Bloom Growth Studio
Privacy Policy
Last updated 13 September 2026 · Bloom Growth Studio is operated by Vast Learning, LLC.
Bloom Growth Studio is a tool advertisers use to create advertising creative and to publish it into their own Meta (Facebook and Instagram) ad accounts. This page explains what the tool reads, what it writes, where it is kept, and how to ask for it to be deleted. It is written in plain language on purpose.
Who this policy is about
The people who use Bloom Growth Studio are advertisers and their marketing teams. The tool is not a consumer product: it does not collect data from the people who see the ads, it has no tracking pixel of its own, and it does not build profiles of consumers.
What we collect about you, the user
- Your account: name, work email address, password (stored only as a salted hash), and role.
- Your activity in the tool: what you generated, when, and which ads you published — so your team can see who made what.
- Ordinary server logs (request paths, timestamps, error traces). Secrets and access tokens are redacted before anything is written to a log.
Meta permissions we use
When an advertiser connects a Meta account, the app asks for these permissions and uses them only for the purpose named:
ads_management— create paused campaigns, ad sets, ads and creatives in the advertiser's own ad account, upload the images for them, list the ad account's Instagram accounts and pixels, and read those ads' performance numbers.pages_show_list— list the Facebook Pages the advertiser manages, so an ad can be published as the correct Page.pages_read_engagement— read the selected Page's name and basic details (Meta requires it alongsideads_management).pages_manage_ads— run the ads from the advertiser's selected Page.
What we read from Meta
- Ad account details: id, name, currency, time zone.
- Campaigns, ad sets, ads and their creatives — names, ids, status, targeting settings and the ad copy and images.
- Performance numbers (insights): spend, impressions, clicks, and purchase or lead counts, plus the figures derived from them such as cost per result.
- Facebook Page and Instagram account ids and names for the Pages the advertiser manages.
We read aggregate advertising results. We do not request, download or store the personal data of the people who saw or clicked an ad, and we do not use Meta data to build audiences or profiles.
What we write to Meta
- New campaigns, ad sets, ads and ad creatives — always created paused, so nothing starts spending without a person turning it on in Ads Manager.
- Images uploaded to the advertiser's own ad-account image library, for use in those creatives.
- Names and tracking URL parameters on the objects we create.
We do not change budgets, delete existing campaigns, or touch anything the tool did not create.
Where the data is kept
Everything is stored on a private virtual server located in the United States (Phoenix, Arizona), operated by Hostinger, in a PostgreSQL database, with generated images on the same server's disk. Traffic to the app is encrypted (HTTPS). When an advertiser connects with Facebook, the Meta access token that connection gives us is stored in that database encrypted (AES-256-GCM), is only ever used on our server for that advertiser's own company, is never sent to the browser and never written into logs, and is deleted when the advertiser disconnects or asks Meta to delete their data. Our own service keys are held as server-side environment secrets, never sent to the browser and never written into logs. Access to the tool requires a named account; there is no public sign-up.
How long we keep it
- Ad performance data and the creative history: kept for as long as the advertiser uses the service, because the tool learns from past results. Removed within 30 days of a written request or of the account closing.
- Account records: kept while the account is active, then deleted within 30 days.
- Server and audit logs: kept up to 12 months.
- Records of data deletion requests: kept as proof that the request was handled.
Who else processes data for us
- Meta Platforms — the advertising platform the data comes from and goes back to.
- Stripe — subscription and payment processing. Card details go directly to Stripe; we never see or store them.
- AI model providers (the image and text generation services the studios run on) — they receive the prompts and reference images needed to produce creative. They are not given Meta account credentials or performance data tied to a person.
- Our hosting provider — Hostinger, which runs the server in the United States that the app runs on.
We do not sell data, and we do not share it with anyone for advertising or marketing purposes of their own.
Deleting your data
If your business connected its Meta account. The connection gives us one access credential that belongs to your business, not to a person, and does not expire on its own. It is deleted in any of these ways:
- Disconnect in the app. In Settings → Connect Meta, press Disconnect. We delete the credential immediately and ask Meta to revoke it.
- Remove the app in Meta. In Meta Business Settings → Integrations, remove the app. The next time the tool tries to use the credential Meta refuses it, and we delete it then.
- Ask us. Write to omer@vest.media and we delete your business's connection and data.
If a person asks Facebook to delete their data for this app, we record the request and give them a confirmation code and a status link. We do not hold personal data about that person from Meta, because the connection belongs to the business; any connection tied to their Facebook id is deleted.
For your own data as a user of the tool, there are two ways to ask:
- From Facebook. In your Facebook settings, remove the app and choose to send a request to delete your data. Meta notifies us automatically, and you are shown a confirmation code and a link to a status page for that request.
- By email. Write to omer@vest.media and say what you would like deleted. We answer within 30 days.
You can also ask for a copy of what we hold about you, ask for corrections, or withdraw consent, using the same address.
Children
The service is for business use by adults. It is not directed at children and we do not knowingly collect data from anyone under 18.
Changes to this policy
If this policy changes we update the date at the top of the page. Material changes are also announced to account holders.
Contact
Vast Learning, LLC, operator of Bloom Growth Studio — omer@vest.media.