
Bluvee Optics
Privacy Policy
Last updated 20 September 2026
Who we are
Bluvee Optics (the “application”, “app” or “Service”) is an advertising analytics application operated by ECOMSALVI FZCO, a free zone company registered in Dubai, United Arab Emirates(“we”, “us”). We provide the Service to businesses (“customers”) that choose to connect their own advertising accounts to it. Access is restricted to people each customer has authorised, who sign in with an approved account. This policy explains what data the application processes, how and why we process it, and how it can be deleted.
Platform Data we access
When a customer connects a Meta ad account through Facebook Login for Business, we access “Platform Data” from that ad account, and from the Facebook Pages the customer grants alongside it, through the Meta Marketing API and Graph API. The permissions we request are used only to read: ads_read, business_management, pages_show_list and pages_read_engagement. Meta labels business_managementas “Manage your business” on its consent screen. We use it to list authorised business portfolios and their owned or shared Pages, so a customer can save a business and Page connection to their workspace in Optics. This saves an association within Optics; it does not claim, transfer or change ownership of an asset in Meta. Specifically:
A customer may instead supply a system user token they generate themselves. Such a token can carry two further read permissions, pages_read_user_content and instagram_basic. These resolve the post and the Instagram media an ad runs as, and they also let the Service read public commentson that business’s own Page posts and Instagram media, so it can summarise what people are saying about the business. We store the comment text and its permalink. We do not ask Meta for, or store, the commenter’s name or account id. These permissions are read-only and are never required; a customer who does not grant them keeps every other feature.
- Ads Insights — aggregate performance metrics such as spend, impressions, frequency, and return on ad spend.
- Ad and creative metadata — ad names, creative identifiers, and references to ad video and image assets.
- The Page post an ad was built from — the post id, its media (image or video) and thumbnail, so the customer sees the creative next to its numbers.
- A selected Page’s own published posts — post text, publication dates and original-post links, displayed with the Page’s name and id so the customer can review that Page’s content.
- Business, ad account and Page identity — ids, names, and applicable account currency and status, so the customer can choose which assets to connect and see which are connected.
We access only the ad accounts and Pages a customer explicitly grants in the login dialog. We do not read private messages, and we do not write anything to a customer’s ad account or Page.
Where a customer grants the two optional Page and Instagram permissions above, the Service stores the text and permalink of public comments on that business’s own posts. It does not request or retain the commenter’s name or account id, so we hold no identity for the people who wrote them. What is stored lives inside that one customer’s workspace; we do not build profiles of individuals, do not match people across customers, and never use any of it for advertising.
How we use it
We use Platform Data solely to provide the Service to the customer who connected the account — for example, reporting spend efficiency, identifying high-performing creative, comparing that customer’s own ads over time, and reviewing published Page content through their saved business and Page connection. Selecting a Page for this content view does not replace the ad account supplying Live Ads. Each customer sees only the data from accounts they connected. We do not use Platform Data to advertise to anyone, to build profiles of individuals, to train models, or to provide a product or service to any other customer or third party.
We process Platform Data only as described in this policy and in accordance with applicable laws and regulations and Meta’s Platform Terms and Developer Policies.
Storage and security
Platform Data is stored in access-controlled databases dedicated to the Service. Access tokens are stored encrypted and are write-only: no person can read a stored token back through the application. Access to the app and to the underlying data is limited to authorised people, who authenticate using an approved email and password account or single sign-on. We apply reasonable technical and organisational measures to protect the data against unauthorised access, and we review who holds access.
The Service uses cloud infrastructure providers, including Vercel, Supabase, Google Cloud and Redis Cloud, which process data on our behalf. Redis Cloud stores connection records and cached reporting data for the Service.
Google Ads data
A customer may also connect their own Google Ads account. We request one scope, https://www.googleapis.com/auth/adwords, and use it to read their account identifier, campaign and ad group names, spend, impressions, clicks and conversion counts, so the Service can report their advertising performance back to them.
Google’s consent screen describes that scope as permitting an application to “see, edit, create, and delete your Google Ads accounts and data”. Google offers no read-only alternative for this API, so every integration requests the same scope. We only read.We do not create, edit, pause, or delete campaigns, budgets, or any other object in a customer’s Google Ads account.
Bluvee’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell or rent Google user data; we do not transfer it except as necessary to provide the Service, to comply with applicable law, or as part of a merger or acquisition under equivalent protections; we do not use it for advertising; and we do not use it to develop, improve, or train generalised artificial intelligence or machine learning models. Humans do not read it, except with the customer’s explicit consent to resolve a support issue, where required by law, or where the data has been aggregated and anonymised for security or abuse prevention.
A customer may disconnect Google Ads at any time from Data Setup in their workspace, which deletes the stored credential immediately. They may also revoke our access directly at myaccount.google.com/permissions. Deletion of data already collected is covered below.
Sharing
We do not sell or rent Platform Data, and we do not share it with any third party for that party’s own purposes. It is shared only with the infrastructure providers named above, which process it on our instructions to run the Service, and where we are required to disclose it by law.
Data retention and deletion
We retain Platform Data for as long as the customer’s ad account remains connected and the data is needed to provide the Service. Where the account was connected through Facebook Login for Business, removing the application in your Meta Business settings ends our access at Meta immediately. Where you supplied a system user token yourself, that token is not tied to the application, so ending its access means deleting the system user, or removing its access to the assets, in your own Meta Business settings. In either case, removing our stored copy of the token and the Platform Data held for that account is done by us on request: email the address below and we complete it within 30 days.
To request deletion of any Platform Data we hold, or to remove the Service’s access to your ad account, email us at jack@bluvee.ai from an address associated with the connected account, or remove the app in your Meta Business settings. We will action valid deletion requests within 30 days and confirm by email.
Bluvee Clipper browser extension
This policy also covers Bluvee Clipper, our Chrome extension for saving web references and accessible ad creatives to Bluvee Optics. When you save a reference or start an ad capture, it processes source URLs and titles, selected text, screenshots, images, videos, ad copy, advertiser or creator details, engagement counts, ad identifiers and lifecycle information where available. It also processes the attribution name, board, notes and tags you provide. Screenshots may include personal information visible on the page; review what you choose to save.
Results are sent to the Optics deployment configured in the extension and its storage services, including Google Cloud Storage through signed upload URLs. Funnel Spy captures contribute to the shared ad library under the workspace service terms and may be available to other users of that library. These browser captures are separate from the connected-account Meta Platform Data and Google Ads data described above. Your browser session may retrieve source content, but the extension does not export your Meta, Instagram or TikTok cookies or passwords to Optics. It sends your Optics access token to your configured deployment for authentication.
On supported Meta Ad Library, Instagram and TikTok pages, the extension temporarily observes recent video request URLs to resolve media for clipping. Up to 60 URLs per tab are held in memory and cleared on navigation, tab closure or service-worker restart. Page scripts inspect supported content and add capture controls; an ad library is not uploaded until you start capture. Media is requested from source websites and their delivery networks. YouTube references use public metadata and save links rather than downloaded YouTube videos.
Workspace URLs, access tokens, attribution name and preferences use Chrome sync storage and may sync through your Google account. These extension settings are distinct from the encrypted connected-account credentials described above. Capture queues, progress, failed items, brand configuration and pending completion reports use local storage so interrupted captures can resume. Brand configuration is refreshed periodically. Media is processed in memory, a bundled offscreen page generates video thumbnails, and capture status and extension version are communicated to supported Optics pages.
We use extension data to save references, capture ads, display progress and maintain the Optics integration. We do not sell it, use it for advertising or creditworthiness, or transfer it for unrelated purposes. Bluvee Clipper complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.
You can cancel capture, remove workspace credentials in Settings and revoke a device token in Optics. Uninstalling removes local extension data but does not delete content already uploaded to Optics or its shared library. Uploaded content remains until deleted through the product or a valid deletion request. For access or deletion, including shared-library content, contact support@bluvee.ai. We action valid deletion requests within 30 days.
Contact
For any questions about this policy or to make a data request, contact ECOMSALVI FZCO at jack@bluvee.ai.
