LEGALLast updated: August 25, 2026

Privacy Policy

This policy explains which personal data we process when you use Mecra, for which purposes and on which legal bases, who we share it with, and how long we keep it. It is written to meet our transparency duties under Turkey's Personal Data Protection Law No. 6698 (KVKK) and the EU General Data Protection Regulation (GDPR).

1. At a glance

  • We never sell or rent your personal data and we build no advertising profiles about you.
  • We access your ad accounts only as far as you authorise us to. When you disconnect, we try to revoke the token at the network and then delete our record of it.
  • AI generation runs on your own API key; only the initial project analysis runs on ours. Either way, the content goes to the provider you chose.
  • There are no advertising or tracking cookies. The one third-party measurement tool is Google Analytics, and we explain below how to turn it off.
  • We do not collect personal data about the people who see your ads: from the networks we only pull aggregate figures that cannot be traced to an individual.

This section is a summary only; the full text below is what binds us.

2. Scope, controller and our roles

This policy covers the Mecra web application and related services offered at mecraapp.com (together, the “Service”). The party acting as data controller under both KVKK and GDPR is Mecra (“we”). Contact details are in the last section.

We act in two different roles. For your account, your business profile, security and the operation of the Service, we determine the purposes and means — there we are the controller. For the content you put into your projects, your ad copy and creatives, your targeting choices and the data pulled from your connected ad accounts, you determine the purpose; we process that data on your instructions in order to provide the Service to you. You remain responsible for the lawfulness of that content and for any information duties you owe to third parties.

The rules of use are set out separately in the Terms of Service.

3. Personal data we process

We process only what is needed to run the Service, keep it secure and meet our legal obligations:

CategoryContentSource
Account and identityEmail address, password (stored irreversibly by Supabase Auth — we cannot read it), name, profile picture, interface language and currency preferenceFrom you at sign-up; name and picture come from Google if you sign in with Google
Business profileBusiness name, sector, business size and phone number in international format. Collected in the mandatory setup step after sign-up; the phone number is unique per accountFrom you
Project and brand dataProject name and description, sector, website address, brand voice and tone, words to avoid; plus the brand profile derived from analysis (summary, audience, products, colour palette, design language, keywords, competitors)From you + automated analysis of your website
Campaign dataCampaign names, objectives, budget and currency, targeting choices, status, the campaign identifiers held by the platform, and performance figuresFrom you + your connected ad accounts
Creatives and mediaAd headlines, body copy and calls to action; images and videos you upload or generate, with their dimensions, format and durationFrom you + AI generation
AI recordsThe prompts you send, analysis inputs and outputs, agent chat messages, the model and prompt version used, and per-request token / image / second counts with estimated costWhile you use the Service
Platform connectionsThe connected ad account's id and name, the list of accounts available to you, the permissions you granted, platform-specific settings (for example the page used for publishing), and OAuth access/refresh tokens with their expiryFrom the platform when you connect
AI API keysProvider name, the key itself, a masked display of its last four characters, validation status, and the list of models that key unlocksWhen you add one in Settings
Team dataEmail addresses of the people you invite, their roles, and the scope and status of the invitationFrom you
Activity logWhich user did what in which project (publish, analyse, generate), the model and prompt version used, the timestamp and the user's email addressAutomatic
FeedbackThe message you send, its type and the page it was sent fromFrom the feedback form
Early access requestName, email, company and website, monthly ad budget range, how you heard about us, your note and the form language; plus browser information and the referring address if presentFrom the early access form
Technical recordsRequest logs and error traces produced by our hosting provider; an irreversible hash of your IP address used to enforce abuse limits (the address itself is not stored in those counters); and the verification result produced by the bot protection on the sign-in, sign-up and password reset pagesAutomatic

What we do not collect.We process no payment or card data — the Service is free and we operate no payment infrastructure. We do not pull personal data about the people who see your ads or fill in your forms: for lead forms we read only the form’s name and id, never the submitted records. We do not ask for special categories of personal data (health, beliefs, biometrics and the like) and we expect you not to enter them into the Service.

4. Data from your connected ad accounts

Mecra can currently connect to these ad networks: Meta Ads, Google Ads, Microsoft Ads, TikTok Ads, LinkedIn Ads, X Ads, Reddit Ads, Pinterest Ads, and Snapchat Ads. The connection is made through the platform’s own consent screen (via OAuth): your platform password never reaches us.

The platform itself shows you which permissions you are granting. Broadly, the access we ask for covers:

  • Listing the ad accounts you can reach so you can pick one,
  • Reading campaigns, ad sets and ads, and — on your instruction — creating, updating, pausing or removing them,
  • Reading performance reports (aggregate figures such as impressions, clicks, spend and conversions),
  • Listing targeting options, conversion tracking assets and lead forms,
  • On some networks, reading and publishing the organisational assets an ad technically needs in order to run (such as a page, an organisation account, a board or a post).

How tokens are protected. Access and refresh tokens are held server-side only, are never sent to your browser, and are refreshed in the background when they expire. When you disconnect, we attempt to revoke the token at the platform and then delete the record. Campaign and report data already pulled remains in your project; you can remove it by deleting the campaign or the project.

We do not sell data obtained from ad platforms, do not combine it with other users’ data, and do not use it for any purpose beyond the reports and AI suggestions we show you. Each platform’s developer terms require the same.

5. AI: inputs, outputs and providers

AI works in two distinct ways in the Service, and where your data goes depends on which one is running:

  • Generation with your own key. Copy, image and video generation and the agent chat run on the API key you add in Settings. Your prompts, brand context, chosen reference images, relevant campaign data and chat history are sent directly to the provider you selected.
  • Project analysis with our key.The deep analysis that runs when you first set up a project uses Mecra’s own provider key. In this step the website address you give is opened in a real browser; the page text and a screenshot, together with the logo and images you uploaded, are sent to a multimodal model in order to derive your brand profile.

Providers you can connect a key for today: Anthropic, OpenAI, Google, ByteDance, Higgsfield AI, Black Forest Labs, Kuaishou, Runway, and xAI.

Providers’ data policies differ, and the choice is yours. Some providers commit that API inputs and outputs are not used to train their models, while others may use inputs to improve their products or expose them to human review on free or basic plans. Which provider and which plan your key belongs to determines this outcome directly, so we recommend reading the provider’s terms before connecting a key. That processing is governed by the contract between you and the provider.

Your key is used only to carry requests you started. It is never returned to the interface or shown in records; only its last four characters are displayed, masked.

No automated decision-making. Copy, images, targeting and budget suggestions produced by AI are suggestions; none of them is applied or published without your approval. We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the meaning of KVKK art. 11(g) and GDPR art. 22.

6. Purposes and legal bases

We determine a legal basis for each processing activity separately; we do not fall back on consent for everything.

PurposeExampleLegal basis
Opening your account and providing the ServiceSign-up and sessions, creating projects and campaigns, generating creatives, publishing and reporting on connected accountsFormation and performance of a contract — KVKK art. 5/2-c · GDPR art. 6(1)(b)
Mandatory business setupCollecting business details and a phone number; keeping accounts uniquePerformance of a contract — KVKK art. 5/2-c · GDPR art. 6(1)(b)
AI generation and project analysisPassing your prompts to the provider, reviewing your website, deriving the brand profilePerformance of a contract — KVKK art. 5/2-c · GDPR art. 6(1)(b)
Transactional emailVerification, password reset, team invitations, welcome and application confirmation messagesPerformance of a contract — KVKK art. 5/2-c · GDPR art. 6(1)(b)
Handling early access requestsRecording your request, getting back to you, sending an invitationSteps taken at your request prior to a contract — KVKK art. 5/2-c · GDPR art. 6(1)(b)
Security and abuse preventionSession validation, access control, bot protection on sign-in pages, daily usage limits, rate limiting via a hashed IP, activity loggingLegitimate interests — KVKK art. 5/2-f · GDPR art. 6(1)(f)
Improving the Service and fixing faultsReviewing feedback and error recordsLegitimate interests — KVKK art. 5/2-f · GDPR art. 6(1)(f)
MeasurementMeasuring how many visitors arrive and where they drop off (Google Analytics)Requires consent — KVKK art. 5/1 · GDPR art. 6(1)(a). See the Cookies section
Legal obligations and protecting rightsResponding to lawful requests from authorities, preserving evidence in a disputeLegal obligation — KVKK art. 5/2-ç · GDPR art. 6(1)(c); establishment and defence of legal claims — KVKK art. 5/2-e · GDPR art. 6(1)(f)

Where we rely on legitimate interests we balance them against your rights and freedoms, and you have the right to object to that processing.

7. Cookies, local storage and measurement

We use no advertising, retargeting or behavioural profiling cookies. The cookies used on the site are:

NameTypePurposeDuration
sb-…-auth-tokenStrictly necessary (first party)Authenticating and keeping your session openUntil the session is renewed or you sign out
mecra-langStrictly necessary / preference (first party)Your interface language, so the page renders in the right language on the server1 year
sidebar_statePreference (first party)Whether the dashboard sidebar is open or collapsed7 days
_ga, _ga_…Measurement (third party — Google Analytics)Distinguishing visitors and sessions; page views and a few sign-up funnel stepsSet by Google; up to two years by default

Being straight about measurement.We use Google Analytics 4, in the production environment only. What we measure is page views and whether a handful of steps — sign-in, sign-up and the early access form — were completed. Measurement cookies are not strictly necessary and the law requires prior consent for them; we are building a cookie preference panel to collect that consent. Until it ships, you can block measurement through your browser’s cookie settings or with Google’s official opt-out add-on; blocking it does not affect how the Service works. For how Google processes this data, see Google’s own explanation.

Bot protection. The security check that runs on the sign-in, sign-up and password reset pages may place a short-lived technical cookie depending on how it is used. That cookie serves security and is strictly necessary; it is not used for measurement or advertising.

Local storage.What we keep in your browser’s local storage is never sent to our servers and stays on your device: theme preference, currency preference, the open project and your project list, the project id created during setup, a pending team invitation, and the autosaved draft in the ad editor. You can remove these by clearing your browser data.

8. Who we share data with

Our infrastructure and service providers — they process your data only on our instructions, to provide services to us:

  • Supabase — authentication, database, file storage and a single edge function. Privacy policy
  • Cloudflare — hosting, content delivery, image optimisation, sending transactional email, rate-limit counters, the bot protection on our sign-in pages (Turnstile), and the browser service that opens your website during project analysis. Privacy policy
  • Resend — fallback email provider used when sending through Cloudflare fails. Privacy policy
  • Google — measurement (Google Analytics) and, if you use Sign in with Google, authentication. Privacy policy

Through actions you start, data is passed to:

  • Ad platforms (Meta Ads, Google Ads, Microsoft Ads, TikTok Ads, LinkedIn Ads, X Ads, Reddit Ads, Pinterest Ads, and Snapchat Ads) — when you build or publish a campaign, its structure, targeting choices, ad copy and media files are sent to your connected ad account. From that point on, the relevant platform’s own terms and privacy policy apply.
  • AI providers (Anthropic, OpenAI, Google, ByteDance, Higgsfield AI, Black Forest Labs, Kuaishou, Runway, and xAI) — when you start a generation or analysis, your prompts and the relevant context are sent to the provider you selected.

Other cases. We may share the minimum data required to respond to lawful requests from competent public authorities, to protect our rights, or to keep users safe. In a merger, acquisition or similar corporate transaction, data may pass to the acquirer provided the protections in this policy continue to apply; we would tell you beforehand.

We do not sell your personal data, do not disclose it to third parties for marketing, and do not operate as an ad network.

9. International transfers

The servers of our infrastructure providers, the ad platforms and the AI providers are located outside Türkiye. Your data is therefore transferred abroad.

Under KVKK. Article 9, as amended by Law No. 7499 and in force since 1 June 2024, sets a tiered order: first an adequacy decision by the Board; if there is none, appropriate safeguards provided by the parties (the standard contract published by the Board, binding corporate rules, a written undertaking, or an international agreement); and only if neither is available, the narrowly interpreted exceptional cases that may be relied on incidentally. The Board has not issued an adequacy decision for any country or sector to date. We therefore base our transfers on the appropriate safeguards in art. 9(2); where a standard contract is used, it is notified to the Board within five business days of signature.

Under GDPR. Chapter V applies to transfers outside the EU/EEA: we rely on a European Commission adequacy decision where one exists and otherwise on appropriate safeguards such as the Standard Contractual Clauses (SCCs).

Transfers to ad platforms and AI providers happen on your instruction and are largely governed by your own relationship with that provider; we recommend checking their policies for the transfer mechanisms they use.

10. Retention periods

We keep personal data for as long as it is needed for the purpose it was processed for, and afterwards only where a legal obligation or the establishment, exercise or defence of a legal claim requires it. In practice:

DataRetention
Account, business profile, projects, campaigns, creatives, media and AI recordsFor as long as your account is open. Deleted on your request; you can also delete individual projects, campaigns and creatives yourself
Platform connections and OAuth tokensFor as long as the connection lasts. When you disconnect we attempt to revoke the token at the platform and delete the record; tokens are in any case subject to the validity period the platform sets
AI API keysDeleted the moment you remove them in Settings; entering a new key deletes the old record and writes a new one rather than updating it
Team invitationsExpire after 14 days if not accepted; the invitation record remains with its outcome and you can cancel it
Usage countersKept in daily windows so that daily limits can be enforced
Hashed IP address (rate limiting)Only for the length of the counter window — at most 24 hours. The address itself is not stored
Server logs and error tracesSubject to our hosting provider's maximum 7-day log retention window
Activity logKept for account security and accountability; when your account is deleted, the identifying information in these records is removed as well
Early access requestsFor as long as the early access programme runs; deleted earlier on your request
Feedback messagesUntil reviewed and closed; may be kept briefly afterwards as a product development record

Backups.Deleted data may remain in backups for a short period until our providers’ routine backup cycle completes. Those backups exist for disaster recovery only; we do not restore a deleted record from a backup.

11. Security

  • All traffic is encrypted with TLS.
  • The database enforces row level security: each user can reach only the data of projects they own or are a member of. Team access is role-based (owner, admin, editor, viewer).
  • AI keys and OAuth tokens are held server-side only; the client layer has no read permission on them and they are never sent to the browser.
  • Media files you upload or generate are stored in a non-public area; access is granted only through short-lived signed links.
  • Passwords are stored irreversibly by our authentication provider; we can neither read nor change them.
  • The activity log is kept in a form that cannot be altered or deleted afterwards.
  • The sign-in, sign-up and password reset pages are protected by bot protection(Cloudflare Turnstile). During verification your IP address and basic browser signals are sent to Cloudflare; per the provider’s own statement this data is processed for security only and is not used for advertising or user tracking. This step is necessary to stop brute-force attempts and automated account creation.

No system is completely secure. If we detect a personal data breach we notify the Turkish Data Protection Board under KVKK art. 12(5) as soon as possible (as a rule within 72 hours, per the Board’s decision) and inform the affected individuals; under GDPR we notify the competent supervisory authority under art. 33 and, where required, the affected individuals under art. 34.

12. Your rights and how to use them

Under KVKK art. 11, by applying to the data controller you have the right to:

  • Learn whether your personal data is being processed,
  • Request information if it has been processed,
  • Learn the purpose of processing and whether the data is used accordingly,
  • Know the third parties in Türkiye or abroad to whom your data is transferred,
  • Request correction of incomplete or inaccurate data, and that this be notified to the third parties it was transferred to,
  • Request erasure or destruction under the conditions in KVKK art. 7, and that this be notified to the third parties it was transferred to,
  • Object to an adverse outcome produced solely by automated analysis,
  • Claim compensation for damage suffered because of unlawful processing.

If you are in the EU/EEA, under GDPR you additionally have the rights of access (art. 15), rectification (art. 16), erasure (art. 17), restriction of processing (art. 18), data portability (art. 20), objection to processing based on legitimate interests (art. 21), and withdrawal of consent where processing is based on it. Data portability is not separately listed in KVKK; we apply it for our users covered by GDPR.

What you can do yourself. You can update your name, language and currency preference in Settings; change your password; delete your AI key; disconnect platform connections; and delete projects, campaigns and creatives. To have your whole account deleted or your data exported, you need to send us a request at the address below — there is not yet a one-step account deletion control in the dashboard.

Send requests to info@mecraapp.com. Once we have verified your identity we reply free of charge within 30 days at the latest under KVKK art. 13, and as a rule within one month under GDPR (extendable by two further months, with notice to you). None of these rights is absolute; if the rights of others or our legal obligations mean we cannot meet a request in whole or in part, we will explain why in writing.

Complaints. You can complain to the Turkish Data Protection Authority or, in the EU/EEA, to the supervisory authority of your country.

13. Email communications

We send you transactional email only: email verification, password reset, team invitations, the welcome message and confirmation of an early access request. These messages are part of how the Service works and carry no marketing content.

We do not send newsletters or promotional electronic messages. If we start to, we will obtain your prior consent as required by Turkish Law No. 6563 on the Regulation of Electronic Commerce and the Commercial Electronic Message Regulation, manage that consent through the national Message Management System (İYS), and include an easy opt-out in every message.

14. Children's privacy

The Service is intended for business use and is not offered to people under 18. We do not knowingly collect children’s data; if we learn that we have, we delete it without delay. If you believe we process data about your child, please contact us.

15. Changes to this policy

We may update this policy as the Service evolves or the law changes. The date of the current version is shown at the top of the page. We announce changes that materially affect you, in the app or by email, before they take effect. Continuing to use the Service after a change means you have read the current policy; where new processing requires your consent, that consent is obtained separately.

16. Contact

For any privacy question, request or application: info@mecraapp.com

For the rules of use, see the Terms of Service.