Legal
Privacy Policy
Effective date: 27 August 2026 · Last updated: 27 August 2026
This policy explains what information AI Sync handles, why we handle it, how long we keep it, and how you can have it deleted. It applies to the AI Sync service at anisync.link and to the platform connections developers authorize through it.
1. Who we are and what this covers
AI Sync (referred to as “AI Sync,” “we,” “us,” or “our”) provides integration infrastructure that developers use to connect to marketing platforms, retrieve data those platforms make available, normalize it, and route it into their own systems.
This Privacy Policy applies to the anisync.link website and to the AI Sync service. It does not apply to third-party platforms you connect to AI Sync — those platforms have their own privacy policies governing their handling of your data.
In many integrations, AI Sync acts on behalf of the developer or organization that set up the connection. Where that is the case, that customer determines the purposes of the processing and we process data according to their instructions and the permissions granted.
2. Information we collect
Account and service information
- Contact details supplied when a developer sets up access, such as name and email.
- Configuration you create in the service: connection names, routing destinations, schedule settings, and retention preferences.
- Operational records: API request logs, delivery attempts and outcomes, error traces, and timestamps, used to run and debug the service.
- Basic technical data from the website, such as IP address and user agent, in standard server logs.
Platform credentials
When you authorize a connection, we receive and store access and refresh tokens issued by the platform. We store these encrypted and use them only to make the calls the connection requires. We do not receive or store your password for any third-party platform.
Meta/Facebook Platform Data
Where a user connects a Meta/Facebook account, AI Sync may access the following, and only to the extent the permissions granted during authorization actually authorize it:
- Basic profile and account identifiers for the authorizing user, such as user ID and name, to associate the connection with the correct account.
- Pages the user administers, including Page IDs, names, and metadata.
- Ad accounts the user can access, including account IDs, currency, and status.
- Campaigns, ad sets, ads, and creatives, including names, objectives, budgets, targeting configuration exposed by the API, and status.
- Insights and analytics, such as impressions, reach, spend, clicks, and conversion metrics.
- Lead Forms and lead information submitted through those forms, which may include a person's name, email address, phone number, and answers to custom form questions.
We do not attempt to access Meta data outside the granted permissions, and reducing or revoking a permission reduces what we can retrieve on subsequent calls.
3. How we use information
- To authenticate connections and keep them working.
- To retrieve, normalize, and deliver platform records to the destinations the connecting user configured.
- To provide dashboards, sync status, delivery history, and error reporting.
- To operate, secure, monitor, and troubleshoot the service, including preventing abuse and investigating incidents.
- To respond to support requests and to communicate about the service.
- To meet legal, tax, and accounting obligations.
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We do not use Meta Platform Data to build independent advertising profiles or to train general-purpose models.
4. Basis for processing
Where data protection law such as the GDPR or UK GDPR applies, we generally rely on: performance of a contract, to provide the service a customer has requested; legitimate interests, to secure, maintain, and improve the service in a way that is proportionate; and legal obligation, where retention or disclosure is required by law. Where consent is the appropriate basis — including consent given at platform authorization — processing depends on that consent, and it can be withdrawn by disconnecting the integration. Which basis applies depends on the specific processing and jurisdiction; if you need a determination for your own compliance records, contact us.
5. Sharing and service providers
We share information only in these circumstances:
- With the platforms you connect, to the extent needed to make the authorized API calls.
- With the destinations you configure, because delivering records to your endpoint or warehouse is the purpose of the integration.
- With service providers that support the service under contract. These fall into generic categories: cloud hosting and infrastructure (for example Amazon Web Services, where used), managed database and storage providers, error monitoring and logging tools, and email delivery for transactional and support messages. Providers are permitted to process data only to deliver their service to us.
- For legal reasons, where disclosure is required by law, legal process, or to protect rights and safety.
- In a business transfer, such as a merger or acquisition, subject to this policy continuing to apply to the transferred data.
6. Storage and security
Data is stored on managed cloud infrastructure. We use TLS for data in transit and encryption at rest for stored data, including platform tokens. Access to production systems is restricted to personnel who need it, authentication to those systems requires multi-factor authentication, and administrative access is logged. Tokens are not returned in plaintext through the API or the interface.
No system is completely secure. We maintain safeguards appropriate to the sensitivity of the data, but we cannot guarantee absolute security. If an incident affects your data, we will notify affected customers as required by applicable law.
Data may be processed in countries other than yours, including the United States. Where required, we rely on appropriate transfer mechanisms such as Standard Contractual Clauses.
7. Retention
- Platform records and normalized data are kept for the retention period configured on the connection, and are removed when a connection is deleted.
- Tokens are deleted when a connection is removed, revoked at the platform, or expires without renewal.
- Operational logs are retained for a limited period for security and debugging, then deleted or de-identified.
- Account and billing records are retained as long as needed for the relationship and for legally required periods afterwards.
8. Your rights
Depending on where you live, you may have the right to access the personal information we hold about you, correct it, delete it, restrict or object to processing, receive a portable copy, and withdraw consent. You can also lodge a complaint with your local supervisory authority.
To exercise a right, email privacy@anisync.link. We will verify the request before acting on it. Where AI Sync processes data on behalf of a customer, we may direct your request to that customer and support them in responding.
9. Meta-specific limitations
- We use Meta Platform Data only to provide and improve the integration the connecting user set up, in line with the permissions granted and Meta's Platform Terms and Developer Policies.
- We do not sell, license, or rent Meta Platform Data.
- We do not transfer Meta Platform Data to data brokers, ad networks, or monetization services.
- We do not use Meta Platform Data to make eligibility decisions about people, such as for credit, insurance, housing, employment, or similar purposes.
- We delete Meta Platform Data when the connection is removed, when the user requests deletion, or when Meta requires it — subject to narrow legal retention obligations.
10. How to delete your data
You can have data removed in two ways:
- Disconnect AI Sync from your Meta/Facebook account through Settings → Business Integrations, or delete the connection inside AI Sync. This stops further access.
- Email privacy@anisync.link to request deletion of data already stored.
Full step-by-step instructions, including what to include in a deletion request, are on the Facebook User Data Deletion Instructions page.
11. Children
AI Sync is a developer tool and is not directed to children. We do not knowingly collect personal information from children. If you believe a child's information has reached us, contact us and we will remove it.
12. Changes to this policy
We may update this policy as the service changes or as legal requirements evolve. The effective date at the top shows the current version. Material changes will be communicated to active customers by email or in-service notice before they take effect where practicable.
13. Contact
Privacy questions, rights requests, and deletion requests: privacy@anisync.link. We aim to acknowledge messages within a few business days.
AI Sync is an independent product and is not affiliated with, endorsed by, or sponsored by Meta Platforms, Inc., Google LLC, or TikTok.