Privacy Policy
Last updated: 6 September 2026
This policy covers adkemist.io and the Adkemist platform. Adkemist is a Meta Ads analytics and decision-support tool: it reads the performance of ads you already run and tells you what it makes of them.
1. Who we are
Kamil Fachtali, carrying on business as THE FATALI PARTNERS, operates Adkemist.
Adkemist is a sole proprietorship (entreprise individuelle) based in Québec, Canada, and is the party responsible for the data described here.
For any question about this policy or about your data, write to privacy@adkemist.io.
2. What we collect
Your Adkemist account
- Email address
- Name, and profile picture URL if you sign in with Google
- The date you completed onboarding
- Your workspace, and which people belong to it
Business figures you enter yourself
Optional, and used only to turn ad metrics into money:
- Average order value
- Gross margin
- 90-day customer lifetime value
- Currency, business model and objective
- A free-text description of your business
Your Meta connection
When you connect a Meta ad account we store:
- Your Meta user ID
- The ID and name of the ad account you selected
- An access token, so we can read your data without asking you to sign in again
Advertising performance data from Meta
For the ad account you connect, we read and store:
- Campaign, ad set and ad names, objectives, status and budgets
- Daily aggregate figures: impressions, clicks, outbound clicks, amount spent, reach, frequency, purchases, leads, landing page views, adds to cart, checkouts started, and purchase value
- Video retention counts: plays, ThruPlays, and how many views reached each quarter of the video
- A breakdown of the same figures by placement, for example Facebook Feed or Instagram Stories
Technical and security information
- A session cookie, so you stay signed in. We use no advertising or analytics trackers and set no third-party cookies.
- Server logs kept by our hosting provider, which record request paths, timing and IP addresses for security and fault-finding.
Support communications
If you write to us, we keep the message and our reply so the conversation makes sense the next time.
3. What we deliberately do not collect
These are design choices, not oversights.
We do not look at your creative content. Adkemist never downloads, stores or analyses the image or the video in your ads. Every conclusion it reaches comes from numbers. When it says an ad is tiring out, that is frequency and click-rate arithmetic, not an opinion about your photograph.
We do not receive data about your customers. Meta returns aggregate counts only — “412 purchases” — never who bought, their email, or any identifier. No personal data about the people who saw or clicked your ads reaches us.
We never modify your campaigns. Adkemist reads, interprets and recommends. It requests no write permission from Meta and issues no request that changes a campaign. Every change is one you make yourself in Meta Ads Manager.
We do not collect payment information. Nothing charges a card today, and the application has no payment integration.
4. Why we process it
| Purpose | Legal basis (GDPR) |
|---|---|
| Authenticating you and maintaining your account and workspace | Performance of a contract |
| Connecting the Meta ad account you choose, and syncing its data | Performance of a contract |
| Displaying, analysing and explaining that performance, and producing diagnostics, reports, alerts and Kiro’s answers | Performance of a contract |
| Answering your support messages | Performance of a contract |
| Keeping the service running, secure and free of faults | Legitimate interest |
| Meeting a legal obligation where one applies | Legal obligation |
We do not sell your data. We do not use it for advertising. We do not use it to train machine-learning models.
5. Your Meta data, specifically
Adkemist reads your Meta advertising data only after you authorise it, and only for the ad account you select.
The permission we request is ads_read, and it is the only one. It is read-only. Adkemist cannot create, edit, pause, publish or scale a campaign, an ad set, an ad, a budget or a targeting setting, and it issues no request that would.
We use that data to provide the analysis you asked for, and:
- We do not use it to build advertising audiences, custom or otherwise
- We do not sell it, and we do not share it for anyone else’s marketing
- We do not combine it with data from other Adkemist customers
You can disconnect Meta at any time, from your Adkemist settings or from Meta’s own Business integrations page. Removing Adkemist there also tells Meta to send us a deletion request, which we act on automatically.
6. Who else sees it
We use a small number of providers to run Adkemist. Each one processes data only as needed to provide its service to us, under its own contract and instructions from us.
| Provider | What it receives |
|---|---|
| Supabase Database and authentication | Everything described in section 2. This is where your account, your Meta connection and your advertising data are stored, in the US West (Oregon), us-west-2 region. |
| Vercel Hosting and application infrastructure | Requests to the site pass through it, so it handles your data in transit and keeps server logs including IP addresses. |
| Anthropic The model behind Kiro and the written reports | When you ask Kiro a question or generate a report, we send the figures the answer needs: campaign and ad names, the performance numbers for the period, and the business context you entered. Your email, your access token and your Meta IDs are not sent. Anthropic does not train its models on this data. |
| Meta Platforms The source of the advertising data | Contacted to read your data, using the token you authorised. We send it no data of yours beyond what an authenticated read requires. |
If you connect Slack or Telegram to receive alerts, the alert we send is delivered through that service and is visible to whoever can see the channel you chose. If you connect a Shopify store, we read its order totals to compare against what Meta reports.
7. Where it is processed
Adkemist is operated from Québec, Canada, but your data is not stored there. The database sits in the United States (US West (Oregon), us-west-2), and our hosting and AI providers operate from the United States as well. Support messages and anything you send us by email are processed wherever our mail provider operates.
Where data leaves the European Economic Area, our providers rely on the European Commission’s standard contractual clauses.
8. How long we keep it
We keep data for as long as we need it to provide the service to you, and after that only where we have to: to meet a legal obligation, to resolve a dispute, or to keep the service secure.
- Your account data, while your account exists.
- Advertising performance data, while your account exists, so the tool can compare this week with last month.
- Your Meta access token, until you revoke our access, the token expires — Meta expires them after about 60 days — or you delete your account.
- A record that a deletion request was made, after the deletion itself. It holds a confirmation code and a date, and nothing that identifies you.
You can ask us to delete your data at any point. See the next section.
9. Deleting your data
You can have everything erased. The full instructions, including what is removed and what is not, are on the data deletion page.
In short: write to privacy@adkemist.io from the address on your account. We delete your account, your Meta connection and every row of advertising data associated with it within 30 days, and confirm in writing.
You can also stop us reading your Meta data without deleting your account, by disconnecting it in Adkemist or removing Adkemist from Meta’s Business integrations settings.
10. Your rights
You can ask us for a copy of your data, correct it, delete it, restrict how we use it, or object to our using it. Account details can also be changed directly in Settings.
Write to privacy@adkemist.io. We answer within one month.
If you are in Québec you may complain to the Commission d’accès à l’information. Elsewhere in Canada, to the Office of the Privacy Commissioner. In the European Union or the United Kingdom, to your national data protection authority.
11. Security
We take reasonable technical and organisational measures to protect your data. Access is scoped to your own workspace at the database level, so one customer’s rows are unreachable from another customer’s session. Your Meta access token is never sent to the browser; it is read only by the server process that calls Meta on your behalf. All traffic is encrypted in transit.
No service can promise perfect security, and we do not hold a formal security certification. If we ever learn of a breach affecting your data, we will tell you and the relevant authority as the law requires.
12. Children
Adkemist is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children.
13. Changes
If we change this policy we will update the date at the top and, for anything that materially affects you, email you before it takes effect.
Kamil Fachtali, carrying on business as THE FATALI PARTNERS, sole proprietorship (entreprise individuelle) registered in Québec, Canada. NEQ 2281866352. Postal address available on request to privacy@adkemist.io.