Privacy Policy
Last updated: 27 July 2026
This policy explains what information adUniScale collects when you use our website and platform, why we collect it, who else processes it, and what you can ask us to do with it. We have tried to describe what the product actually does rather than what is merely permitted, including the parts that are easy to overlook.
1. Who we are
adUniScale platform is operated by adUniScale AI Private Limited, a company incorporated under the laws of India (CIN: U62099KA2026PTC223379), with its registered office at Innov8, Prestige Tech Park, Platina 2, 11th Floor, No. 32/2,34/1, Outer Ring Road, Kadubeesanahalli, Bengaluru, Karnataka 560087, India.
In this policy, "we", "us" and "our" refer to that company. "You" refers to anyone who visits our website or holds an account on our platform. For the purposes of the Digital Personal Data Protection Act, 2023 ("DPDP Act"), we are the Data Fiduciary for the personal data described below, and you are the Data Principal.
You can reach us at hello@aduniscale.ai for any question about this policy.
2. Information we collect
Account information
When you create an account we store your email address, your display name, and a profile picture if you upload one. Authentication is handled by Supabase; if you sign in with a password, that password is stored by Supabase and is never visible to us or held in our database. We do not collect your phone number, postal address, date of birth, or any payment or financial information.
Content you create
The platform exists to turn a brief into ad creative, so the brief is the bulk of what we hold:
- Creative briefs — the brand and product information, tone and context, description, cultural notes and target region you type into the platform. These are free-text fields and we store whatever you enter, so please do not paste confidential material you would not want stored.
- Uploaded images — brand logos, product and reference photographs, profile pictures, and any masks you paint in the image editor. Only image files are accepted, up to 10 MB each.
- Editing instructions — the text you type in the conversational image editor is stored verbatim alongside each edit, so that an image's revision history remains intelligible.
- Generated output — the scripts and images the AI produces for you, retained so you can return to them.
Usage and account records
We keep a record of each AI request: which provider and model was used, the request type, whether it succeeded, how long it took, and any error message. For debugging and quality purposes, this record also stores the prompt text sent to the model, which is assembled from your brief. We also keep a ledger of credit activity — grants, charges and refunds — with a short description of what each entry was for.
What we do not collect
We run no analytics, product telemetry, error-tracking, session replay or advertising trackers of any kind. There is no Google Analytics, no advertising pixel, and no third-party script that profiles you. We do not buy personal data about you, and we do not sell, rent or trade your personal data to anyone.
3. How we use your information
- To generate scripts and images from the briefs you submit.
- To create and operate your account, authenticate you, and keep you signed in.
- To meter and account for credit usage, including refunding credits when a generation fails.
- To diagnose faults, monitor reliability and improve the quality of the product's output.
- To send you account emails (see section 6).
- To detect and prevent misuse, and to comply with legal obligations.
We do not use your briefs, uploaded images or generated output to train our own models, and we do not use them to build advertising profiles.
4. AI providers who process your content
adUniScale does not run its own models. When you generate or edit something, the relevant part of your brief — and, where the feature requires it, your uploaded images — is transmitted to the third-party AI provider whose model is selected for that request. You can see and choose the model in the product for most operations.
| Provider | What it is used for | Processing location |
|---|---|---|
| OpenAI | Script generation, image generation and editing | United States |
| Microsoft Azure OpenAI | Script generation, image generation and editing | United States |
| Anthropic | Script generation; describing uploaded reference images | United States |
| Google Cloud Vertex AI (Gemini) | Script generation, image generation and editing | United States and other Google Cloud regions |
| Replicate | Image generation and editing (FLUX, Ideogram) | United States |
| Sarvam AI | Script generation in Indian languages | India |
Two behaviours are worth calling out because they are not obvious from the interface. First, when the script model you have chosen cannot read images, any reference images you uploaded are sent to a separate vision model to be described in words, so that the description can inform the script — meaning your images may reach a provider other than the one named on the model selector. Second, when a brand logo is placed in "blended" mode, the logo image is sent to the image model as a reference; in the default exact-placement mode it is composited by us and is not sent.
Each provider handles data under its own terms. We select providers that commit not to train their models on data submitted through their business APIs, but we do not control their systems and you should consult their policies if that matters to you.
5. Where your data is stored, and transfers outside India
Our database and authentication run on Supabase, hosted on Amazon Web Services in the Mumbai (ap-south-1) region. Our application server runs on Google Cloud Run in Mumbai (asia-south1). Uploaded and generated images are stored in Cloudflare R2.
However, the AI providers listed in section 4 process content outside India, principally in the United States. Google Vertex AI is configured to route to whichever Google Cloud region can serve the selected model, which may be outside India. By using the generation features you acknowledge that your briefs and uploaded images are transferred outside India for processing. Sarvam AI is the one listed provider that processes in India.
6. Other services we rely on
| Service | What it is used for | Location |
|---|---|---|
| Supabase | Authentication and application database | AWS Asia Pacific (Mumbai), India |
| Google Cloud Run and Cloud Logging | Application server and operational logs | asia-south1 (Mumbai), India |
| Cloudflare (R2, Pages, CDN) | Image storage, website and application hosting | Global edge network |
| Resend | Delivery of account emails only | United States |
| Google Fonts | Web fonts loaded by your browser on our pages | Global |
Cloudflare serves our website and application and therefore processes your IP address and request metadata as part of delivering them. Our server logs record operational detail such as the provider, model and outcome of a request; they do not record email addresses or prompt text. Resend delivers account emails only — confirmation, magic link, password reset and similar — and receives the recipient address for that purpose.
Our pages load fonts from Google Fonts, which means your browser contacts Google's servers and Google receives your IP address and user agent whenever you view a page. We mention this explicitly because it is a real transfer that is easy to overlook.
7. Images are served from unguessable public links
This is important, so we state it plainly. Images you upload and images the platform generates are stored under a randomly generated identifier and served from a link containing that identifier. Anyone who has the link can open the image without signing in. The link is effectively the key: the identifiers are random and cannot practically be guessed or enumerated, but they are not additionally protected by a login check.
This design lets you paste a creative into a document, a chat or a review tool and have it render. It also means you should treat these links as confidential and share them only with people you intend to have access.
8. Cookies and browser storage
We do not set cookies, and we use no advertising or analytics cookies whatsoever. Our applications keep a small amount of data in your browser's local storage, which stays on your device and is not transmitted to us as a cookie would be:
- your sign-in session, so you are not logged out on every visit;
- your light or dark theme preference;
- the page you were heading to before signing in, so we can return you there;
- an unsent draft of the brief you are working on, so a refresh does not lose your work.
Clearing your browser storage for our site removes all of this and signs you out.
9. How long we keep things
We keep your account and its content for as long as your account exists, because the product's value is in returning to past work. There is no automatic expiry.
You can delete individual creatives and individual assets at any time from within the product; doing so removes the stored image files as well.
If you ask us to close your account, we delete your account record, your creatives and your credit history. Some operational records — the AI request logs described in section 2, and image edit instructions — are retained in a de-identified form with the link to your account removed, because they are used for cost accounting and reliability analysis. These records can contain the prompt text derived from your briefs. If you want those records erased outright rather than de-identified, say so in your request and we will do it.
10. Security
Access to the platform requires authentication, and requests are verified on every call. Data is encrypted in transit. Our database is not exposed to the public internet. Access to production systems is limited to people who need it.
You should also know that our administrators can view accounts and their content, including creatives, briefs, prompts, editing instructions and credit history, through an internal administration tool. This access exists to provide support, investigate faults and manage credits. We restrict it to staff who need it and it is used for those purposes only.
No system is perfectly secure. If we become aware of a personal data breach affecting you, we will notify you and the Data Protection Board of India as the DPDP Act requires.
11. Your rights under the DPDP Act
As a Data Principal you have the right to:
- Access — obtain a summary of the personal data we hold about you and how it is processed, and the identities of others it has been shared with.
- Correction and completion — have inaccurate or incomplete data corrected or completed, and have data updated.
- Erasure — have your personal data deleted, unless we are required to retain it to comply with law.
- Grievance redressal — raise a complaint with us about how we handle your data, and receive a response.
- Nomination — nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
To exercise any of these, email hello@aduniscale.ai. We will acknowledge within 7 days and aim to resolve within 30 days. We may need to verify your identity before acting. If you are not satisfied with our response, you may complain to the Data Protection Board of India.
12. Children
adUniScale is a business tool and is not directed at children. You must be at least 18 years old to hold an account. We do not knowingly collect personal data from anyone under 18; if we learn that we have, we will delete it.
13. Changes to this policy
We may update this policy as the product changes. When we do, we will revise the date at the top of this page, and for significant changes we will notify account holders by email. Continuing to use the platform after a change means you accept the updated policy.
14. Contact and grievance officer
Questions, requests and complaints about this policy or your personal data should go to our Grievance Officer:
adUniScale AI Private Limited
Innov8, Prestige Tech Park, Platina 2, 11th Floor, No. 32/2,34/1
Outer Ring Road, Kadubeesanahalli,
Bengaluru, Karnataka 560087, India
hello@aduniscale.ai