Privacy

What we collect, why, who helps us run the studio, and your choices, in plain words.

Last updated October 2, 2026

Who we are

Apartic Studio is run by Apartic LLC ("we", "us"). This page explains what we collect when you use apartic.ai, why we collect it, who helps us run the studio, and the choices you have. It is written for customers in the United States.

Apartic Studio is offered to businesses in the United States. Sign in codes can go to a United States or Canadian mobile number.

What you give us

  • Your email address, when you sign in or buy your first ads. If you sign in with Google or Apple, we also get the name on that account.
  • Your mobile number. We ask for it when you sign in to your account or buy a plan, and use it only to text you sign in codes. Your first 2 ads for $5 don't need one.
  • Your card. Card details go from your browser straight to Stripe and never reach our server. We keep only what Stripe sends back: its reference numbers for you and your card, the card brand, the last 4 digits, and a fingerprint code Stripe uses to spot the same card again. We save the card with Stripe so the purchases you choose later can be charged.
  • Your photos, links and words: the product photos, logos and brand files you upload, the pages you link to, and the notes, claims, reviews, client names and answers you type.
  • The ads we make for you, including drafts that didn't pass our checks.
  • Your orders and billing: what you ordered and paid, refunds, your plan, and what you agreed to and approved (which version of the Terms, which claims you confirmed, which ads you approved, and when).
  • Your answer to "How did you hear about us?", if you pick one.
  • Notes you send us through the contact form.

What we collect automatically

  • Device and sign in details: a random device code kept in a cookie (we store only a scrambled version of it), the kind of browser and computer (for example "Chrome on Mac"), when each device signed in, and your time zone.
  • Your internet address (IP). We use the full address to limit sign in attempts, free reads and payment attempts. Full internet addresses are kept for 30 days, then deleted. Everywhere else, including our server's request log, we keep only a shortened network address that points to a network, not a person.
  • How you found us. When you arrive on our start pages, we note the page you landed on, the campaign tags in the link (utm), Meta's click code (fbclid) and the site that sent you. Two cookies of our own hold this for 90 days: apt_ft for your first visit and apt_lt for your last. When you sign up, we save them with your account.
  • If you arrive from a Google ad, Google's click code (gclid, gbraid or wbraid) is kept in the same first and last visit cookies for 90 days and saved with your account.
  • Meta events, only when they are switched on. No Meta code runs in your browser: our server sends Meta a short note when you land on our start pages (Page View), see your free read (View Content), enter your email (Lead) and buy your first ads (Purchase). Each note can carry: the event's name and time; the page address, with the private part of the link taken out; your internet address; your browser string (the browser and device it says it is); Meta's click cookies (_fbc, and _fbp when your browser has one); a scrambled version of your device code; on View Content, the kind of product your read was about (for example "kitchen"); on Lead and Purchase, a scrambled (hashed) version of your email; and on Purchase, its value, $5. We never send Meta your phone number, your photos or your name.

Your visits to our pages

We keep our own simple record of visits to our public pages (the start pages, Terms, Privacy and Contact), on our own server. No outside analytics company gets it. A cookie of ours, apartic_vid, holds a random visitor code so we can tell one browser's visits apart. With it we record:

  • The pages you view and when, how many visits you've made, and about how long you've spent on our pages while they were in view.
  • How you arrived: the first page you landed on, the campaign tags in the link (utm), whether the link came from one of our ads (an ad click code), and the site that sent you.
  • Your country, from the country code Cloudflare adds to each request (not your address).
  • What you looked at: our sample ads, prices and plans, and whether you started a free read and the website of the link you read. If you give us your email, we also keep a short note of what that read found (the product's name and category, and the top reason and question from its reviews), so our emails can be about your product after the read itself is deleted.
  • Your answers on our email card: the email you give us (and whether you confirmed it with a code) and, if you tap one, where you sell (an ecommerce marketplace, Shopify or your own site, or ads for clients). From these and the pages above we guess which kind of seller you are, so we can show you the most useful examples and emails.

Records of visitors who never give us an email are deleted after 180 days. In the EU, the EEA, the UK and Switzerland nothing is recorded, and no apartic_vid cookie is set, until you tap OK on the notice at the top of our pages; No thanks keeps it off. Anywhere else, to stop the record on a browser, write to us. Saying no never blocks anything on the site.

Why we use it

  • To make and deliver your ads: reading your product, planning the ads, making them, and checking each one against your photos.
  • To take payment, run your plan and its limits, and give refunds.
  • To sign you in and keep your account safe: codes, devices, and limits that stop abuse and repeat use of first time offers.
  • To measure which of our own ads bring customers.
  • To send you email and texts about your account: sign in codes, ads ready, a check in after your ads arrive, a note before your plan renews, and notices about your account.
  • If you give us your email on our email card: a code to confirm it, then a few short emails over the next days with examples for your kind of business and a link back to where you left off. These stop once you buy, and each has an unsubscribe link.
  • To improve our pages and our offers, from the visit record described above.
  • To keep a record of what you agreed to and approved, in case of a dispute.
  • To answer you when you write to us.

We don't sell your personal data for money. We do share the limited data in the Meta and Google Ads events described above with them, so we can measure and improve our own ads, and each handles it under its own terms. Some state privacy laws call that "sharing" or a "sale" for targeted advertising. To opt out, use Meta's ad settings and the industry opt out at aboutads.info/choices, and block or delete cookies in your browser. You can also ask us to delete what we hold about you (see Your choices).

We don't use your photos or ads to train AI models. The studio's own taste and quality checks learn only from the studio's own work, never from customers' orders.

Where your data is kept

Customer data (uploads, orders and account details) is stored on a server in Germany (Hetzner, EU).

The companies listed below help run the studio. Most are based in the United States and may handle your data there or in other countries.

Who helps us run it

We share data only with the companies that run parts of the studio for us, and only what each one needs:

  • Hetzner hosts our server in Germany, where your account, photos, orders and ads are stored.
  • Cloudflare carries all traffic to and from apartic.ai and protects it from attacks. It also checks that the part of your email after the @ can receive mail.
  • OpenAI makes the ad images from your product photos and screens every photo and typed word for content we don't allow. It gets your photos, our written instructions and a scrambled account number, never your name or email.
  • Anthropic reads your photos, product page, reviews and notes to plan the ads, write headlines and check the results, and searches the web for your brand.
  • Stripe takes payments and keeps your card. It gets your email, your card and what you buy.
  • Postmark sends our emails. It gets your email address and the message.
  • Twilio texts you sign in codes and checks that a number is a mobile number. It gets your phone number and the code. On phones that support it, Twilio may deliver a code as an RCS message, which passes through Google's messaging service.
  • Meta gets the events described above from our server, only when they are switched on.
  • Google Ads: if you came from a Google ad, we tell Google when you enter your email on the pay page and when you buy, using Google's click code. If that code is missing but you came from a Google ad, we may send a scrambled (hashed) version of your email instead. We never send your photos, phone number or page addresses.
  • Google: our account pages load their fonts from Google, so Google sees your internet address when they load. Google also checks that your email's domain can receive mail. If you choose Continue with Google, Google signs you in and sends us your email and name.
  • Apple: only if you choose Continue with Apple. Apple signs you in and sends us your email (or a private relay address) and your name.

When you give us a product link, we also read that public page and its public reviews. Those sites see our server, not you.

Cookies

Our own cookies:

  • Sign in (30 days) and device (about 13 months): keep you signed in and tell your devices apart.
  • Sign in step (30 minutes): remembers where you are while you sign in, including the email you typed.
  • Time zone (1 year), the client you're viewing (1 year, agencies) and reminders you closed (30 days): small settings for your account pages.
  • apt_ft and apt_lt (90 days): the first and last way you arrived, described above.
  • apartic_vid (about 13 months): the random visitor code of the visit record above; "off" when you turned the record off. apartic_eu_ok (1 year): you tapped OK on the notice about it.
  • _fbc (90 days): set only when our Meta events are on and you came from a Meta ad, so a purchase can be matched to that ad.

We don't put Meta's pixel on our pages, so Meta's own code sets no cookies here. Stripe sets its own cookies on the payment page to prevent fraud. You can block or delete cookies in your browser; without the sign in cookies you can't sign in.

How long we keep it

  • A free read that never leads to a purchase is deleted after 7 days, except a record of when it happened and how you arrived. If you typed your email on the payment page, it is kept with how you arrived for up to 30 days, in case you come back to sign up.
  • Sign in links and codes stop working after 20 minutes (texted codes after 10). Our records of them, of sign in attempts and of phone checks are deleted within 30 days, and the history of new device sign ins after 60 days.
  • Full internet addresses: kept for 30 days, then deleted. The shortened network address stays with your devices and our abuse records, with no set end date yet.
  • Your account, photos, orders, ads and billing: kept while your account is open. We don't delete them on a schedule yet. Ask us and we will.
  • Records of payments and of what you agreed to and approved: kept for at least 4 years, even after your account is deleted, in case of taxes or a dispute.
  • Notes you send through the contact form: kept until you ask us to delete them.

Your choices

  • See, fix or delete your data, or close your account: send us a note through the contact form from the email on your account, and say what you want. We confirm it's you, then do it within 30 days, keeping only the records we must keep (above).
  • Email: messages about your account and orders come with the account. The few emails that follow our email card each have an unsubscribe link that works in one click. In the EU, the EEA, the UK and Switzerland we send them only if you tick Send me tips and updates by email on the card. To stop check in emails, tell us through the contact form.
  • Visit record: in the EU, the EEA, the UK and Switzerland it starts only when you tap OK on the notice; anywhere, ask us through the contact form to stop it.
  • Texts: we only text sign in codes, never marketing.
  • Phones and devices: remove a phone or sign out a device on your Devices page.
  • Cookies: block or delete them in your browser (see above).
  • Meta: opt out of ads based on your activity in Meta's ad settings and at aboutads.info/choices.

Do Not Track

Your browser may send a Do Not Track signal. There is no agreed standard for what it should mean, so the studio does not change what it does when it gets one. What we collect, and what we send Meta, is described above, and so are your ways to opt out.

How we protect it

Card numbers go from your browser straight to Stripe and never reach our server. Sign in links expire quickly and are stored only in scrambled form. Our server opens no web ports to the internet: all traffic reaches it through Cloudflare. Only we can see your account, and only to make your ads, help you, or look into abuse.

Children

The studio is for businesses and people 18 or older. We don't knowingly collect data from anyone younger.

Changes to this page

When this page changes, the date at the top changes too. If a change matters, we email you before it applies.

Contact about privacy

Questions about privacy or your data go through our contact form.