Last updated 15 September 2026
Privacy policy
This policy explains what data Limechop processes, why, on what legal basis, who we share it with, how long we keep it, and how you can exercise your rights. It applies to the website limechop.com and the application at app.limechop.com (together, “Limechop”), including our use of Meta's Marketing API through Facebook Login for Business.
1. Who is responsible
The data controller is Brandrip MB, a company registered in Lithuania (company code [company code — fill in]), [registered address — fill in]. Privacy questions and requests: privacy@limechop.com. We have not appointed a Data Protection Officer; the contact above handles all privacy matters and responds within one month.
2. What Limechop does
Limechop reads competitors' advertisements from public advertising transparency libraries (Meta Ad Library, Google Ads Transparency Center, TikTok Commercial Content Library), analyses which ads keep running, decodes the creative angle of those ads, generates new draft advertisements for your business, and — if you connect your Meta ad account — creates those drafts in your account in a paused state. Limechop never publishes or activates an ad on your behalf.
3. The data we process
| Category | Examples | Source |
|---|---|---|
| Account data | Email address, name, password hash or login token, brand name and description you enter | You |
| Meta data (Facebook Login for Business) | App-scoped user ID, business ID, ad account IDs and names, Page IDs and names, Instagram account ID, and an access token (stored encrypted); ad-account currency and status | Meta, with your authorisation |
| Ads we create for you | Draft campaigns, ad sets, creatives and ads created in your ad account, and their IDs | Generated by Limechop, stored in your Meta account and ours |
| Public ad-library data | Advertisements published by third-party advertisers in public transparency libraries: creative text, images, start/end dates, disclosed reach ranges, advertiser name and Page ID | Meta, Google and TikTok public libraries |
| Product truth and style | What your product is and offers, tone-of-voice and visual style choices | You |
| Usage data | Pages visited, actions taken in the app, timestamps; server logs (IP address, user agent) | Your device |
| Early-access signups | Email address | You |
| Correspondence | Emails you send us | You |
4. Why, and on what legal basis
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Providing the service: watching the advertisers you choose, scoring their ads, generating your drafts, creating paused drafts in your Meta account | Account, Meta data, ads we create, product truth | Contract — Art. 6(1)(b) |
| Reading and analysing public advertising-library data | Public ad-library data | Legitimate interest — Art. 6(1)(f): the data is published by law for transparency; our analysis does not target the individuals appearing in ads |
| Generating drafts with a language model | Product truth, style, and the decoded angle of public ads | Contract — Art. 6(1)(b) |
| Security, abuse prevention, debugging | Usage data, logs | Legitimate interest — Art. 6(1)(f) |
| Product analytics (cookieless, aggregated) | Usage data | Legitimate interest — Art. 6(1)(f) |
| Early-access and product emails | Email address | Consent — Art. 6(1)(a); withdraw any time via the link in each email |
| Accounting and legal obligations | Billing records (when paid plans exist) | Legal obligation — Art. 6(1)(c) |
5. How we use Meta data specifically
- We request the permissions
ads_management,ads_read,pages_show_list,pages_read_engagementandbusiness_management. They are used only to list your ad accounts and Pages so you can choose one, to create draft ads in the account you chose, and to read the performance of the ads Limechop created. - Your access token is stored encrypted (AES-256-GCM) on servers in Germany and is never shown to you or anyone else after you connect. It is deleted when you disconnect Meta in Settings, delete your account, or after 90 days without use.
- Every draft is created paused. Limechop does not activate ads, change budgets of running ads, or spend money. You control activation in Meta Ads Manager.
- We do not sell, rent or share Meta data with third parties, and do not use it for advertising of our own.
- Our use of Meta data is governed by the Meta Platform Terms and Developer Policies.
6. Who we share data with (processors)
| Provider | Role | Location · safeguard |
|---|---|---|
| Hetzner Online GmbH | Application hosting | Germany (EU) |
| Supabase | Database, file storage | EU region · Data Processing Agreement |
| Anthropic PBC | Language model that decodes ad angles and writes drafts | United States · EU Standard Contractual Clauses and EU-US Data Privacy Framework; inputs are not used to train models |
| Apify | Reading public advertising libraries | Czech Republic (EU) |
| Meta Platforms Ireland Ltd | Source of your ad-account data and destination of drafts | Ireland (EU) |
| Vercel Inc. | Website hosting and cookieless analytics | United States · EU-US Data Privacy Framework |
| Resend | Transactional email | United States · Standard Contractual Clauses |
Where a provider is outside the EU, transfers rely on the safeguard listed. We do not share personal data with anyone else unless required by law.
7. How long we keep data
- Meta access tokens: until you disconnect, delete your account, or 90 days without use — whichever comes first.
- Ad-account, Page and draft references: for as long as your account exists, then 30 days.
- Public ad-library data: up to 24 months, for longevity analysis; it concerns advertisers, not you.
- Account data: 30 days after you delete your account (immediate removal from live systems; backups expire within 90 days).
- Server logs: 90 days. Early-access emails: until you unsubscribe or 24 months of inactivity.
8. Your rights
You can access, correct, export, restrict or delete your data, object to processing based on legitimate interest, and withdraw consent at any time. Email privacy@limechop.com; we answer within one month. In the app you can disconnect Meta and delete your account yourself, with immediate effect (see section 9). You may complain to the Lithuanian State Data Protection Inspectorate (VDAI), L. Sapiegos g. 17, LT-10312 Vilnius, ada@ada.lt, or to your local supervisory authority.
9. Deleting your data
You can have every piece of data Limechop holds about you deleted — including everything obtained from Meta — at no cost, from any country, in one of three ways.
Delete it yourself, immediately
- Disconnect Meta: in app.limechop.com → Settings → Meta ads → Disconnect. This deletes your access token, the list of your ad accounts and Pages, and the references to drafts we created. It takes effect immediately.
- Delete your account: Settings → Brands → Delete. This removes the brand, its drafts, product truth, style settings and Meta connection.
Drafts already created in your Meta ad account remain there, because they are yours; delete them in Meta Ads Manager if you wish.
Ask us
Email privacy@limechop.com from the address on your account (or, for Meta data, mention the business or Page you connected). We confirm receipt within 3 working days and complete deletion within 30 days. Backups expire within a further 60 days.
Requests that arrive through Meta
If you remove Limechop from your Facebook or Business settings, Meta sends us a deletion request. We record it, delete the associated data, and provide a status page at limechop.com/deletion-status/<confirmation code>, which Meta shows you. The same 30-day timeline applies.
What gets deleted
- Your Meta access token (encrypted at rest until then)
- Ad-account, Page, Instagram and business identifiers and names
- Draft ads and their creatives stored by Limechop, and their references to your Meta account
- Your account, brand profile, product truth, style and voice settings
- Usage data tied to your account
What we keep: records we are legally required to retain (for paid accounts, invoices for the statutory period), and public advertising-library data about third-party advertisers, which does not concern you personally.
10. Automated processing
A language model decodes the angle of public ads and writes draft copy. This produces suggestions for you to review; it makes no decision with legal or similarly significant effects about any person (Art. 22 does not apply).
11. Security
Tokens are encrypted at rest; access to production systems is restricted and logged; data moves only over TLS. To report a vulnerability, email security@limechop.com — see Security.
12. Cookies
limechop.com uses cookieless, aggregated analytics and sets no tracking cookies, so no consent banner is shown. app.limechop.com sets one strictly necessary session cookie to keep you signed in.
13. Changes
We'll post changes here with a new date. Material changes to how we use Meta data will be announced in the app before they take effect.