Privacy Policy — Senditor

Last updated: 2026-10-06

Who we are. Clawmont, contactable at [email protected].

What this product is. Senditor helps an advertiser prepare ad creatives, have them approved by the person responsible, and publish the approved ones into an advertising account that the advertiser already owns. During the current pilot the software runs on a machine operated by us or by the advertiser, not as a public website.

What we hold, and why.

Your Meta connection. When you press "Connect Meta" and approve our app, Meta issues us an access token for your account. We immediately exchange it for a longer-lived token, which lasts approximately 60 days, and store that token, together with your Meta user id (the number Meta gives your account, which tells us whose token it is), on the machine running the software, in a file readable only by the operating-system user that runs it. You sign in once: that one token serves every client workspace you manage. For each workspace we also store, in a separate file with no token in it, your Meta user id and the ID and name of the one ad account, the one Facebook Page and the one ad set you select for it. When you add ad accounts as workspaces in one step, each new workspace is named after its ad account unless you rename it, and that name is stored with it. "Unlink" on a workspace removes that workspace's selection only. "Disconnect Meta" removes your stored token, including an older workspace token unless another active operator owns that workspace. Your bound workspaces then read as not connected until you sign in again. Neither one deletes anything on Meta: your ad accounts, Pages and ads stay exactly as they are. We use the token only to perform the actions described in this policy on your behalf. We do not transmit it to any third party, we do not include it in any report, export or email the product produces, and it is never displayed in the product's interface. It stops working on its own when it expires, and you can revoke it at any time from your Facebook account settings under Business Integrations, which ends our access immediately. A token that has stopped working stays in its file until you press "Disconnect Meta".

Ad data we read from Meta. With your permission we read the list of ad accounts you can access, the list of Pages you manage, the names of the ad account and ad set you select, and performance figures for ads in your account — impressions, clicks, spend, click-through rate, cost per thousand impressions, frequency and reach. We use these only to show you and your client how your ads are performing, inside your own workspace. With those two lists we also read the ID and name of the business that owns each ad account and Page, only to show it beside them and to suggest the Page that belongs to the same business as an ad account; we do not store it. We do not combine your data with any other advertiser's, we do not use it to train models, and we do not sell or share it.

Ad data we write to Meta. When you approve a creative and confirm publication, we upload that image to your ad account, create an ad creative attributed to your selected Page, and create an ad in the ad set you selected. Every ad we create is created PAUSED. We never create or modify campaigns, budgets, bids, schedules or audience targeting, and we never set an ad to active.

AI checks. When the AI checks or the folder sort are switched on for a workspace, we send the images and ad text being checked to OpenAI's API, which returns a review. OpenAI does not use API data to train its models and may keep it in abuse-monitoring logs for up to 30 days. We never send your Meta token or your performance figures. The result stays in the run folder on your machine. A workspace with AI switched off sends nothing.

Ad set suggestions. When AI ad set suggestions are switched on, and only for a folder our own rules could not match to an ad set, we send the folder's name, plain words from its ad text and the names of your active campaigns and ad sets to TypeSafe AI, Inc. in the United States, whose model picks one of those ad sets or none. We exclude account and ad identifier fields, remove links and email addresses, and filter text that resembles a password or key; private information written into names or ad text may remain. We never send image files, your saved Meta token or performance records from Meta. TypeSafe processes this under its data processing agreement, which includes the EU Standard Contractual Clauses, does not use it to train models, and states no fixed retention period. You confirm every placement; the suggestion only pre-fills it.

AI text checks. When AI text checks are switched on, each ad's headline and primary text go to TypeSafe AI, Inc. in the United States to flag a possible Meta policy risk. We exclude account and ad identifier fields, remove links and email addresses, and filter text that resembles a password or key; private information written into ad text may remain. We never send image files, your saved Meta token or performance records from Meta. TypeSafe processes this under its data processing agreement, which includes the EU Standard Contractual Clauses, does not use it to train models, and states no fixed retention period. This is an operator-only warning, not a policy approval; it never stops an ad from being sent for client approval.

Run artifacts. Each time you produce a batch of creatives, the product writes a folder on the machine it runs on containing the images, the ad copy, the quality-check results, a record of every API call it made and what it cost, and the resulting campaign plan. These files are how you can audit what the product did. They stay on that machine. They never contain your access token.

Approval records and receipts. When you send creatives to a client for approval, we create a link containing an unguessable token that expires. Anyone with that link can view those creatives and record a decision. We store each decision — approve or reject, any comment, the name typed by the person deciding, and the time — as an append-only record, and we generate a receipt page showing those decisions. We keep the full history rather than only the latest decision, so a changed mind remains visible. These records stay on the machine running the software. Do not enter personal information into an approval comment; the field exists to say why a creative was rejected.

Email we send. When a batch is ready for review we send one email to the address the operator configured for that workspace, containing the approval link and nothing else about you. It is sent through the mail server named in the operator's own configuration; when no mail server is configured the link is printed for the operator to send by hand, and the run records that no email was sent.

What we do not collect. We do not collect your Facebook profile beyond your Meta user id, which Meta returns during connection, we do not read your Page's posts, comments, messages, reactions or followers, we do not use cookies for advertising, and we do not have analytics that track you.

Where it is stored. On the machine running the software. During the pilot that is a machine we operate on your behalf, or your own. There is no shared multi-tenant database.

How long we keep it. Your access token and your Meta user id until you press "Disconnect Meta". The token stops working when it expires or when you revoke it, but its file stays on the machine until you press "Disconnect Meta". Each workspace's selection, with your Meta user id, until you press "Unlink" on it. When a workspace that kept its own token is moved onto your one sign-in, that old token file is kept, readable only by the account running the software, in local/pilot/auth/meta_quarantine/<your-workspace>/ so the move can be undone, until the first ad published through your one sign-in is confirmed paused or, once that token has expired, the next clean-up; "Unlink" on that workspace and "Disconnect Meta" delete it at once. A copy whose record cannot be read stays until "Unlink" or "Disconnect Meta". Run artifacts, approval records and receipts until you delete them or ask us to.

How to delete your data. See "Deleting your data" at https://app.senditor.ad/data-deletion.

Changes. If we change this policy we will update the date above and tell pilot participants directly.

Contact. [email protected].


Pricing · Privacy policy · Deleting your data · For a Meta reviewer