KITWRKS builds practical automation tools. This policy explains what we collect on kitwrks.com, what happens when you use Mass Creative or create a hosted lead-magnet tool, and what happens when you connect Meta Ad Loader to your Meta business assets.
What this policy covers
This policy covers the KITWRKS website and account, Mass Creative, hosted lead-magnet tools, build delivery emails, the KITWRKS Meta connection relay, and the hosted Meta Ad Loader. Connected CRMs, automation platforms, AI providers, Meta, and other third-party services process information under their own terms and privacy policies.
KITWRKS is operated by Build Better Digital LLC, a United States company. Build Better Digital LLC is the controller of personal information KITWRKS collects for its own site, account, billing, support, and product operations. A lead-magnet creator remains responsible for the prospect information collected through that creator's tool and connected systems.
Lead Magnet Builder data
When you create a lead magnet, we process the business details, audience, offer, problem, website URL, owner email, tool copy, questions, result logic, branding, and call-to-action settings you provide or generate. We store the published tool configuration so the public experience remains available. We also store non-identifying event counts such as views, starts, completed results, and call-to-action clicks.
Creator access requires a KITWRKS account. The site-managed passwordless sign-in flow provides the creator's email address and, when available, display name. We use that identity to own projects, associate Meta Ad Loader connections and subscriptions, enforce build allowances, record aggregate AI usage, and suspend abusive use.
If you connect Google Sheets, GoHighLevel, or a webhook, KITWRKS stores the connection details needed to route submissions. Secret values are encrypted at rest and are not included in public pages or source-code exports. You should disconnect the integration or rotate its token if you believe a private management link or credential has been exposed.
Information entered by your prospects
A hosted lead magnet may ask a prospect for their name, email, answers, and consent. The KITWRKS service receives that submission over an encrypted connection, creates the result, and forwards it to the destination selected by the tool creator. V1 does not offer a browsable KITWRKS lead list and does not send the result by email. Successful submission payloads are not retained as permanent lead records by KITWRKS. Delivery metadata may be kept without the prospect's answers or contact details so the creator can understand whether the tool is operating.
Tool creators choose their questions, consent language, privacy link, destination, and follow-up. Their connected destination independently stores and processes the submission under the creator's account and that provider's terms. Prospects should contact the tool creator about information held in the creator's CRM, spreadsheet, or automation system.
Website and email data
When you request a build, we collect the email address you provide and the source that brought you here, such as YouTube, LinkedIn, X, or a direct visit. We use that information to deliver the build, send occasional related builds or practical automation notes, and understand which channels are useful. Kit handles email delivery and subscriber records. Cloudflare hosts and delivers the public website and hosted applications, including the private D1 and R2 storage described in this policy, and may process ordinary request logs and privacy-focused, aggregate site analytics.
To understand which pages and channels lead to account creation, KITWRKS may save a first-touch source, campaign parameters, the landing-page path, and the referring site's hostname with a new account. We do not save the full referring URL or unrelated query parameters for this purpose. The browser copy can be cleared through your browser's local storage and cookie controls.
Mass Creative data
When you use Mass Creative, we process the offer facts, website or product-page URL, answers, product or service images, logos, brand documents, research sources, approved brief, creative matrix, generation instructions, generated images, quality checks, review decisions, exports, and credit usage associated with your workspace. Project and billing metadata is stored in Supabase. Uploaded assets and generated media are stored in private Cloudflare R2 storage and are made available to your authenticated session through short-lived signed links.
Mass Creative sends the approved business context, selected assets, and structural examples needed for a generation request to Google's Gemini service. Google Cloud Vision may inspect generated creative text for quality checks. If you choose optional research, ScrapeCreators may retrieve selected public source material from supported sites. You must review generated images, visible copy, claims, and product accuracy before using an output in advertising.
What Meta Ad Loader accesses
When you choose to connect Meta, Meta tells the connection service which permissions you granted. The tool may then access the business assets you authorized, including your Meta user ID, ad account names and IDs, account status, currency and timezone, campaigns, ad sets, Facebook Pages, Instagram identities, pixels or datasets, custom conversions, and conversion settings. It uses this information only to show available assets; create the paused campaign and ad set you request or validate an existing destination; apply your selected budget, country, age, gender, placement, dataset, and conversion-event settings; validate the batch you approve; upload your media; and create paused ads in the selected ad set. The product does not offer interest targeting.
How the Meta connection works
After you approve access in Meta, a separate KITWRKS relay hosted by Railway exchanges Meta's authorization code, checks the permissions you granted, and temporarily holds the resulting access token, token proof, and Meta user ID behind a random one-time ticket. Railway processes the connection request and this short-lived authorization data as the relay's hosting provider. The ticket can be redeemed only by the authenticated hosted Meta Ad Loader flow that started the connection. It is valid for five minutes and is removed immediately when redeemed; expired tickets are rejected and cleared from temporary memory during relay cleanup. The token is never placed in the browser address.
After the one-time exchange, the hosted Meta Ad Loader encrypts the Meta access token and token proof before storing them with limited connection metadata in a private Cloudflare D1 database. Those records are scoped to the KITWRKS account that initiated the connection and are used by the server only to make the Meta API calls you request. The relay does not retain your creative files, campaign data, or ad account data after the ticket exchange.
Hosted Meta Ad Loader data
The hosted service stores destination snapshots, ad copy, destination URLs, batch plans, launch ledgers, and receipts in private Cloudflare D1 storage. These records can include ad-account, campaign, ad-set, Page, Instagram, pixel or dataset, and custom-conversion names and IDs, plus account status, currency, timezone, destination, attribution, optimization, billing, budget, and conversion-event metadata. The service sends the exact approved batch to Meta and creates ads in a paused state.
When you open the results view, the service requests recent ad status and aggregate performance from Meta and returns it to your authenticated browser. KITWRKS does not store that results response as a separate performance-history table in V1.
Creative files you upload are stored in a private Cloudflare R2 bucket so the server can transfer them to Meta. They are not public objects. The default retention window is 30 days; after expiry the app will no longer use the file and removes it during storage cleanup, unless you delete it sooner or we must keep it longer to resolve security, legal, or service-integrity issues. Deleting a hosted copy does not delete an ad or media object that Meta has already received.
AI-assisted use
The Lead Magnet Builder may send creator-supplied business context and the selected concept to Moonshot AI's Kimi API to generate structured tool content. Published analyzers, generators, plan builders, and other tools marked as AI-powered may also send the prospect's answers and the tool's result instructions to Kimi to create the promised personalized result. Those answers are treated as data, not instructions, and are not retained as a browsable KITWRKS lead record. Deterministic tools do not make a prospect-time AI request.
The hosted Meta Ad Loader handles connection, discovery, destination configuration, batch planning, approval, upload, reports, and receipts through the browser without requiring an AI assistant. Its ordinary workflow does not send your Meta access token, Meta asset data, creatives, batch plan, or reports to an AI model.
If you separately choose to share information with an AI assistant, that provider processes what you submit under your account settings and its terms. KITWRKS does not control that separate disclosure. Do not provide an assistant with Meta credentials or other secrets.
Sharing, sale, and advertising
We do not sell or rent personal information, and we do not use Meta connection data to build advertising profiles or advertise to you. We share information only with providers needed to run the requested service, such as Kit for email, Cloudflare for the site and hosted application storage, Supabase for accounts and Mass Creative project records, Google Gemini for Mass Creative generation, Google Cloud Vision for visual quality checks, ScrapeCreators for optional public-source research, Moonshot AI for lead-magnet generation, a creator-selected Google, GoHighLevel, webhook, or automation destination for lead routing, Railway for the connection relay, Stripe for subscriptions and one-time subscriber top-ups, and Meta for authorization and ad creation. An AI provider may receive information only as described here or when you separately choose to send it. We may also share information when required by law, to protect rights and security, or as part of a business transfer.
Retention and security
Subscriber information is kept until you unsubscribe or request deletion. A redeemed Meta token is removed from the relay immediately. An unredeemed ticket becomes unusable after five minutes and is cleared from temporary memory during relay cleanup. Encrypted Meta credentials and associated connection metadata remain in private D1 storage until you disconnect or ask us to delete them. Uploaded Meta Ad Loader creatives have a default 30-day retention window, after which the app stops using them and removes them during storage cleanup. Destination, batch, security, subscription, credit-purchase, payment-event, and transaction records may be retained for the period reasonably needed to provide the service, prevent abuse, resolve disputes, and meet accounting or legal obligations. Lead-magnet tool configurations and creator-account usage records remain until the creator deletes them or requests deletion; successful prospect submissions are not retained as a KITWRKS lead list. We use reasonable technical and organizational safeguards, but no system can guarantee absolute security.
Your choices and deletion
Every marketing email includes an unsubscribe link. You can disconnect Meta from the hosted Meta Ad Loader, revoke KITWRKS in Meta's Business Integrations settings, delete an uploaded creative in the app before it is used by an active batch, request deletion support, or ask us to access, correct, or delete information we hold. Disconnecting KITWRKS does not remove ads or other objects already created in Meta. Step-by-step directions are on the data deletion page.
Children
KITWRKS is intended for business users and is not directed to children under 18. We do not knowingly collect personal information from children.
Changes and contact
We may update this policy as the tools or legal requirements change. The effective date at the top identifies the latest version. Questions or privacy requests can be sent to hello@kitwrks.com. Build Better Digital LLC is based in the United States.