AdBase Home

Last updated: 26 September 2026

Privacy Policy

AdBase is an ad library for ecommerce teams and their AI agents. This policy explains what personal data we process when you use getadbase.com, why, and what rights you have.

Who we are

AdBase is operated by Terminus, based in the Netherlands (“we”, “us”). We are the controller of the personal data described here. Questions or requests: info@terminus-sst.com.

What we collect

  • Account data: your email address and password. Passwords are stored only as a hash by our authentication provider; we never see them.
  • Workspace data: the organizations you create or join, memberships and roles, the competitors on your watchlists, the websites and brands you ask us to look up, and the ads you save.
  • Connected apps: when you connect an AI app, the app’s name, the fact that you approved it, and the access tokens issued to it.
  • Technical data: IP address, browser details, and request logs kept by our hosting provider, plus the country derived from your IP address, which we use only to pick English or Dutch on the homepage.
  • Emails to us: whatever you send when you request access or contact us.

Public ad data

The ads, emails, and landing pages in AdBase are commercial content that brands publish themselves. We collect ads from public sources such as the Meta Ad Library, capture public landing pages, and subscribe to brand newsletters with mailbox addresses on postboxhome.com that belong to AdBase, not to you or any other person. This content can contain names or images of people who appear in ads, or the name of an advertiser’s contact person as published in the ad library. We process it for the legitimate interest of providing market research on public advertising. If you appear in this content and want it removed, email us.

We use AI models to tag and transcribe this public content. Your account data, watchlists, and questions are not sent to these models.

Why we use it

  • To create and secure your account and let you sign in (performance of our agreement with you).
  • To provide the product: your workspace, watchlists, saved ads, and lookups (performance of our agreement).
  • To keep the service reliable and secure and to prevent abuse (legitimate interest).
  • To respond to access requests and support questions (legitimate interest).
  • To comply with legal obligations.

We do not sell personal data, show advertising, or use your data to train AI models.

AI apps connected through MCP

You can connect AdBase to AI apps such as Claude or ChatGPT through our MCP server. After you sign in and approve the app on our consent screen, it receives an access token and can read and act on your AdBase data on your behalf, within the permissions of your account. Whatever the app does with the answers is governed by that app provider’s own terms and privacy policy. You can revoke access at any time from the account menu under Connected apps.

Service providers

We rely on the following providers, who process data on our behalf and only as needed for their service:

  • Supabase — authentication and our database: your account, organizations, watchlists, saved ads, and connected apps.
  • Vercel — hosting of the website and app, including request logs (IP address, user agent, requested URL).
  • Hetzner — servers that run our background jobs (collecting and analyzing public ads, emails, and landing pages).
  • Cloudflare R2 — storage of ad creatives, landing page screenshots, and newsletter copies.
  • Amazon Web Services (SES, S3, SQS) — receiving newsletters sent to the addresses AdBase uses to subscribe to brands.
  • ScrapeCreators and Bright Data — retrieving public ads and advertiser pages from the Meta Ad Library and social profiles.
  • Firecrawl and Browserless — loading and capturing public landing pages and brand signup forms.
  • OpenRouter (Google Gemini) and Typesafe AI — classifying and describing public ads, emails, and advertisers.

Some of these providers are located in, or have sub-processors in, countries outside the European Economic Area, such as the United States. Where that happens, transfers rely on safeguards such as the EU–US Data Privacy Framework or the European Commission’s Standard Contractual Clauses.

Cookies and local storage

We use only cookies and storage that are needed for the site to work. We do not use analytics, advertising, or tracking cookies.

  • Authentication cookies that keep you signed in.
  • adbase-organization — remembers your active organization.
  • adbase-locale — remembers whether you chose English or Dutch.
  • sidebar_state — remembers whether the app sidebar is open.
  • adbase-theme (local storage) — remembers your light, dark, or system theme.

How long we keep data

We keep account and workspace data for as long as your account exists. When you ask us to delete your account, we delete your account and workspace data within 30 days, except where we must keep something longer by law. Hosting logs are kept for a limited period by our providers. Public ad data is not tied to your account and is kept as part of the library.

Your rights

Under the GDPR you have the right to access, correct, delete, or export your personal data, to restrict or object to its processing, and to withdraw consent where we rely on it. To use any of these rights, including deleting your account, email info@terminus-sst.com from the address on your account. We respond within one month. You can also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or your local supervisory authority.

Security

Data is sent over HTTPS. Database access is limited per organization, so members see only their own organization’s workspace. No system is perfectly secure; if a breach affects your data, we will inform you and the authorities as the law requires.

Changes

We may update this policy as AdBase evolves. The date at the top shows the latest version. For material changes we will notify account holders by email. See also our Terms of Service.