Privacy Policy
Version dated August 11, 2026
This Privacy Policy explains how Qurve Labs LLC (registration number 2026-002047565, 30 N Gould St, Sheridan, WY 82801, USA) processes personal data of users of the Fabrika platform at https://fabrika.ad. For the purposes of the EU General Data Protection Regulation (GDPR), the Company is the data controller.
1. Data we process
- Account data: e-mail address, display name, password hash, organisation name.
- Social sign-in data: identifier, name and e-mail provided by the sign-in provider (e.g. Google).
- Content you upload: brand books, images, logos, briefs and other materials submitted for generation.
- Usage and technical data: operations you run, log records, IP address, browser information.
- Billing data: balance, top-up and spending history. Card details are processed by payment providers and never reach our servers.
2. Purposes and legal bases
- Providing the Service (contract performance): account management, running generation operations, delivering results, support.
- Billing and accounting (contract performance; legal obligation).
- Service security and abuse prevention (legitimate interest).
- Product analytics and improvement of generation quality (legitimate interest).
- Communications you have requested (contract performance or consent).
3. Processors and transfers
To provide the Service we share data with processors acting on our instructions: hosting and infrastructure providers, payment providers, e-mail delivery services, and third-party AI model providers that process your uploaded content solely to produce your requested outputs. Where processors are located outside the EEA, transfers rely on appropriate safeguards such as the EU Standard Contractual Clauses.
We do not sell personal data and do not use your uploaded content to train our own or third-party foundation models.
4. Advertising platform integrations and Google user data
You can connect advertising accounts (e.g. Google Ads, Meta) to export your generated creatives as draft campaigns and to manage those campaigns from your dashboard. When you connect a Google Ads account via Google sign-in (OAuth scope https://www.googleapis.com/auth/adwords), we access it only to: (a) list the Google Ads accounts available to you so you can choose an export destination; (b) upload your creatives and create the campaign, ad group and ads you requested — always in a paused state, so nothing runs until you enable it yourself in Google Ads; (c) read your campaign statistics to show reports and recommendations in your dashboard; and (d) apply the campaign changes you explicitly request.
OAuth access and refresh tokens are stored encrypted and used solely to provide the features you have enabled. We read your campaign performance data to show statistics, reports and recommendations in your dashboard, and we change existing campaigns (status, budget, bidding strategy, targeting, ads) only when you explicitly request that change in the Service; we never delete your campaigns. We do not use any Google Ads data for advertising, profiling, model training or any other purpose. Google user data is never sold and is not shared with anyone except the processors listed above, strictly as needed to run the Service.
You can revoke access at any time by disconnecting the account in Settings → Integrations (this deletes the stored tokens) or in your Google Account security settings (myaccount.google.com/permissions). Fabrika's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. Data protection and Google integrations
You may connect your Google accounts to the Service by an explicit action of your own; without such a connection we neither request nor receive access to them. When you connect Google Analytics (GA4) we get read-only access to the statistics of your properties; when you connect Google Search Console we get read-only access to search query and indexing data for your verified properties; when you connect Google Ads, access is used to read campaign statistics and to create the draft campaigns you request.
The data received is used solely to display statistics and analytics in the Service interface and to carry out the tasks you request. We apply the following protection measures: data is transmitted only over a secure connection (TLS); OAuth tokens are stored encrypted — application-level encryption with an instance key — and are never displayed in the interface; each organisation's data is isolated from that of other organisations; connecting and disconnecting integrations is limited to users with the organisation administrator role, and imported data is accessible only to members of that organisation.
When you disconnect an integration, the stored access tokens and the data imported through that integration are deleted from the Service. You may also revoke access at any time in your Google Account security settings (myaccount.google.com/permissions) and request deletion of your data or account at hello@fabrika.ad.
Our use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Information received from Google APIs is never sold, is not used for advertising, profiling or model training, and is not shared with third parties other than the infrastructure providers needed to operate the Service or where required by law. https://developers.google.com/terms/api-services-user-data-policy
6. Retention
Account data is kept for as long as your account exists. Uploaded content and generated results are kept so you can access them in your dashboard and are deleted upon account deletion, except where retention is required by law (e.g. accounting records) or for the establishment of legal claims.
7. Your rights
Subject to the GDPR you have the right to:
- access your personal data and receive a copy;
- rectify inaccurate data;
- erase data ("right to be forgotten");
- restrict or object to processing based on legitimate interest;
- data portability;
- withdraw consent at any time where processing is based on consent;
- lodge a complaint with a data-protection supervisory authority in your country of residence.
To exercise these rights, write to hello@fabrika.ad. We respond within one month.
8. Cookies
The Service uses cookies and similar technologies that are strictly necessary for authentication and security (e.g. the session refresh cookie). We also use Google Analytics (Google Ireland Ltd.) to measure site usage; analytics data is pseudonymous and processed under Google's data-processing terms.
Campaign attribution cookies (technical). Before any analytics consent is given, and only if you arrive from an advertising campaign, we store two technical identifiers for up to 30 days: ade_click_v1, an opaque click token issued by our own ad tracker, and ade_utm_v1, which holds the campaign source, medium and campaign name, the Google Ads (gclid) or Yandex Direct (yclid) click identifier, and the reviewed public landing route you arrived on. They serve a single purpose — connecting a subsequent registration to the campaign that produced it — and are never used to profile you, to target advertising, or to share data with third-party advertising networks. We do not store the full URL, search terms or any account fields in them. If you arrive without campaign parameters, nothing is stored at all.
Both cookies are deleted from your browser as soon as the registration is linked to an account. The campaign attribution record then kept on the account is erased when you withdraw analytics consent in Privacy settings or delete the account; the ad click token is retained for as long as the account exists, because reconciling paid clicks with the ad tracker is a strictly necessary measurement we owe under the advertising service contract.
With your consent, a browser cookie keeps a minimized first-touch record for up to 30 days: the product, reviewed landing route, locale, referring hostname and the remaining campaign identifiers (such as ad content and campaign id) that the technical cookies above deliberately leave out. We do not store the full URL, search terms, prompts or account fields in this record. After account linking, the browser cookie is deleted and the minimized record is retained on the account for aggregate acquisition measurement until you withdraw analytics consent in Privacy settings or delete the account. If an authenticated deletion fails, a strictly necessary pending marker (up to one year) asks for explicit confirmation for the currently signed-in account and is removed on success. Anonymous decline creates no account-deletion marker.
9. Changes and contact
We may update this Policy; the current version is always available on this page. Questions about privacy: hello@fabrika.ad (Qurve Labs LLC, 30 N Gould St, Sheridan, WY 82801, USA).