Privacy Policy
Last updated: May 19, 2026
This Privacy Policy explains how Challenging Apps LLC ("we", "us", or "our") collects, uses, stores, and protects your information when you use Admelo and related services (the "Service"). It should be read together with our Terms of Use.
Who we are
Challenging Apps LLC is the data controller for personal information described in this policy. The Service is offered primarily to businesses and advertisers in the United States; individual users may also create accounts to manage their own Meta ad accounts. We do not sell your personal information.
Third-party platforms
Meta and our other vendors process data under their own terms and privacy policies. We do not control how Meta handles your ad account, campaigns, or platform data outside Admelo. For questions about Meta's processing, contact Meta directly or use Meta's account and app settings.
Information we collect
- Account data: information you provide when you sign up or manage your account (for example, email, authentication identifiers from our login provider, and optional profile or preference settings).
- Billing data: subscription status and payment-related information processed by Stripe; we do not store full payment card numbers on our servers.
- Product usage: actions you take in the Service, feature usage, security logs, and diagnostics needed to operate and improve the Service.
- Chat and AI inputs: messages, prompts, campaign briefs, and related content you submit to AI-assisted features; we process these to provide the features you request.
- Newsletter: if you subscribe on our blog, we collect your email and basic subscription metadata (for example, source and timestamps).
- Meta (Facebook) integration: if you connect a Meta ad account, we receive data made available through Meta's APIs after you authorize our app, including OAuth credentials and advertising data needed for the features you use (such as ad account, campaign, ad set, and ad identifiers; configuration; performance and insights metrics; pixels and audiences where enabled; and related metadata as exposed by Meta).
- Cookies and similar technologies: see the section below on cookies and analytics.
How we use information
We use the information above to:
- Provide, maintain, secure, and improve the Service;
- Authenticate you and manage your account;
- Connect to Meta on your behalf when you complete Facebook Login / OAuth;
- Display analytics, manage campaigns, and perform actions you initiate;
- Run AI-assisted chat, generation, and optimization features;
- Process payments and send service-related communications;
- Measure marketing and product performance;
- Comply with law and enforce our terms.
Cookies and analytics
We and our service providers use cookies, pixels, and similar technologies to operate the Service and understand how it is used. Depending on your browser and settings, this may include:
- Essential cookies for authentication and security (for example, session cookies from our authentication provider).
- Product analytics (for example, PostHog) to understand feature usage and improve the Service.
- Marketing and site analytics (for example, Meta Pixel and Google Analytics) on our marketing pages and, where configured, across the Service.
- Performance monitoring (for example, Vercel Speed Insights) to measure page performance.
You can control cookies through your browser settings. Blocking certain cookies may affect sign-in or parts of the Service. Where required by law, we will honor applicable opt-out signals or preferences you submit to us.
AI features
When you use AI chat, campaign generation, account-context recommendations, or similar features, we send relevant prompts and context to third-party AI providers (such as OpenAI or Anthropic, depending on configuration) to generate responses. We may also use observability tools (such as Langfuse) to log prompts, tool calls, and errors for debugging and quality improvement. Do not submit sensitive personal information you do not want processed by these providers. AI outputs may be inaccurate; you are responsible for reviewing actions before publishing to Meta or other platforms.
Meta / Facebook
Our use of Meta technologies is subject to Meta's Privacy Policy and Platform Terms. Connecting Meta is optional. You can disconnect or revoke access through your Meta account settings and through the Service (account connection settings).
When you connect Meta, we may receive identifiers such as your Meta user ID, name, email, profile picture URL (if provided by Meta), encrypted access tokens, and ad account, campaign, and performance data needed for the Service. We request permissions such as ads_management, business_management, pages_show_list, pages_manage_ads, pages_read_engagement, instagram_basic, and leads_retrieval. Campaign and performance reads use ads_management; we do not request a separate ads_read permission. We do not sell data we receive from Meta.
After you disconnect Meta in Admelo or revoke our app in Meta, we delete Meta connection rows and encrypted access tokens from our database promptly when you remove all connected ad accounts (or the last remaining account). We also revoke our app's permissions at Meta when no Admelo connection remains. When you remove Admelo from your Facebook account, Meta may send us a deauthorize callback or a platform data-deletion request; we process both by deleting matching meta_connections rows for your Facebook user id, revoking stored tokens where applicable, and logging the request. Data-deletion callbacks also return a confirmation code and status page. Limited security, backup, or audit records may be retained longer where necessary.
If you need to request deletion of personal data we hold about you (including Meta-related data) outside those automated callbacks, email support@admelo.com from your Admelo account email. We will verify your request and aim to complete deletion within 30 days, except where we must retain certain records by law or for fraud prevention, billing, or security.
Service providers
We do not sell your personal information. We share data with service providers who help us run the Service, only as needed for their services and under appropriate agreements. These providers may include:
- Supabase (authentication and database hosting)
- Stripe (payments and subscriptions)
- Vercel (hosting and performance)
- Resend (transactional email)
- PostHog (product analytics)
- OpenAI and/or Anthropic (AI inference)
- Langfuse (AI observability, when enabled)
- Sentry (error monitoring, when enabled)
- Meta (when you connect an ad account)
Storage and security
We store data using reputable cloud infrastructure and databases. Meta access tokens and other credentials are encrypted at rest where supported and used solely to provide the Service on your behalf. We apply administrative, technical, and organizational measures appropriate to the nature of the data, but no method of transmission or storage is completely secure.
Retention
We retain information for as long as your account is active or as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. After a verified request to close your account, we aim to delete or anonymize personal data within 30 days, except where retention is required by law or legitimate needs such as billing records, fraud prevention, or security logs (which may be kept for a limited additional period).
Your choices and rights
You can:
- Access and update certain account information in the product;
- Disconnect Meta in account connection settings;
- Manage cookies through your browser;
- Opt out of marketing emails using the unsubscribe link in those messages.
Depending on where you live (including under U.S. state privacy laws), you may also have the right to request access to, correction of, deletion of, or a copy of your personal information, and to object to or restrict certain processing. To exercise these rights, email support@admelo.com. We will respond to verified requests as required by applicable law and aim to complete deletion within 30 days where applicable.
California residents
If you are a California resident, you may have the right to know, access, delete, and correct personal information, and to opt out of certain sharing for cross-context behavioral advertising. We do not sell personal information as defined under the CCPA/CPRA. To exercise your rights, contact support@admelo.com.
We will not discriminate against you for exercising your privacy rights, including by:
- Denying you goods or services;
- Charging different prices or rates;
- Providing a different level or quality of services; or
- Suggesting you may receive different pricing or service levels.
Users outside the United States
The Service is directed primarily to users in the United States. If you access the Service from elsewhere, your information may still be processed in the United States, where our providers operate. By using the Service, you understand that protections may differ from those in your home country.
Children
The Service is not directed to children under 13 (or the minimum age required in your jurisdiction), and we do not knowingly collect their personal information.
Changes
We may update this Privacy Policy from time to time. We will post the updated version on this page and update the "Last updated" date. Material changes may also be communicated through the Service or by email where appropriate. Continued use after changes take effect means you accept the revised policy.
Contact
For questions about this Privacy Policy or our data practices, contact us: