Legal
Privacy Policy
Last updated: 28 September 2026
This Privacy Policy explains what data AntiAdBlock Core processes, why, and your rights. It covers two very different groups: (a) our customers, publishers who hold an account with us; and (b) the visitors to our customers' websites who encounter the detection script.
1. Privacy by design: website visitors
The detection script is built to be privacy-preserving. It does NOT fingerprint visitors, does NOT build visitor profiles and does NOT store any identifier that singles out a visitor. It only reports anonymous, aggregated counters to us. For each customer Site and each calendar day: how many checks ran, how many indicated an ad blocker, how many were resolved, and counts by browser family, device type, approximate country, hour of the day (UTC) and page path (only the most visited paths), all derived from the standard headers every browser sends with a request and kept only as daily totals.
To count recoveries correctly, the script keeps a small first-party entry on the customer's own domain: in the browser's local or session storage and, when the Site spans several subdomains, in a first-party cookie set on that domain. It holds only a timestamp flag, such as that an ad blocker was seen in that browser or that a recovery was already counted. It contains no identifier, is not used for advertising, profiling or tracking, and expires after 30 days.
Because that entry is stored on the visitor's device, the customer should describe it in the privacy or cookie policy of their Site and decide, under the rules that apply to them, whether their consent tool must cover it. You remain responsible for any other tags on your Site.
Like any web server, ours receives the IP address of the visitors whose browsers load the script or send a report. We use it in transit to derive the approximate country and to protect the Service against abuse; it is not stored in the statistics and is not linked to any visitor identity. It is also recorded, together with the browser user agent and the requested address, in our server access logs, which are kept for security and troubleshooting and deleted automatically after 14 days.
A short-lived, server-issued session identifier and a HMAC key are embedded in each served script purely to authenticate event reports; they are not linked to any visitor identity and expire within minutes.
2. Data we process about customers
When you register and use the dashboard we process: your name and email; a securely hashed password; an encrypted optional security PIN; your plan and billing status; your verified Site domains; support tickets you open; and security metadata such as login timestamps and IP addresses used for rate-limiting and abuse prevention. If you choose to add them in Settings, we also store optional billing and contact details (a billing or postal address, a phone number, a tax identification number, and one additional contact channel), used only to prepare your invoices and to reach you about your account. These optional details are stored with your account, so they are included in any access or deletion request you make, and you can clear them yourself at any time.
We also record, at the moment you create your account, how you reached us: the referring website and any campaign tags in the address you arrived with (utm_source and similar), plus the first page of ours you opened. We use it only to understand which channels bring us customers. It is stored with your account, so it is included in any access or deletion request you make, and it never contains anything you typed.
IP addresses used in rate-limiting and abuse records are hashed with a secret salt. As a security measure we do keep, in plain form, the IP address of your most recent sign-in and a security log of your account: each sign-in, failed sign-in attempt, lockout after too many attempts and password reset request, and the changes made to your account, your Sites and your subscription, by you or by our administrators, each with its date and, where there is one, the IP address it came from. Sign-in and password-reset entries are deleted automatically after 30 days. Server access logs also record the IP address of every request to our service, as described in section 1.
3. Payment data
We do not collect or store your card or payment details. Payments are handled by Stripe, which acts as Merchant of Record through its Link service and processes your payment information under its own privacy policy. We receive only the transaction result and the information needed to provision your plan.
4. Why we process data (legal bases)
We process customer data to perform our contract with you (provide the Service), to comply with legal obligations (accounting, tax), and on the basis of our legitimate interests (security, abuse prevention, improving the Service). Server access logs, including IP addresses, are processed on the basis of our legitimate interest in keeping the Service secure and available. Aggregated visitor counters are anonymous statistical data.
5. Sharing
We share data only with processors who help us run the Service: our hosting/CDN provider, our payment provider (Stripe), and our email-delivery provider, each bound to protect it. We do not sell personal data. We may disclose data if required by law or to protect our rights.
6. Retention
We keep customer-account data while your account is active and for as long as needed afterwards to meet legal and accounting obligations. Aggregated daily statistics are retained for service history. Hashed security metadata is retained only as long as needed for abuse prevention. Server logs, which include IP addresses, are deleted automatically within 14 days. In your account's security log, sign-in and password-reset entries are deleted automatically after 30 days; the other entries are kept while your account is active and are deleted with it, except the payment records we must keep for accounting. The first-party entry kept in the visitor's browser expires after 30 days.
7. Your rights
Under the GDPR and Spanish data-protection law you have the right to access, rectify, erase, restrict and port your personal data, and to object to certain processing. To exercise any right, or to complain, contact us at the address below. You may also lodge a complaint with the Spanish supervisory authority (AEPD).
8. International transfers & security
Where data is processed outside the EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. We protect data with encryption in transit (TLS), hashed credentials, encrypted secrets, scoped database access and least-privilege controls.
9. Contact
Data controller: AntiAdBlock Core. For any privacy question or request: [email protected].