sugarLENS Sign in

Data & security

How sugarLENS handles your data

The questions data-protection teams ask before a brand connects its ad accounts, answered the way we answered them. Every statement below was verified against the running system.

What is read from the ad managers

Campaign structure and performance via the official interfaces of Meta, Google, TikTok, Snapchat and Reddit: campaigns, ad sets, ads, daily spend, impressions, clicks, video views, watch time, conversions, plus aggregated audience breakdowns by age, gender and country as the platforms provide them.

Previews of the creatives (thumbnails) are stored. During AI analysis a video may be processed temporarily as a file; the master files you upload are kept in our storage.

We do not read individual user profiles, names or contact details from any ad account. Audience data is exclusively the aggregated evaluations the platforms provide.

Stored, not queried live

Data is stored in sugarLENS, not only fetched on demand. That is what makes trend analyses over long periods, year-on-year comparisons and creative benchmarks possible.

Storage is a PostgreSQL database at Supabase in the EU (Ireland). The backend runs on Railway, also within the EU. AI analysis runs on Google Vertex AI in the EU region; the global fallback is disabled.

Data is kept for the duration of the collaboration and is not passed to third parties for their own purposes.

How it is protected

In transit, TLS. At rest, AES-256 for the database and file storage. The providers we run on hold the certifications: Supabase is SOC 2 Type II certified and the underlying AWS infrastructure is certified to ISO 27001 and SOC 2. JUSTADDSUGAR itself holds no certification of its own.

Access inside sugarLENS is enforced in the database with row-level security: a client login can only ever read the brands it was granted, and every API request runs under that login's own permissions.

Two administrators at JUSTADDSUGAR manage access. Staff only see the brands they work on. A nightly backup copies every table that cannot be re-fetched from a platform into a second, equally EU-hosted project.

Access to your ad accounts

sugarLENS reads through access you grant in the platform's own business manager: a partner assignment on Meta, an advertiser assignment on TikTok, a manager link on Google Ads. Read permissions only; sugarLENS never changes a campaign, a budget or an ad.

You can revoke that access in the platform at any moment. From then on no new data arrives.

Deletion when the collaboration ends

Two steps. First the data flow stops, because the platform access is revoked. Then all stored data for the brand is deleted from the production database and, with the next nightly swap, from the backup.

Organic and community data

Facebook and Instagram organic data is retrieved once per night via Meta's Graph API for pages you connect. TikTok organic via TikTok's official interface with an application registered by JUSTADDSUGAR. Comments are stored to measure sentiment and to let the community team answer from one inbox; reply and hide actions are only possible with an explicit grant.

Questions from your data-protection team?

We answer them in writing and sign a data processing agreement. Write to sugarlens@justaddsugar.de.