best-in-slot
PricingLibraryFAQStart free

Privacy Policy

Last updated: September 12, 2026

best-in-slot turns your website and brand inputs into Meta ad creative, and — if you connect an Instagram account — into organic posts we can publish for you. Doing that means handling data about you and your business, and this page explains all of it: what we collect, why, who processes it, how long we keep it, and how to get it deleted. It covers the marketing site (bestinslot.ai), the product app (app.bestinslot.ai), and the data we access through the Meta Marketing and Instagram APIs. Our Terms of Service govern your use of the product; our Data Deletion page has the step-by-step deletion instructions.

1. Who is responsible for your data

The data controller is Göksu Yıldırım, an individual sole proprietor doing business as best-in-slot, based in Türkiye (“we”, “us”, “our”). Under Türkiye’s data protection law (KVKK, Law No. 6698) that makes us the veri sorumlusu; where the GDPR applies, we are the controller in its sense too. For anything about your data, write to [email protected] — it reaches the founder directly.

2. What we collect

Your account

  • Email and password (the password is stored only as a hash, by our auth provider Supabase) — or, if you sign in with Google, your email and the name on your Google profile.
  • Session cookies that keep you signed in to the app (see the cookie table below).

Your email address is the one thing you must provide: without it we can’t create the account or provide the service, so it’s a contractual requirement. Everything else below is collected only when you use the feature it belongs to.

Your business inputs

  • Website URLs you give us, and the page content and screenshots we fetch from them to learn about your business.
  • Brand details — the business summary we write for you, brand colours and identity, and the audience profiles generated from it (all editable by you).
  • Uploaded images — your logo and product photos, stored in a private bucket and served only through short-lived signed links.
  • Product details — names, descriptions, and features you add to your product library.

What we generate for you

  • Ad concepts, AI-generated images, ad copy, and the saved sessions (“flows”) that hold them, plus records of each generation job — its inputs and results.

Meta data (only if you connect your Meta account)

  • Your Meta user ID and name, the permissions you actually granted, and a long-lived access token — encrypted at rest and decrypted only to make the requests you initiate.
  • What we read to let you publish: your ad accounts, your active campaigns (name, ID, status, and objective), your active ad sets (name, ID, status, optimization goal, and promoted object — the pixel, Page, or app the ad set promotes), your Facebook Pages and linked Instagram accounts, and — to match an existing ad’s format — one sibling ad’s creative settings.
  • A record of each ad we create at your request: the exact copy and images sent, and the resulting ad, creative, and ad set IDs.

Instagram posting (only if you link an Instagram account)

  • Which account you post as — the Instagram professional account’s ID, username, and profile picture URL, plus the Facebook Page it is linked to (ID and name). One account per brand; you can unlink it at any time.
  • The posts themselves — the captions, hashtags, alt text, and images we generate for you, and the schedule you set for them. Images are stored in the same private bucket as everything else; when a post publishes, we give Instagram a link that expires within the hour so it can fetch the image once.
  • A record of what went out — the Instagram media ID and permalink of each published post. Like and comment counts are read on demand and never stored: we ask Instagram when you open a published post, and hold the answer for five minutes.

Billing

  • When you first buy something, we pass your email and name to Dodo Payments (our merchant of record) to create your customer record. We store subscription status, plan, payment IDs, and your credit ledger. Card numbers, billing addresses, and invoices never touch our systems — they live with Dodo.

Visits to this website

  • The marketing site uses the Meta Pixel to measure whether our own ads work. It sets the cookies in the table below, and we also forward page-view events to Meta server-side with your IP address and browser user agent (details in section 4).
  • The marketing site also runs Umami, an analytics tool we host ourselves on our own infrastructure — the numbers are not sent to a third-party analytics company. It records the page you looked at, the site that linked you here, your approximate country, and coarse device information (browser, operating system, screen size, language). It sets no cookies, it stores no IP addresses, and it does not follow you to any other site.
  • Marketing measurement starts by default unless you have opted out — see section 4. The product app uses server-side Meta conversion tracking for confirmed signups, checkout starts, and paid purchases when marketing measurement is allowed. It does not load the Meta Pixel or Umami.

Pre-launch waitlist

  • If you joined our waitlist before launch, your email (and the website you optionally shared) is stored with Resend, our email provider for that list, and a hashed version of the email was sent to Meta once to measure the signup. Email us and we’ll remove you.

Server logs

  • Our backend logs requests for debugging with pseudonymized user references (a short hash, not your ID or email). IP addresses are used in memory to rate-limit requests; our application doesn’t store them. Our hosting provider (Railway) keeps its own standard access logs.

3. Why we use it, and on what legal basis

  • To provide the service — building your brand profile, generating concepts, images, and copy, and creating the ad — paused unless you switch that off at publish time — in the ad set you choose when you ask. Legal basis: performance of our contract with you.
  • To bill you — subscriptions, credits, and automatic credit refunds when a generation fails. Legal basis: contract, plus legal obligation for the bookkeeping records we must keep.
  • To keep the service running and safe — debugging, rate limiting, preventing abuse of credits, and tracking what each generation costs us. Legal basis: our legitimate interest in running a secure, solvent service.
  • To measure our own marketing — the Meta Pixel and our self-hosted Umami analytics on this website, and server-side signup and purchase measurement in the app. Measurement starts automatically unless you have turned it off. Section 4 explains what these tools do and how to opt out.
  • To respond to lawful requests — legal basis: legal obligation.

We don’t use your data for anything else. In particular: we don’t train AI models on your content, we don’t sell your data, and we don’t send marketing email. The product sends the signup confirmation (via Supabase) and, if you use Instagram posting, transactional notifications about your own posts. There are five, and this is all of them: a post is ready to review, a posting slot passed without your approval, a post failed, your schedule paused, and — off by default — a post went live. Each can be switched off by category in the product and carries an unsubscribe link, with one exception: the notice that a post failed has neither, because a post that did not go out is something you need to know about. Legal basis: performance of our contract with you.

4. Cookies & tracking

These are all the cookies we set, on either domain:

CookieWhereWhat it doesLifetime
bis-marketing-consentbestinslot.ai and app.bestinslot.aiRemembers your choice and shares it between our website and app.180 days
_fbpbestinslot.aiSet by the Meta Pixel to distinguish browsers, so Meta can tell us whether our ads led to visits, signups, or purchases. The app can read this value for server-side attribution.90 days (per Meta’s documentation)
_fbcbestinslot.aiRecords the Meta ad click that brought you here (only set when you arrive from a Meta ad). Shared with the app to attribute signups and purchases to that click.90 days (per Meta’s documentation)
sb-*app.bestinslot.aiSupabase session cookies that keep you signed in to the app. Strictly necessary — no tracking.Your sign-in session, refreshed while you use the app

Alongside the Pixel in your browser, the marketing site forwards page-view events to Meta server-side (Meta’s “Conversions API”): the event, the page URL without its query string or fragment, the _fbp/_fbc values, your IP address, and your user agent. No email or name is sent with website page views. When measurement is allowed, the app also sends confirmed signup, checkout, and successful purchase events, including the purchase amount and currency. To match those events, it sends SHA-256 hashes of your verified email and account identifier, together with your browser attribution details. Hashing does not make this data anonymous. Attribution and delivery records are kept for up to 90 days; matching data in an event is removed once delivery succeeds. Opting out clears retained matching data and cancels queued events. Events already delivered to Meta cannot be recalled through this tracking system. The app also keeps working data in your browser’s local storage (your active brand and unsaved wizard drafts); that data stays on your device.

Marketing measurement is on by default. It starts when you visit, without waiting for a banner response, unless you previously turned it off. The website shows a choice bar based on your region; the app has no banner. Your explicit choice is saved in a first-party cookie shared by the website and app, with local storage as a fallback. When you are signed in, we also retain your tracking preference to control queued server events. To change it later, use Cookie choices in the website footer or Marketing privacy choices in the app’s Settings. A website withdrawal is also sent to the app when your sign-in session is available; otherwise the app applies it on your next signed-in visit.

To opt out of the Pixel, any of these also work:

  • block or delete third-party cookies for bestinslot.ai in your browser, or browse with an ad blocker — the site works fine without the Pixel;
  • adjust your Meta ad preferences and “off-Facebook activity” settings in your Meta account;
  • email [email protected] and we’ll help.

5. Who processes your data

We don’t sell your personal information. We share it with the service providers below because the product literally runs on them — each gets only what its job needs:

  • Supabase — authentication, database, and private file storage. Holds your account, all app data, and your uploaded and generated images.
  • OpenAI — image generation. Receives the image prompts plus your logo, product photos, and drafts as reference images. OpenAI’s API terms state API data is not used to train its models, and API abuse-monitoring logs are kept up to 30 days.
  • OpenRouter — text generation (business summaries, audiences, ad copy). Receives your scraped site text, brand and product details, page screenshots, and generated images for copywriting, and routes them to the model provider serving the request. OpenRouter states it does not use inputs or outputs for training.
  • Firecrawl — fetches and screenshots the website URLs you give us. Receives only those URLs.
  • Meta — twice, in different roles: the Marketing API when you connect your ad account (section 6), and the Pixel / Conversions API on the marketing site (section 4). Meta processes that data under its own terms.
  • Dodo Payments — our merchant of record. Receives your email and name at first purchase and handles checkout, cards, invoices, and tax in its own right, under its own buyer terms and privacy policy.
  • Railway — hosts our backend, this website, and the Umami instance below. Sees request traffic as any host does.
  • Umami — the analytics described in section 2. We run it ourselves on Railway rather than sending visits to an analytics company, so the only party that receives this data is us.
  • Resend — our transactional email provider. Holds the pre-launch waitlist, and delivers the product’s own notifications about your Instagram posts. Receives your email address and the contents of that message; nothing else from your account.

Beyond these, we disclose personal data only if the law requires it or to protect the rights, safety, and security of our users and the service.

6. Meta platform data

When you connect Meta to run ads, we request exactly these permissions: ads_management, ads_read, business_management, pages_show_list, and pages_read_engagement — and we store only the permissions you actually granted.

Connecting for Instagram posting asks for two more — instagram_basic (to list the Instagram professional accounts behind your Pages, and to read back a published post’s permalink and counts) and instagram_content_publish (to publish the post itself). We ask for those two only if you open the posting area: connecting to run ads never requests them.

We use Meta platform data for exactly two things: letting you browse your own ad accounts, campaigns, ad sets, and Pages, and creating the ad you generated in the ad set you choose — paused by default, live at creation only if you explicitly choose that when you publish; and, if you linked an Instagram account, publishing the posts you approved or scheduled to that account.

We do not sell it, use it to advertise to you, analyse it for any other purpose, or share it with anyone except the processors above as needed to run the service. Your access token is encrypted at rest and used only for requests you initiate.

Disconnect any time from within the product: we ask Meta to revoke the app’s access and delete the stored token immediately. Full instructions, including account deletion, are on the Data Deletion page — which also serves as our data-deletion instructions for Meta platform data.

7. Where your data goes (international transfers)

We’re based in Türkiye; most of the providers above run their infrastructure in the United States, so your data is processed there. We don’t pretend that’s avoidable for a product like this — instead, here’s honestly how it’s safeguarded:

  • each provider processes personal data under the data-processing terms in its service agreement;
  • Railway is certified under the EU-U.S. Data Privacy Framework (with the UK and Swiss extensions), per its published certification;
  • Supabase and our other processors rely on the EU Standard Contractual Clauses or equivalent contractual safeguards;
  • where Türkiye’s KVKK applies to a transfer, we rely on the mechanisms of Law No. 6698 as amended.

Email us if you’d like more detail on any specific provider.

8. How long we keep it

  • Your account and content — kept while your account exists. Ask us to delete it (see below) and we complete the deletion within 30 days, then confirm by email.
  • Meta connection — the stored token is deleted the moment you disconnect. If you simply stop using the service, the token itself expires after roughly 60 days.
  • In-app deletions — deleting a brand immediately deletes its audiences, products, and saved flows. Deleting a single product photo or your logo removes it from your account right away; the underlying stored file is purged when your account is deleted.
  • Instagram posts — a post you rejected or archived keeps its record, but its images are deleted from our storage 30 days later. A published post keeps its images for as long as your account does: it is still on your profile, and we do not delete anything from Instagram itself — the API has no way to, and you remove a post in the Instagram app.
  • Billing and credit records — kept as long as bookkeeping and tax rules require (in Türkiye, up to 10 years), plus a record of each ad we created at your request.
  • Waitlist emails — kept until you ask to be removed or the list is retired.
  • Backups — residual copies in our database provider’s automated backups roll off on its standard rotation.

9. Your rights

Wherever you are, you can ask us to access, correct, or delete your data, or to stop processing it — by emailing [email protected]. We may ask you to confirm you control the account’s email address first. Specifics by regime:

EEA & UK (GDPR)

  • Access, rectification, erasure, restriction of processing, data portability, and objection — including objection to processing based on our legitimate interests.
  • Where processing rests on consent, you can withdraw it at any time (withdrawal doesn’t affect what happened before).
  • You can lodge a complaint with the data protection authority in your country — though we’d appreciate the chance to fix things first.

Türkiye (KVKK)

  • You have the rights in Article 11 of Law No. 6698 — including learning whether and how your data is processed, requesting correction or deletion, and objecting to results produced solely by automated analysis. Exercise them via the same email.
  • If you believe your KVKK rights were violated, you can also lodge a complaint with the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu).

California (CCPA/CPRA)

  • In California’s categories, we collect: identifiers (email, name, account IDs), commercial information (subscriptions, credits, payments), and internet activity (pages visited on this site, Pixel events).
  • We don’t sell personal information. Our use of the Meta Pixel and Conversions API on the marketing site may count as “sharing” for cross-context behavioral advertising under California law. To opt out of that sharing, use any route in section 4 — including simply emailing us.
  • You can request access, deletion, or correction, and we will never discriminate against you for exercising a privacy right. best-in-slot is a small business that may not meet the CCPA’s applicability thresholds, but we honor these requests regardless.

10. Children

best-in-slot is a business tool for adults. It is not directed to anyone under 18, and we don’t knowingly collect data from children. If you believe a child has given us data, email us and we’ll delete it.

11. Security

Concretely, what protects your data:

  • all traffic is encrypted in transit (TLS);
  • your Meta access token is encrypted at rest;
  • uploaded and generated images live in a private bucket and are served only through signed links that expire after 24 hours;
  • the database is locked so that only our backend service can read it — there is no direct client access;
  • server logs pseudonymize user references;
  • card data never touches our systems (it stays with Dodo).

No system is perfectly secure, and we won’t claim ours is — but if a breach ever affects your data, we’ll tell you and the relevant authorities as the law requires.

12. Changes to this policy

When this policy changes, we update the “Last updated” date above. For material changes we’ll notify you by email or in the product before they take effect.

13. Contact

Questions, requests, complaints: [email protected]. You’ll get the founder, not a ticket queue.

best-in-slot

Create ads and Instagram posts from your brand. Publish to Instagram now, schedule ahead, or put daily posting on autopilot.

Product

  • How it works
  • Pricing
  • FAQ
  • Ad Generator
  • Compare

Learn

  • Library
  • Complete Ad Angles
  • Ad Guides
  • Ad Examples

Legal

  • Privacy
  • Terms
  • Data deletion

Contact

[email protected]

© 2026 best-in-slot · Issue #01 ·