Last updated · this month
Privacy policy.
This page is maintained by Signalframe to explain what data we handle when you use our reporting product. Plain English first; the legal terms are in Terms of service.
What we collect
- Account info — the email, name, and password hash you use to sign in.
- Meta ad data — via read-only OAuth: campaign, adset, and ad-level insights, creative previews, hourly and demographic breakdowns, going back 90 days.
- Billing — Stripe holds your card. We store the last four digits, brand, and subscription status.
- Product usage — anonymous events (page views, feature interactions) so we know what to fix. Turn this off in Settings → Privacy.
What we never do
- We never write to your Meta account. Our access is read-only.
- We never sell or rent your personal information.
- We never share your ad-account data with other customers.
- We never train third-party models on your data.
How we store and protect it
Data is stored on managed infrastructure in the United States. It's encrypted in transit (TLS 1.2+) and at rest (AES-256). Access is limited to on-call engineers with least-privilege credentials and full audit logs.
Subprocessors
We use a small set of vendors to run the product: our cloud host, our database provider, Stripe for billing, and a transactional email service. Each is contractually bound to the same handling standards we hold ourselves to. Ask privacy@signalframe.co for the current list.
Your rights
You can access, export, correct, or delete your data at any time from Settings, or by emailing us. If you're in the EU, UK, or California, you also have the right to object to processing and to lodge a complaint with your local regulator. See Data deletion and Opt out.
Retention
We keep ad-account data for as long as your subscription is active. On cancellation, we retain it for 30 days in case you reactivate, then permanently delete it. Backups roll off within 90 days.
Contact
Questions or requests: privacy@signalframe.co. We respond within two business days.