1. Introduction
Kotoh ("we," "our," or "us") operates the kotoh.ai platform, an AI-powered ad creative generation
service for businesses. This Privacy Policy explains how we collect, use, disclose, and safeguard
your information when you use our service.
2. Information We Collect
Account Information
When you create an account, we collect:
- Business name and contact information
- Login credentials (username and password)
- Product and brand information you provide for ad generation
Facebook Integration Data
If you connect your Facebook Ads account, we collect:
- OAuth access tokens (used to access your ad account on your behalf)
- Ad account IDs you select
- Ad performance data (impressions, clicks, spend, conversions)
- Ad creative metadata
We do not collect or store your Facebook password. Authentication is handled
entirely by Facebook's OAuth system.
Usage Data
We automatically collect:
- Log data (IP address, browser type, pages visited)
- Ad generation history and preferences
- Approval/rejection actions and feedback
3. How We Use Your Information
We use collected information to:
- Provide and maintain our ad generation service
- Generate AI-powered ad creatives tailored to your products
- Sync and analyze ad performance data from connected platforms
- Improve our AI models based on your feedback (approved/rejected ads)
- Communicate with you about your account and service updates
- Ensure security and prevent fraud
4. Data Sharing and Disclosure
We do not sell your personal information. We may share data with:
- Service Providers: Third-party services that help us operate (cloud hosting,
image storage, AI processing). These providers are contractually bound to protect your data.
- Facebook/Meta: When you use the Facebook integration, data flows between
our service and Facebook's APIs as necessary to provide the requested functionality.
- Legal Requirements: When required by law or to protect our rights.
5. Data Retention
We retain your data for as long as your account is active or as needed to provide services.
Generated ad creatives and associated data are retained until you delete them or close your account.
Facebook access tokens are stored securely and can be revoked at any time through the Settings
page or by disconnecting the integration.
6. Data Security
We implement industry-standard security measures including:
- Encryption of data in transit (HTTPS/TLS)
- Secure storage of credentials and tokens
- Regular security assessments
- Access controls and authentication
7. Your Rights
You have the right to:
- Access: Request a copy of your personal data
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your data (see Data Deletion)
- Disconnect: Revoke Facebook integration at any time via Settings
- Export: Download your approved ad creatives
8. Facebook Data
When you connect your Facebook account, you authorize us to access certain data from your
Facebook Ads account. You can revoke this access at any time by:
- Going to Settings in Kotoh and clicking "Disconnect Facebook"
- Removing Kotoh from your Facebook Business Settings
For data deletion requests related to Facebook data, please visit our
Data Deletion page.
9. Children's Privacy
Our service is not intended for individuals under 18 years of age. We do not knowingly
collect personal information from children.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by
posting the new policy on this page and updating the "Last updated" date.
11. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us at:
Email: privacy@kotoh.ai
© 2026 Kotoh. All rights reserved.