Privacy Policy
Last updated 17 September 2026. This policy explains what Exeria Sawakli ("Sawakli", "we") collects, why, and how you control it. Sawakli is operated by Exeria; contact [email protected].
What Sawakli is
Sawakli is an advertising dashboard. Agencies ("managers") and their clients use it to see Meta advertising results (Facebook and Instagram), follow changes made to campaigns, record sales figures, and — for managers — manage campaigns. People sign in with an email and password. Access to Meta data happens only after someone chooses Continue with Facebook or Connect my Facebook and grants it on Facebook.
Information we collect
Your Sawakli account
- Name, email address and role (admin, manager or client), and which manager a client belongs to.
- Your password, stored only as a salted PBKDF2-SHA256 hash; we cannot read it.
- Sign-in sessions and API keys, stored only as SHA-256 hashes, and failed sign-in counters keyed by a hash of email and IP address.
Data from Meta, after you grant access
- Access tokens issued by Meta for the business, ad accounts, Pages and Instagram accounts you selected, with the token owner's Meta ID and name, the permissions granted and the token expiry.
- Asset details: IDs, names, currency and time zone of those ad accounts, Pages and Instagram accounts.
- Advertising data read from the Meta Marketing API when a report is shown: campaigns, ad sets, ads, budgets, targeting settings, creatives and results such as spend, impressions, clicks and conversations. Report results are kept as a history so reports and before/after comparisons can be shown.
- Campaign changes: the settings of a campaign, ad set or ad just before and after a change made through Sawakli, and a log of actions taken.
- Page and Instagram data, only for managers who use those features: posts, comments, Messenger and Instagram Direct conversations, and insights, read when viewed and kept in the report history.
Information you add
- Sales periods (units sold, prices, costs, exchange rates), pasted report text, and CSV files created in Sawakli.
- Customer lists uploaded to create Meta Custom Audiences: emails and phone numbers are normalised and SHA-256 hashed inside Sawakli before being sent to Meta; Sawakli keeps only the counts, never the list.
How we use it
- To show you advertising results, campaign changes and profit calculations for the accounts you are allowed to see.
- To let managers make the campaign changes they ask for (for example budgets, targeting, pausing ads), and to let clients see the accounts they connected or were given access to.
- To keep the service secure: authentication, preventing abuse, and audit logs of actions.
We do not sell personal data, use it for our own advertising, or build profiles of people from Meta data. Data obtained through Meta is used only to provide Sawakli to the person or business that granted it, in line with Meta's Platform Terms.
Who can see your data
- Managers see the Meta accounts they connected and the accounts their clients connected for them.
- Clients see only the ad accounts their manager assigned to them or that they connected themselves, read-only.
- Other managers and admins cannot see another manager's accounts, tokens or data.
- If a manager connects an AI assistant (Claude by Anthropic) with a Sawakli API key, the data that manager asks about is sent to that assistant under the manager's own agreement with Anthropic.
Service providers
- Google Cloud (Google LLC): hosting, database and file storage in the European Union.
- Cloudflare: domain name service and network protection for the Sawakli address.
- Meta Platforms: the source of advertising, Page and Instagram data, and the destination of changes you make.
Cookies
Sawakli uses only essential cookies: a sign-in session cookie (HttpOnly, 7 days) and a short-lived cookie that secures the Facebook sign-in (10 minutes). There are no analytics or advertising cookies.
Retention and deletion
- Account data and connected Meta data are kept while the Sawakli account is active.
- Removing a connection in Sawakli, or removing Sawakli from your Facebook business integrations, deletes the stored access token and the linked asset details; Sawakli can no longer read that data.
- Expired sessions and old failed sign-in counters are deleted automatically. Database backups are kept for 7 days.
- See Data deletion for how to remove your data, including through Facebook.
Security
Sawakli is served only over HTTPS. Passwords, sessions and API keys are stored hashed; access is limited by role; the database and storage are private to the service. No system is perfectly secure, but we act promptly on any incident.
Your choices and rights
You can see and remove connections at any time in Sawakli, revoke Sawakli's access in your Facebook settings, and ask us to access, correct or delete your personal data by writing to [email protected]. We answer within 30 days.
Changes
We will update this page when our practices change and show the new date at the top.