PRODUCTS · SERVICES · EVENTS · MORE
Your information.
Your choices.
How Adforlio handles information in the invited campaign workspace, where AI providers are involved, and how to ask about your data.
Contact about your information
Adforlio is the contact for information handled in this workspace. Write to support@adforlio.com or use our business contact address: 9, Race Course Road, Kaduna, Nigeria.
For general account help, contact support@adforlio.com. Send requests from your account email where possible. Never send passwords, sign-in codes, API keys, full card details or unrelated identity documents.
Information used in the workspace
Account and sign-in information includes your email, account identifier, session information and security records. Campaign information includes the brands and offers you enter, audiences, descriptions, confirmed facts, instructions, uploaded references, generated drafts and outputs.
Operational records include job status, credit reservations and history, billing-country information, notification preferences and support correspondence. Where purchasing is enabled, order summaries, verification results, adjustments and the accepted agreement are also recorded. Payment details entered on Paystack are handled by Paystack; do not enter card details in campaign fields.
Offerings can be services, events, products, software, courses, initiatives or other lawful offers. Supply only information and images you are authorised to use. Avoid confidential client records, identity documents and sensitive personal information in creative prompts or uploads.
Why the information is used
We use the information to provide the workspace you request, keep campaign versions and files available, account for credits, investigate failures, protect accounts and answer support or rights requests. Purchase records support payment reconciliation, disputes and applicable record-keeping duties.
Optional campaign emails use your notification preference. Essential sign-in and security messages are separate. Purchase confirmations, when purchasing and receipt delivery are enabled, are transaction messages rather than a marketing subscription. Viewing this page is not consent to optional email or permission to generate content.
When content reaches an AI provider
AI concept requests send relevant brand, offer and campaign text to OpenAI. AI scene and concept-video requests send the relevant descriptive brief to Higgsfield, which can route requests to its upstream model providers. Generative requests require the campaign's approval and available access and funding. Composed static layouts and photo or text-layout videos do not need an AI-media generation request.
OpenAI's published API policy excludes model training by default unless the API customer opts in. That is separate from retention for abuse monitoring or other permitted purposes; the application does not claim Zero Data Retention.
Adforlio's administrator confirmed on 3 October 2026 that the training setting is off in the Higgsfield API Workspace used by Adforlio. Higgsfield allows up to 10 business days to process an opt-out. The date it was switched off and the provider's effective processing date have not been independently established, so the confirmation date is not presented as the opt-out's effective date.
The opt-out is not retroactive, applies to API content rather than other Higgsfield products, and does not extend to Excluded Models under Higgsfield's terms. Upstream model providers can have separate data-use conditions. Turning training off does not mean zero retention or automatic deletion of request records, outputs or backups. Avoid confidential or sensitive material until the applicable model and processing arrangements have been checked.
Review the OpenAI API data controls and Higgsfield API terms. Those links describe provider terms, not a claim that every optional account setting has been enabled.
Providers and international processing
Render runs the application. Supabase provides the database, authentication and file storage. OpenAI and Higgsfield support the AI operations described above. Resend delivers account or campaign messages, and Paystack processes payments when a checkout is available. Support email is received at the contact address above.
These providers and their infrastructure may process information outside your country, including outside Nigeria. No Nigeria-only hosting, universal no-training promise or automatic deletion from every processor is stated here. Contact us for the applicable processing and transfer information before supplying material with specific confidentiality or location requirements.
Files, originals and access
Workspace file downloads are account-restricted. Authorised administration, troubleshooting and provider processing can still involve access to information needed for those purposes. Access restriction is not a promise of end-to-end encryption or that providers never process content.
For supported new AI imports, Adforlio retains the original provider image (PNG, JPEG or WebP) or MP4 video separately from the processed export. The source record identifies that distinction; some earlier outputs have no retained original. File hashes support integrity checks, not independent verification of a claim, person, venue or Content Credentials.
Approximate country and website statistics
We use an approximate country derived from the connection IP to display prices automatically. The country lookup uses a local database on our server; it does not send the IP to a separate geolocation API. An estimate can be wrong. Your approved billing country determines checkout eligibility; contact support for a correction.
First-party analytics records daily aggregate counts of approved page categories, page views, 30-second engagement and navigation-click categories, grouped by approximate country, broad device type and referral-source category. It does not store raw IP addresses, account identifiers, campaign content, payment details, full URLs or query strings in analytics records. Counts are events rather than unique people.
Published blog articles also have daily aggregate counts linked to their public article identifier. The current public URL slug is sent to validate the article and is not stored as a separate analytics field. We count views, at least 30 seconds with the page visible and window focused, a completion signal after reaching 75% of the article body and meeting that engagement condition, and clicks grouped into fixed destination categories. The browser counts each event or click category at most once per page load; reloading can count again. These are not unique readers, proof that someone read or understood the article, or sales attribution. Click records contain no full destination URL, email address or query string.
No analytics cookies, browser identifiers or device fingerprints are used. Collection respects Do Not Track and Global Privacy Control signals. Recognised signed-in staff and common bots are excluded. Aggregates older than the rolling 90-day window are pruned when analytics records or reports are processed; that does not establish a purge deadline for inactive databases, provider logs or backups. These events are not sent to Google Analytics or advertising trackers.
Customer administration and blog publishing
Authorised administrators can view account details, billing-country and purchase summaries, balances and creation summaries to operate and support the service. Viewing creation details or available private file previews requires a recorded reason and is audited. Blog authors and editors do not gain customer-administration access through their publishing role.
Hiding an account changes its visibility in the administration directory. Suspension or archival restricts access, but does not delete its identity, creative work or financial records; already accepted jobs may finish. Administrative access and changes are recorded for accountability. Audit retention is reviewed separately, with no automatic audit-purge deadline claimed.
Published blog posts, selected author bylines, tags and images are public. Drafts and unpublished images are restricted by staff role. Unpublishing cannot recall copies already taken by others. Blog drafts, files and publishing records have no automatic deletion deadline; ask us for an assisted review. A customer campaign does not become blog content without the necessary separate permission.
Cookies and notifications
The application uses essential access, refresh and request-protection cookies for sign-in and security. Removing these cookies can sign you out or interrupt protected requests. This information page adds no analytics script, tracking pixel or consent cookie.
Change optional campaign-email settings under Notifications. Turning those emails off does not delete earlier messages from mailboxes or delivery records, and does not disable essential account communication.
Retention and requests to remove information
Retention depends on the account and campaign purpose, unresolved jobs or transactions, security investigations and applicable record-keeping requirements. There is no verified universal purge interval. Provider records and backups can have different retention rules from the active Adforlio workspace.
Ask us to review a correction, restriction or deletion using the contact above. Requests need proportionate identity and scope verification. We will distinguish eligible records from any justified retention and explain relevant limitations. A request or an account export does not itself erase uploads, retained originals, agreements, backups or records held by another provider.
Access and other choices
Sign in to Privacy & data for a structured workspace export. Media files and full purchase agreements use separate private downloads. Authentication and security logs, support correspondence, sandbox records, backups and external-provider records are not all included in that export; ask for an assisted review where needed.
Depending on applicable law, you may have rights to information and access, correction, objection or restriction, portability, deletion, withdrawal of consent where consent applies, and review of relevant automated decisions. You can also raise a concern with the Nigeria Data Protection Commission or your relevant supervisory authority. A workspace feature does not limit those rights.
Scope and changes
This information describes the invited workspace. It is separate from the commercial policy bundle and does not approve or open paid checkout. Any later published commercial Privacy Notice will be identifiable by its policy version; previously accepted purchase agreements remain separately recorded.
We will update this page when the described data handling changes. Material changes that need notice or a choice must be handled before the changed use; merely viewing this page does not authorise them.