Cevra
How it worksWhy CevraYour teamGuides
Start free
Open navigation
How it worksWhy CevraYour teamGuides
Sign inStart free

Built in India for Indian D2C sellers who'd rather grow their brand than babysit a dashboard.

Start free

Explore

How it worksWhy CevraYour teamQuestions
© 2026 Cevra · Not affiliated with Meta
PrivacyTerms
CEVRA
Privacy Policy

Your data, handled with care.

Last updated · July 10, 2026

Cevra helps Indian D2C sellers run Meta ads with AI agents. This policy explains, in plain English, what we collect, why we collect it, who we share it with, and the control you have over it. It applies to cevra.co and the Cevra application.

1. Who we are

Cevra (“Cevra”, “we”, “us”) operates an AI-powered advertising platform that creates, launches, and optimises Meta advertising campaigns on behalf of sellers. We are the data fiduciary for the account and business information you give us, and a data processor for the customer data you bring to us to build audiences and measure conversions (see Section 4).

Cevra is an independent tool. We are not affiliated with, endorsed by, or sponsored by Meta Platforms, Inc. You can review, manage, and delete your data at any time directly from your Cevra dashboard — see Section 10.

2. Information you give us

When you sign up and use Cevra, you provide:

  • Account details — your name, email address, and a password (which we store only as a salted hash, never in plain text).
  • Brand profile — your brand name, industry, store URL, target audience, brand voice, and budget preferences, so our agents understand your business.
  • Product information — product names, descriptions, prices, and destination links for the items you advertise.
  • Media — the photos and videos you upload to build your ads. These are stored in secure object storage and used to assemble your creatives.
  • Meta connection details — your Meta System User access token, Ad Account ID, Page ID, and (optionally) Pixel / dataset ID. These credentials are encrypted at rest using AES-256-GCM, are never displayed back to you after entry, and are never shared or sold.

3. Information we receive from Meta

With your authorisation, and only to run and improve your campaigns, we access data through the Meta Marketing API:

  • Ad account details (name, currency, status).
  • Campaign, ad set, and ad status and settings that we create or manage for you.
  • Performance metrics — spend, impressions, clicks, and conversions such as purchases.
  • Pixel / Conversions API event signals, where you have connected them.

We use this strictly to build, monitor, and optimise the ads we run for you. We access only what your connected assets expose and nothing more.

4. Customer data you bring (and how we treat it)

To build Custom Audiences or send conversion events (Conversions API) on your behalf, you may provide customer information such as hashed email addresses or phone numbers and purchase/order events. When you do this, we act as your data processor — we handle that data only on your documented instructions, to create your audiences and send your conversions.

Customer identifiers are hashed as required by Meta before transmission. We do not use your customers’ data for our own purposes, and we do not sell it. You are responsible for having a lawful basis to share this data with us and Meta, and for informing your customers as your local law requires.

5. How we use your information

  • Deliver the service — create, launch, and manage your ad campaigns through the Meta Marketing API.
  • Run our AI agents — write ad copy, assemble creatives from your uploaded photos, quality-check them, and optimise live campaigns against your cost targets.
  • Communicate with you — email verification, password resets, approval requests, and performance or budget alerts.
  • Operate, secure, and support — troubleshoot, prevent abuse, and keep the platform reliable.
  • Meet legal obligations — comply with applicable law and Meta’s platform requirements.

We do not sell your personal data, and we do not use it for advertising unrelated to your own campaigns.

6. AI processing

Cevra uses third-party large language models to write your ad copy and to analyse your uploaded images (computer vision) so the copy matches what is actually in each photo. To do this we send the relevant product details and a short-lived, signed link to the image to our AI provider.

We send only what is needed to generate your outputs, and we do not permit your data to be used to train third-party public models beyond producing your results. Every AI-assisted creative is quality-scored and policy-checked before it is shown to you or used.

7. Who we share information with

We share data only with service providers that help us run Cevra, and only what is necessary:

  • Meta Platforms — to create and run your ads on your ad account. Meta’s handling of that data is governed by Meta’s own terms and your relationship with Meta.
  • Our AI provider — to generate ad copy and analyse images, as described in Section 6.
  • Infrastructure providers — server hosting, object storage (Cloudflare R2) for your media, our database, and cache. These providers process data under confidentiality and security obligations.

We may also disclose information if required by law, to enforce our terms, or to protect the rights and safety of our users and the public. We never sell your data.

8. How we protect your data

We encrypt data in transit using HTTPS/TLS, and we encrypt sensitive secrets at rest — your Meta tokens and API keys are stored with AES-256-GCM encryption. We use access controls, secure HTTP-only session cookies, per-IP rate limiting, and audit logging. No system is perfectly secure, but we treat your credentials and data as if they were our own.

9. How long we keep it

We keep your data while your account is active so we can run and improve your ads. Meta credentials are retained only as long as needed to operate your campaigns. When you disconnect Meta, we delete the stored Meta credentials. When you delete your account, we delete or de-identify your personal data and uploaded media within a reasonable period, except where we must retain limited records to meet legal, tax, or accounting obligations.

10. Deleting your data

You are always in control of your data, and everything is self-service inside the app:

  • Disconnect Meta at any time from Settings → Connections in your dashboard. This immediately erases your stored Meta credentials.
  • Delete your account and all your data from Settings → Delete account. When you confirm, we erase your stored Meta access token, delete every photo and video you uploaded, revoke your sessions, and remove your account. This happens right away and cannot be undone.

This section also serves as our data deletion instructions as required by the Meta Platform Terms. Deleting your account from Settings → Delete account removes the data associated with your Meta login. We may keep only limited records where the law requires (for example, tax or accounting), never including your Meta access token or uploaded media.

11. Your rights

Under India’s Digital Personal Data Protection Act, 2023 (and, where applicable, other data-protection laws), you have the right to:

  • Access the personal data we hold about you and request a summary of how it is processed.
  • Correct or update inaccurate or incomplete data.
  • Request erasure of your personal data.
  • Withdraw consent — for example, by disconnecting Meta — at any time.
  • Raise a grievance and have it addressed.

You can exercise most of these rights yourself from your dashboard: view and edit your brand, product, and account details in Settings, disconnect Meta in Settings → Connections, and erase everything in Settings → Delete account. If you are in a region with additional rights (such as the EU/UK), you may also have rights to data portability and to object to certain processing, which you can raise through your account.

12. Cookies and sessions

We use a single secure, HTTP-only session cookie to keep you signed in. We do not run third-party advertising or tracking cookies on our own website. (The Meta Pixel, if you use one, runs on your store — not on cevra.co — and only if you set it up.)

13. Children

Cevra is a business tool intended for use by people aged 18 and over. It is not directed at children, and we do not knowingly collect personal data from anyone under 18.

14. International transfers

Some of our providers (for example, Meta and our AI provider) may process data on servers outside India. Where they do, we rely on their contractual and technical safeguards to protect your data consistent with this policy.

15. Changes to this policy

We may update this policy as the product or the law evolves. We will post the new version here and update the “Last updated” date above. For material changes, we will give you notice — for example, by email or an in-app message.

16. Managing your data

You control your data directly from your Cevra dashboard: Settings to view and update your details, Settings → Connections to disconnect Meta, and Settings → Delete account to erase your account and everything in it. No email or form is needed — the controls are built into the app.

This document is provided for transparency and to explain how Cevra works. It is not legal advice. The companion document is available here: Terms of Service.