Privacy Policy
Last updated August 19, 2026 · Version 1
1. Data controller
AdLighter is operated by Sefirot Srl, a company registered in Italy with its registered office at Via Vittorio Amedeo Cignaroli 8, 10152 Torino, Italy, VAT number IT11963260010, REA TO-1254392. Sefirot Srl is the data controller for the personal data described in this policy: it decides why and how that data is processed.
Sefirot Srl has not appointed a Data Protection Officer (DPO). Under Article 37 of the GDPR, appointing one is not mandatory for a company of this size and with this type of processing; questions about this policy can be sent to the contact details in the Contact section below.
2. What we collect
We collect the following categories of personal data when you use AdLighter:
- Account data: your email address and name, used to create and identify your account.
- Billing data: billing address, VAT number or Codice Fiscale, Codice Destinatario, and country, collected to issue invoices and comply with tax law. Card details are entered directly into Stripe's hosted checkout and are handled entirely by Stripe: they never reach Sefirot's servers.
- Content you create or upload: product descriptions, images, scripts, and the ad creatives AdLighter generates for you, stored so you can retrieve and reuse your work.
- Usage and cost logs: records of which features you use, when, and their processing cost (table api_logs), used to enforce plan limits and to bill credits accurately.
- Support correspondence: the content of any email or message you send us when you ask for help.
3. Why we process it, and on what legal basis
We rely on four legal bases under the GDPR, depending on the processing activity:
- Performance of the contract: most processing, including account data, content storage, and generating your ad creatives, is necessary to provide the AdLighter service you subscribed to.
- Legal obligation: we process billing data to issue invoices and keep accounting records, since Italian law (art. 2220 of the Codice Civile) requires us to retain fiscal documents for 10 years.
- Legitimate interest: we rely on this basis for two specific activities. First, our refund anti-fraud blocklist retains an email address and a card fingerprint associated with a refund claim, so we can recognise and block repeat abuse of the refund policy. Second, we send a single reminder email to accounts that registered but never subscribed, to recover an abandoned signup. In both cases we have weighed this interest against your rights and consider the impact on you limited and proportionate; you can object as described in Your rights below.
- Consent: non-essential cookies are set only with your consent, which you can give or withdraw at any time. See our Cookie Policy for the full list.
4. How AI providers process your content
AdLighter's core function is to send the content you submit, such as product descriptions, reference images, and scripts, to third-party artificial intelligence providers, which process it and return the generated text, image, voice, or video you requested. We use Anthropic (Claude) and OpenAI for text generation; OpenAI and Google (Gemini) for image generation; ElevenLabs for voice synthesis; fal.ai for image and video generation; and Exa for market research search.
Each of these providers operates its own commercial or API terms, separate from their free consumer products. As at the date of this policy, and subject to each provider's terms as they stand from time to time: Anthropic's and Google's published terms state explicitly that content submitted through paid, commercial use is not used to train or improve their models (Anthropic, Google). OpenAI publishes a similar commitment in its own API data usage policy (OpenAI); we were not able to re-verify the current wording of that page while writing this policy, so we link it here rather than quote it. ElevenLabs, fal.ai, and Exa each carve business and API customers out of the training use that applies to their free consumer products, and instead govern that data under separate commercial terms (ElevenLabs, fal.ai, Exa).
These are commitments each provider makes in its own terms, not a guarantee Sefirot gives on their behalf. Provider terms can change; if this matters to you, read the linked terms directly rather than relying only on this summary.
None of this processing amounts to automated decision-making that produces legal effects on you or similarly significantly affects you: the AI providers generate the content you asked for, they do not decide anything about your account, your access, or your rights.
5. Sub-processors
We share personal data with the following sub-processors, each engaged under a data processing agreement (or, for our AI providers, their standard commercial or API terms) that limits their use of the data to providing the service to us:
- Supabase: database, authentication and stored content. Ireland (eu-west-1).
- DigitalOcean: application hosting; media storage (Spaces). Amsterdam (ams3).
- Anthropic: text generation. United States.
- OpenAI: text and image generation. United States.
- Google: text and image generation (Gemini). United States.
- ElevenLabs: voice synthesis. United States.
- fal.ai: image and video generation. United States.
- Exa: market research search. United States.
- Stripe: payment processing, billing data. United States / Ireland.
- Resend: transactional email delivery. United States.
- FiscalHub: fiscal transaction reporting. Italy.
- Fatture in Cloud: electronic invoicing. Italy.
- European Commission (VIES): VAT number validation. European Union.
6. International transfers
Our database (Supabase, Ireland) and our media storage (DigitalOcean Spaces, Amsterdam) are both located inside the European Union, so no transfer occurs for that data.
Only a subset of our sub-processors involve a transfer of personal data outside the EU: our AI providers (Anthropic, OpenAI, Google, ElevenLabs, fal.ai, Exa), Stripe, and Resend. Where we transfer personal data to a country outside the EU/EEA that the European Commission has not recognised as offering an adequate level of protection, we rely on the European Commission's Standard Contractual Clauses (SCCs) with that provider, supplemented, where the provider is certified, by the EU-US Data Privacy Framework (DPF).
7. How long we keep your data
We keep account data for as long as your account is active. If it becomes inactive, we apply the following schedule:
- Signups that never convert to a paying customer: we send a notice at 5 days of inactivity and delete the account 2 days later, at day 7, if no subscription has started.
- Lapsed paying customers (a subscription that has ended): we send a warning at 30 days after the subscription ends. Low-usage accounts are then deleted at day 37. Accounts above the low-usage threshold receive a second warning at day 60 and are deleted at day 67 if the account has not been reactivated.
You can delete your account yourself at any time from Settings; this does not wait for the schedule above.
Fiscal records (invoices and related accounting data) are kept for 10 years, as Italian law requires, in Fatture in Cloud, FiscalHub, and Stripe. The refund anti-fraud blocklist keeps an email address and card fingerprint for as long as the abuse risk that justified listing them persists.
8. Your rights
Under the GDPR you have the right to: access the personal data we hold about you; have inaccurate data corrected (rectification); have your data deleted (erasure); restrict how we process it; receive a copy of it in a portable format; and object to processing based on our legitimate interest.
To exercise any of these rights, contact us at info@sefirot.it. You can also delete your account yourself at any time from Settings, without contacting us.
If you believe we have not handled your data properly, you have the right to lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Roma, Italy.
9. Security
We apply technical and organisational measures appropriate to the risk: data in transit is encrypted with TLS; our database enforces row-level security, so a user's data is only reachable within the workspace it belongs to; the credentials that bypass those restrictions are confined to backend services and are never exposed to the browser; and access to production systems is limited to the personnel who need it to operate the service.
Authorised Sefirot personnel may access an account, including its content and generated history, to provide you with support or to investigate a reported fault, limited to what is necessary for that purpose.
No system is completely secure, and we cannot guarantee absolute security. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Garante and, where required, you, within the timeframes set by the GDPR.
10. Children
AdLighter is not directed at, and is not intended for use by, anyone under 18 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at info@sefirot.it and we will delete it.
11. Changes to this policy
We may update this policy as our processing activities, our sub-processors, or the law change. When we do, we update the date at the top of this page and increase the version number if the change is substantive. We will notify you of material changes by email or with a notice inside the app; continuing to use AdLighter after a change takes effect means you accept the updated policy.
12. Contact
For questions about this privacy policy, or to exercise your rights, contact us:
- Sefirot Srl, Via Vittorio Amedeo Cignaroli 8, 10152 Torino, Italy
- VAT IT11963260010
- REA TO-1254392
- PEC sefirotsrl@pec.it
- Email info@sefirot.it