AdLibrarySpy is open source. Contributions welcome

Privacy policy

Last updated 27 September 2026

AdLibrarySpy (adlibraryspy.com) is a free shop and ad intelligence tool. This page explains what we store about you when you browse the site or use an account, why, and how to have it removed. The Chrome extension has its own policy.

Browsing without an account

Public pages (shops, ads, the directory, the weekly report) need no account and set no cookies from our server. If you arrive through a tagged link (for example ?ref= or ?utm_source=), the page stores that tag in a first-party cookie, als_ref, for 30 days, so that if you sign up we know which link brought you. It holds only the tag, nothing about you.

Meta pixel. To measure our own ads on Facebook and Instagram, pages load Meta’s pixel, which reports each page view and, once, that a new account was created (with an internal account ID, never your email or name). Meta sets its own cookies to do this (_fbp, and _fbc when you arrive from one of our ads, which our page may also write so the ad click is not lost). When an account is created, our server also tells Meta directly (Meta’s Conversions API), so the signup is counted even if the pixel was blocked or the sign-in link was opened on another device. It sends a one-way hash of your email address and of your account ID, those two Meta cookies, and the IP address and browser you signed up from, which Meta uses to match the signup to an ad click. Its use is covered by Meta’s privacy policy.

Google Analytics. To see which pages are used and how visitors find us, pages load Google Analytics, which records page views, scrolls, outbound link clicks and site searches, with your browser, device and approximate location. It sets its own first-party cookies (_ga, _ga_*) from the page, never from our server; its use is covered by how Google uses information from sites that use its services.

Browser tracking protection or an ad blocker stops these without affecting the site. We use no other third-party analytics or advertising trackers.

Your account

  • Email address and name, to sign you in, show you in your workspace and send you account email.
  • Workspace name, members, their roles and pending invitations.
  • What you save in the app: favorites and folders, tracked brands, hidden shops, recently viewed items, and API keys (stored only as a hash).
  • An activity log of changes made in your workspace, with the IP address they came from, which workspace owners can see.
  • How you found us: the als_ref tag above and the page you signed up from, and Meta’s _fbc/_fbp ids when present, which identify the ad click.

Signing in

Email link. We email you a one-time link that expires after 20 minutes. We store the address it was sent to, a hash of the link (never the link itself), and the IP address and browser that asked for it.

Sign in with Google. If you choose it, Google sends us a signed token confirming your Google account ID, your email address (only if Google has verified it) and your name. We check the token with Google and keep your Google account ID so the same Google account always signs into the same AdLibrarySpy account. We receive nothing else from your Google account: no password, contacts, files, mail or calendar, and we get no ongoing access to it. Google’s handling of your sign-in is covered by Google’s privacy policy.

Sessions. Once you are signed in, a cookie named ml_session keeps you signed in for up to 30 days. It is HTTP-only (page scripts cannot read it) and holds a random token; we store only its hash, together with the IP address and browser name of that sign-in, so a session can be revoked at once. A second cookie, als_in, only tells our pages that this browser is signed in (so the homepage does not offer Google sign-in again); it grants no access. Signing out removes both.

Email we send

Sign-in links, invitations you or your team send, and confirmations when you change your address. The weekly report is sent only if you subscribe, and every issue has an unsubscribe link. We send from our own mail servers and never give your address to anyone else.

Security and abuse protection

To stop abuse we count requests per IP address, and sign-in attempts per IP address and per email address, in short-lived counters. Our own product metrics record a few milestones per account (signed up, first save, first tracked brand, invitation sent or accepted) with your account and workspace IDs, in our own database.

Who processes it

  • Amazon Web Services hosts the application and its database.
  • Cloudflare delivers the site and sees each request, including your IP address, to serve and protect it.
  • Google, when you choose Sign in with Google, and through Google Analytics described above.
  • Meta, through the pixel and the signup report described above.

We do not sell your data, and we use it only to run AdLibrarySpy.

The data AdLibrarySpy shows

The shops, ads and traffic estimates in AdLibrarySpy describe businesses, drawn from public sources such as public storefronts and public ad libraries. If you believe a page shows personal information about you, write to [email protected] and we will review it.

Keeping and deleting your data

We keep your account data while your account exists. Expired sign-in links and sessions stop working at once and are no longer used. To get a copy of your data, correct it, or delete your account and the personal data tied to it, email [email protected] from the address on your account. We act on the request within 30 days. Workspace content you created for your team stays with the workspace unless you are its only member.

Changes

If we start collecting anything new, we will update this page before it happens and change the date above.

Contact

Questions or requests about your data: [email protected].

AdLibrarySpy · free shop and ad intelligence