Privacy Policy
This policy explains what data Paperplane collects, why, how it is protected, and the choices you have.
Last updated August 30, 2026
1. Who we are
Paperplane is an account editor for Meta ads. For the advertising data you connect, we act as a processor on your behalf — we handle it only to provide the service you direct. For your account and billing details, we act as a controller.
2. Data we collect
- Account
- Your name, email, and authentication identifiers when you sign up (via email or Google).
- Workspace & team
- Workspace names, member roles, invitations, and access history.
- Connected ad data
- A mirror of the ad accounts you connect — campaigns, ad sets, ads, creatives, and settings — used to let you edit and publish.
- Creative uploads
- Images/videos you stage for new ads, held transiently and removed after publishing or a short sweep.
- Billing
- Handled by Stripe; we store your plan, subscription status, and a Stripe customer reference — not full card numbers.
- Usage & logs
- Actions in the app, an append-only audit log, sign-in events (method, IP, device), and error diagnostics.
3. How we use data
- to provide, secure, and improve the service;
- to read and, on your confirmation, write changes to your ad accounts;
- to process subscriptions and prevent abuse;
- to provide support (see “Support access” below);
- to comply with legal obligations.
We do not sell your data, and we do not use your advertising data to train models or for our own advertising.
4. Meta platform data
When you connect a Meta ad account, we access it only through Meta’s official APIs and only to the extent you authorize. Access tokens are encrypted and are only ever handled by our background worker — never exposed to your browser or to other customers. We keep a mirror of your account structure to make editing fast; we do not read data from accounts you have not connected. Our use of information received from Meta’s APIs follows Meta’s Platform Terms and Developer Policies.
5. Subprocessors
We rely on a small set of vetted providers to run the service:
- Vercel
- Application hosting (no Meta tokens).
- Supabase
- Database, file storage, and authentication.
- Trigger.dev
- Background jobs — the only layer that handles a decrypted Meta token to talk to Meta.
- Stripe
- Billing and payments (billing identity only; no advertising data).
- Upstash
- Rate-limit counters (no advertiser content).
- Sentry
- Error monitoring, with tokens and personal data scrubbed before events are sent.
- Resend
- Transactional email, where enabled.
6. Support access
Our support staff can never sign in as you and cannot see your ad spend or performance. When they need to help, they open an audited, time-boxed “support view” that shows only your account structure and change history — never your credentials, budgets as performance, or personal messages. Every such access is recorded.
7. Retention & deletion
We keep data for as long as your account is active or as needed to provide the service. Creative uploads are transient. You can request deletion of your account and associated data at any time; see our Data Deletion page. Some records (e.g. the append-only audit log and billing records) may be retained where required for security or legal compliance.
8. Security
Access to your data is isolated per workspace and enforced at the database level. Meta tokens are encrypted at rest, and only trusted server processes can decrypt them. We log and monitor access, and scrub secrets and personal data from diagnostics.
9. Cookies
Paperplane uses only essential, first-party cookies to keep you signed in and remember interface preferences (such as your active workspace and sidebar state). We do not use third-party advertising or tracking cookies.
10. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to certain processing. To exercise them, contact us at the address below. Because much of the connected ad data is controlled by you, some requests are best made from within your workspace.
11. Changes & contact
We may update this policy; material changes will be posted here with a new date. Questions or requests? Contact phueledmedia@gmail.com.