KlidooČeština

Privacy policy

Klidoo is operated by [TODO: legal name], [TODO: IČO], [TODO: street, city, postcode, Czech Republic].

Last updated 2026-08-18

What this service does

Klidoo reads the performance of your Meta (Facebook and Instagram) advertising once a day, proposes a small number of concrete changes, and carries out only the ones you approve. It never changes your advertising on its own.

What we store

We hold only what the service needs to work:

  • Your email address and name, which come from the Google account you sign in with — there is no password with us.
  • An access token for your Meta advertising account, which you grant through Meta and we store encrypted (AES-256-GCM). We never see or ask for your Facebook password.
  • Advertising data read from Meta: campaigns, ad sets, ads, their spend and results, for roughly the last 30 days on a rolling basis.
  • If you connect Instagram: your business profile's posts, their thumbnails and public engagement figures.
  • The proposals we generated, your approvals and rejections, and what we then changed in your account.
  • A short niche overview we generate to find similar public ads, and snapshots of those public competitor creatives (images are hotlinked, not re-hosted as your assets).

Why we are allowed to hold it

We process this data to perform the contract you enter into by signing up (GDPR Article 6(1)(b)). We do not use it for advertising, we do not profile you, and we do not sell it to anyone.

Who else sees it

We use a small number of processors, each for one purpose, and no others:

  • Meta Platforms — the source of the advertising data and the target of any change you approve.
  • Anthropic — the AI model that drafts the daily proposals receives your recent performance figures. It does not receive your email address, your access token, or any personal data about your customers.
  • AdLibrary — when we show public ads from businesses in your niche for inspiration, we query their commercial ad index. We store a snapshot of those public creatives and metrics; we do not send them your Meta access token or customer data.
  • Google — handles sign-in, so it knows when you sign in to Klidoo. We receive your email address and name from your Google account, nothing else.
  • Railway — hosts the application and the database, inside the European Union.

Transfers outside the EU

Meta, Anthropic and AdLibrary process data outside the EU (including the United States), under the European Commission's standard contractual clauses where required.

Cookies

One cookie, which keeps you signed in, plus a short-lived one during the Meta connection that exists to stop a forged request. No analytics, no advertising trackers, nothing shared with anyone.

How long we keep it

Advertising figures roll forward as they age out of the windows we read. Everything else stays while your account exists and is deleted when you ask us to.

Deleting your data

Write to [TODO: hello@example.com] from the address you signed up with and say you want your data deleted. We will erase your account, your stored access token, your advertising data and your proposal history within 30 days, and confirm by email when it is done.

You can also cut our access off yourself at any time, without writing to us: in Facebook, under Settings → Business integrations, remove Klidoo. That immediately stops us reading anything new. It does not by itself delete what we already hold, so send the email as well if that is what you want.

Your other rights

You may ask us for a copy of your data, for corrections, or for us to stop processing it, at [TODO: hello@example.com]. If you think we have handled your data badly, you can complain to the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů).

Changes

If we change anything that matters, we will email the address on your account before it takes effect.

Terms