Legal

Privacy Policy

Last updated: June 2026

1. Introduction

tadan (“we”, “our”, “us”) provides an AI-powered ad compliance scanner that checks your ad copy and landing pages against the policies of major ad platforms. This Privacy Policy explains what data we collect, how we use it, and the choices you have.

By using tadan, you agree to the practices described below. If you do not agree, please do not use the service.

2. Information We Collect

Account data. When you create an account, we collect your name, email, and a hashed password. We never see or store your plaintext password.

Scan data. When you run a compliance scan, we store the ad copy or landing page URL you submit, the platforms you targeted, the violations we flagged, and the risk score we returned. This powers your scan history.

Usage data. We log basic request metadata (IP address, user agent, timestamps) to operate the service, prevent abuse, and debug issues.

Anonymous analytics. We use Umami to collect anonymized, aggregate page-view statistics (which pages are visited, what device or country a visit came from). This helps us understand how tadan is used so we can prioritize improvements. Umami is configured to be cookie-less and does not collect any personally identifiable information. You can opt out by enabling your browser's “Do Not Track” signal — Umami respects it automatically.

3. How We Use Your Information

  • To run compliance scans and return verdicts to you
  • To save and display your scan history (only you can access it)
  • To authenticate you and protect your account
  • To send essential service emails (sign-in links, security alerts) — we do not send marketing email
  • To respond to support requests you initiate

4. Cookies and Local Storage

Session cookies. tadan uses better-auth to manage your login session. better-auth sets a single HTTP-only cookie containing a signed session token. We do not set any tracking or advertising cookies.

Analytics.Our self-hosted Umami instance is configured without cookies. It identifies unique visitors using a one-way hash of IP address + user agent that is rotated every 24 hours, and does not set anything in your browser's storage.

Local storage.We store one flag in your browser's localStorage to remember whether you have signed in on this device before. This is used only to route the “Get started” button to the correct page. You can clear it at any time from your browser settings.

5. Third-Party Services

To run scans, we forward your ad copy to third-party AI model providers (via OpenRouter) and to vector search systems. These providers receive only the text you submit — never your account data, password, or payment info.

We also use a managed Postgres database (with the pgvector extension) to store your scans and the policy document embeddings our scanner compares against.

For aggregate, anonymized usage analytics we use Umami, self-hosted on our own infrastructure. The analytics script receives only the current page URL, referrer, viewport size, and a rotated visitor hash. It does not receive your account email, scan content, or any other input you type into tadan.

We do not sell your data. We do not share your scan content with other customers. Aggregated, anonymized usage statistics may be used to improve the product.

6. Data Security

We use industry-standard encryption in transit (HTTPS) and at rest (provider-managed disk encryption). Passwords are hashed with bcrypt. Access to production data is restricted to a small number of team members. That said, no system is 100% secure — if you suspect your account has been compromised, contact us immediately.

7. Your Rights

  • Access. You can view all your scans from the History page at any time.
  • Deletion. You can delete individual scans, or contact us to delete your entire account and all associated data.
  • Export. On request, we will export your scan history as JSON or CSV.
  • Correction. You can update your name and email from your account settings.

8. Children’s Privacy

tadan is not directed to children under 16. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.

9. Changes to This Policy

We may update this policy as the product evolves. We will post the revised version here and update the “Last updated” date below. For material changes, we will notify you by email.

10. Contact

Questions about this policy or your data? Email us at tadan@erencakar.com.