Privacy policy
Varaliq is operated by ATG Enterprises – FZCO, United Arab Emirates. Contact support@atg.enterprises with privacy questions or requests. Varaliq is a new replacement for the discontinued CopySwift product. The Meta integration currently uses the existing CopySwift app registration.
Information we process
We process your account email, authentication information, workspace membership, brand details, creative briefs, uploaded or generated assets, job history and credit usage. When you connect Meta, the enabled features may process your Meta user identifier, access tokens, granted permissions, advertising accounts, Pages, campaign and ad identifiers, creative content and advertising performance data. If you explicitly use lead retrieval, lead-form responses may contain personal information.
Why we use it
We use this information to authenticate you, keep workspaces separate, produce and store creative, perform actions you approve, display advertising results, manage usage and billing, and investigate service problems. Meta publishing requires a review step; the initial publishing flow creates paused ads. We do not sell Meta Platform Data or use it to build advertising profiles outside the service.
Service providers
Supabase provides authentication, database and private asset storage. Vercel hosts the application and runs server functions. OpenAI provides image generation and Anthropic provides draft copy. Billing uses Stripe when activated; email delivery uses Resend. When you import a public brand website, ScreenshotOne captures a visual reference of that page. ScreenshotOne receives the public website URL, not your Meta access tokens or ad-account data. We pass each provider only the information needed for the requested feature. Image and copy prompts use brand information and the brief; our generation pipeline does not send Meta access tokens or retrieved leads to AI providers. Payment-card details are collected by Stripe, not stored in our application database. Clerk and Firebase are not used by this replacement application.
AI apps you connect
If you connect an AI app through MCP, you choose one workspace and approve read access to its brand information, creative copy and images, generation status, credit balance and synced ad insights. The connected app receives that information when it calls a tool. MCP does not share Meta access tokens, lead responses or payment credentials, and cannot generate or publish ads. The receiving app handles the information under its own terms and privacy policy. You can revoke access from Connected apps. Revocation prevents future access; it does not delete information already received by that app. Connector credentials are stored as hashes, with expiring access and workspace permissions checked on each request.
Email and cookies
Authentication uses essential session cookies. We retain your acquisition-page choice to tailor workspace setup. If you opt in to onboarding tips, we send a short first-ad series; you can unsubscribe through any message. The sequence stops when your workspace creates its first ad. Account security and billing messages are separate from optional onboarding tips. Optional product-usage analytics are provided by PostHog US Cloud only if you enable Usage analytics. We send selected action names and an anonymous session identifier; we do not enable session replay or automatic form capture, and we exclude email addresses, brand briefs, Meta identifiers and ad content. You can turn this off in the footer or workspace header. Advertising trackers are not enabled in this release.
Retention and deletion
Workspace records and creative assets are retained while your account or workspace remains active or until you request deletion. Disconnecting Meta removes the connection token; it does not automatically erase previously imported results, leads or creative. To request deletion of your account, workspace or Meta-derived information, email support@atg.enterprises. We verify your authority, remove the relevant application data and confirm completion, aiming to respond within 30 days. We may retain limited billing or security records where needed for legal obligations or dispute resolution. Backup copies can persist for the hosting provider’s backup retention period and are not used as active application data. Deleting an asset in Varaliq does not delete an ad already created in Meta; manage those ads in Meta or include them in your request.
Security and international processing
We use workspace access controls, private storage and encryption of Meta connection tokens and retrieved lead fields. Access is restricted according to workspace role. Our providers may process information in countries outside your own, including the region selected for our Supabase project. No internet service can guarantee absolute security.
Your choices
You can update brand information, disconnect Meta, unsubscribe from optional emails, and request access, correction, export or deletion by emailing support@atg.enterprises. Please identify the account and request without including passwords or access tokens. You can also remove the app through Meta’s business integration settings. Where applicable, you may raise a concern with your data-protection authority.
Changes
We update this policy when the service, processors or product name changes. The legal operator and this policy’s contact address remain the reference for privacy requests. A new product name does not by itself transfer your information to a new legal operator.