Privacy Policy

Last updated 29 August 2026

reFloq generates ad creative and launches it on your Meta ad account. To do that it needs access to that account, and it stores what it needs to keep working between sessions. This page says exactly what that is.

Who we are

reFloq (“we”, “us”) operates the service at refloq.com. For questions about this policy or your data, write to privacy@refloq.com.

What we collect

Account details. Your name, email address, and profile picture URL. If you sign in with a password we store a salted scrypt hash of it, never the password itself.

Meta connection. When you connect Meta we store your Facebook user ID and a long-lived access token, encrypted at rest with AES-GCM. We also store the identifiers you choose during setup: ad account ID and name, Page ID and name, and Pixel ID.

Brand and campaign data. The website URL and brand details you provide, the creative we generate for you, the experiments and ad placements you launch, and the daily performance metrics we read back from Meta for those ads.

Session cookie. One first-party cookie (refloq_session) holding a signed token that keeps you logged in. No third-party advertising cookies are set by refloq.com.

What we do with it

We do not sell your data and we do not share it for advertising.

Staff access to your account

reFloq is an assisted product. When you ask us to, or when generated creative is not good enough to stand behind, a member of our team can open your account and work in it directly — reviewing your brand and creative, building ads by hand, and launching campaigns on the ad account you connected.

That access is restricted to our team, every session is logged with the account it was used on and what was done there, and nothing is launched that you have not agreed to. If you would rather nobody did this, email privacy@refloq.com and we will mark the account no-touch.

Meta permissions, and why each one

Processors we send data to

We use third-party services to run the product. Each receives only what its job needs:

How long we keep it

We keep your data while your account exists. When you delete your account we remove your user record, and every brand profile, generation run, creative, experiment, ad placement and metric attached to it is deleted with it. Ads already published on Meta are not removed by this — they live on your ad account, and you delete them in Meta Ads Manager.

Disconnecting Meta removes the stored access token. Backups may retain data for up to 30 days before rolling off.

Your rights

You can request access to, correction of, or deletion of your data at any time. The fastest route is the delete my data page, which removes everything immediately. For anything else, email privacy@refloq.com and we will respond within 30 days.

You can also revoke reFloq’s access from Meta directly, under Settings → Business Integrations on your Facebook account. That stops all future access immediately.

Security

Meta access tokens are encrypted at rest with AES-GCM. Traffic to and from refloq.com is served over HTTPS. Access tokens are never sent to the browser.

Children

reFloq is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children.

Changes

If this policy changes materially we will update the date at the top and, where the change affects how we use data you have already given us, tell you in the app before it takes effect.