adkemist ·

Privacy Policy

1. Who we are

Kamil Fachtali, carrying on business as THE FATALI PARTNERS, operates Adkemist.

Adkemist is a sole proprietorship (entreprise individuelle) based in Québec, Canada, and is the party responsible for the data described here.

For any question about this policy or about your data, write to privacy@adkemist.io.

2. What we collect

Your Adkemist account

Business figures you enter yourself

Optional, and used only to turn ad metrics into money:

Your Meta connection

When you connect a Meta ad account we store:

Advertising performance data from Meta

For the ad account you connect, we read and store:

Technical and security information

Support communications

If you write to us, we keep the message and our reply so the conversation makes sense the next time.

3. What we deliberately do not collect

These are design choices, not oversights.

4. Why we process it

PurposeLegal basis (GDPR)
Authenticating you and maintaining your account and workspacePerformance of a contract
Connecting the Meta ad account you choose, and syncing its dataPerformance of a contract
Displaying, analysing and explaining that performance, and producing diagnostics, reports, alerts and Kiro’s answersPerformance of a contract
Answering your support messagesPerformance of a contract
Keeping the service running, secure and free of faultsLegitimate interest
Meeting a legal obligation where one appliesLegal obligation

We do not sell your data. We do not use it for advertising. We do not use it to train machine-learning models.

5. Your Meta data, specifically

Adkemist reads your Meta advertising data only after you authorise it, and only for the ad account you select.

The permission we request is ads_read, and it is the only one. It is read-only. Adkemist cannot create, edit, pause, publish or scale a campaign, an ad set, an ad, a budget or a targeting setting, and it issues no request that would.

We use that data to provide the analysis you asked for, and:

You can disconnect Meta at any time, from your Adkemist settings or from Meta’s own Business integrations page. Removing Adkemist there also tells Meta to send us a deletion request, which we act on automatically.

6. Who else sees it

We use a small number of providers to run Adkemist. Each one processes data only as needed to provide its service to us, under its own contract and instructions from us.

ProviderWhat it receives
Supabase
Database and authentication
Everything described in section 2. This is where your account, your Meta connection and your advertising data are stored, in the US West (Oregon), us-west-2 region.
Vercel
Hosting and application infrastructure
Requests to the site pass through it, so it handles your data in transit and keeps server logs including IP addresses.
Anthropic
The model behind Kiro and the written reports
When you ask Kiro a question or generate a report, we send the figures the answer needs: campaign and ad names, the performance numbers for the period, and the business context you entered. Your email, your access token and your Meta IDs are not sent. Anthropic does not train its models on this data.
Meta Platforms
The source of the advertising data
Contacted to read your data, using the token you authorised. We send it no data of yours beyond what an authenticated read requires.

If you connect Slack or Telegram to receive alerts, the alert we send is delivered through that service and is visible to whoever can see the channel you chose. If you connect a Shopify store, we read its order totals to compare against what Meta reports.

7. Where it is processed

Adkemist is operated from Québec, Canada, but your data is not stored there. The database sits in the United States (US West (Oregon), us-west-2), and our hosting and AI providers operate from the United States as well. Support messages and anything you send us by email are processed wherever our mail provider operates.

Where data leaves the European Economic Area, our providers rely on the European Commission’s standard contractual clauses.

8. How long we keep it

We keep data for as long as we need it to provide the service to you, and after that only where we have to: to meet a legal obligation, to resolve a dispute, or to keep the service secure.

You can ask us to delete your data at any point. See the next section.

9. Deleting your data

You can have everything erased. The full instructions, including what is removed and what is not, are on the data deletion page.

In short: write to privacy@adkemist.io from the address on your account. We delete your account, your Meta connection and every row of advertising data associated with it within 30 days, and confirm in writing.

You can also stop us reading your Meta data without deleting your account, by disconnecting it in Adkemist or removing Adkemist from Meta’s Business integrations settings.

10. Your rights

You can ask us for a copy of your data, correct it, delete it, restrict how we use it, or object to our using it. Account details can also be changed directly in Settings.

Write to privacy@adkemist.io. We answer within one month.

If you are in Québec you may complain to the Commission d’accès à l’information. Elsewhere in Canada, to the Office of the Privacy Commissioner. In the European Union or the United Kingdom, to your national data protection authority.

11. Security

We take reasonable technical and organisational measures to protect your data. Access is scoped to your own workspace at the database level, so one customer’s rows are unreachable from another customer’s session. Your Meta access token is never sent to the browser; it is read only by the server process that calls Meta on your behalf. All traffic is encrypted in transit.

No service can promise perfect security, and we do not hold a formal security certification. If we ever learn of a breach affecting your data, we will tell you and the relevant authority as the law requires.

12. Children

Adkemist is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children.

13. Changes

If we change this policy we will update the date at the top and, for anything that materially affects you, email you before it takes effect.