AdLoomly
SECURITY

Your ad accounts are protected

Our founding team runs its own TikTok ad spend through this exact platform. Protecting connected ad accounts isn't a compliance checkbox for us — it's self-interest. Here is exactly how we do it.

AT REST

AES-256 encryption at rest

All stored data — campaign metadata, performance metrics, and access tokens — is encrypted at rest with AES-256.

IN TRANSIT

TLS 1.2+ in transit

Every connection — between your browser and AdLoomly, and between AdLoomly and the TikTok Marketing API — is encrypted with TLS 1.2 or higher.

AUTHORIZATION

Official OAuth 2.0 only

We connect exclusively through TikTok's official OAuth 2.0 advertiser authorization. Never passwords. Never scraping. Never browser automation.

LEAST PRIVILEGE

Least-privilege scopes

We request only the TikTok Marketing API scopes our features actually need — ad account info, campaign/ad group/ad management, reporting, and automated rules. The full scope list is documented in our TikTok integration docs.

REVOCATION

Immediate revocation

Disconnect from inside AdLoomly, or revoke access from TikTok Business Center — either path stops all API calls immediately, and all TikTok-derived data is deleted within 30 days.

ISOLATION

Isolated per-tenant data

Every workspace's data is logically isolated. Your campaigns, rules, and metrics are never visible to — or queryable by — any other customer.

ACCOUNTABILITY

Full audit logs

Every rule execution and every campaign launch is recorded with a timestamp and a diff of what changed — so you can always see exactly what AdLoomly did, and when.

TOKENS

Encrypted token vault

TikTok access tokens live in an encrypted vault, are never exposed to the browser, and are only decrypted server-side at the moment an API call is made.

OUR HARD LINE

What we NEVER collect

Some data simply never enters our systems. Not encrypted, not anonymized, not "only for 30 days" — never.

  • Your TikTok password. OAuth 2.0 means you only ever type it on TikTok's own pages.
  • End-user / viewer personal data. We never request or receive data about people who see your ads.
  • Audience list member data. The contents of your Custom Audiences stay on TikTok, full stop.
  • Your ad account's payment details. Billing between you and TikTok is none of our business.
  • Data from ad accounts you didn't explicitly connect. We only touch accounts you authorized, one by one.
COMPLIANCE

Where we are today

We'd rather tell you honestly where we stand than paste a wall of badges we haven't earned yet.

Honest status: early-stage, no shortcuts

AdLoomly is an early-stage product. We operate GDPR-aligned processes and honor CCPA requests — access, deletion, and portability — via privacy@adloomly.com. Formal certifications such as SOC 2 are on our roadmap and will be published on this page when complete. Until then, we won't claim them.

Breach notification commitment

If we confirm a personal-data breach, affected customers are notified without undue delay — and within 72 hours of confirmation — with what happened, what data was involved, and what we're doing about it.

RESPONSIBLE DISCLOSURE

Found a vulnerability? Tell us.

Report security issues to security@adloomly.com. We respond within 24 hours. We will not pursue or support legal action against researchers who act in good faith, avoid privacy violations and service disruption, and give us reasonable time to fix the issue before public disclosure.

TRANSPARENCY

Who touches your data

Every third party that processes data on our behalf is listed publicly, with its purpose and location.

View sub-processors →

Ready to automate your TikTok Ads?

Built on the official TikTok Marketing API • Early access — no credit card required