Ditto: Privacy Policy

Last updated: 2026-09-26

Ditto is a private software tool operated by Aylon, an independent media buyer (the "operator", "I"). It is used only by the operator to create and manage Meta (Facebook and Instagram) ads for advertisers he works with, directly or through advertising agencies. Ditto is not offered to the public and has no public sign-up.

Contact for any privacy question or request: anyverse.co.il@gmail.com

What Ditto does

Ditto takes creative files (images and videos) and ad copy prepared by the operator, and creates ads in Meta ad accounts that the advertiser has shared with the operator. New ads are created paused and are activated only by a person.

Information Ditto processes

Ditto does not collect information about people who see or click the ads, does not read ad insights or audience data, and does not use cookies or tracking on these pages.

Meta permissions Ditto uses

Ditto requests only what it needs to create ads: ads_management, ads_read, business_management, pages_show_list, pages_read_engagement, pages_manage_ads and instagram_basic. They are used only to list the ad accounts, Pages and Instagram accounts shared with the operator and to create ads in them.

Google Drive

When the operator imports media from Google Drive, Ditto uses the drive.file scope: it can open only the files the operator picks in the Google file picker. It does not browse or scan the Drive. Ditto's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How information is used

Only to prepare, launch and monitor ad launches requested by the operator, and to notify the operator about their result (in the Ditto console and in the operator's private WhatsApp management group). The information is never sold, rented, used for advertising, or used to train AI models.

Where information is stored and who can see it

Retention

Ads created in Meta belong to the advertiser's ad account and are governed by Meta's policies; Ditto does not delete them.

Security

Access tokens and keys are encrypted at rest (AES-256-GCM). The server accepts connections only from the operator's private network. Every call to Meta goes through a single audited client, and access is limited to what the operator needs.

Your choices and rights

You may ask to see, correct or delete information that Ditto holds about you or your business, as described in the Data Deletion Instructions. You can also remove the operator's access at any time in Meta Business Settings (Partners, or Users → System users), or, if you connected with your own Facebook login, remove the app in Facebook Settings → Apps and Websites. The operator handles requests in line with applicable law, including the Israeli Protection of Privacy Law.

Changes

If this policy changes, the new version will be published at this address with a new date.