// LEGAL

Privacy Policy

Last updated: 21 July 2026

This Privacy Policy explains how AdSnoop ("AdSnoop", "we", "us", or "our") collects, uses, shares, and protects personal data when you visit adsnoop.app or use our competitive ad-intelligence service (the "Service"). It should be read together with our Terms of Service. It also describes the rights you have over your personal data and how to exercise them.

AdSnoop is operated by Alwyn Ventures (the "Company"). For the purposes of the EU/UK General Data Protection Regulation (GDPR) and India's Digital Personal Data Protection Act, 2023 (DPDP Act), the Company is the data controller / Data Fiduciary responsible for your personal data. If you have any questions, contact us at admin@alwynventures.com.

  1. Information we collect
  2. Where it comes from
  3. How we use information
  4. Legal bases (GDPR)
  5. Cookies & tracking
  6. How we share information
  7. International transfers
  8. Data retention
  9. Security
  10. Your rights
  11. Children's privacy
  12. Automated processing
  13. Changes to this policy
  14. Contact & grievances

1. Information we collect

We collect the following categories of personal data:

Account data

When you create an account, we collect your name, email address, and authentication credentials (such as a hashed password or a sign-in identifier from a single sign-on provider). We may also store your account settings and preferences.

Subscription & billing data

If you purchase a paid plan or credits, our third-party payment processor collects and processes your payment details (such as card or payment-instrument information) directly. We do not store full card numbers on our systems. We retain limited billing records such as your plan, transaction identifiers, billing status, amounts, and invoices.

User-provided inputs

To operate the Service, you provide inputs such as competitor App Store URLs, brand names, brand colors, characters, calls-to-action, and any brand assets or creative material you upload or enter. These inputs are used to generate your results.

Usage & activity data

We collect data about how you interact with the Service — for example, the runs you initiate, credits consumed, features used, log and diagnostic events, approximate location derived from your IP address, device and browser type, and referring pages.

Cookies & session data

We use cookies, session tokens, and similar technologies to keep you signed in, remember preferences, secure the Service, and understand usage. See Cookies & tracking.

Communications

If you contact us for support or otherwise correspond with us, we keep a record of that communication and its contents.

2. Where it comes from

Most personal data comes directly from you when you register, subscribe, or use the Service. Some data (such as usage, device, and log data) is generated automatically as you interact with the Service. Limited billing confirmation data is received from our payment processor.

Separately, the Service analyzes publicly available advertising data — competitor advertising that is published through public advertising-transparency sources. This advertising material is created and published by third parties, is publicly accessible, and is analyzed by the Service for its format, structure, and creative patterns. We are not the source of that advertising and are not affiliated with the platforms on which it appears.

3. How we use information

We use personal data to:

We do not use your uploaded brand assets or private inputs to build or market products for other customers.

4. Legal bases for processing (GDPR)

Where the GDPR applies, we rely on the following legal bases:

PurposeLegal basis
Creating your account and delivering the ServicePerformance of a contract (Art. 6(1)(b))
Billing, renewals, and tax/accounting recordsContract and legal obligation (Art. 6(1)(b),(c))
Security, fraud prevention, and service improvementLegitimate interests (Art. 6(1)(f))
Analytics and non-essential cookiesConsent (Art. 6(1)(a)), where required
Marketing communicationsConsent or legitimate interests, as applicable
Meeting legal and regulatory obligationsLegal obligation (Art. 6(1)(c))

Where we rely on legitimate interests, we balance those interests against your rights and freedoms. You may object to such processing as described in Your rights.

5. Cookies & tracking

We use a small number of cookies and similar technologies:

You can control cookies through your browser settings and, where offered, through our cookie controls. Blocking strictly necessary cookies may prevent parts of the Service from working. We honor recognized opt-out signals (such as Global Privacy Control) where legally required.

6. How we share information

We do not sell your personal data. We share personal data only in the following circumstances:

Our service providers are bound by confidentiality and data-protection obligations and are not permitted to use your personal data for their own purposes.

7. International data transfers

We and our service providers may process personal data in countries other than the one in which you reside, including countries that may not provide the same level of data protection as your home jurisdiction. Where we transfer personal data internationally, we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), transfers to jurisdictions recognized as providing adequate protection, or other lawful transfer mechanisms. You may contact us for more information about these safeguards.

8. Data retention

We keep personal data for as long as needed to provide the Service and for the purposes described in this Policy. In general:

When personal data is no longer needed, we delete it or irreversibly anonymize it. Specific retention periods are set out in our internal retention schedule and applied consistently across the categories above; where the law prescribes a minimum retention period (for example, for tax and accounting records), we retain the relevant data for that period.

9. Security

We implement reasonable technical and organizational measures designed to protect personal data — including encryption in transit, access controls, authentication safeguards, and monitoring. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a personal-data breach that affects you, we will notify you and the relevant authorities as required by applicable law.

10. Your rights

EU / UK (GDPR)

Subject to conditions and exceptions in the law, you have the right to: access your personal data; rectify inaccurate data; request erasure; restrict or object to processing; request data portability; and withdraw consent at any time (without affecting prior processing). You also have the right to lodge a complaint with your local supervisory authority.

California (CCPA / CPRA)

If you are a California resident, you have the right to know what personal information we collect and how we use and disclose it; to access and delete it; to correct inaccurate information; and to opt out of the "sale" or "sharing" of personal information and to limit the use of sensitive personal information. We do not sell your personal information and do not "share" it for cross-context behavioral advertising as those terms are defined under California law. We will not discriminate against you for exercising your rights.

India (DPDP Act, 2023)

If you are in India, you have the right to access a summary of your personal data and our processing, including the identities of other Data Fiduciaries and Data Processors with whom it has been shared; to correction, completion, updating, and erasure of your personal data; to grievance redressal through the mechanism described in Contact & grievances (which you should use before approaching the Data Protection Board of India); and to nominate another individual to exercise your rights in the event of your death or incapacity. We process personal data on the basis of your consent or the legitimate uses permitted under the DPDP Act, and you may withdraw consent at any time with the same ease as it was given (withdrawal does not affect processing carried out before withdrawal). Where consent is managed through a Consent Manager registered with the Board, you may give, manage, review, and withdraw consent through that mechanism.

How to exercise your rights

To make a request, email admin@alwynventures.com. We will verify your identity and respond within the timeframes required by applicable law. You may use an authorized agent where the law permits. There is no charge for a reasonable request.

11. Children's privacy

The Service is a business tool intended for adults and is not directed to children. We do not knowingly collect personal data from anyone under 18 years of age (or the applicable age of digital consent in your jurisdiction, such as 16 in parts of the EU). If you believe a child has provided us personal data, contact us and we will delete it. Where the DPDP Act applies, we do not knowingly process children's data without verifiable parental consent or engage in tracking, behavioral monitoring, or targeted advertising directed at children.

12. Automated processing

The Service uses AI/automated processing to analyze publicly available advertising data and to generate creative suggestions and other outputs. This processing supports the features you request and does not produce legal or similarly significant decisions about you. Generated outputs are suggestions for your review; you decide how to use them.

13. Changes to this policy

We may update this Policy from time to time. When we make material changes, we will update the "Last updated" date and, where appropriate, notify you through the Service or by email. Your continued use of the Service after an update means you accept the revised Policy.

14. Contact & grievances

For privacy questions or to exercise your rights, contact:

AdSnoop — Alwyn Ventures
Alwyn Ventures, Delhi, India
Email: admin@alwynventures.com

Grievance Officer (India / DPDP Act). If you are in India, you may address grievances to our Grievance Officer at admin@alwynventures.com. We will acknowledge and respond to your grievance within the timeframes prescribed under the DPDP Act and the rules made under it. If you are not satisfied with our response, or if we fail to respond within the prescribed period, you may escalate to the Data Protection Board of India. EU/UK users may also lodge a complaint with their local supervisory authority.

Questions about this policy? Contact admin@alwynventures.com.