Privacy Policy
Last updated 29 August 2026
reFloq generates ad creative and launches it on your Meta ad account. To do that it needs access to that account, and it stores what it needs to keep working between sessions. This page says exactly what that is.
Who we are
reFloq (“we”, “us”) operates the service at refloq.com. For questions about this policy or your data, write to privacy@refloq.com.
What we collect
Account details. Your name, email address, and profile picture URL. If you sign in with a password we store a salted scrypt hash of it, never the password itself.
Meta connection. When you connect Meta we store your Facebook user ID and a long-lived access token, encrypted at rest with AES-GCM. We also store the identifiers you choose during setup: ad account ID and name, Page ID and name, and Pixel ID.
Brand and campaign data. The website URL and brand details you provide, the creative we generate for you, the experiments and ad placements you launch, and the daily performance metrics we read back from Meta for those ads.
Session cookie. One first-party cookie (refloq_session) holding a signed token that keeps you logged in. No third-party advertising cookies are set by refloq.com.
What we do with it
- Authenticate you and keep you signed in.
- Read your ad accounts, Pages and Pixels so you can pick which to use.
- Generate ad creative from the brand information you give us.
- Create and manage campaigns, ad sets and ads on the ad account you selected.
- Read performance metrics for those ads and show them back to you.
We do not sell your data and we do not share it for advertising.
Staff access to your account
reFloq is an assisted product. When you ask us to, or when generated creative is not good enough to stand behind, a member of our team can open your account and work in it directly — reviewing your brand and creative, building ads by hand, and launching campaigns on the ad account you connected.
That access is restricted to our team, every session is logged with the account it was used on and what was done there, and nothing is launched that you have not agreed to. If you would rather nobody did this, email privacy@refloq.com and we will mark the account no-touch.
Meta permissions, and why each one
ads_management— create and manage the campaigns you launch.ads_read— read delivery and conversion metrics for your ads.business_management— list the ad accounts and businesses you can use.pages_show_list,pages_read_engagement,pages_manage_ads— publish ads from the Page you choose.public_profile— your name and picture, so the app knows who is signed in.
Processors we send data to
We use third-party services to run the product. Each receives only what its job needs:
- Meta Platforms — ad creation, delivery and reporting.
- Anthropic and Google — language and image models that generate ad copy and creative from your brief.
- fal.ai and Cloudflare — image and video generation.
- Backblaze B2 — storage for generated creative assets.
- Our database host — the managed Postgres database holding everything above.
How long we keep it
We keep your data while your account exists. When you delete your account we remove your user record, and every brand profile, generation run, creative, experiment, ad placement and metric attached to it is deleted with it. Ads already published on Meta are not removed by this — they live on your ad account, and you delete them in Meta Ads Manager.
Disconnecting Meta removes the stored access token. Backups may retain data for up to 30 days before rolling off.
Your rights
You can request access to, correction of, or deletion of your data at any time. The fastest route is the delete my data page, which removes everything immediately. For anything else, email privacy@refloq.com and we will respond within 30 days.
You can also revoke reFloq’s access from Meta directly, under Settings → Business Integrations on your Facebook account. That stops all future access immediately.
Security
Meta access tokens are encrypted at rest with AES-GCM. Traffic to and from refloq.com is served over HTTPS. Access tokens are never sent to the browser.
Children
reFloq is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children.
Changes
If this policy changes materially we will update the date at the top and, where the change affects how we use data you have already given us, tell you in the app before it takes effect.