This policy explains exactly what MyAdDaddy collects from you and from the ad accounts you connect, why we collect it, who it is shared with, and how to get rid of it. It is written to be read, not to be survived.

MyAdDaddy is operated by Blue Tide Exteriors LLC, 1780 E. Bert Kouns Industrial Loop, Suite 907, Shreveport, LA 71105, United States.

Current status

MyAdDaddy has not launched. No ad platform connection is live yet, so no real ad account data is being processed today. This policy describes the service as it is built, so that what happens to your data is settled before anything of yours reaches it.

1. What we collect

Everything below is either something you typed into the app, something you explicitly connected, or something an ad platform sent back to us about an account you connected.

CategoryWhat it is
AccountYour email address and an encrypted password hash. We never store your password in readable form.
Business profileYour website address, business name, industry and description, and a summary of your tone of voice derived from them. All entered or triggered by you.
Knowledge filesDocuments you choose to upload, such as pricing sheets, service lists and brand guidelines, stored under your account.
Ad account connectionsAccess and refresh tokens issued by an ad platform when you connect an account, plus the account name and account ID so the app can show you what is connected.
Campaign dataCampaign, ad set and creative names, objectives, structures, budgets, bids, targeting descriptions and audience definitions, as they exist in the accounts you connected.
Spend figuresAmounts spent per day, per month, per platform and per campaign, together with the daily and monthly ceilings you set.
Performance figuresImpressions, clicks, click-through rate, cost per click, conversions, cost per acquisition, return on ad spend, hook rate, hold rate, frequency, and each platform's attribution window.
CRM-verified conversionsIf you connect a CRM, the conversions it confirms, so the app can show verified results next to platform-reported ones.
Creative contentHeadlines, body copy, calls to action, the stated hypothesis behind each concept, and any images or video generated for it.
Your settingsAutonomy mode per action type, spend ceilings, and your custom rules.
Decision recordsEvery proposed action with its reasoning and projected impact, whether you approved or rejected it, what actually ran, and the result once known.

We do not collect your ad platform passwords, your card or bank details, your contacts, your location, your advertising device identifiers, or your browsing activity on other sites. We do not use tracking cookies for advertising, and we do not sell data to anyone, ever.

Some settings never leave your phone. Which sections you choose to hide on the Command screen is stored on your own device and is never sent to us.

2. Why we collect it

  • To run your account and keep your data separate from every other customer's.
  • To show you your own numbers in one place, across the accounts you connected.
  • To enforce your limits so a spend ceiling can be checked before an action runs rather than after.
  • To propose changes and to explain the reasoning behind each one.
  • To act on the accounts you connected, but only within the autonomy mode you set for that kind of action.
  • To keep an audit trail of what was done, why, and what happened, so you can check the automation's work.
  • To draft campaign copy that sounds like your business rather than like anyone's.

3. Your connected ad accounts

When you connect Meta, Google, TikTok, LinkedIn or X, you log in through that platform's own login window. Your password is entered on their site, not ours, and we never see it.

What the platform gives us back is a token that permits a specific, limited set of actions: broadly, reading the accounts and campaigns you administer, reading their spend and performance, and making the campaign changes you have authorised through your autonomy settings. We request no more than that.

What the app is allowed to change is set by you, not by us. Each kind of action carries its own autonomy mode. On observe it only watches. On propose it must ask and wait. Only on auto and auto plus does it act without asking, and even then an action that would breach your daily spend ceiling is refused.

You can disconnect any account from inside the app at any time. You can also revoke our access directly from the platform's own settings, independently of us, and that takes effect immediately. When you disconnect, we delete the stored tokens for that account.

4. Spend and performance figures

Your spend figures are commercially sensitive and we treat them that way. They are used to draw your own screens, to enforce your own ceilings, and to generate your own reports. They are not pooled into benchmarks, not used to train anything, not shown to other customers in any form including anonymised or aggregated, and not sold.

If we ever want to use aggregate figures for anything, we will ask you first and you will be able to say no without losing access to the product.

5. How AI is used

Two different things in the app are described as AI, and they work differently.

Rules and detection

Your custom IF and THEN rules, the spend ceiling checks and the creative fatigue detection are ordinary arithmetic running on your own numbers. Nothing is sent anywhere for these. They are deterministic: the same numbers always produce the same result.

Generated copy and media

When you ask the app to build a campaign, we send our AI provider the offer you described and the relevant fields of your business profile so it can draft headlines, body copy and calls to action. When you ask for an image or a video for a concept, that request goes to our media generation provider. We do not send your email address, your access tokens, your spend figures or your CRM data to either of them.

Worth stating plainly

Generated copy is a draft for you to approve. Nothing generated is published or spent against without you accepting it first.

6. Who we share data with

Only the service providers required to make the product work:

ProviderWhat they handle
SupabaseDatabase, authentication, file storage and the server functions that talk to the ad platforms.
Our AI providerDrafting campaign copy from your offer description and business profile, as described in section 5.
HiggsfieldGenerating images and video for a creative concept, when you ask for one.
Meta, Google, TikTok, LinkedIn, XReceive the campaign changes you authorised, for the accounts you connected, and return the spend and performance figures for those accounts.

We may also disclose information where we are legally required to. We do not sell, rent or trade your personal data, and we do not share it for anyone else's advertising.

7. How long we keep it

  • While your account is open we keep your data so the product works.
  • Connection tokens are deleted as soon as you disconnect that account.
  • The action log is kept for as long as your account is open, because an audit trail you cannot look back through is not an audit trail.
  • On account deletion your profile, uploaded files, connections, campaign and spend records, settings, rules, decision history and reports are permanently deleted within 30 days.
  • Backups may hold residual encrypted copies for a short period after deletion before being overwritten on the normal backup cycle.

8. Security and isolation

Every record in our database carries an account identifier, and database-level row security rules make it structurally impossible for one customer's data to be read by another. That isolation is enforced by the database itself rather than by application code remembering to check.

Data is encrypted in transit. Ad account tokens are held server-side and are never exposed to the app on your phone. Calls to the ad platforms happen on our servers, not on your device.

No system is perfectly secure, and we will not claim otherwise. If a breach affects your data we will tell you.

9. Your rights

Wherever you live, we will honour these:

  • Access: ask for a copy of what we hold about you.
  • Correction: most of it you can edit directly in the app; ask us for the rest.
  • Deletion: see the data deletion instructions.
  • Withdraw connection: disconnect any ad account at any time, from the app or from the platform.
  • Portability: ask for your data in a machine-readable format.
  • Object: tell us to stop a particular processing activity.

Depending on where you live you may have additional rights under the GDPR, the UK GDPR, or state privacy laws such as the CCPA. Write to us and we will apply whichever gives you more protection. We respond within 30 days and we do not charge for it.

10. Children

MyAdDaddy is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us data, contact us and we will delete it.

11. Changes to this policy

If we change this policy we will update the date at the top. For any change that materially affects how we handle your data, we will email you before it takes effect.

12. Contact

Privacy questions, requests, or complaints: privacy@myaddaddy.com  ·  anything else: hello@myaddaddy.com