Last updated 29 September 2026
Privacy Policy
1. Who we are
Roaswise is operated by Karina 2710 EOOD, 2A Lilyana Dimitrova St., 7400 Isperih, Bulgaria, UIC (ЕИК) 207661771, Commercial Register of Bulgaria (“we”, “us”). This policy explains what personal data we process when you visit our website or use the Roaswise service, and the rights you have over it.
We act in two roles:
- As controller for the data about you as a user: your account, sign-in, billing contact, and how you use the service.
- As processor for the data our customers bring into a brand, such as their Meta ad accounts, creative assets and anything they upload. The customer is the controller of that data, and our processing of it is governed by the Data Processing Agreement. If your data reached us that way, please contact the brand concerned first.
Privacy questions: eczenn@gmail.com.
2. What we collect
You give us
- Account details: name, username, email address and password (stored only as a one-way hash). If you sign in with Google, we receive your name and email address from Google.
- Workspace details: the brands and agencies you belong to, your role, and the email addresses of people you invite.
- Content: brand settings, Guardrails, Brand Style Guides, uploaded images, Inspiration Sources, approvals and comments.
- Billing details: billing name, address and tax ID. Card details go straight to Stripe; we never see or store them.
- Messages you send to us, for example to support.
From Meta, when you connect an ad account
- Your Meta user ID and an access token, which we store encrypted.
- The ad accounts you select, with their campaigns, ad sets, ads, creatives, budgets, audience settings and performance figures (spend, results, revenue as reported by Meta). This is aggregated advertising data; it does not identify the people who saw your ads.
Collected automatically
- IP address, browser type and request times, in server and security logs.
- An audit log of every change made in a brand, with who made it, when, and what it replaced. Members of the brand can see it.
- The cookies and browser storage described in section 9. We use no analytics, advertising or tracking cookies.
3. Why we use it, and on what legal basis
| Purpose | Data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Create and run your account; sign you in; keep you signed in | Account details, cookies | Contract (6(1)(b)) |
| Provide the service: sync ad data, run the Agent, generate creatives, apply the changes you approve or allow | Workspace details, content, Meta data | Contract (6(1)(b)) |
| Bill you and keep accounting records | Billing details, subscription history | Contract (6(1)(b)); legal obligation (6(1)(c)) |
| Send transactional email, daily digests and critical alerts | Name, email address | Contract (6(1)(b)). Critical alerts cannot be turned off because they protect your ad spend. |
| Keep the service secure; detect abuse; keep the audit log | Logs, IP address, audit log | Legitimate interests (6(1)(f)): protecting the service and our customers |
| Answer your messages and improve the service | Messages, aggregated usage | Legitimate interests (6(1)(f)): supporting and developing our product |
| Comply with law, respond to lawful requests, defend legal claims | Any of the above, as needed | Legal obligation (6(1)(c)); legitimate interests (6(1)(f)) |
4. AI processing
Roaswise uses AI models to analyse ad performance, write Proposals and generate ad copy, images and video. To do this we send the relevant brand data (performance figures, brand details, briefs and reference images) to the AI providers listed in section 5. We send only what a task needs.
We do not use your data to train AI models, and we use our AI providers under business terms that do not allow them to train on it.
The Agent makes decisions about ads, not about people. It does not make decisions that produce legal or similarly significant effects on individuals within the meaning of GDPR Article 22. Every change it makes stays inside the Guardrails you set and can be reverted.
5. Who we share it with
We do not sell personal data, and we do not share it for advertising. We share it only with:
- Other members of your brand or agency, who see your name, role and activity in that workspace.
- Meta, when the service reads from or writes to your ad account at your instruction.
- Our service providers (processors), under written contracts that limit them to processing on our instructions:
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Runs the application, database and job queue | Germany |
| Cloudflare, Inc. | Serves the web app; stores creative media and encrypted database backups (R2) | Global network; storage in the brand's data region |
| Meta Platforms Ireland Ltd. | The ad platform the Agent reads from and writes to, at your instruction | EU / USA |
| Anthropic, PBC | Language model (Claude) that analyses performance and drafts Proposals and copy | USA |
| Google LLC | Image generation (Gemini); optional sign-in with Google | USA |
| Features & Labels, Inc. (fal.ai) | Video generation (Seedance models) | USA |
| Stripe Payments Europe, Ltd. | Subscriptions, payments and invoices | EU / USA |
| Resend (Plus Five Five, Inc.) | Transactional email, digests and alerts | USA |
- Authorities or courts, where the law requires it.
- A buyer or successor, if our business is sold or merged. We will tell you before your data becomes subject to a different privacy policy.
6. International transfers
When you set up a brand you choose whether its data is stored in the EU or in the US. Some of our providers, including our AI providers, process data in the United States wherever the brand is stored.
Where personal data leaves the European Economic Area, the United Kingdom or Switzerland, we rely on the EU-U.S. Data Privacy Framework where the recipient is certified, or on the European Commission’s Standard Contractual Clauses (with the UK Addendum), together with the additional safeguards they require. You can ask us for a copy at eczenn@gmail.com.
7. How long we keep it
| Data | Kept for |
|---|---|
| Your account | Until you delete it. Deletion erases your personal data immediately and signs out every session. |
| A brand's data, including Meta data, media and Agent memory | Until an Owner deletes the brand. A deleted brand can be restored for 30 days, then it is permanently erased. |
| Meta data after you remove the Roaswise app on Facebook or ask Meta to delete it | Access tokens at once; the rest as described under Data deletion |
| Data exports | 7 days after they are created, then deleted |
| Encrypted backups | 60 days, then overwritten |
| Invoices and billing records | As long as tax and accounting law requires |
| Security logs | No longer than needed to investigate and prevent abuse |
8. Your rights
Under the GDPR and UK GDPR you have the right to:
- access the personal data we hold about you, and receive a copy;
- have inaccurate data corrected;
- have your data erased;
- restrict or object to our processing, including processing based on legitimate interests;
- receive your data in a portable, machine-readable format;
- withdraw any consent you have given, without affecting processing before you withdrew it.
Much of this you can do yourself: edit or delete your account on your profile page, and, as a brand Owner, export or delete a brand’s data from its settings. For anything else, email eczenn@gmail.com. We answer within one month and may ask you to confirm your identity first.
You can also complain to a data protection authority, in particular where you live or work. Ours is the Commission for Personal Data Protection (КЗЛД), Bulgaria.
9. Cookies and browser storage
We use only what the service needs to work. Because none of it is optional, we do not ask for cookie consent. We use no analytics, advertising or third-party tracking cookies.
| Name | Type | Purpose | Expires |
|---|---|---|---|
| session_id | Cookie (HttpOnly) | Keeps you signed in | When you sign out or the session ends |
| csrf_token | Cookie | Protects your account from cross-site request forgery | With the session |
| session:hint | Local storage | Remembers that this browser was signed in, so the right home page opens | When you sign out |
| ws:last | Local storage | Reopens the brand or agency you used last | Until you clear your browser storage |
Stripe may set its own strictly necessary cookies on its checkout pages to prevent fraud.
10. Security
We encrypt data in transit with TLS, encrypt Meta access tokens at rest with a key kept apart from our backups, hash passwords, keep each brand’s data isolated from every other brand’s, and limit what each role can see and do. No system is perfectly secure; if a breach puts your data at risk we will tell you and the authorities as the law requires.
11. Children
Roaswise is a business service for people aged 18 and over. We do not knowingly collect data from anyone younger.
12. Changes to this policy
We will post any change here and update the date at the top. If a change materially affects how we use your data, we will tell you by email or in the app before it takes effect.
13. Contact
Karina 2710 EOOD, 2A Lilyana Dimitrova St., 7400 Isperih, Bulgaria. Email eczenn@gmail.com.