Legal
Privacy Policy
What AdScoop collects, what never leaves your browser, and how to have your data removed.
Overview
AdScoop is a Chrome extension that runs on the Meta Ad Library, and a web app that holds the ads you save there. This policy explains what it collects, what it deliberately does not, and what you can ask us to delete.
It covers the extension, the website at adscoop.app, and the web app at app.adscoop.app. AdScoop is operated by Taher El Sheikh, and "we" below means the same.
What We Collect
AdScoop works without an account for searching, reading the days badge and downloading. None of that reaches our servers.
When you sign in, we keep an account record:
- Email address
- the address you sign in with. It identifies your account and opens your library on a new browser or machine
- User ID
- an internal identifier that links your account to the ads you save
- Profile name
- your first name, shown on the share pages you create, as in "Taher shared this board with you"
- Sign-in tokens
- kept as a hash so the extension and the web app can prove they are you
When you save an ad, we keep the ad:
- Saved ads
- for each ad you save, the advertiser's name and page, the ad's copy, headline, call to action, landing link, format, dates, platforms and the full ad data as Meta served it to your browser, plus when you saved it
- Archived creative
- a copy of each saved ad's images and video, so it still plays after Meta's own links expire. Stored once per ad, not once per user
- Boards, tags and transcripts
- the boards you put an ad in, the tags you give it, and a transcript if you have made one
- Share links
- a random identifier for each ad or board you have shared, and nothing else
When you transcribe a video, we keep a record of the job:
- Transcription jobs
- one row per transcription: the ad, the advertiser, the length of the audio, and whether the job finished
- Monthly usage
- the transcription minutes used this month, which is how the 500 minute monthly allowance is counted
- Google Sheets token
- kept only if you connect Google Sheets, and only so a spreadsheet can be created when you export
We do not collect your browsing history, your Facebook account, your searches, or anything from sites other than the Ad Library.
Three features send data on purpose, because they cannot work any other way: saving, transcription and Google Sheets export. Each is described below, and none of them runs until you click it.
What Stays in Your Browser
The extension reads the ad data the Ad Library already sent your browser to draw the page. That is where the days badge, the format label and the download button come from. It lives in the tab while the tab is open and is never uploaded.
The same is true of most of what AdScoop does:
- Brand search asks Meta from inside your own Ad Library tab, using your own session. The query never reaches our servers, and results are cached in the extension's memory only.
- Downloads go straight from Meta to your device. The file never passes through our servers.
- CSV exports and zip files are built by the extension or the web app and saved by your browser.
- Recent searches, your display and sort settings, and a local copy of your library are kept in the extension's own storage on your machine.
Saved Ads and the Library
Clicking Save sends the ad to our servers, because that is what lets you open it in another browser and keeps it after Meta's links expire. The extension writes the ad to its local storage first, then sends the same record to a Cloudflare Worker, which stores it in a database against your user ID.
In the background, the extension also fetches the ad's images and video from Meta's content servers, without your Facebook credentials, and uploads them through the worker into our media storage. Each file is stored under an unguessable key, once per ad: an ad saved by fifty people is kept once. When the last person who saved an ad removes it, the files are deleted 24 hours later.
Your library syncs both ways, roughly once a minute while it is open. Removing an ad removes it from the database and, subject to the grace period above, its media.
Transcription
Transcribing a video sends its audio off your device, because a speech model has to hear it.
The extension sends Meta's own link to the video, together with the ad ID, the advertiser's name and your user ID, to our Cloudflare Worker. The worker fetches the video, runs it through Whisper on Cloudflare Workers AI, and returns the text to your browser. Very long videos are transcribed up to a size limit and marked as partial.
The audio is processed in memory and is not saved. The model runs on Cloudflare's own infrastructure, so nothing is sent to OpenAI or to any other AI provider. What remains is the job row described above, kept to count your usage against the monthly allowance and to refund a job that failed.
Google Sheets
If you connect Google Sheets, an export creates a spreadsheet in your Google account, so it needs your permission and sends the rows you are exporting.
The first time, Google asks you to connect your account. We store the resulting token on our servers against your user ID and use it for one job: creating a spreadsheet and writing your exported rows into it. Those rows pass through the worker to Google and are not kept on our side. We do not open, read, change or delete anything else in your Google account, and you can disconnect AdScoop at any time at myaccount.google.com/permissions.
Browser Permissions
Chrome lists an extension's permissions when you install it. Here is what AdScoop asks for, and why:
- Site access
- the Meta Ad Library at facebook.com/ads/library, Meta's GraphQL endpoint for brand suggestions, and adscoop.app. AdScoop runs on no other page and cannot see any other site you visit
- Storage and unlimited storage
- hold a local copy of your library, your settings and recent searches. Saved ads carry their full data, which is why the ordinary storage quota is not enough
- Side panel
- lets the toolbar icon open the AdScoop panel beside the page
- Tabs and scripting
- let the panel open or reuse an Ad Library tab and run a brand search inside it, and open the web app when you ask
- Alarms
- schedule the background sync of your library
AdScoop does not request the identity permission and does not read your Chrome profile. Your email address reaches us only when you type it into the sign-in page.
How We Use It
Your data is used to run the product, and for nothing else:
- Open your library in any browser you sign in to.
- Keep saved ads playable after Meta's links expire.
- Serve the share pages you create, and take them down when you turn a link off.
- Count transcription minutes against the monthly allowance.
- Create a spreadsheet when you export to Google Sheets.
- Answer your support emails.
We do not sell your data, we do not rent it, and we do not use it to train models.
Service Providers
Three companies process data on our behalf. Each gets only what its job needs:
- Cloudflare
- hosts the website and the web app, runs the workers, stores the account database and the archived creative, and runs the transcription model
- Supabase
- handles sign-in, either with Google or with a code sent to your email address
- provides Google sign-in if you choose it, and receives the rows of a Google Sheets export when you run one
Meta is not a service provider. AdScoop reads what Meta's pages already show you, and Meta does not receive anything from us.
Storage, Security and Retention
Account records and saved ads live in Cloudflare D1, archived creative in Cloudflare R2, and every request to our workers runs over HTTPS. Media is stored under keys that cannot be guessed from an ad ID.
We hold no passwords. Sign-in is handled by Supabase, so a password never reaches us. There is nothing to pay for, so we hold no card details either.
We keep your account and your library for as long as the account exists. Media is deleted 24 hours after the last person who saved an ad removes it. Transcription job rows and monthly usage are kept as quota records. When you ask us to delete your data, we delete the record, your saved ads, and any media no one else has saved.
Your Rights
You can ask for a copy of your data, a correction, or its deletion. Email taher@adscoop.app and we will act on it within 30 days.
Some of it you can do yourself. Remove ads from your library, turn off any share link, disconnect Google Sheets from your Google account, and remove the extension to clear everything it stored locally.
If you are in the UK or the EU, we process your account data to provide the service you signed up for, and on a legitimate interest in running the product. You have the right to access, correct, export and delete that data, and to complain to your local supervisory authority.
If you are in California, we do not sell or share personal information as the CCPA defines those terms.
Children's Privacy
AdScoop is not intended for anyone under 13, and we do not knowingly collect information from children. If you believe a child has given us information, email us and we will delete it.
Changes to This Policy
We update this policy as the product changes. The current version is always at adscoop.app/privacy, and the date at the top says when it last moved. Material changes are announced in the extension or by email.
Contact
Taher El Sheikh is the data controller for everything described here. Questions about this policy, or about data we hold, go to the same place:
- Data controller
- Taher El Sheikh, creator of AdScoop
- Location
- San Francisco, California, United States
- taher@adscoop.app