Privacy Policy for Ad finder

Privacy Policy for the Coming Soon Ad finder app: anonymous authentication, local storage, providers, subscriptions, opt-in analytics and privacy rights.

Scope, status and controller

Last updated: October 7, 2026. Ad finder is Coming Soon for iOS and Android. This policy describes its intended public-release practices, not a claim that the pre-release build already implements every launch requirement. Sharply Labs Ltd., Tel Aviv, Israel, is the controller and operator. Contact hello@sharplylabs.com. Storez LLC, 30 North Gould Street, Sheridan, WY 82801, United States, supports U.S. operations and billing and may be the contracting entity where applicable and identified in checkout or order documentation. Sharply Labs Ltd. remains the app operator.

What the app handles

Ad finder helps marketers and creative teams find public Meta ads, save references into collections, and download available creative assets into an on-device library. Collections, saved-ad metadata and downloaded creative assets are stored locally on your device. Public ad content may still contain personal information or third-party rights; public visibility does not remove those protections. Requests to retrieve public ads are processed through the backend and its service providers.

Anonymous identity and backend processing

The app uses Firebase anonymous authentication only, with no email/password account. An anonymous Firebase user ID supports service access, credit accounting, subscription entitlements and security; anonymous authentication does not mean that all associated information is unidentifiable. Google Firebase and Google Cloud provide the backend. Firestore and callable/scheduled functions are configured in europe-west3. This configuration is not a guarantee that every provider or every data item stays in Germany or the EEA. Request-ledger records and operational/security metadata support reliable requests, credit reconciliation and abuse prevention.

Public ad retrieval and ScrapeCreators

ScrapeCreators is called through the backend, and its API key remains server-side. It may process public ad URLs/content and request or operational metadata under its own privacy policy. This processing is used to retrieve available public ad information and creative assets. Local collections and downloaded assets are distinct from the public content and request information processed to fulfil a retrieval request.

Subscriptions and store services

RevenueCat manages subscriptions and entitlements and receives the Firebase user ID to associate purchase status with the anonymous identity. If optional analytics is enabled after opt-in, RevenueCat may also receive the Firebase App Instance ID for attribution. Opting out removes that analytics identifier from subsequent sync where supported. Purchases and store-related processing are subject to Apple App Store or Google Play services and their policies. The app is Coming Soon; its public store and payment lifecycle remains subject to launch validation. Billing and accounting information may be processed by the applicable store, RevenueCat, and the relevant operations or billing entity as needed.

Optional analytics: public-release requirements

For the public release, optional Firebase Analytics/GA4 must be OFF by default and collect only after explicit opt-in. This is the policy and requirement for release, not a statement that the current pre-release build already implements it. RevenueCat-to-GA4 billing events are disabled at launch. Optional analytics is used to understand app usage and improve the experience and may involve app-instance identifiers, usage events and SDK device or technical metadata under Google's policies. Analytics must not intentionally include search text, pasted URLs, collection names or downloaded creative content. Information needed to fulfil an ad retrieval request is separate from optional analytics.

Purposes and legal bases

We process information to provide requested ad retrieval, maintain anonymous service access and credits, validate entitlements, address support requests, protect the service, and meet legal obligations. Where data protection law requires a legal basis, service and purchase processing relies on performance of a contract or steps you request before a contract; optional analytics relies on consent; operational security and abuse prevention rely on legitimate interests, subject to the required balancing of your rights; and legally required recordkeeping relies on legal obligations. We use information only as needed for these purposes and do not treat analytics consent as permission to include your research or creative content in analytics.

Recipients and international transfers

Recipients may include Google/Firebase/Google Cloud, RevenueCat, ScrapeCreators, Apple or Google store services, the applicable operations/billing entity, and advisers or authorities where necessary for support, security or law. Providers process information under their own terms and policies. Processing may take place outside your country, including outside the EEA. Where applicable law requires transfer safeguards, we use the applicable lawful transfer mechanism, such as contractual safeguards or a recognized adequacy framework, as appropriate to the provider and transfer. You can request further information about applicable safeguards at hello@sharplylabs.com; no specific geographic storage guarantee is made.

Retention

Request-ledger records are targeted for deletion about 24 hours after creation using asynchronous TTL; deletion may not be instantaneous. Operational/security logs normally remain no longer than 30 days, with longer retention only for an active incident or legal need. GA4 data follows the shortest practical configured retention and Google's policies. Anonymous identity and entitlement records remain only as needed for service, purchase lifecycle, fraud/security or law. Support messages remain until resolved plus reasonable follow-up or legal needs. Billing/accounting records remain as required by law. Locally stored content remains under your device's storage controls; deleting local content does not automatically delete provider records or cancel a subscription.

Your choices, access and deletion

For the public release, you may decline optional analytics and withdraw consent for future optional collection. Opting out removes the analytics identifier from subsequent RevenueCat sync where supported; it does not itself erase data already held by providers. You can manage locally stored collections and assets on your device and manage subscriptions through the relevant store. Send access, correction or deletion requests to hello@sharplylabs.com. Because identity is anonymous, we may need information sufficient to locate and verify the relevant records; do not send passwords or payment-card details. We respond under applicable law, with lawful identity-verification and retention limits rather than a promise of immediate deletion. Depending on your location, rights may include access, correction, deletion, restriction, objection, portability, withdrawal of consent, and complaint to a competent data protection authority. Withdrawal does not affect the lawfulness of earlier consent-based processing.

Security

We use appropriate technical and organizational measures designed to protect information, including keeping the ScrapeCreators API key server-side. No method of transmission, backend processing or device storage is absolutely secure. You are responsible for protecting your device and any locally stored or exported content. We do not promise absolute security or recovery of deleted local files.

Children's privacy

Ad finder is intended only for people aged 18 or older. It is not directed to children, and we do not knowingly collect children's information. If you believe a person under 18 has provided information, contact hello@sharplylabs.com so we can investigate and take appropriate action.

Changes and contact

We may update this policy as the app approaches public release or as practices, providers or legal requirements change. We will publish the revised policy with an updated date and provide additional notice or obtain consent where required. Questions, rights requests and privacy concerns should be sent to hello@sharplylabs.com, for Sharply Labs Ltd., Tel Aviv, Israel.