Privacy policy
Last updated 2026-09-06
AdFigures is made by Raylabs. This page says what we collect, why, where it is kept, who can see it, and how to delete it. It is written in plain English on purpose. If anything is unclear, write tohello@raylabs.io.
What AdFigures does
AdFigures shows a business owner four numbers and one sentence about their ads, and sends a notification when a new lead or order lands. To do that it reads results from Meta (Facebook and Instagram ads) and Google Ads after you, or the agency that manages your ads, sign in and allow it. It only reads. It never changes an ad, a budget or a setting.
What we collect
Your account
Your email address, your name if you give it, and the one-time codes we email you to sign in. If you use Sign in with Apple, the identifier Apple gives us for your account.
Your phone
The push notification token Apple issues for the app on your device, your locale, and whether Live Activities are on. That is what lets us send a ping and nothing more.
Your advertising results
With your permission, from the Meta and Google Ads accounts connected to your workspace: account names and ids, campaign names, and daily figures such as amount spent, people reached, clicks, leads, orders and revenue. A lead notification carries the lead's name and which ad it came from, as the platform provides it.
Access tokens
When you sign in to Meta or Google, the platform issues an access token that lets AdFigures read on your behalf. Tokens are encrypted at rest with a key held outside the database. They are never sent to your phone.
Questions you ask
If you type a question into Ask, we keep the question and the numbers needed to answer it so we can show the answer and apply the daily limit.
Technical logs
Our hosting provider keeps short-lived request logs (IP address, path, timing, errors) so we can keep the service reliable and stop abuse.
AdFigures has no advertising trackers and no third-party analytics kit, on the website or in the app. We do not sell data, and we do not use your data for advertising.
Why we use it
- To show your numbers and the sentence about them.
- To send the notifications you turned on.
- To answer questions you ask.
- To email you sign-in codes and invitations.
- To keep the service secure and working.
- To meet legal duties, such as answering a lawful request.
Under the GDPR the legal bases are the contract with you (the first four points), our legitimate interest in a secure, reliable service (the fifth), and legal obligation (the sixth). Connecting a platform and turning on notifications are things you choose, and you can undo both at any time.
Google data
AdFigures' use and transfer of information received from Google APIs adheres to theGoogle API Services User Data Policy, including the Limited Use requirements. In practice: we only use your Google Ads data to show you your own numbers and notifications; we do not pass it to anyone except the providers named below, and only so they can run the service; we do not use it for advertising; and no person at Raylabs reads it unless you ask us to, it is needed for security, or the law requires it.
Meta data
Where an agency connects Meta on behalf of its clients, Raylabs acts as a technology provider for that agency under Meta's Platform Terms. Each client's data is kept in its own workspace and is never shown to another agency or another client.
Where it is kept and for how long
Everything is stored with Cloudflare in the European Union (Western Europe region) and encrypted in transit and at rest. We keep your data while your account and workspace exist. Then:
- Disconnecting a platform deletes its access token immediately.
- Deleting your account removes your sessions, devices and memberships, and replaces your email address with a placeholder so nothing can be linked back to you.
- Deleting a workspace removes its numbers and notification history.
- Backups expire within 30 days.
Who can see it
The people in your workspace: the agency staff who manage it and the owners they invited. And the providers that run parts of the service for us, each under a contract that limits them to that job:
- Cloudflare hosts the service and the database, in the European Union.
- Apple delivers push notifications to your iPhone.
- Resend sends the sign-in code and invitation emails.
- Anthropic writes the answers in Ask. It receives the question and the numbers needed to answer it, never your tokens, and does not use them to train its models.
Some of these providers process data in the United States under standard contractual clauses. We do not sell or rent data to anyone.
Your rights
You can ask for a copy of your data, correct it, delete it, or object to how we use it. You can withdraw a permission at any time by disconnecting a platform or deleting your account. To do any of this, use the app or write to hello@raylabs.io from the email address on your account. We answer within 30 days. If you are in the European Union you can also complain to your data protection authority. The delete your data page lists every way to remove data step by step.
Children
AdFigures is for businesses and is not meant for anyone under 18.
Changes
If this policy changes, the new version appears here with a new date at the top. If a change matters to you, we tell you in the app or by email first.