Legal

Privacy policy

Last updated: August 15, 2026

This policy explains how AI Prompt Genius LLC, doing business as AdsOnBread, collects, uses, retains, and shares information when we operate the AdsOnBread website, portals, SDK, and contextual advertising network.

The short version

  • We do not build cross-site profiles, use behavioral targeting, sell personal information, or use fingerprinting.
  • Ad selection is contextual: it is based on the extension category, the requested ad format, and the language — not on who you are.
  • The SDK assigns a random pseudonymous token a 24-hour lifetime. We store only a one-way HMAC of that token for frequency capping and scrub it after 24 hours.
  • For developers and advertisers, we collect the account information needed to run the marketplace, review applications, bill campaigns, and pay out earnings.

Who is responsible for this service

AI Prompt Genius LLC, doing business as AdsOnBread, is the controller of information AdsOnBread uses to operate its advertising network and account portals. Extension publishers remain responsible for their own extensions and privacy notices.

Data processed when an extension displays an ad

When an approved extension requests an ad, the SDK and our delivery service process:

  • The extension and campaign involved, ad format, requested browser language, time, and whether the impression was billable or frequency-capped.
  • A coarse country-level location derived from the network request. We do not request or store precise location.
  • A random SDK token and its 24-hour expiration time in the extension’s local browser storage. An expired token is never sent again and is replaced the next time the SDK runs. Clearing extension storage or uninstalling the extension also removes the record.
  • The request IP address, which Cloudflare necessarily processes to route the request. Before AdsOnBread persists anything for abuse prevention, the edge Worker converts the IP and SDK token into separate keyed HMAC values; the submitted token and raw IP are not stored in the delivery database.
  • A per-impression identifier and, if an ad is clicked, a click record linked to that impression for billing accuracy and redirection to the advertiser’s HTTPS landing page.

We use the token HMAC for an eight-hour billable-impression cap and to return the same ad when an extension repeats a request within one minute. We use the IP HMAC for network-wide abuse limits. Neither value is used for behavioral targeting, combined with data from other services, or shared with advertisers.

We do not collect names, email addresses, page content, or browsing history from extension viewers. SDK 1.1.0 never reuses a token after its 24-hour expiration. Browser storage does not automatically delete expired records, so if the extension does not run again, an expired record may remain until the next SDK use, the user clears extension storage, or the extension is uninstalled. On the next use, the SDK replaces it before making an ad request. During the publisher upgrade period ending September 15, 2026, SDK 1.0.0 may retain its earlier random value locally; AdsOnBread nevertheless HMACs it before storage and applies the server retention limits below. After that deadline, older SDK versions are not eligible for ad delivery.

If you click an ad, the advertiser’s privacy policy governs what happens after you reach its website.

Data we collect from developers and advertisers

When you apply for or hold an AdsOnBread account, we collect:

  • Account and business details such as name, email, company, website, location, billing address, login sessions, and optional multi-factor or passkey configuration. Stytch handles password credentials; AdsOnBread does not store plaintext passwords.
  • Application and publisher details such as extension listings, install and regional metrics, browser support, business descriptions, and review decisions.
  • Billing and payout details: advertiser payments are processed by Stripe, and we store payment status and amounts — not card numbers. Developer payouts use the PayPal or Wise email address you save in your payout settings.
  • Delivery statistics: impressions, clicks, spend, and earnings associated with your campaigns or extensions.
  • Campaign content, landing URLs, uploaded creative files, delivery settings, and contextual targeting selections.
  • Operational records such as service emails, support correspondence, consent or unsubscribe preferences, short-lived authentication state, and security logs.

Website storage and third-party resources

The account portals use strictly necessary, HTTP-only session cookies for authentication. Public pages load fonts from Google Fonts. Login and application pages may load Cloudflare Turnstile, and billing pages may load Stripe. These providers receive ordinary request information under their own privacy terms. We do not use advertising cookies on the AdsOnBread website or in the SDK.

How we use data

  • To deliver, measure, and bill contextual ads at the agreed CPM.
  • To review applications, campaigns, and creatives so the marketplace stays trustworthy.
  • To calculate and pay developer earnings.
  • To secure the service: preventing fraud, abuse, invalid traffic, and unauthorized account access.
  • To send service emails such as application decisions, account-creation links, and billing or payout notices. These are required to operate your account and are not marketing.
  • To send occasional marketing email about AdsOnBread, if you have asked to hear from us. Every marketing email carries a one-click unsubscribe link, and you can opt out at any time from the preferences link in the footer of any email we send.
  • To comply with legal obligations such as tax and accounting requirements.

Legal bases for processing

  • Contract: to review and administer developer and advertiser accounts, deliver funded campaigns, calculate earnings, process billing, and provide requested support.
  • Legitimate interests: to deliver and measure contextual ads, enforce short frequency caps, prevent invalid traffic, secure the service, and improve reliability without building behavioral profiles.
  • Consent: for optional marketing email and wherever applicable law requires consent. You may withdraw consent without affecting earlier lawful processing.
  • Legal obligation: to maintain tax, accounting, payment, sanctions, and other records required by law.

Service providers we share data with

We disclose information only as needed to operate the service:

  • Cloudflare — network delivery, hosting, D1 and R2 storage, security, Turnstile, operational logs, and Analytics Engine.
  • Stytch — account authentication, including password reset emails and optional two-factor authentication.
  • Stripe — advertiser payment processing.
  • PayPal and Wise — developer payouts, using the payout email you provide.
  • Resend — transactional service emails.
  • Sentry — error monitoring, so we can find and fix failures.
  • Google Fonts — delivery of website font files.

These companies generally act as service providers or processors, although payment providers may act as independent controllers for their compliance obligations. We may also disclose information if required by law or to protect the rights, safety, and integrity of AdsOnBread or others. We do not sell personal information or share extension-viewer data with advertisers beyond aggregate campaign reporting.

International processing

AdsOnBread is based in the United States, and information may be processed in the United States and other countries where our providers operate. Where European or UK law requires a transfer mechanism, we use applicable contractual safeguards or another legally recognized mechanism. Contact us to request more information about safeguards relevant to your data.

Data retention

  • The local SDK token expires and is no longer sent after 24 hours. Its expired browser-storage record is replaced on the next SDK use and can be removed sooner by clearing extension storage or uninstalling. Token and IP HMAC values are scrubbed from active D1 delivery records after 24 hours.
  • De-identified impression and click records are retained for 13 months for reporting, billing reconciliation, fraud review, and disputes.
  • Analytics Engine delivery events contain no SDK token or IP value and expire after Cloudflare’s three-month retention period.
  • Cloudflare Workers operational logs are retained according to our plan, currently no longer than seven days.
  • D1 recovery history may retain deleted or scrubbed values for up to 30 additional days. Recovery data is access-restricted and is not used for ordinary processing.
  • Account information is retained while the account is active. After verified closure, we delete operational profile data while keeping payment, payout, tax, and accounting records for up to seven years where required.
  • Rejected applications are retained for 24 months. Expired login, verification, and rate-limit state is deleted automatically.
  • Marketing suppression records are kept until the recipient affirmatively opts back in so we can honor the opt-out.

Your rights and choices

Depending on where you live, you may have rights to know or access, correct, export, delete, restrict, or object to processing of your personal information; withdraw consent; and appeal a denied request. Developers and advertisers can update most account information in their portal. For anything else — including account deletion — contact us at support@adsonbread.com and we will respond within the timelines required by applicable law.

Extension viewers can reset the local SDK token by clearing the extension’s local storage or uninstalling the extension. Because the token expires and AdsOnBread stores only a short-lived HMAC, we may be unable to verify or retrieve records belonging to a particular viewer. We will explain that limitation rather than attempting to identify the person through additional data.

European and UK residents may also complain to their local data-protection supervisory authority. California and other US residents may exercise applicable privacy rights without discriminatory treatment. We do not sell personal information or use it for cross-context behavioral advertising.

Children

AdsOnBread accounts are for adults acting as developers or businesses. AdsOnBread does not accept integrations into extensions directed primarily to children under 13 or a higher minimum age required by local law. Publishers must not use the SDK in a child-directed service, and advertiser campaigns must not target children. Contact us immediately if you believe the SDK is operating in a child-directed extension.

Changes to this policy

We may update this policy as the service evolves. We will post the new version here and update the date at the top. For material changes affecting account holders, we will give notice through the portal or by email.

Contact

Questions about privacy? Email support@adsonbread.com or write to us at:

788 N 700 E Apt 2
Provo, UT 84606
United States