Last updated · July 10, 2026
Cevra helps Indian D2C sellers run Meta ads with AI agents. This policy explains, in plain English, what we collect, why we collect it, who we share it with, and the control you have over it. It applies to cevra.co and the Cevra application.
Cevra (“Cevra”, “we”, “us”) operates an AI-powered advertising platform that creates, launches, and optimises Meta advertising campaigns on behalf of sellers. We are the data fiduciary for the account and business information you give us, and a data processor for the customer data you bring to us to build audiences and measure conversions (see Section 4).
Cevra is an independent tool. We are not affiliated with, endorsed by, or sponsored by Meta Platforms, Inc. You can review, manage, and delete your data at any time directly from your Cevra dashboard — see Section 10.
When you sign up and use Cevra, you provide:
With your authorisation, and only to run and improve your campaigns, we access data through the Meta Marketing API:
We use this strictly to build, monitor, and optimise the ads we run for you. We access only what your connected assets expose and nothing more.
To build Custom Audiences or send conversion events (Conversions API) on your behalf, you may provide customer information such as hashed email addresses or phone numbers and purchase/order events. When you do this, we act as your data processor — we handle that data only on your documented instructions, to create your audiences and send your conversions.
Customer identifiers are hashed as required by Meta before transmission. We do not use your customers’ data for our own purposes, and we do not sell it. You are responsible for having a lawful basis to share this data with us and Meta, and for informing your customers as your local law requires.
We do not sell your personal data, and we do not use it for advertising unrelated to your own campaigns.
Cevra uses third-party large language models to write your ad copy and to analyse your uploaded images (computer vision) so the copy matches what is actually in each photo. To do this we send the relevant product details and a short-lived, signed link to the image to our AI provider.
We send only what is needed to generate your outputs, and we do not permit your data to be used to train third-party public models beyond producing your results. Every AI-assisted creative is quality-scored and policy-checked before it is shown to you or used.
We encrypt data in transit using HTTPS/TLS, and we encrypt sensitive secrets at rest — your Meta tokens and API keys are stored with AES-256-GCM encryption. We use access controls, secure HTTP-only session cookies, per-IP rate limiting, and audit logging. No system is perfectly secure, but we treat your credentials and data as if they were our own.
We keep your data while your account is active so we can run and improve your ads. Meta credentials are retained only as long as needed to operate your campaigns. When you disconnect Meta, we delete the stored Meta credentials. When you delete your account, we delete or de-identify your personal data and uploaded media within a reasonable period, except where we must retain limited records to meet legal, tax, or accounting obligations.
You are always in control of your data, and everything is self-service inside the app:
This section also serves as our data deletion instructions as required by the Meta Platform Terms. Deleting your account from Settings → Delete account removes the data associated with your Meta login. We may keep only limited records where the law requires (for example, tax or accounting), never including your Meta access token or uploaded media.
Under India’s Digital Personal Data Protection Act, 2023 (and, where applicable, other data-protection laws), you have the right to:
You can exercise most of these rights yourself from your dashboard: view and edit your brand, product, and account details in Settings, disconnect Meta in Settings → Connections, and erase everything in Settings → Delete account. If you are in a region with additional rights (such as the EU/UK), you may also have rights to data portability and to object to certain processing, which you can raise through your account.
Cevra is a business tool intended for use by people aged 18 and over. It is not directed at children, and we do not knowingly collect personal data from anyone under 18.
Some of our providers (for example, Meta and our AI provider) may process data on servers outside India. Where they do, we rely on their contractual and technical safeguards to protect your data consistent with this policy.
We may update this policy as the product or the law evolves. We will post the new version here and update the “Last updated” date above. For material changes, we will give you notice — for example, by email or an in-app message.
You control your data directly from your Cevra dashboard: Settings to view and update your details, Settings → Connections to disconnect Meta, and Settings → Delete account to erase your account and everything in it. No email or form is needed — the controls are built into the app.
This document is provided for transparency and to explain how Cevra works. It is not legal advice. The companion document is available here: Terms of Service.