Adwright

[ Legal ]

Privacy Policy

Last updated October 10, 2026

This is a plain-language draft that describes how Adwright works today. It’s being reviewed and may change before launch.

The short version

We collect what we need to run your account, research your product, make your ads, bill you and keep the service working, and we record how Adwright is used so we can fix problems and improve it. To research a product we read public web pages: the one you paste, and your competitors’. We don’t sell your data, advertising and analytics tags only run if you allow them, and your full card number never reaches our servers. Where the law asks us to, we only record how you use Adwright once you allow it.

What we collect

DataWhy
Name, email address and a hashed passwordYour account, sign-in, and emails about your account
Your projects: the links you paste and the options you pick, the brand kit, the research and the ads, your edits, and pictures you uploadThe product itself. Kept until you delete the project or your account.
Card brand, last four digits, expiry, name on card and billing country/postcode; invoices and billing details you addBilling. The full card number and security code stay in your browser.
For each link you paste, what our crawler reads from that public page and a few more pages on the same site: the copy, prices, offers, ratings and the reviews quoted there, structured data, the colours, fonts and logo, and the pictures that could go in an ad. App Store links are read through Apple’s public lookup serviceResearching your product, building your brand kit and making your ads. The facts and the pictures we copy are kept with your project; the page itself is read in memory and dropped. See AdwrightBot for how the crawler behaves.
For competitor research: the public pages of the competitors you name or the research suggests, and, when it’s switched on, answers from an AI web search about your market and competitors’ ads from Meta’s Ad LibraryGrounding the research in what your market really says. A summary is kept in your project’s research, with its sources. Competitors’ pictures aren’t kept.
If you ask our crawler to stay away from your site: its domain, your email address and your noteKeeping the crawler away and replying to you. Kept as the record of your request while it’s in force.
For each browser you’re signed in on: its user agent (the browser, operating system and kind of device), its IP address with the last part hidden (like 203.0.113.x) and roughly where that is (a city, region and country)Showing your active sessions in Settings → Sign-in & security, so you can spot one you don’t recognise and sign it out. The full address is never kept with a session. The place is looked up on our own server, from a location database we keep there, so the address isn’t sent anywhere else. Signing a session out deletes it; one left alone expires 30 days after it was last used, and then the address and place are forgotten (the sign-in record, with its browser, stays until you delete your account). Places come from IP Geolocation by DB-IP.
A random device id in a cookie, wuizard_did, set the first time a browser opens sign-up, sign-in or the appStopping one person from taking more than one free trial. It identifies the browser, not you, and carries nothing else. At sign-up we keep a keyed hash of it, never the id itself.
Keyed hashes made at sign-up and when you save a card: of your email address (with dots and any +tag taken out), your IP address (for IPv6, just its network), the device id above and the card’s fingerprint from Stripe. With them, your email’s domain (like gmail.com), whether a free trial was allowed and, once the account is deleted, whether it had a trial or a plan with a confirmed email addressChecking for abuse, like a second free trial from the same person, browser, network or card. A keyed hash can’t be turned back into the address, network or card it came from. These are kept after you delete your account, so deleting it and signing up again doesn’t bring another free trial.
Notes about unusual activity on your account (like a burst of AI requests, scripted traffic, several sign-ups from one browser or network, or a request that tries to get round the AI guidelines), how many AI requests you made each day for the last 30 days, and any limit staff put on the accountSpotting abuse and protecting other customers. Staff may review the notes. All of it is deleted with your account.
Posts, comments, votes and reports on the feedback boardSharing and discussing ideas for Adwright. Posts and comments are public (to anyone, search engines included) with your account’s name; votes and reports aren’t. When you delete your account, your votes and any ban go, and your posts and comments stay without your name, as “Deleted account”, because other people’s replies and votes hang off them.
The images and animations you ask for: your descriptions and the filesMaking the media for your ads; kept so you can use them again until you delete them
What you ask the in-app assistant and what it did: its replies, the pages it opened, the controls it pressed (by their names), what it typed, and a description of the page it was working on with private fields left outShowing the assistant’s history in its panel and carrying on a request. Kept 30 days. You can clear it from the panel at any time, and it’s deleted with your account. The assistant never reads password, code, payment or key fields, or anything we mark private.
Page views on our public website: the page, the site that linked to it, and a visitor code made from your IP address and browser with a key we delete after two daysCounting visitors and which pages lead to sign-ups. We don’t store your IP address or browser, and can’t follow you from one day to the next. Skipped if your browser sends Do Not Track or Global Privacy Control.
Session recordings inside the signed-in app: the pages you visit and what you click and scroll. What you type into fields, your chats with the assistant and your prompts are hidden, and card details and anything we mark private are never recordedFinding and fixing problems people run into. Deleted after 30 days. Off if you opt out in Settings → Privacy & data, or if your browser sends Do Not Track or Global Privacy Control. Where consent is needed (see Analytics), only once you allow it.
How you use Adwright, in the app and on our website: the pages you open, the buttons and links you press, the forms you send (the names of their fields, never what you type), AI requests, billing changes and errors. With each: when, your IP address and the place it’s in, your browser, operating system and kind of device, and the version of AdwrightMeasuring what works, fixing problems and keeping the service secure. It’s first-party: it stays with us and is never sold or shared. Kept 13 months, the full IP address only 30 days. For an account it’s off if you opt out in Settings → Privacy & data (Do Not Track doesn’t change it). Signed-out visitors are skipped if the browser sends Do Not Track or Global Privacy Control. See Analytics for the details.
While we test a change to a page (an A/B test): which version of it you were shown, and on our website a random id in a cookie, wuizard_aid, that keeps showing you the same versionSeeing which version works better. It’s first-party: it stays with us and is never sold or shared, and we keep a keyed hash of the id, never the id itself. If you sign up, the version you saw stays with your account so the page doesn’t change on you; it’s in your data export and deleted after 180 days. No id is set, and you aren’t counted, if your browser sends Do Not Track or Global Privacy Control, or after you choose Reject all in the cookie banner. Accounts that opt out in Settings → Privacy & data aren’t counted either.
Only if you allow them: what Google Analytics, Google Ads and Meta Pixel collect on our website, and your sign-up, trial and first payment (see Cookies)Measuring our website, and which of our ads bring people to Adwright

Analytics and session recordings

We measure how Adwright is used ourselves, with no analytics company in between. Each thing that happens is recorded as an event, with:

  • What happened. A page you opened, a button or link you pressed (by its label, like “Export”), a form you sent (by the names of its fields, never what you typed in them), an AI request (the feature, how much it used and whether it worked, never your prompt), a billing change, or an error you ran into.
  • Who and when. Your account (signed out, a visitor code that changes every day), the time, the browser session it happened in, your plan, and the version of Adwright.
  • Where from. Your IP address and the country and city it’s in. Signed out, we keep only the network part of the address, never the whole of it. Where we need your consent (see below) and you haven’t given it, the events our servers record about your account keep only the network part and the country.
  • On what. Your browser and its version, your operating system and the kind of device. Events don’t keep your browser’s full user agent; a session recording keeps it with the recording, so the visit can be replayed as your browser showed it.

Session recordings, in the signed-in app only, replay the pages, clicks and scrolling of a visit, so we can see a problem the way you met it. Everything typed into a field is hidden before it leaves your browser, and so are your chats with the assistant and your prompts; card forms and anything we mark private are never captured. Events link to the recording of the moment they happened, and to the errors in the same session, so we can see what led to a problem.

Why, and on what legal basis

What we doLegal basis
Running your account and the features you use, and billing youOur contract with you (GDPR article 6(1)(b))
Keeping invoices and payment recordsOur legal obligations, like tax law (article 6(1)(c))
Recording sign-ups, billing changes, AI requests and errors; keeping the service secure and stopping abuseOur legitimate interests in running a reliable, secure service (article 6(1)(f))
Recording the pages, clicks, forms and sessions in your browser, if you’re in the EU, the EEA, the UK or Switzerland, or we can’t tell where you areYour consent (article 6(1)(a)), asked for when you first visit. Until you allow it, none of it leaves your browser.
The same, everywhere elseOur legitimate interests in improving Adwright, with the opt-out below
Reading public web pages, yours and your competitors’, to research a product someone asked us toOur legitimate interests, and theirs, in researching a product from what’s publicly on the web, with the opt-out on our crawler page
Google Analytics and advertising tagsYour consent, in the cookie banner

Under the Australian Privacy Act, we only collect what’s reasonably necessary to provide and improve Adwright, mostly from you directly, and this policy is our notice of what we collect and why.

How long we keep it

  • Events: 13 months, then they’re deleted.
  • Your full IP address in an event: 30 days. After that only its network is kept.
  • Session recordings: 30 days.
  • Error reports: 90 days.

Your choices

  • Settings → Privacy & data turns product analytics or session recording off for your account. Either stops from then on, in every browser.
  • Where we ask for your consent, Cookie settings changes your choice for this browser at any time. Turning analytics off stops it straight away; what was already recorded is kept as above, unless you ask us to delete it.
  • If your browser sends Do Not Track or Global Privacy Control, nothing is recorded while you’re signed out, and your sessions are never recorded.

Cookies

We sort cookies into three groups, plus two of our own, for A/B tests and referral and affiliate links. Necessary cookies are set without asking, and so is the A/B test cookie while we’re testing a change to the website (it isn’t set if your browser sends Do Not Track or Global Privacy Control, and Reject all removes it). Analytics and marketing tags load only after you allow them in the cookie banner, and none of them loads if you choose Reject all.

GroupWhat it’s forTags and cookies
Necessary, always onKeeping you signed in, keeping the site secure (including stopping repeat free trials), remembering your cookie choice for six monthsOurs only: wuizard_session (it can’t be read by scripts on the page), wuizard_consent and wuizard_did (a random device id, kept 400 days; it can’t be read by scripts on the page)
A/B tests, only while one runs on our websiteShowing you the same version of a page while we test a change to it, and counting which version works betterOurs only: wuizard_aid, a random id kept for a year (it can’t be read by scripts on the page)
Referral and affiliate links, only when you open oneCounting your signup for whoever’s link you opened: for a friend’s referral link, so you get your extra trial credits and they get their reward; for an affiliate’s link, so the affiliate earns a commission on what you pay. With the visit we keep a keyed hash of the id (never the id), which kind of page you landed on and the link’s campaign tags. If you don’t sign up within 60 days we delete that record; if you do, it stays with your account and is in your data export. A friend’s referral link sets the cookie even with Do Not Track, Global Privacy Control or Reject all, since your extra credits depend on it, and then we keep only the hash. An affiliate’s link doesn’t set it at all then.Ours only: wuizard_ref, a random id kept for 60 days, the links’ window (it can’t be read by scripts on the page)
AnalyticsCounting visits and how the site is used, so we can improve it. Where consent is needed, this choice also covers our own analytics (see Analytics)Google Analytics: _ga cookies, kept for up to two years. Our own analytics sets no cookie: the id of a session recording is kept in that browser tab only, until it closes
MarketingMeasuring which of our ads bring people to Adwright: when someone who saw one signs up, starts a trial or subscribes. Google and Meta may also use it to show you our ads.Google Ads: _gcl cookies, 90 days. Meta Pixel: _fbp and _fbc, 90 days

None of these tags is switched on right now. You’ll only see the banner where we need your consent for our own analytics.

What the tags get: the page you’re on, with anything private in its address left out (we never report share links, links from our emails or receipts), the site that sent you, and, when you sign up, start a trial or subscribe, that it happened and the plan’s price. Never your name, your email address, what you type or what’s in your projects.

When you’re signed in, we keep a copy of your choice with your account, so our servers follow it too, for six months from when you made it. With marketing allowed, our servers also tell Meta about your sign-up, trial and first payment, so each is counted once. They send a hashed copy of your email address (never the address itself) and, when it happened in your browser, that browser’s IP address and type, which Meta’s pixel would see anyway. With analytics allowed, they tell Google Analytics about your first payment, with this browser’s Google Analytics ID, which we keep with your account only while analytics is allowed. Turning a group off stops these too.

If your browser sends Global Privacy Control, marketing stays off unless you switch it on yourself while it’s sent, even if you allowed it before.

Changing your choice

Use Cookie settings in the footer of our website, or Settings → Privacy & data when you’re signed in. Turning analytics off stops it from then on.

Local storage

Your browser also stores a few preferences locally, like a collapsed sidebar or which alerts you’ve read, and for the tab you have open, whether analytics needs your consent where you are and the id of its session recording. Our own count of visits to the website (above) doesn’t use cookies; only A/B tests do, as described above.

Emails

We send emails about your account and billing: confirming your address, password resets, receipts, payment problems and reminders you ask for. We’ll only send product news if you opt in, and every such email will have an unsubscribe link.

Sharing

  • We don’t sell personal data.
  • A share link you turn on makes that project’s research and ads visible to anyone with the link, but not your email or usage.
  • We use service providers for hosting, email delivery, payments, AI models (reading your page, researching your market and competitors, and writing your ads), AI web search and image and video generation. They process data only to provide those services to us. The AI providers receive what they need to return a result: the facts read from the pages, your options and what you ask for. When it’s switched on, Meta’s Ad Library is asked about your competitors (never about you). We’ll list them here before launch.
  • Card payments are handled by Stripe, which stores your card. We keep only its brand, last four digits and expiry date.
  • Only if you allow them (see Cookies), Google and Meta receive what their tags collect, to measure our website and our ads.
  • We may disclose information if the law requires it.

Who at Adwright can see your account

A small number of staff can look up accounts to help with support, billing and abuse. Support staff can see your account, usage and projects and watch session recordings; only a few administrators can change plans or billing, or view the app as you see it (read-only, for up to 30 minutes, to reproduce a problem). In our analytics, support staff see events with a masked email address, the network part of the IP address and the country; only those administrators see full IP addresses, places and email addresses there. Every time staff look at or change an account, or open those details, it’s written to an internal audit log that can’t be edited.

Where your data is stored and processed

Your account, your projects and the analytics and recordings described above are kept on servers we run for Adwright, not with an analytics company. Some of our service providers, for card payments, email delivery and AI models, process data in other countries, including the United States. When data about people in the EU, the EEA, the UK or Switzerland goes to a country without an adequacy decision, we rely on the standard contractual clauses approved for that. Under the Australian Privacy Act, we take reasonable steps to make sure anyone overseas who receives your information handles it in line with the Australian Privacy Principles.

How long we keep it

We keep your data while your account is open, and analytics for the periods in Analytics. When you delete your account, we remove your personal data within 30 days, including its events and recordings, except invoices and records we must keep for tax and accounting, the keyed hashes we keep to stop repeat free trials (see What we collect), and your posts and comments on the feedback board, which stay without your name.

Your choices and rights

Wherever you live, you can ask us for a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it. You can see and change most of it in the app yourself, and Settings → Privacy & data downloads everything your account holds, including its analytics events.

  • Under the Australian Privacy Act, you can access and correct the personal information we hold about you (Australian Privacy Principles 12 and 13). If you’re not happy with how we handle a complaint, you can take it to the Office of the Australian Information Commissioner at oaic.gov.au.
  • Under the GDPR and the UK GDPR, you can also ask us to restrict or stop using your data, object to what we do on legitimate interests, take your data with you, and withdraw your consent at any time (what was done before stays lawful). You can complain to the data protection authority where you live.

We answer within 30 days, and may need to check it’s really you first.

Security

Passwords are hashed, session tokens are stored only as hashes, links in emails are single-use and expire, and every page our crawler reads is fetched from a public address only, never one on a private network.

Contact

Privacy questions or requests: support@adwright.co.