At AdsLuma (ADSERA Bilişim ve Yazılım Hizmetleri Limited Şirketi), we treat user privacy as a top priority. This Privacy Policy explains what data we collect, how we store it, with whom we share it, and your rights when using the AdsLuma platform.
1. Data We Collect
We collect data in the following categories:
- Account data: Name, surname, email, phone, company name, hashed password.
- Platform integration data: Campaign, performance and analytics data fetched from your Google Ads, Meta Marketing, GA4 and Search Console accounts.
- Usage data: In-app navigation, clicks, report generation, AI queries.
- Technical data: IP address, browser type, device info, session IDs (via cookies).
- Content data: Your brand brief, content drafts, AI chat history, uploaded images.
2. How We Use Your Data
- Provide core platform services (dashboards, analytics, AI Copilot, content generation).
- Manage your account and session security.
- Calculate and visualize your performance metrics.
- Generate AI-driven recommendations, insights and content (your data is NOT used for model training).
- Improve service quality, detect bugs.
- Comply with legal obligations (KVKK, GDPR, tax law).
3. Data Sharing
We never sell your data. We only share data with third parties in these cases:
- AI providers: Anthropic (Claude), Google (Gemini), FAL (image generation) — only request-specific context, no training.
- Payment processor: Stripe (subscription info only).
- Infrastructure: Cloudflare (CDN/DNS), Cloudflare R2 (file storage), hosting provider.
- Legal requirement: Upon court order or competent authority request.
4. Google API Services User Data Policy
AdsLuma integrates with Google services (Google Analytics 4, Google Search Console, and Google Ads) through Google's official APIs. This section explains how we handle data received from Google APIs.
What we access. When you connect your Google account to AdsLuma, we request the following permissions, each only with your explicit OAuth consent:
- Google Analytics (
analytics.readonly): read-only access to the Google Analytics 4 properties you select, in order to retrieve reporting and performance data. - Google Search Console (
webmasters.readonly): read-only access to the verified sites you select, in order to retrieve search performance data (queries, clicks, impressions, positions). - Google Ads (
adwords): access to the Google Ads accounts you select, used solely to retrieve campaign structure, metrics, and performance reports for the accounts you connect.
How we use it.Data received from Google APIs is used exclusively to provide AdsLuma's core features to you: displaying your dashboards, generating reports, and producing AI-assisted insights about your own accounts. We do not use Google user data for advertising or ad targeting, we do not sell it, and we do not use it to build profiles unrelated to the service you requested.
Limited Use disclosure. AdsLuma's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
AI processing.Where you use AdsLuma's AI-assisted features, relevant portions of your Google user data may be processed by our AI service providers strictly on a per-request basis, solely to generate the analysis or insight you requested. Google user data is not used to train AI models, whether ours or our providers'. Human access to this data does not occur except with your explicit consent, for security purposes, to comply with applicable law, or as part of aggregated and anonymized internal operations.
Storage and security. OAuth tokens obtained from Google are stored encrypted (AES-256-GCM) and are never logged in plain text. All Google user data is stored in tenant-isolated form and retained only for as long as your integration remains connected.
Revoking access and deletion. You may disconnect your Google account from AdsLuma at any time from your integration settings, or revoke AdsLuma's access directly through your Google Account permissions page at myaccount.google.com/permissions. Upon disconnection or account deletion, associated Google user data is deleted from our systems within 30 days, except where retention is required by law.
5. Data from Meta Platforms
AdsLuma integrates with Meta advertising services (Facebook and Instagram) through Meta's official Marketing API. This section explains how we handle data received from Meta Platforms.
What we access. When you connect your Meta ad accounts to AdsLuma, we request access permissions (such as ads_read) only with your explicit authorization through Meta's login and consent flow. We access advertising data related to the ad accounts you select — including campaign structure, performance metrics, spend, and audience-level aggregated statistics. We do not access your personal profile content, private messages, or data belonging to accounts you have not connected.
How we use it.Data received from Meta Platforms is used exclusively to provide AdsLuma's core features to you: displaying your dashboards, generating reports, and producing AI-assisted insights about your own ad accounts. We do not sell Meta platform data, we do not share it with third parties for their own purposes, and we do not use it for advertising or ad targeting outside the service you requested.
AI processing.Where you use AdsLuma's AI-assisted features, relevant portions of your Meta advertising data may be processed by our AI service providers strictly on a per-request basis, solely to generate the analysis or insight you requested. Meta platform data is not used to train AI models, whether ours or our providers'.
Storage and security. Access tokens obtained from Meta are stored encrypted (AES-256-GCM) and are never logged in plain text. All Meta platform data is stored in tenant-isolated form and retained only for as long as your integration remains connected.
Platform Terms compliance. AdsLuma's use and transfer of information received from Meta APIs will adhere to the Meta Platform Terms and applicable Meta Developer Policies.
Revoking access and deletion. You may disconnect your Meta account from AdsLuma at any time from your integration settings, or remove AdsLuma's access directly through your Facebook account settings under Business Integrations. Upon disconnection or account deletion, associated Meta platform data is deleted from our systems within 30 days, except where retention is required by law. To request deletion of your data, you may also contact us at the address in the Contact section; deletion requests are honored within 30 days.
Use of Google User Data
When a user connects their Google account to our platform, we access the following data within the scope of the permissions granted:
- Google Ads: campaign structure, ad spend, performance and conversion metrics
- Google Analytics: website traffic and conversion data
- Google Merchant Center: account information, product listings, product feed status and disapproved product records
We process this data solely to provide reporting, analysis and error detection services to the user. Our platform is read-only; it does not create, edit or delete any campaigns, product data or account settings.
Adsluma's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We do not use this data for serving advertisements
- We do not sell or transfer this data to third parties
- We do not allow humans to read this data, except with the user's explicit consent, for security purposes, to comply with applicable law, or where necessary to operate the service
- We delete the relevant data when a user disconnects their account
6. Cookies
AdsLuma uses only necessary and functional cookies:
- Session cookie (
adsluma_session) — to maintain your login session. - CSRF token — form security.
- Preference cookies — language, date range, saved views.
We do not use marketing or third-party advertising cookies.
7. Data Retention
- Account data: Active duration + 90 days (after deletion request).
- Platform integration data: As long as account is connected; deleted within 30 days after account removal.
- AI chat history: Until you delete (default auto-archive after 12 months).
- Audit logs: 6 months (some legal records kept longer).
8. Security Measures
- All traffic encrypted via HTTPS (TLS 1.3).
- Passwords hashed with bcrypt, never stored as plaintext.
- Platform OAuth tokens stored with AES-256-GCM encryption.
- Multi-tenant isolation: every query is tenant-scoped.
- AI responses post-filtered against cross-tenant data leakage.
- Regular security audits (OWASP Top 10 + LLM Top 10).
9. Your Rights (KVKK Art. 11 / GDPR)
- Access and obtain a copy of your data,
- Request correction of inaccurate or incomplete data,
- Request deletion or destruction of data (account closure),
- Object to data processing,
- Request processing restriction,
- Request data portability to another service provider.
To exercise these rights, contact [email protected]. Response within 30 days.
10. Children's Privacy
AdsLuma is not intended for users under 18. We do not knowingly collect personal data from individuals under 18.
11. Policy Updates
This Privacy Policy may be updated from time to time. Significant changes will be communicated via email or in-app notification. Last update date is shown above.
12. Contact
- Email: [email protected]
- Address: Maslak Mah. AOS 55. Sk. 42 Maslak B Blok No:4 Int. Door No: 542 Sarıyer / Istanbul
- Phone: +90 850 304 37 10
For the detailed KVKK notice, see our KVKK page.