Last updated: 2026-10-05
SocialBuster (formerly Meta Ads Studio) is a tool a business or an agency uses to run its own Meta (Facebook and Instagram) advertising. It is operated by SEO Busters Corporation, and anyone can sign up for an account or be invited to join a workspace. This policy explains what data the product collects, why, and how it is handled.
SocialBuster connects to a Meta (Facebook and Instagram) advertising account through Facebook Login to sync ad performance data, analyze creative performance, help draft ad copy and images with AI, and let the account owner manage campaigns. Every change to a live Meta ad, including pausing an ad, changing a budget, or publishing a new one, is started by a person in the product and confirmed by them. Nothing is changed on Meta automatically.
Once someone connects their Meta account, the product obtains: their Meta user id and name; the ad accounts, Facebook Pages and Instagram accounts they grant access to, and those accounts' names, ids, currency and time zone; the campaigns, ad sets, ads and their daily performance numbers, such as spend, impressions, clicks, conversions and similar metrics; Page posts and their engagement counts, to the extent their access token can read them; and the creative assets, such as images, headlines and ad copy, attached to those ads.
The permissions requested at login are:
Sign-in email and authentication are handled by Supabase Auth. The product itself never sees or stores a raw password.
When you create an account, we collect your first and last name and your email address. During onboarding we ask what best describes your work (agency, brand, freelancer, software, local business or other) and how you heard about SocialBuster. If you answer Other to the second question, you can add a short note in your own words. We use the answers to set up the product around how you work and to count which kinds of teams sign up and where they come from. We also record which version of the Terms and this policy you agreed to, and when.
If you choose Continue with Google, Google shares your name, email address and profile picture with us. We use them to create your account and to show your name and picture in the product. We never receive your Google password, and Google handles your sign-in under its own privacy policy.
When an owner or admin invites someone to a workspace, we keep the invited email address with the invitation. It is kept to send the invitation and to check it when it is accepted, since an invitation can only be accepted by someone signed in with that address.
We also keep a short record of each invitation email we send: the address, the workspace, who sent it and when. It is kept so that the product cannot be used to send one address a flood of invitations, so it is not deleted when an invitation or a workspace is. Each record is deleted automatically after 7 days.
Paid plans and free trials are billed through Stripe, which collects and processes your card details on its own checkout page. SocialBuster never sees or stores your card number. We keep the Stripe customer and subscription ids for your account, your plan and its status, and a record of each invoice and payment, so we can show your plan and keep it in step with Stripe.
Email delivery is optional. When it is switched on, emails the product sends, such as workspace invitations, go through Resend, which receives the recipient's email address and the message. An invitation names the workspace and the person who sent it.
Meta access tokens and other third-party API keys are encrypted at rest and only ever decrypted on the server, never sent to a browser.
All data belonging to one workspace, meaning one client or team's data, is kept apart from every other workspace by database-level access rules, so one workspace cannot see another workspace's data.
SocialBuster uses the following third-party services to operate: Supabase, for hosted database, authentication and file storage; Netlify, which hosts the application and runs its server code and scheduled jobs, so the requests you make to the product and its answers pass through Netlify's servers; OpenRouter, which routes AI text-generation requests to an underlying model provider, used for AI-drafted ad copy; and fal.ai, used for AI-generated ad images. Text or images submitted to these AI features, such as fact sheet content, prompts, or reference images, is sent to these providers to produce the generated result.
For accounts, sign-in and payments it also uses:
The product uses an authentication session cookie and a workspace-selection cookie, both needed for the product to work. The workspace-selection cookie, mas_workspace, remembers which workspace you last opened. It holds that workspace's id and lasts one year.
It also sets these cookies, only when you use the feature that needs them:
sb_plan_intent: when you pick a plan on the pricing page before you have an account, it remembers the plan and billing interval you chose, so they are still there when you finish signing up. It lasts 1 hour and holds no personal data.mas_identity_filter_v2: when you use the brand filter in the sidebar to show only one brand, it remembers your choice, so every page shows that brand. It holds the id of the brand you chose, or a placeholder meaning all brands, and lasts one year.mas_meta_oauth_state: when you start connecting a Meta account, it holds a signed token made of your user id, your workspace id, a random value, the page to come back to and the time you started. It is used only to check that the return from Meta is the connection you started. It lasts 10 minutes and is removed when the connection finishes.The product does not use any advertising or tracking cookies of its own. Stripe and Google run their own checkout and sign-in pages and may set their own cookies there.
The product does not use this data for its own advertising and does not sell it to third parties. It is a tool a business uses to run its own advertising.
Disconnecting a Meta account inside the product's Settings, or removing the app from Facebook's own Business Integrations settings, deletes the stored access token and the connection record. This is also handled automatically the moment Meta notifies the product of a removal, through /api/meta/deauthorize and /api/meta/data-deletion. Historical ad performance data already synced into a workspace before a disconnection is kept for that workspace's own records unless its owner asks for full deletion by contacting privacy@seobusters.io.
There is no automatic time-based deletion yet. Data is kept until a workspace owner asks for it to be deleted or the workspace itself is removed.
For privacy questions or to request deletion of your data, contact privacy@seobusters.io.
SocialBuster is operated by SEO Busters Corporation.