Privacy Policy

Last updated: March 23, 2026

1. Introduction

Gavio ("we", "us", or "our") operates the website gavio.ai and the Gavio platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

2. Information We Collect

2.1 Account Information

When you register, we collect your email address and an encrypted password. If you sign in via Google, we receive your name and email from Google.

2.2 Google Ads Data

When you connect your Google Ads account, we access your advertising campaign data (spend, clicks, impressions, conversions) via the Google Ads API. We use this data solely to generate reports and AI-powered insights for you. We do not sell or share your Google Ads data with third parties.

2.3 Payment Information

Payments are processed by Stripe. We do not store your credit card number. Stripe provides us with a customer ID and subscription status to manage your plan.

2.4 Usage Data

We may collect information about how you access and use the Service, including your IP address, browser type, pages visited, and timestamps.

3. How We Use Your Information

  • To provide, maintain, and improve the Service
  • To generate AI-powered advertising reports and insights
  • To process payments and manage subscriptions
  • To send you service-related emails (reports, account notifications)
  • To respond to your requests and support inquiries
  • To detect and prevent fraud or abuse

4. Data Sharing

We do not sell your personal data. We may share data with:

  • Stripe — for payment processing
  • Google — to access your Google Ads data via their API (with your explicit consent)
  • Anthropic — we send anonymized/aggregated campaign metrics to generate AI insights; no personally identifiable information is sent
  • Resend — for transactional email delivery
  • Fly.io — our hosting provider (data is stored in the EU — Stockholm region)

5. Data Storage & Security

Your data is stored on servers in the EU (Stockholm, Sweden) via Fly.io. We use encryption in transit (TLS/HTTPS) and encrypt passwords with bcrypt. Access to production systems is restricted.

6. Your Rights (GDPR)

If you are in the EU/EEA, you have the right to:

  • Access — request a copy of your personal data
  • Rectification — correct inaccurate data
  • Erasure — request deletion of your account and data
  • Portability — receive your data in a machine-readable format
  • Object — object to processing based on legitimate interest
  • Withdraw consent — disconnect Google Ads access at any time

To exercise these rights, email us at privacy@gavio.ai.

7. Cookies

We use essential cookies and localStorage to maintain your session (JWT authentication token) and language preference. We do not use third-party tracking cookies or analytics services.

8. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we will remove your personal data within 30 days. Anonymized, aggregated data may be retained for analytics purposes.

9. Children's Privacy

Our Service is not directed to individuals under 16. We do not knowingly collect personal data from children.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or via a notice on our website.

11. Contact

If you have questions about this Privacy Policy, contact us at:

privacy@gavio.ai