lime/chop

Last updated 15 September 2026

Privacy policy

This policy explains what data Limechop processes, why, on what legal basis, who we share it with, how long we keep it, and how you can exercise your rights. It applies to the website limechop.com and the application at app.limechop.com (together, “Limechop”), including our use of Meta's Marketing API through Facebook Login for Business.

1. Who is responsible

The data controller is Brandrip MB, a company registered in Lithuania (company code [company code — fill in]), [registered address — fill in]. Privacy questions and requests: privacy@limechop.com. We have not appointed a Data Protection Officer; the contact above handles all privacy matters and responds within one month.

2. What Limechop does

Limechop reads competitors' advertisements from public advertising transparency libraries (Meta Ad Library, Google Ads Transparency Center, TikTok Commercial Content Library), analyses which ads keep running, decodes the creative angle of those ads, generates new draft advertisements for your business, and — if you connect your Meta ad account — creates those drafts in your account in a paused state. Limechop never publishes or activates an ad on your behalf.

3. The data we process

CategoryExamplesSource
Account dataEmail address, name, password hash or login token, brand name and description you enterYou
Meta data (Facebook Login for Business)App-scoped user ID, business ID, ad account IDs and names, Page IDs and names, Instagram account ID, and an access token (stored encrypted); ad-account currency and statusMeta, with your authorisation
Ads we create for youDraft campaigns, ad sets, creatives and ads created in your ad account, and their IDsGenerated by Limechop, stored in your Meta account and ours
Public ad-library dataAdvertisements published by third-party advertisers in public transparency libraries: creative text, images, start/end dates, disclosed reach ranges, advertiser name and Page IDMeta, Google and TikTok public libraries
Product truth and styleWhat your product is and offers, tone-of-voice and visual style choicesYou
Usage dataPages visited, actions taken in the app, timestamps; server logs (IP address, user agent)Your device
Early-access signupsEmail addressYou
CorrespondenceEmails you send usYou

4. Why, and on what legal basis

PurposeDataLegal basis (GDPR)
Providing the service: watching the advertisers you choose, scoring their ads, generating your drafts, creating paused drafts in your Meta accountAccount, Meta data, ads we create, product truthContract — Art. 6(1)(b)
Reading and analysing public advertising-library dataPublic ad-library dataLegitimate interest — Art. 6(1)(f): the data is published by law for transparency; our analysis does not target the individuals appearing in ads
Generating drafts with a language modelProduct truth, style, and the decoded angle of public adsContract — Art. 6(1)(b)
Security, abuse prevention, debuggingUsage data, logsLegitimate interest — Art. 6(1)(f)
Product analytics (cookieless, aggregated)Usage dataLegitimate interest — Art. 6(1)(f)
Early-access and product emailsEmail addressConsent — Art. 6(1)(a); withdraw any time via the link in each email
Accounting and legal obligationsBilling records (when paid plans exist)Legal obligation — Art. 6(1)(c)

5. How we use Meta data specifically

6. Who we share data with (processors)

ProviderRoleLocation · safeguard
Hetzner Online GmbHApplication hostingGermany (EU)
SupabaseDatabase, file storageEU region · Data Processing Agreement
Anthropic PBCLanguage model that decodes ad angles and writes draftsUnited States · EU Standard Contractual Clauses and EU-US Data Privacy Framework; inputs are not used to train models
ApifyReading public advertising librariesCzech Republic (EU)
Meta Platforms Ireland LtdSource of your ad-account data and destination of draftsIreland (EU)
Vercel Inc.Website hosting and cookieless analyticsUnited States · EU-US Data Privacy Framework
ResendTransactional emailUnited States · Standard Contractual Clauses

Where a provider is outside the EU, transfers rely on the safeguard listed. We do not share personal data with anyone else unless required by law.

7. How long we keep data

8. Your rights

You can access, correct, export, restrict or delete your data, object to processing based on legitimate interest, and withdraw consent at any time. Email privacy@limechop.com; we answer within one month. In the app you can disconnect Meta and delete your account yourself, with immediate effect (see section 9). You may complain to the Lithuanian State Data Protection Inspectorate (VDAI), L. Sapiegos g. 17, LT-10312 Vilnius, ada@ada.lt, or to your local supervisory authority.

9. Deleting your data

You can have every piece of data Limechop holds about you deleted — including everything obtained from Meta — at no cost, from any country, in one of three ways.

Delete it yourself, immediately

Drafts already created in your Meta ad account remain there, because they are yours; delete them in Meta Ads Manager if you wish.

Ask us

Email privacy@limechop.com from the address on your account (or, for Meta data, mention the business or Page you connected). We confirm receipt within 3 working days and complete deletion within 30 days. Backups expire within a further 60 days.

Requests that arrive through Meta

If you remove Limechop from your Facebook or Business settings, Meta sends us a deletion request. We record it, delete the associated data, and provide a status page at limechop.com/deletion-status/<confirmation code>, which Meta shows you. The same 30-day timeline applies.

What gets deleted

What we keep: records we are legally required to retain (for paid accounts, invoices for the statutory period), and public advertising-library data about third-party advertisers, which does not concern you personally.

10. Automated processing

A language model decodes the angle of public ads and writes draft copy. This produces suggestions for you to review; it makes no decision with legal or similarly significant effects about any person (Art. 22 does not apply).

11. Security

Tokens are encrypted at rest; access to production systems is restricted and logged; data moves only over TLS. To report a vulnerability, email security@limechop.com — see Security.

12. Cookies

limechop.com uses cookieless, aggregated analytics and sets no tracking cookies, so no consent banner is shown. app.limechop.com sets one strictly necessary session cookie to keep you signed in.

13. Changes

We'll post changes here with a new date. Material changes to how we use Meta data will be announced in the app before they take effect.