This Privacy Policy explains how Generads ("Generads", "we", "us", or "our") collects, uses, shares, and protects personal information when you use the Generads platform at https://generads.ai and its related applications, APIs, and services (together, the "Service"). Generads is an AI creative platform that helps ecommerce brands generate ad creatives, emails, landing pages, and related marketing content.
Please read this policy alongside our Terms of Service. By using the Service you agree to the practices described here. Where the Service is offered to organisations, the organisation's agreement with us also governs how we handle data on its behalf.
1. Who We Are and Contact Details
The entity responsible for the Service is Generads (the "operator"). You can reach us at:
- Product name: Generads
- Privacy contact email: privacy@generads.ai
- Website: https://generads.ai
- Location: Australia. Our full registered postal address is available on request.
For personal data of users in our own products, Generads generally acts as the data controller. For end-customer data that flows through a connected platform (for example, a brand's own Klaviyo account), Generads generally acts as a data processor / service provider on behalf of that brand. See Section 20 for details. Where an EU/UK representative or Data Protection Officer is required by law and appointed, their contact details will be made available; until then, direct all privacy enquiries to privacy@generads.ai.
2. Scope of This Policy
This policy covers all personal information processed through the Generads Service, including our website, web application, and backend functions. It applies to two groups of data subjects:
- Account users: the people who sign up for and use Generads (founders, marketers, agency staff, invited team members).
- End-customers and contacts: the individuals whose personal data flows through platforms a user connects to Generads (for example, customer profiles, list members, and engagement events inside a connected Klaviyo account). This data belongs to the connecting brand; we process it on that brand's instructions.
This policy does not govern third-party websites, platforms, or services that you connect to or visit, which have their own privacy policies.
3. Categories of Personal Information We Collect
We collect only the information needed to operate the Service. The categories below also map to the statutory categories used under the California Consumer Privacy Act ("CCPA"/"CPRA").
3.1 Account and authentication identity
Email address, full name, nickname, contact email, timezone, email-verified flag, your role and admin status, and your Supabase user ID. Passwords and password-reset flows are handled by our authentication provider (Supabase Auth); we do not store your password ourselves. Your email is the primary identifier and is also written into audit logs and team invitations. CCPA category: identifiers.
3.2 Brand identity and marketing context
Brand name, tone, logo URL, colour palette, compliance rules (must-say / never-say), your AI brand-interview answers stored as a "Brand Context Vault", and any markdown brand documents you upload. CCPA categories: identifiers; commercial information.
3.3 Products and catalogue data
Product names, descriptions, types, tags, variants, prices, images, and AI-enriched marketing fields (pain points, personas, hooks, reviews, claims). CCPA category: commercial information.
3.4 Uploaded images and screenshots
Ad-creative template uploads, email header/footer screenshots, reference images for image generation, and brand/product images. These are stored in our cloud storage buckets. CCPA category: commercial information; visual information you choose to upload.
3.5 Generated creatives, emails, landing pages, and chat
AI-generated images and ad creatives, generated emails, generated landing pages and suggestions, and your brainstorm/help chat messages. CCPA categories: commercial information; user-generated content.
3.6 Voice and audio recordings
Browser-recorded audio you submit when you use voice prompting. Audio is used for speech-to-text transcription; the cleaned transcript is returned to you. CCPA category: audio information.
3.7 Competitor and external website content
Competitor brand/keyword search strings and country filters you enter for ad research, and any website URL you (or we, for onboarding) ask us to analyse, including scraped page HTML, summaries, branding colours, and full-page screenshots of that site. CCPA categories: commercial information; internet activity.
3.8 Klaviyo connection data
When you connect a Klaviyo account, we store per-brand OAuth access tokens, refresh tokens, expiry, and granted scopes. Through these tokens we may read and write your Klaviyo profiles, lists, segments, events, campaigns, and templates. See Section 12 for full detail. CCPA categories: identifiers; commercial information; internet activity (end-customer data within your Klaviyo account).
3.9 Audit logs and activity metadata
Action records (action type, user ID, user name, target email, and details such as brand, entity, status, and model), cost/usage tracking, storage metering, and scheduled-generation history. CCPA categories: identifiers; internet/usage activity.
3.10 Team and agency membership and invitations
Invitee email addresses, assigned roles, and the inviter's ID, stored in-app to manage team and agency membership. CCPA category: identifiers.
3.11 Error, diagnostic, and session-replay data
Frontend exceptions, breadcrumbs, performance traces, backend exception messages and stack traces, and, on error, a session replay of the screens you were viewing. Please note that our session replay is currently unmasked, so on-screen content (including content visible in the app at the time of an error) can be captured. User context attached to errors is limited to your user ID, and your email is scrubbed from breadcrumbs. CCPA categories: internet/usage activity; technical/diagnostic information.
3.12 Network and technical identifiers
Your IP address, request headers, and authentication token are transmitted at the network/transport layer to every service that handles your requests (our hosting and the AI and research providers listed in Section 7) as a standard part of serving requests. We do not maintain a dedicated application-level IP-logging table. CCPA category: internet activity; identifiers.
We do not collect government identifiers, biometric identifiers, precise geolocation, payment-card data, or special categories of data as a designed feature of the Service.
4. Sources of the Data
We obtain personal information from the following sources:
- Directly from you: when you register, complete your profile, build a brand, add products, upload images, type or speak prompts, run searches, and chat in the app.
- From connected platforms: when you connect Klaviyo, we receive data from your Klaviyo account (profiles, lists, segments, events, campaigns, templates) via OAuth.
- From integrations and partners: our AI and research subprocessors (Section 7) return generated content, transcripts, analyses, and scraped data that we store.
- From publicly available sources: public website content we scrape at your request (your own or a pasted URL) and public competitor advertising data from the Meta Ad Library (via our ad-research providers).
- Automatically: technical and diagnostic data generated as you use the Service (Sections 3.11 and 3.12).
Where we obtain personal data about an individual from a source other than that individual (for example, end-customer data inside a connected Klaviyo account, or individuals named in scraped or public advertising content), the source is the connecting brand's platform or the public source described above. We process such data on behalf of the connecting brand.
5. How We Use Your Information and Our Legal Basis
We use personal information for the purposes below. For users in the EEA/UK, the GDPR legal basis for each purpose is stated.
- Account creation, login, profiles, and role-based access — to provide the Service you signed up for. Legal basis: performance of a contract.
- Generating creatives, ad copy, emails, landing pages, and chat responses — the core function of the Service; this requires sending your brand context, product details, prompts, and uploaded images to AI providers (see Section 6). Legal basis: performance of a contract.
- Brand auto-setup and context ranking — analysing your brand interview, uploaded documents, and (at your request) your website to keep outputs on-brand. Legal basis: performance of a contract.
- Voice transcription — converting voice prompts to text. Legal basis: performance of a contract.
- Ad-spy / competitor research — running the searches you request against public ad libraries. Legal basis: performance of a contract; our legitimate interest in providing research tools.
- Klaviyo integration — connecting your Klaviyo account and pushing/reading templates, campaigns, lists, profiles, and events at your direction. Legal basis: performance of a contract; consent given via the OAuth authorisation.
- Team and agency management — inviting and managing members. Legal basis: performance of a contract; our legitimate interest in collaboration features.
- Audit logging, cost and storage metering, and scheduling history — operating, securing, and accurately accounting for the Service. Legal basis: legitimate interests; legal obligation where applicable.
- Error monitoring, debugging, and session replay — keeping the Service reliable and fixing faults. Legal basis: legitimate interests.
- Security, fraud prevention, and abuse detection — protecting users and the Service. Legal basis: legitimate interests; legal obligation.
- Service communications and, where applicable, marketing — administering your account and, with consent where required, sending product updates. Legal basis: legitimate interests for service messages; consent for marketing where required.
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may object to such processing (see Section 10). For CCPA purposes, the "business or commercial purpose" for each category corresponds to the purposes above: providing and personalising the Service, generating creative output, integrating with platforms you connect, securing and auditing the Service, debugging, and meeting legal obligations.
6. AI Processing Disclosure
Generads is an AI platform. To produce the outputs you ask for, we send your content to third-party AI providers. Specifically, the following are transmitted to one or more AI subprocessors listed in Section 7:
- Prompts and chat messages you type or speak.
- Brand context, including your brand interview answers, brand context vault, uploaded brand documents, and brand compliance rules.
- Product details and AI-enriched marketing fields.
- Uploaded and reference images, including product images, brand images, ad-creative templates, and email header/footer screenshots, which are sent for vision analysis and as reference images for image generation.
- Voice audio, which is sent for speech-to-text transcription.
- Website content we scrape at your request, which may be sent to an AI provider for summarisation and ranking.
You should avoid placing personal data into prompts, documents, or images that is not necessary for generating your marketing content. The AI providers process this data to return outputs to us; the providers' own terms and privacy practices apply to their handling.
7. How We Share Data and Our Subprocessors
We do not sell your personal information. We share data only with the service providers / subprocessors below, who process it on our behalf to deliver the Service, and where required by law. The list below is the complete set of subprocessors used.
7.1 Subprocessor list
- Supabase — core backend: account authentication, application database, file storage, and the edge functions where generation and scraping run. Receives essentially all personal and customer data: account identity, brand/product data, uploaded images, generated outputs, Klaviyo tokens, audit logs, voice-audio passthrough, and IP/authentication data at the transport layer.
- Anthropic (Claude API) — text and vision generation and brand-context summarisation/ranking. Receives brand context, uploaded brand documents, product details, brand-interview answers, pasted-link content, email screenshots (vision), and prompts.
- OpenRouter — routing to text and vision models for template analysis, brainstorm/help chat, prompt enhancement, and branding extraction. Receives uploaded template image URLs (vision), brand/product context, chat messages, prompts, and scraped branding content.
- OpenAI — high-quality image generation/editing and voice transcription (Whisper). Receives image prompts and reference images (including your uploaded product/brand images) and raw voice audio.
- Google AI (Gemini API) — standard-quality image generation. Receives image prompts (including brand-compliance and brand-vault text) and reference images.
- xAI (Grok API) — generating landing-page suggestions. Receives brand/product context used to suggest landing pages.
- Firecrawl — scraping a website you provide for branding, screenshot, summary, and HTML during brand setup and onboarding. Receives the target website URL and returns page content that we then store/process.
- ScrapeCreators — primary ad-research provider that scrapes the public Meta Ad Library for competitor ads and advertiser typeahead. Receives your competitor search query and country/status filters. No account personal information is sent.
- Meta / Facebook (Ad Library Graph API) — fallback ad-research provider and Ad Library deep links. Receives your search query and country/status filters. No account personal information is sent.
- Klaviyo — per-brand email marketing integration via OAuth (see Section 12). Receives the OAuth authorisation exchange; we in turn receive access to the connected account's profile, list, segment, event, campaign, and template data.
- Sentry — error monitoring, performance tracing, and on-error session replay. Receives exception messages and stack traces, breadcrumbs, performance traces, your user ID (email scrubbed from breadcrumbs), and unmasked session replays that can capture visible on-screen content.
We may also disclose personal information to professional advisers, to comply with law or legal process, to enforce our terms, to protect rights and safety, and to a successor entity in connection with a merger, acquisition, or sale of assets.
7.2 CCPA disclosure categories
In the preceding 12 months we have disclosed the categories of personal information described in Section 3 to the service providers above for the business purposes described in Section 5. We have not sold personal information and have not shared personal information for cross-context behavioural advertising. The categories of third parties that receive personal information are: cloud hosting and backend providers, AI/machine-learning providers, web-scraping and ad-research providers, marketing-platform integrations, and error-monitoring providers.
8. International Data Transfers
Generads and several of our subprocessors operate in the United States and other countries outside the EEA and the UK. Using the Service therefore involves transferring your personal data to those countries, which may not provide the same level of protection as your home jurisdiction.
Where we transfer personal data out of the EEA or UK, we rely on an appropriate safeguard, such as the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), or an adequacy decision where one applies. We choose subprocessors that offer appropriate protections for the data they handle on our behalf, and each transfer to those providers is covered by these safeguards. You may request a copy of the relevant safeguard by contacting privacy@generads.ai.
9. Data Retention
We retain personal information for as long as your account is active and as needed to provide the Service, then for the periods below:
- Account, brand, product, generated content, and uploaded files — retained while your account is active and deleted or anonymised within a reasonable period after account closure, unless we must keep them longer for legal, accounting, or security reasons.
- Voice audio — used transiently for transcription; we retain the transcript, not a long-term store of the raw audio, beyond what is needed to deliver the result.
- Klaviyo OAuth tokens — retained only while the integration is connected; destroyed on disconnect, uninstall, or account deletion (see Section 12).
- Audit, access, change, and usage logs — retained for security, accountability, and integration-compliance purposes, generally for at least 365 days, after which they are deleted or anonymised.
- Error and diagnostic data — retained for our error-monitoring provider's standard retention period and then purged.
Where exact periods are not fixed, we determine retention based on the purpose for which the data was collected, the need to provide the Service, and applicable legal, regulatory, and security requirements.
10. Your Rights
10.1 GDPR / UK GDPR rights
If you are in the EEA or UK, you have the right to: access your personal data; rectify inaccurate data; erase data ("right to be forgotten"); restrict processing; data portability; object to processing based on legitimate interests; withdraw consent where processing is based on consent; and lodge a complaint with your supervisory authority.
10.2 CCPA / CPRA rights (California residents)
If you are a California resident, you have the right to: know the categories and specific pieces of personal information we collect, use, and disclose; delete personal information we hold about you; correct inaccurate personal information; opt out of the sale or sharing of personal information; limit the use of sensitive personal information; and to not be discriminated against for exercising your rights. As stated in Section 7, we do not sell or share personal information for cross-context behavioural advertising and do not use sensitive personal information for purposes that would trigger the right to limit.
10.3 End-customer data
Where we process end-customer data on behalf of a connecting brand (for example, Klaviyo data), we act as a processor/service provider. We will refer requests from those end-customers to the relevant brand and will assist that brand in responding, including by honouring deletion requests across the connected account.
11. How to Submit Requests and Verification
You can exercise your rights using either of these methods:
- Email: privacy@generads.ai
- In-app: using the account and privacy controls within the Generads application.
To protect your data, we will verify your identity before acting on a request, typically by confirming control of the email address associated with your account and asking for information that matches our records. You may use an authorised agent to submit a request on your behalf; we may require proof of the agent's authority and verification of your identity.
We aim to acknowledge requests promptly and to respond within the timeframes required by applicable law (generally within 30 days under the GDPR, extendable where permitted, and within 45 days under the CCPA, extendable by a further 45 days with notice). We do not charge a fee for most requests, except as permitted by law for manifestly unfounded or excessive requests.
12. Klaviyo Integration
Generads offers an optional Klaviyo integration. Connecting Klaviyo is entirely at your choice.
12.1 What connecting Klaviyo does
When you connect Klaviyo, you authorise Generads through Klaviyo's OAuth 2.0 (PKCE) flow. Klaviyo issues us an access token and refresh token scoped to your account. These tokens grant Generads access to your Klaviyo account so we can read and write marketing data on your behalf.
12.2 What we read and write, mapped to scopes
We request the least-permissive set of OAuth scopes needed for the integration. Depending on the features you use, this includes:
- accounts:read — required by default; reads account metadata to identify the connected account.
- profiles (read/write) — reads and writes customer/contact profile records, which include personal data such as names, emails, phone numbers, and addresses.
- lists / segments (read/write) — reads and manages list and segment membership.
- events (read/write) — reads and writes engagement and behavioural events (such as opens, clicks, and purchases).
- campaigns / templates (read/write) — reads and pushes email templates and campaigns.
- flows / tags (read) — reads flow and tag metadata where needed for the relevant feature.
Through these scopes, Generads processes end-customer personal data belonging to your Klaviyo account (profile/contact records, list and segment membership, event/engagement data, campaign and flow data, and account metadata). For this data we act as a processor/service provider on your behalf, and you remain the controller of your customers' data.
12.3 How tokens are stored
Klaviyo OAuth tokens are stored securely on the backend with service-role access only and are never exposed to the browser/client. Tokens are held encrypted at rest, access tokens expire and are refreshed as needed, and credentials are not hardcoded.
12.4 How to disconnect and revoke
You can disconnect Klaviyo at any time from within Generads. Disconnecting from either side (Generads or Klaviyo) revokes the connection on both ends: we revoke and destroy the stored access and refresh tokens, and we delete or anonymise synced Klaviyo data that we no longer need. To honour erasure of end-customers across a connected account, deletion requests can be processed through Klaviyo's Data Privacy API. To request deletion of Klaviyo-related data we hold, contact privacy@generads.ai.
13. Sale / Sharing Opt-Out
Generads does not sell personal information and does not share personal information for cross-context behavioural advertising as those terms are defined under the CCPA/CPRA. Because we do not engage in such sale or sharing, we are not required to provide a "Do Not Sell or Share My Personal Information" link; if our practices change, we will provide that mechanism and update this policy. We also do not use sensitive personal information for purposes that would require a "Limit the Use of My Sensitive Personal Information" link.
14. Right to Withdraw Consent and Marketing Opt-Out
Where we rely on your consent, you can withdraw it at any time by emailing privacy@generads.ai. If we ever send optional marketing communications, you will be able to opt out using the unsubscribe mechanism in those messages or by contacting us at the same address. Withdrawing consent or opting out does not affect the lawfulness of processing carried out before the withdrawal, and we may still send you essential service and account messages needed to operate your account.
15. Cookies and Tracking Technologies
We use cookies and similar technologies that are strictly necessary to run the Service, including authentication and session cookies that keep you logged in, and a small number of technologies used for error monitoring and performance (via our error-monitoring provider). We do not use cookies for selling data or for cross-context behavioural advertising. You can control cookies through your browser settings; disabling strictly necessary cookies may stop parts of the Service from working. Where required, we will present a cookie consent mechanism and any further detail in a separate cookie notice.
16. Security Measures
We use technical and organisational measures designed to protect personal information, including:
- Encryption in transit using TLS 1.2 or higher for data moving between you, Generads, and our subprocessors.
- Encryption at rest using AES-256 (or an industry-standard equivalent) for stored personal information and OAuth tokens.
- Access controls, including role-based access, service-role-only access to sensitive secrets such as Klaviyo tokens, and multi-factor authentication on systems that access personal data.
- Secrets management, with credentials and API keys held in a secrets store rather than hardcoded, and access tokens that expire and refresh.
- Logging and monitoring of access, changes, and key actions, with audit logs retained for accountability and security review.
No system can be guaranteed completely secure. We encourage you to use a strong, unique password and to keep your credentials confidential.
17. International Transfers Within Our Supply Chain
Our subprocessors are located in various countries, primarily the United States. All transfers of personal data to those providers are governed by the safeguards described in Section 8 (International Data Transfers), which applies in full to our supply chain.
18. Automated Decision-Making and Profiling
Generads uses AI to generate marketing content (creatives, ad copy, emails, landing pages, suggestions) and to rank and summarise brand context. This is content generation rather than decision-making that produces legal or similarly significant effects about you. We do not make solely automated decisions that have legal or similarly significant effects on individuals within the meaning of Article 22 of the GDPR. If we ever introduce such processing, we will disclose the logic involved, its significance, and the consequences, and we will provide the safeguards required by law.
19. Children's Data
The Service is intended for businesses and is not directed to children. We do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact privacy@generads.ai and we will delete it. Where the Service processes end-customer data inside a connected platform, the connecting brand is responsible for ensuring it has a lawful basis and any required consent, including for minors under applicable law.
20. Controller vs Processor Roles
Generads acts as a data controller for the personal data of our account users (for example, account identity, profile, audit, and diagnostic data). Generads acts as a data processor / service provider for end-customer personal data that flows through a platform you connect (for example, customer profiles, list membership, and events in your Klaviyo account). For that processor-side data, you (the connecting brand) are the controller and remain responsible for the lawful basis, notices, and consents required to share that data with us, and we process it only on your documented instructions and as needed to provide the Service.
21. Changes to This Policy
We may update this policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you in-app or by email. We review this policy at least every 12 months. Your continued use of the Service after an update takes effect means you accept the revised policy.
22. Contact and Complaints
For any privacy question, request, or complaint, contact us at privacy@generads.ai.
If you are in the EEA or UK and believe we have not handled your personal data lawfully, you have the right to lodge a complaint with your local data protection supervisory authority. If you are a California resident, you may also contact the California Privacy Protection Agency (CPPA) or the California Attorney General. We ask that you contact us first so we can try to resolve your concern directly.