window and request immediate permanent deletion at kontakt@ad2.app.
Processing payments and issuing invoices (via Stripe)Art. 6(1)(b) & Art. 6(1)(c), contract & legal obligation
Complying with legal obligations (tax, accounting, record-keeping)Art. 6(1)(c), legal obligation: Polish Accounting Act (Ustawa o rachunkowości), Tax Ordinance (Ordynacja podatkowa), VAT Act (Ustawa o VAT).
Processing in-app feedbackArt. 6(1)(f), legitimate interests: ad2app's interest in improving the Service through user feedback.
Improving and developing the Service (usage analytics, session replay, and error tracking via PostHog)Art. 6(1)(a), consent, given via the cookie consent banner and withdrawable at any time. No analytics events are captured and no analytics cookies are set before you make a choice. Supplemented by Art. 6(1)(f), legitimate interests, for aggregate, pseudonymised product statistics.
Security, fraud prevention, and abuse detectionArt. 6(1)(f), legitimate interests: ad2app's interest in maintaining platform integrity and protecting users from harm, which overrides the minimal intrusiveness of security logging.
Transfer of personal data in a merger, acquisition, or business asset saleArt. 6(1)(f), legitimate interests: ad2app's legitimate interest in completing lawful business restructuring, balanced against data subjects' interests. Data subjects will be notified before their data is subject to a materially different privacy policy.
Sending marketing and lifecycle emails (for example onboarding tips, feature announcements, and upgrade suggestions)Art. 6(1)(a), consent, given by an optional, affirmative opt-in choice that is never pre-selected on your behalf, and withdrawable at any time via the unsubscribe link included in every such email or by contacting us at kontakt@ad2.app. Withdrawal does not affect the lawfulness of prior processing. Transactional emails (account verification, security notices, billing receipts) are sent under Art. 6(1)(b) and are not affected by this preference.

Data Protection Impact Assessment (Art. 35 GDPR): We have assessed our processing activities against the criteria of Art. 35(1) GDPR and concluded that a full Data Protection Impact Assessment is not currently mandated. This assessment is documented under our Art. 5(2) accountability obligations and reviewed annually, and will be revisited if the nature or scope of our processing changes materially.

5. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes described in this policy, or as required by applicable law. Retention periods correspond to the processing purposes identified in Section 4:

  • Account data: for the duration of your account plus a 30-day recovery window after you delete it. During the window your account is deactivated and your data (profile, scheduled posts, drafts, settings, analytics history) is held solely so the account can be restored if the deletion was a mistake. After 30 days a scheduled job permanently and irreversibly purges it. You may request immediate permanent deletion, waiving the recovery window, by explicitly stating this in a request to kontakt@ad2.app.
  • What is immediate and irreversible even during the recovery window: when you delete your account, we immediately disconnect your connected social accounts and revoke the associated access at our publishing processor Zernio. This is not undone by recovering your account; if you restore your account within the 30 days, your ad2app data comes back but you must reconnect your social platforms yourself.
  • What account deletion does not do: deleting your ad2app account does not delete the posts you already published to your social media platforms; that content lives on those platforms under their terms, and you manage or delete it there. Our deletion and revocation requests to Zernio (including removal of the profile container Zernio maintains for your account) are sent immediately; if a request fails we retry it, so completion on Zernio's side can lag briefly behind your deletion. Separately, at the end of our overall relationship with Zernio, our data processing agreement requires them to delete all remaining copies within 10 business days of the cessation of services, with written certification of completion.
  • Post content, scheduled posts, and published-post analytics: retained for the duration of your account and deleted with your account data (subject to the 30-day recovery window above). Anonymised aggregated analytics may be retained indefinitely.
  • OAuth tokens: for platforms where Zernio holds your tokens on our behalf, disconnecting an account or deleting your ad2app account triggers an immediate disconnect and revocation request to Zernio (with retries on failure, as above). Any tokens we hold ourselves are deleted immediately on disconnect or account deletion, with no recovery window.
  • Inbox data (DMs and comments): retained for the duration of your account; deleted with your account data (subject to the 30-day recovery window).
  • Invoices and billing records: 5 years from the end of the fiscal year (Polish Accounting Act).
  • Technical logs: up to 90 days.
  • Product analytics events (PostHog): retained in pseudonymised form for the operation of our analytics; deleted within 30 days of an erasure request or consent withdrawal.
  • Session replay recordings (PostHog): 30 days, then automatically deleted.
  • Marketing consent records: we keep a record of when you gave or withdrew marketing-email consent for as long as your account exists plus 3 years, as evidence of compliance.
  • In-app feedback: up to 24 months from submission.

Data processed solely on the basis of consent (analytics cookies, marketing emails) is deleted or ceases to be processed within 30 days of consent withdrawal. Data processed for contractual performance is retained for the duration of the contract plus the applicable limitation period under Polish law (generally 3 years for commercial claims under Art. 118 of the Civil Code, or 6 years for documented claims). Data retained for legal obligation compliance follows the statutory schedule above.

6. Sharing of Personal Data

We do not sell your personal data. We may share it with:

  • Service providers (data processors), engaged under contractual terms that include data protection obligations. A signed Data Processing Agreement (Art. 28 GDPR) is in place with our publishing sub-processor (Zernio); we are finalising written terms for the remaining sub-processors where not yet bound by their standard online DPA:
    • Zernio (contracting entity: ARBICHAT, S.L., trading as “Zernio”, zernio.com), social media API aggregation and publishing: we pass OAuth tokens, post content, media files, and inbox data to Zernio solely to execute publishing and inbox operations on your behalf. The vendor is based in Girona, Spain (EEA); see Zernio's own privacy policy for details of the infrastructure it uses. We have a signed Data Processing Agreement with this vendor; to the extent Zernio processes data outside the EEA, such transfers are covered by Standard Contractual Clauses (Commission Decision 2021/914) under that agreement.
    • Stripe, payment processing: billing address and payment details are collected and held directly by Stripe; we share your email and account identifiers with Stripe to set up and manage your subscription. For processing your subscription payments on our behalf, Stripe acts as our data processor; for fraud prevention, anti-money-laundering checks, and its own regulatory compliance, Stripe acts as an independent data controller under its own privacy policy. Stripe is located in the United States and operates under the EU-US Data Privacy Framework.
    • PostHog (PostHog, Inc.), product analytics, session replay, and error tracking: usage event data (feature interactions, page views, device/browser info), masked session recordings, and error reports are processed only after you have given explicit analytics consent via the cookie banner. Some data we send is identifying rather than pseudonymised in specific cases (for example, transactional email delivery tracking uses your email address directly so we can tell whether an email reached you); we are reviewing which flows can be pseudonymised further. Our PostHog instance is PostHog Cloud EU, hosted in Frankfurt, Germany, analytics data is stored and processed within the EEA. PostHog, Inc. is incorporated in the United States; any residual access from outside the EEA is governed by a Data Processing Agreement incorporating Standard Contractual Clauses (Commission Decision 2021/914).
    • Resend, transactional and product email delivery: we use Resend to send account verification emails, onboarding and lifecycle emails, and to maintain the list of users eligible for those emails. Resend receives your email address, and where relevant your first name and the content of the email (which may include a verification or unsubscribe link). Under Resend's data processing terms, personal data held by Resend is deleted within 90 days after termination of our agreement with them. Resend is a company based in the United States; transfers are covered by Standard Contractual Clauses (Commission Decision 2021/914) or the EU-US Data Privacy Framework where applicable.
    • Vercel Inc.: backend API hosting and compute: server-side application code, API requests, and associated request logs are processed on Vercel's infrastructure. Vercel is located in the United States and transfers are covered by Standard Contractual Clauses (Commission Decision 2021/914).
    • Neon, LLC (an affiliate of Databricks, Inc.), PostgreSQL database hosting: all structured platform data (accounts, connected-account metadata, post content and scheduling metadata) is stored in a Neon-hosted PostgreSQL database operated under the Databricks Master Cloud Services Agreement and the Databricks Privacy Notice. Neon, LLC and Databricks, Inc. are companies incorporated in the United States; whether the database contents leave the EEA depends on the hosting region of our database instance, which we are confirming. To the extent data is processed outside the EEA, transfers are covered by Standard Contractual Clauses (Commission Decision 2021/914).
    • Google Firebase (Firebase Authentication): authentication token verification: authentication tokens issued to users may be verified against Firebase Authentication to validate active sessions. Firebase is a Google service located in the United States and operates under the EU–US Data Privacy Framework.
    • A current list of sub-processors (including names, countries of processing, and applicable transfer safeguards) is available on request at kontakt@ad2.app.
  • Third-party tools you authorize: see Section 6a. These tools are recipients acting on your instruction, not our sub-processors.
  • Legal authorities: where required by law, court order, or to protect the rights and safety of ad2app or third parties.
  • Business transfers: in the event of a merger, acquisition, or sale of assets, personal data may be transferred under Art. 6(1)(f). You will be notified before it becomes subject to a different privacy policy.

6a. Third-Party Integrations You Authorize (MCP)

The Service includes an MCP (Model Context Protocol) server, operated by us as part of the Service, that lets you use ad2app from inside a third-party AI assistant or tool of your choice (for example an AI chat application or a code editor that supports MCP).

These tools are yours, not ours. When you connect one, it acts on your instruction, the same way your own browser does when you use the app directly. We do not select, engage, or control these tools, and they are not our sub-processors. What a tool does with data after retrieving it on your behalf is governed by that tool's own terms and privacy practices, which you should review before connecting it.

How authorization works

Before any access is granted, we show you a consent screen naming the tool and the access it requests. Nothing is shared until you approve. If you approve, our server issues that tool a grant that is enforced on our side: every request the tool makes is checked against what you approved, and the tool can act only within that grant. Depending on the access you approved, a connected tool can list your connected social accounts, create, view, update, cancel, or retry scheduled posts, read post and account analytics, and prepare media uploads, in each case on your behalf and within your own account only.

Revoking access

You can revoke a connected tool's access at any time by contacting us at kontakt@ad2.app; we are adding a self-serve revocation control in your account settings. Revocation immediately invalidates the grant our server issued to that tool; it cannot make further requests. Revocation does not reach back into data the tool already retrieved while authorized; removing that is a matter for the tool itself.

7. International Data Transfers

Your data is primarily processed within the European Economic Area (EEA). Product analytics data (PostHog) is stored and processed on EU servers in Frankfurt, Germany. We use certain processors incorporated outside the EEA or using non-EEA infrastructure, including United States companies (currently: Vercel, Neon (Neon, LLC, an affiliate of Databricks, Inc.), Google Firebase, Stripe, and Resend, plus residual support access by PostHog, Inc.); for Zernio (an EEA company) and Neon, we are confirming the infrastructure and hosting regions involved. For all transfers outside the EEA we ensure adequate safeguards through one or more of the following mechanisms:

  • the EU–US Data Privacy Framework (Commission Implementing Decision 2023/1795) where the recipient is certified;
  • EU Standard Contractual Clauses (SCCs, Commission Decision 2021/914) supplemented by Transfer Impact Assessments confirming equivalent protection in the destination country; or
  • an adequacy decision by the European Commission covering the recipient country.

For Zernio specifically, our data processing agreement requires our prior written consent for any transfer outside the EEA and relies on Standard Contractual Clauses (Commission Decision 2021/914) where such a transfer occurs; Zernio's own internal security documentation references processing certain workloads in North America, which we are confirming operationally.

If you connect a third-party tool via MCP (Section 6a), any transfer of data to that tool happens at your instruction and under that tool's own terms; the safeguards above apply to our processors, not to tools you choose to connect.

You may request copies of applicable SCCs or a summary of our Transfer Impact Assessment findings at kontakt@ad2.app.

8. Your Rights Under GDPR

As a data subject, you have the following rights under the GDPR (Articles 15–22 and Art. 77). To exercise any of these rights, contact us at kontakt@ad2.app. We will respond within 30 days (extendable by a further 60 days for complex requests, with notice). Where we decline to act on a request, we will inform you of the reasons within the same period, along with your right to lodge a complaint with UODO (see Section 12) and your right to seek a judicial remedy.

  • Right of access (Art. 15): obtain a copy of the personal data we hold about you and information about how it is processed.
  • Right to rectification (Art. 16): request correction of inaccurate or incomplete personal data.
  • Right to erasure (Art. 17): request deletion of your personal data where there is no overriding legal basis for continued processing. When you delete your account, your data is held in a deactivated state for 30 days so an accidental deletion can be reversed, then permanently purged; your connected social accounts are disconnected and access revoked immediately, and that part is not reversible. You may request immediate permanent deletion, waiving the recovery window, by explicitly stating this in your request.
  • Right to restriction (Art. 18): request that we limit the processing of your data in certain circumstances.
  • Right to data portability (Art. 20): receive your data in a structured, machine-readable format and transmit it to another controller, where technically feasible.
  • Right to object (Art. 21): object to processing based on legitimate interests. We will cease unless we demonstrate compelling legitimate grounds.
  • Right to withdraw consent (Art. 7(3)): where processing is based on your consent (analytics cookies, marketing emails), you may withdraw it at any time without affecting the lawfulness of prior processing. Marketing-email consent can be withdrawn at any time via the unsubscribe link in any marketing email or by contacting us at kontakt@ad2.app.
  • Automated decision-making (Art. 22): we do not make any decision producing legal or similarly significant effects concerning you based solely on automated processing.
  • Right to lodge a complaint (Art. 77): you have the right to lodge a complaint with the Polish supervisory authority, Urząd Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa, https://uodo.gov.pl, if you believe we are processing your personal data in violation of the GDPR.

Mandatory vs. optional data: Providing certain personal data (email address, name, account credentials) is a contractual requirement for accessing the Service, without it, we cannot create or maintain your account. Other fields (such as phone number) are voluntary. Connecting social media accounts via OAuth is optional but required to access publishing, analytics, and inbox features. Marketing-email consent is entirely optional and never a condition of using the Service.

9. Cookies, Local Storage, and Tracking Technologies

We use cookies, browser local storage, and similar technologies to operate the Service and improve your experience.

  • Strictly necessary cookies: required for authentication sessions and core platform functionality. Cannot be disabled without breaking the Service. Legal basis: Art. 6(1)(b), contract performance; no consent required. Duration: session cookies expire when you close your browser; authentication cookies expire after 30 days of inactivity.
  • Functional cookies: set only in direct response to an action you take (e.g. selecting a language or theme preference), and strictly necessary to deliver that specific function you have requested. They do not track you across sessions beyond preserving your chosen setting. Legal basis: strictly necessary to fulfil your explicit request under Art. 173 of the Polish Telecommunications Act (ePrivacy); no separate consent required. Duration: up to 12 months, or cleared when you clear your browser data.
  • Analytics cookies (PostHog): collect usage event data in pseudonymised form (other than the identifying flows described in Section 6), enable session replay (with form-field values masked; see Section 3), and capture error reports to help us understand and improve how the Service is used. Legal basis: Art. 6(1)(a), consent. No analytics cookies are set and no analytics events are captured before you make a choice in the cookie consent banner shown on first visit. If you accept, PostHog sets a first-party cookie (name beginning ph_) on the ad2.app domain, valid for up to 1 year, shared between our website and the app so you are not asked twice. If you decline, no analytics cookie is set and no events are collected. Analytics data is processed on PostHog Cloud EU servers in Frankfurt, Germany (see Section 6).

You may withdraw or update your cookie consent at any time via the "Cookie settings" link in the footer of our website, or on this Privacy Policy page in the app. Withdrawing analytics consent does not affect platform functionality.

Browser local storage

In addition to cookies, we use browser local storage to preserve application state between sessions. This includes: your language and theme preferences; a cached copy of your subscription tier and status (retained for up to 30 days then invalidated); and draft campaign deadline data. Local storage data is stored on your device only and is not transmitted to our servers independently of your normal usage. It is cleared when you clear your browser data or log out.

10. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction, in accordance with Art. 32 GDPR:

  • Encryption in transit (TLS 1.2+) on every connection, enforced by our hosting and database providers.
  • Hashed storage of passwords using bcrypt with appropriate cost factors. Where you sign in with Google, we never receive a password at all.
  • OAuth tokens we hold directly are encrypted at rest (AES via a server-side key that is never stored beside the data); tokens held by our publishing processor Zernio are subject to Zernio's own security measures under our Data Processing Agreement
  • Server-enforced access grants for third-party tools you authorize via MCP (Section 6a): every request is checked against the access you approved, and grants are individually revocable.
  • Access to production systems is limited to the two people who operate ad2app, each through their own provider account. Every request to a protected part of the Service is authenticated and checked against the account making it, request rates are limited to blunt automated abuse, all input is validated at the API boundary, and our cross-origin policy fails closed, so an unlisted origin is refused rather than allowed. We do not keep a separate application-level audit log of staff access; the logs kept by our hosting, database and payment providers are what we rely on.
  • Pseudonymisation of analytics and usage data where technically feasible, and masking of text in session recordings, so message and comment bodies are not captured (see Section 3).
  • Automated dependency vulnerability scanning; secret scanning before any code is committed; a required review of every change by a second person before it reaches production; and automated test, type and database-schema checks that must pass before a deploy. Our deploy also refuses to build if a required configuration secret is missing, so a misconfigured environment cannot silently reach production. We do not commission external penetration tests. For a two-person company we judge that proportionate to the risk under Art. 32 GDPR, and we will update this page if that changes.
  • Incident detection, response, and escalation procedures, including UODO notification within 72 hours of a qualifying breach under Art. 33 GDPR, and notification to affected data subjects where required under Art. 34 GDPR.
  • Our database provider takes continuous backups with point-in-time recovery, which is what a restore would use, and deleted accounts are held for 30 days before being purged so an accidental deletion can be undone. We have not yet run a full restore drill, so we do not claim a tested recovery time.

11. Third-Party Links, Social Platforms, and Inbox Data

The Service allows you to connect the social media accounts you choose to enable platform features. Supported platforms currently include Instagram, TikTok, X (Twitter), YouTube, LinkedIn, Facebook, Threads, Pinterest, Reddit, and Bluesky. When you authorise an OAuth connection, ad2app receives data from that platform's API as permitted by your OAuth consent screen. The source of all such data is the respective social media platform's API.

Inbox data and third-party communications: when you use the inbox features, direct message conversations and post comments from your connected social media accounts are fetched and stored. This includes messages and comments sent by your followers and other third parties on those platforms. Some of this data (for example public post comments) originates from publicly accessible sources on the connected platform; direct messages do not. Those individuals have not directly provided their data to ad2app. We process this data under Art. 6(1)(b) (to provide the inbox feature you have contracted for) and rely on the exemption in Art. 14(5)(b) GDPR: providing individual notice to each such person would require disproportionate effort given the volume and platform-derived nature of the data. In line with Art. 14(5)(b), and having regard to the number of individuals concerned, the age of the data, and the safeguards applied, we take appropriate measures to protect these individuals' rights, freedoms, and legitimate interests, including by making this information publicly available in this policy and by handling any rights request from such a person received at kontakt@ad2.app; our balancing assessment is documented in our Record of Processing Activities (Art. 30 GDPR). Inbox data is not used for profiling, advertising, or any purpose beyond displaying your social media communications within the platform.

Audience data (Art. 14 GDPR): when you connect a social media account, the connected platform may provide aggregate audience data (e.g. demographic statistics about your followers). This data originates from the social platform and relates to individuals who are not in a direct relationship with ad2app. It is processed solely as anonymous, aggregate statistics and does not identify any individual; it is therefore not personal data within the meaning of the GDPR (Recital 26) and Art. 14 does not apply to it. Insofar as any element of this data were nevertheless treated as personal data, we would rely on the exemption in Art. 14(5)(b) GDPR (disproportionate effort) and discharge our obligation by making this information publicly available in this policy. Audience data is not used for any other purpose.

We are not responsible for the privacy practices of third-party social platforms. Please review their privacy policies before connecting your accounts.

12. Supervisory Authority

You have the right to lodge a complaint with the Polish data protection supervisory authority (Art. 77 GDPR) if you believe we have violated your rights:

Urząd Ochrony Danych Osobowych (UODO)
ul. Stawki 2, 00-193 Warszawa, Poland
https://uodo.gov.pl

13. Changes to This Policy

We may update this Privacy Policy from time to time. Where changes are material, we will notify you by email or by a prominent notice within the Service at least 14 days before the changes take effect. The "Last updated" date at the top of this page always reflects the most recent version.

Previous versions of this Privacy Policy are available on request at kontakt@ad2.app. A changelog summarising material amendments is maintained internally and available to supervisory authorities on request.

14. Contact

For any questions, requests, or concerns regarding this Privacy Policy or your personal data, please contact us at:

Ad2app sp. z o.o.
ul. Juliana Smulikowskiego 4A/21, 00-389 Warszawa, Poland
NIP: 5253042936
KRS: 0001168159
Email: kontakt@ad2.app