PRIVACY & YOUR DATA
Privacy policy
Effective date: 28 September 2026
Fivefold is a private workspace for connecting authorized Meta advertising accounts, reviewing campaign performance, and managing approved campaign changes.
Who operates Fivefold
Fivefold is operated by Evandro Cabral ("we", "us"). For privacy questions or requests concerning data handled by Fivefold, contact cripto_calamar7n@icloud.com. We are responsible for the operation and purposes of this workspace. Meta and other services you use have their own privacy practices.
Information we handle
- Connected account information: ad account identifiers and names, workspace labels, currency, time zone, account status, and connection settings.
- Advertising information: campaign and ad-set identifiers and names, conversion-event settings, delivery status, budgets and bid caps, daily spend, impressions, clicks, and aggregated conversion actions and values returned by Meta. Campaign names or labels can contain personal information if an advertiser includes it.
- Ad-post comments: when requested by the operator and authorized by Meta, comment text, author display names where available, timestamps, reply relationships, post links and associated ad identifiers.
- Authorization information: temporary OAuth authorization codes, access tokens, granted permissions and token validity information used to establish and maintain the authorized connection. Fivefold does not ask for or store your Facebook password.
- Workspace activity: connection and synchronization events, errors, and proposed, approved, rejected or executed campaign changes, including related account and campaign details.
- Security and contact information: authentication sessions, information submitted in privacy requests, and network information processed to deliver and protect the service.
The integration requests campaign-level and ad-set-level aggregated reporting and can retrieve comments on authorized Facebook ad posts. It does not retrieve individual audience members, customer lists, lead submissions or private Facebook messages.
How we use information
We use information to authenticate authorized connections, retrieve and combine advertising reports, display and export results, review ad-post comments, answer authorized analysis requests, troubleshoot errors, secure the workspace, and handle privacy requests. Where management permissions and the workspace's change controls are enabled, we also use it to prepare and execute campaign changes approved by the workspace owner.
Where data protection law applies to personal information, we rely on our legitimate interests in administering our business advertising, securing the service and maintaining accountability, subject to the rights of affected individuals. We also process information when necessary to meet applicable legal obligations. Authorizing access through Meta grants technical permission to access the selected resources; it does not remove your privacy rights.
Who receives information
- Authorized workspace users can access the connected accounts' reports and activity. Account connections are stored separately, but the workspace is designed to compare them together.
- Meta processes authorization and API requests and receives approved campaign updates when that functionality is enabled.
- Oracle Cloud Infrastructure hosts the Fivefold server and its database in the Switzerland North (Zurich) region. Oracle provides the infrastructure used to store information and deliver the service, and may process technical and security information under its applicable service terms and policies.
- AI assistants and their providers receive the tool results or exported reports that an authorized operator requests or shares with them. For example, using Fivefold through Codex can send account information, campaign metrics, requested ad-post comments and change proposals to OpenAI. The provider's terms and the operator's account settings govern that processing. Meta access tokens are not included in Fivefold's MCP tool results.
- Authorities or advisers may receive information when necessary to comply with law or establish, exercise or defend legal claims.
Fivefold does not sell connected account information or use it for unrelated advertising. Relevant provider policies include Meta's Privacy Policy, Oracle's Privacy Policies and OpenAI's Privacy Policy.
Storage and security
The workspace stores its active database on an Oracle Cloud server. Private recovery copies are also kept on the server and on the operator’s computer. Stored Meta access tokens are encrypted. Administrative access requires a password, and MCP access requires a separate credential. Browser access through the public address uses HTTPS. Access controls reduce risk but cannot guarantee absolute security.
Oracle, Meta and any selected AI provider may process information in other countries. Their applicable service terms and privacy notices describe their processing locations and transfer arrangements. Exported reports and assistant conversations are separate copies and follow the storage and retention practices of their destinations.
Retention and disconnection
Ad-post comments and Page access tokens fetched for a comments request are processed transiently and are not saved in Fivefold’s database. Comments displayed in a browser or returned to an assistant may persist at those destinations under their respective practices.
Connected account information and cached metrics are retained for the workspace's reporting and management use until removed. The current version has no automatic age-based deletion schedule for reports, account metadata, change history or audit records.
Using Disconnect locally removes the saved access token and cached metrics for that connection and cancels pending proposals. Account identifiers, labels, metadata and historical activity remain unless separately deleted. A full deletion request can cover those remaining records. We retain information only where still necessary for the stated purposes or an applicable legal requirement.
The essential sign-in cookie expires after eight hours; signing out invalidates its session. Authorization links expire after ten minutes. Expiration prevents further use but is not a promise that all corresponding database records are erased at that moment.
Daily server recovery copies are kept for approximately eight days. The operator also keeps a separate recovery copy outside the server; this copy is replaced or removed manually. Deletion requests include copies under our control. Any recovery from an older backup must reapply completed deletion requests before normal use resumes.
Your choices and privacy requests
You can revoke Fivefold's access through Meta's Business Integrations settings and disconnect the account in Fivefold. Revocation at Meta stops future authorized access but does not itself erase data already stored in this workspace.
Depending on applicable law, you may request access, correction, deletion, restriction or portability of personal information, and object to processing based on legitimate interests. You may also complain to your local data protection authority. Email cripto_calamar7n@icloud.com; we may request proportionate information to verify your identity or authority over an account. We respond without undue delay and within applicable legal deadlines.
See our data deletion instructions for a specific way to request removal. Do not send passwords, access tokens or app secrets with a request.
Cookies and analytics
Fivefold uses an essential session cookie to keep the workspace administrator signed in. The application does not include third-party advertising pixels or analytics scripts. Infrastructure providers may process technical data to operate and secure their services.
Changes to this policy
We will update this page and its effective date when our data practices change. Material changes will be communicated to affected workspace users where required.