Security & data

Your advertising data, handled like it matters

Freshlytics holds performance data for real ad budgets. This page describes exactly what we collect, where it lives, who can reach it and how long we keep it — in plain language, without security theatre.

Last updated August 19, 2026

Encrypted in transit and at rest

All traffic uses TLS 1.2 or higher. Databases and backups are encrypted at rest with AES-256. OAuth access and refresh tokens are encrypted with separate keys and are never written to logs.

Least privilege by default

We request read access for reporting and only ask for write access when you enable an automation feature. Inside Freshlytics, workspace data is isolated per customer and access is scoped by role.

Everything is logged

Authentication events, permission changes, exports and every write sent to the TikTok API are recorded in an append-only audit log available to workspace owners.

What we collect

CategoryExamplesRetention
Account dataYour name, work email, workspace name, role, hashed password or SSO identifierUntil you delete the account
TikTok authorizationEncrypted OAuth access and refresh tokens, advertiser IDs you grantedUntil you disconnect or revoke
Campaign structureCampaign, ad group, ad and creative names, IDs, objectives, budgets, bid strategies, schedules, delivery status13 months
Performance metricsSpend, impressions, clicks, conversions, video engagement, cost metrics by day and hour13 months
Creative metadataCreative IDs, file names, formats and thumbnail images13 months
Product usageServer-side logs of requests to our own application, error traces30 days

What we never collect

  • Personal data of TikTok users who saw, clicked or converted on your ads
  • Audience or Custom Audience member lists, email hashes or phone numbers
  • Organic account data, followers, direct messages or comments
  • Your TikTok password — authorization happens entirely inside TikTok's OAuth flow
  • Payment card data — when billing starts it will be handled by a PCI-compliant payment processor, and card numbers never reach our servers

Where data lives

The application, database and backups run on servers located in the European Union. Backups are encrypted, taken daily and retained for 14 days. Static website content is served through Cloudflare's global network.

Sub-processorPurposeRegion
Hetzner Online GmbHApplication servers, database, encrypted backupsGermany (EU)
Cloudflare, Inc.DNS, CDN, DDoS protection for the websiteGlobal
Postmark (Wildbit / ActiveCampaign)Transactional email — alerts, reports, account noticesUnited States

We publish changes to this list here before they take effect. TikTok advertising data is never sent to any other third party, is never sold, and is never combined into benchmarks shared with other customers.

Access control

  • Production access is limited to the engineers who operate the service, protected by SSO and mandatory two-factor authentication
  • Access to customer data in production requires a documented reason and is logged
  • Secrets and encryption keys are stored in a managed secrets vault, never in source control
  • Separate staging environment that uses synthetic data, never a copy of customer data

Reliability and incident response

We monitor sync freshness, API error rates and job queues continuously. If a security incident affects your data, we will notify affected workspace owners by email without undue delay and no later than 72 hours after we become aware of it, with what happened, what data was involved and what we are doing about it.

Honest status: Freshlytics is an early-stage product. We are not SOC 2 or ISO 27001 certified today, and we will not claim otherwise. The controls above are what we operate now; formal certification is on the roadmap and this page will be updated with real dates when it happens.

Compliance

  • We process advertising data as a processor on behalf of the advertiser, under the GDPR and, where applicable, the CCPA/CPRA
  • A Data Processing Agreement is available on request for every paying customer
  • We comply with the TikTok Advertising API Terms of Service and the TikTok Developer Terms, including their restrictions on data use, retention and onward transfer
  • Data subject requests are answered within 30 days — see data deletion

Reporting a vulnerability

If you believe you have found a security issue, email privacy@freshlytics.site with steps to reproduce. We will confirm receipt within two business days, keep you updated while we fix it, and credit you if you would like. Please do not run automated scans against production or access data that is not yours.

Questions about data handling?

Send them to us directly — we would rather answer a hard question before you connect an account than after.