Privacy policy
Written in plain language on purpose. If anything here is unclear, email hello@athillyads.com and we'll explain — and then fix the wording.
Last updated: 31 August 2026
Who is responsible
AthillyAds is operated by Ampthilly AB, organisationsnummer 559588-0724, with registered office at Bjännberg 121, 905 72 Hörnefors, Sweden. For everything described on this page, Ampthilly AB is the data controller — except for the business content you put into the platform (your pages, campaigns, product feeds), which we process on your instructions, as a processor. Privacy questions go to hello@athillyads.com.
This website
The marketing site you're reading loads no analytics or advertising script until you say it may. Not loaded and then told to behave — never requested at all, so nothing about your visit reaches a third party before you have answered. Decline and the only cookie left is the one remembering that you declined. Change your mind later and every cookie the category had set is deleted on the spot.
Our hosting provider (Cloudflare) processes standard technical request data — IP address, user agent — to serve pages and protect against abuse, as every host does.
Cookies this site can set
| Cookie | Set by | What it does | Kept for |
|---|---|---|---|
aa_consent | AthillyAds | Remembers the answer you gave about cookies, so we stop asking. | 180 days |
__cf_bm | Cloudflare | Tells people from bots, so the site is not swamped by automated requests. | 30 minutes |
cf_clearance | Cloudflare Turnstile | Records that the check on the free tool was passed, so you are not asked again on the next page. | Up to 30 minutes |
_ga, _ga_* | Google Analytics | Counts visits and tells a returning reader from a new one. Set only if you allow Analytics. | 2 years |
The Cloudflare cookies come from our host rather than from us; their exact names and lifetimes are listed in Cloudflare's own cookie documentation. Turn a category off and every cookie it set is deleted on the spot.
The free hint generator
When you use the context hint generator, the page URL you submit — and any optional business context you type in — is sent to our API, which fetches that page and generates the result. We keep a log of these requests: the URL, the context fields, the generated response, and technical details like timing. This log is what lets us find and fix pages the tool handles badly.
Your IP address is used for rate limiting and stored only in hashed form, and those hashes are deleted after 90 days. The tool is protected by Cloudflare Turnstile, which may set a functional cookie strictly to tell humans from bots — it does not track you across sites.
The AthillyAds platform
When you create an account at app.athillyads.com, we store what the service needs to work: your email and name, your organization and team members, the websites and pages you connect, the content we read from them, the brand profiles, campaigns and ads we generate, and — if you connect one — your ChatGPT Ads API key, which is encrypted and never leaves our backend.
Images from your website are only collected and stored if you explicitly confirm the site is yours and grant permission — and that permission can be withdrawn in Settings, which deletes every image we collected.
Where your data lives, and who helps us process it
We aim to store and process personal data within the European Economic Area: the database and file storage run in an EU region, and we are a Swedish company, so GDPR is the frame we operate in. Delivering the service also involves a small set of subprocessors, some of which may process data outside the EEA under EU Standard Contractual Clauses:
- Cloudflare — this website, bot protection, DNS
- Vercel — application hosting
- Supabase — database, authentication and file storage (EU region)
- Trigger.dev — background jobs (site reads, campaign generation)
- OpenRouter — routing to the AI models that write brand profiles, hints and copy
- ScraperAPI — fallback fetching for pages that block ordinary readers
- Stripe — payments (we never see or store your card number)
- Resend — transactional email
We send subprocessors only what they need to do their job, and none of them may use your data for their own purposes.
What we don't do
- We don't sell or rent your data. To anyone, for anything.
- We don't use your private business data to advertise to others.
- Cross-customer benchmarks are aggregated and anonymized — a data point is only published once enough separate accounts stand behind it that nothing can be traced back to any one of them.
Your rights
Under GDPR you can ask for access to your data, have it corrected, exported or deleted, restrict or object to processing, and withdraw any consent you've given. Email hello@athillyads.com and we handle it. You can also lodge a complaint with a supervisory authority — in Sweden, IMY (Integritetsskyddsmyndigheten).
Retention and deletion
Delete your account and we delete the personal data associated with it, keeping only what bookkeeping law requires us to keep (billing records, up to seven years) and anonymous aggregates that identify nobody. Free-tool request logs keep their hashed IP for 90 days, as above.
Changes
If this policy changes in a way that matters, we'll say so visibly on the site — not bury it in a diff.