Privacy policy
Who provides KyvAds
KyvAds is a product of Keyve Digital Company LTDA, registered under CNPJ 67.791.669/0001-10, responsible for the platform and personal data processing described in these documents.
Business address: Curitibanos - SC
Support: [email protected]
Privacy: [email protected]
1. Scope
This policy describes data processing in the KyvAds platform and Chrome extension. The Keyve Digital Company LTDA is responsible for processing necessary to provide the product. This version distinguishes data sent to the server from the library that remains in the browser.
2. Data used
- Account and access: name, email, phone and phone country, hashed password, information needed to verify access, sessions, extension linking and previously authorized devices. Phone country does not necessarily indicate residence. Phone numbers are not considered verified without specific confirmation.
- Profile and welcome: profile photo voluntarily uploaded, self-reported discovery source for KyvAds and, when provided, professional profile and usage goal. Welcome progress and acknowledgment or acceptance of legal document versions are recorded.
- Plan and usage: permissions, grants, validity, quotas, operation reservations and completions. References needed to deduplicate downloads do not constitute synchronization of the entire library.
- Financial: customer, subscription, invoice and payment identifiers, currency and amounts, cancellations, refunds and disputes obtained from Stripe. Card data is provided in Stripe's payment environment.
- Support and communication: support messages, sound and notice preferences, communication authorizations and recorded interactions with KyvAds and partner ads or campaigns when those modules are in use. Providing a phone number or completing welcome does not authorize commercial communications.
- Operations and security: technical logs, failures, administrative changes and audits needed for operation and account protection.
3. Local library
A copy of saved ads, organization and backups is kept locally by the extension. With an account connected and storage activated, new saves send ad data and available creatives to the account's web Library. Existing libraries require a preview and confirmation before import. Content voluntarily sent to support is handled according to the request.
Synchronization includes copy, CTA, links, advertiser data and available image and video files. Media is stored privately and provided with account authorization. Favorites and removals sync both ways. Uploads can be paused; disconnection stops new transmissions and preserves the library. Removing an ad removes its link to the account's library. Personal identity and organization are not published to other users. Reinstalling or clearing the browser may remove local data; keep backups.
4. Purposes and grounds
Data is used to provide accounts and contracted tools, authenticate access, check permissions and quotas, process payments, provide support, protect the service and meet legal obligations. Processing considers contract performance, legal obligations, exercise of rights and other grounds applicable to the purpose, respecting data subject rights.
Your photo identifies you within your account. Welcome answers help understand the audience and improve the experience; acquisition source is self-reported without tracking that proves attribution. Optional fields may be left unanswered.
Optional commercial communications depend on corresponding preferences and authorizations. You may withdraw authorization without interrupting necessary access or support emails. Administrative acquisition, usage and retention indicators are aggregated; they do not prove performance of researched ads.
5. Providers and sharing
Operations use infrastructure and processing providers: Stripe for payments, Resend for emails and Cloudflare for bot protection, public file distribution and configured storage. Data necessary for the service may be processed by these providers according to the function used.
Logos, images and public files distributed through the CDN are separate from private storage. Profile photos are in private storage and displayed only after account authorization, without a public CDN address. This does not make the local library public. Displaying partner campaigns does not itself authorize giving partners your ad list or account information.
Providers may operate outside Brazil. Processing and international transfers must comply with the LGPD and applicable conditions. Their services have their own privacy information: Stripe, Resend and Cloudflare.
6. Cookies and browser storage
The platform uses cookies and storage necessary for sessions, form protection, preferences and authorized device recognition. The extension uses local storage for its library and access credentials in a protected context. Removing this data may require a new login or affect local information.
Bot verification is performed by Cloudflare Turnstile, which processes technical signals according to its service. KyvAds does not create device fingerprints to enforce account blocking. Links to third-party sites are subject to those sites' terms.
Traffic source measurement
When enabled, KyvAds records visits, referring sources and campaign UTM parameters to understand acquisition. Measurement uses the existing session, without fingerprinting or an additional permanent analytics cookie; IP addresses, form data and full URLs are not stored in this data set.
Detailed visits and registration links are retained for up to 90 days; aggregated daily totals for up to 365 days. Registration attribution uses up to 30 days, limited by browser session availability.
You can disable this measurement for this session. Do Not Track and Global Privacy Control signals also disable it. This choice controls only KyvAds first-party source measurement; it does not automatically change administrator-configured third-party pixels and scripts.
7. Retention and protection
Account and operation data is retained as long as needed for the stated purposes. Financial, support and audit records may need retention for legal obligations or exercise of rights, even after account closure. Local information is managed through the user's browser and backups.
Authentication, authorization, credential protection and storage separation controls are used. Absolute security is not guaranteed; report suspected unauthorized access to support.
8. Your rights and choices
You may request confirmation of processing, access, correction, information about sharing and other rights under the LGPD, including deletion, anonymization, blocking or portability when applicable. You may also withdraw consent and object to processing in situations provided by law.
Communication preferences can be changed in your account. Personal data requests should be sent to the privacy contact; we may request proportionate information to confirm ownership. Deletion may be limited by legal obligations or the need to exercise rights, which must be explained in the response.
9. Updates
The published version identifies this policy's date. Relevant changes to purposes, sharing or features must be communicated to users. This policy must reflect the product's actual operation and provider settings.
Contact
Account holders can open a support ticket for questions, cancellation, refund or privacy requests.
For personal data requests, including without account access, write to [email protected].
