Last Updated: September 6, 2026
1. Information We Collect
Meta Ads and Facebook data
- Account information: when you authenticate, AdsAgent may collect public profile details such as name, profile picture, and email address.
- Advertising data: with
ads_read and business_management, AdsAgent can access ad accounts, campaigns, ad sets, ads, and performance data such as spend and impressions. - Page data: with
pages_read_engagement and pages_show_list, AdsAgent can access Facebook Pages and feed-level engagement signals used for review readiness.
1.2 Google Ads Data (Read-mostly, Confirmation-gated Writes)
Google Ads authorization and reporting scope
The Google Ads integration is read-mostly with confirmation-gated writes. AdsAgent reads account and reporting data to provide dashboards and agent-readable reports. Every write is two-step — prepare → Google validate-only dry-run → your explicit confirmation — and nothing happens without your per-action confirmation. Two write surfaces are available: creating advertising assets (image assets and YouTube (video) references to existing public videos; no file upload, no YouTube Data API, no extra scope); and campaign management — status changes (ENABLED↔PAUSED at campaign, ad-group, or ad level), changes to a campaign's daily budget (subject to a daily cap), bidding-strategy changes from a small allowlist, and campaign creation (a created campaign is always created PAUSED). AdsAgent never deletes or removes any entity, never creates ads from your assets or attaches them to ads, makes no change you have not confirmed, acts only on Google Ads accounts you have connected and are authorized to manage, and keeps the hosted MCP endpoint read-only. An asset created — or a campaign-management change made — in your Google Ads account persists in that account and may not be deletable or editable through AdsAgent afterward.
- Google identity: with the OpenID Connect scopes, AdsAgent receives your email address, basic profile, and the OpenID subject identifier to establish your account.
- Account hierarchy: manager (MCC) and customer account structure, including customer name, status, currency, and timezone.
- Billing setup status: whether a connected account has billing configured.
- Daily spend metrics: recent spend and related reporting metrics for connected accounts.
- OAuth authorization: AdsAgent uses OAuth 2.0 and stores only the connection metadata and an encrypted refresh token needed to read on the account owner's behalf, to create the image and YouTube (video) assets you confirm, and to carry out the campaign-management writes you confirm. The refresh token is encrypted at rest, held server-side, and is never exposed to MCP clients or the browser.
1.3 AI Assistants, MCP Connectors, and ChatGPT Apps
When you connect AdsAgent through an AI client
AdsAgent can be connected through OAuth to AI assistants and MCP-compatible clients, including ChatGPT Apps, Claude connectors, and other hosted MCP clients you authorize. When you connect, the client receives an OAuth access token scoped to your AdsAgent workspace. Tool calls made through that connection cause AdsAgent to read or, when you explicitly confirm, change advertising data on your behalf.
- Authorization metadata: client identifier, granted OAuth scopes, connection timestamps, and workspace identity needed to authenticate the connector.
- Tool responses: bounded advertising data returned by MCP tools you or the assistant invoke, such as setup readiness, product cards, performance summaries, saved templates, task status, notifications, and confirmation-gated launch drafts.
- Operational logs: minimal request metadata (for example tool name, request identifiers, and error classifications) used for security, abuse prevention, and support — not full chat transcripts. Retention periods are listed in Section 4. AdsAgent does not send Meta or Google OAuth refresh tokens to AI clients.
Why we process it: to let you inspect and manage authorized advertising workflows through the AI client you chose, including read-only reporting and operator-confirmed changes that require explicit approval inside AdsAgent tools.
Who receives it: when a tool is invoked through ChatGPT Apps, OpenAI receives the tool response so it can display results in your conversation under OpenAI's terms. When you connect through Claude or another MCP host, that host receives the same tool responses under its terms. AdsAgent does not sell this data. We use infrastructure providers such as Supabase and Cloudflare to host the service.
Your choices: disconnect the AdsAgent connector in your AI app settings; revoke AdsAgent OAuth authorization at adsagent.md/docs/mcp-onboarding; revoke underlying Meta, Google, or TikTok platform access using the steps in Section 4; or email support@adsagent.md to request deletion.
1.4 Data We Do Not Collect
AdsAgent does not ask for or store health records, biometric identifiers, government ID numbers, payment-card numbers, CVV codes, or other PCI-regulated payment credentials through ChatGPT Apps, MCP connectors, or the AdsAgent dashboard. Advertising integrations use platform OAuth and read ad-account metadata, performance metrics, and operator-confirmed campaign changes only.
1.5 Service Providers and Recipients
Depending on the features you enable, authorized data may be processed by advertising platforms you connect (Meta, Google, TikTok), mobile measurement partners such as AppsFlyer, AI hosts you authorize (OpenAI for ChatGPT Apps, Anthropic for Claude connectors), and infrastructure providers that operate AdsAgent (Supabase, Cloudflare, Hetzner, Stripe for billing). Each recipient processes only the categories needed to provide the connected feature under its own terms.
2. How We Use Your Information
The uses below describe AdsAgent across all connected platforms. For Google Ads, the integration is read-mostly with confirmation-gated writes: the reporting and visualization uses apply, plus user-confirmed writes — creating image and YouTube (video) assets, and campaign management (status changes, daily-budget changes subject to a cap, bidding-strategy changes from a small allowlist, and always-paused campaign creation). Every write requires a prepare → Google validate-only dry-run → explicit per-action confirmation; AdsAgent never deletes any entity and never makes a change you have not confirmed.
- Dashboard visualization: display ad account, page, and performance information inside AdsAgent.
- Ad management and automation: on platforms where mutation is enabled (e.g. Meta), AdsAgent can support pause, monitoring, and account-intervention workflows when the operator has granted authorization. For Google Ads, AdsAgent supports two confirmation-gated write surfaces: creating image and YouTube (video) assets; and campaign management — status changes (ENABLED↔PAUSED at campaign, ad-group, or ad level), daily-budget changes subject to a cap, bidding-strategy changes from a small allowlist, and campaign creation (always created PAUSED). Each runs as prepare → Google validate-only dry-run → your explicit confirmation; AdsAgent never deletes or removes any entity and makes no change you have not confirmed. Assets and campaign-management changes you confirm are made directly in your Google Ads account and persist there; AdsAgent may not be able to delete or edit them afterward.
- Cross-platform reporting: combine authorized data sources into one operating view.
- AI assistant workflows: when you connect ChatGPT Apps, Claude, or another MCP client, return bounded tool responses so you can inspect and manage authorized advertising data inside that client.
- Service communication: send critical account-related notices when support or intervention is required.
3. Data Sharing and Disclosure
AdsAgent does not sell, trade, or otherwise transfer personally identifiable information, Meta Ads data, or Google Ads data to outside parties for unrelated commercial use.
When you connect AdsAgent to an AI assistant or MCP client you authorize, tool responses from your workspace are transmitted to that client so it can show results in your session. Those clients process the data under their own privacy terms.
Aggregate, non-identifying information may be used for operational analysis, but authorized account data remains tied to servicing the account owner.
4. Data Retention and Deletion
Remove Facebook data
- Go to Facebook Settings and open Apps and Websites.
- Find AdsAgent in the connected apps list.
- Choose Remove to revoke access.
- Email support@adsagent.md to request full deletion from AdsAgent systems.
Remove Google Ads data
- Visit myaccount.google.com/permissions.
- Find AdsAgent in the list of connected apps.
- Use Remove Access to revoke authorization.
- Email support@adsagent.md if you need deletion confirmed from AdsAgent systems.
Disconnect AI / MCP access
- Disconnect or remove the AdsAgent connector inside your AI app (for example ChatGPT Apps or Claude connector settings).
- Revoke AdsAgent OAuth authorization from your AdsAgent account settings or by following adsagent.md/docs/mcp-onboarding.
- MCP OAuth grants stop new tool calls once revoked; cached workspace data remains subject to the retention rules below until deleted.
- Email support@adsagent.md if you need confirmation that MCP authorization metadata was removed from AdsAgent systems.
Retention of Google data: OAuth connection metadata, the encrypted refresh token, account, billing, and spend snapshots, and records of any writes you confirmed AdsAgent perform on your behalf (such as an asset identifier and time of creation, and a record of any confirmed campaign-management action) are retained while the connection is active and for up to 30 days after you revoke access or request deletion, after which they are deleted from AdsAgent systems (routine backups age out on the standard backup cycle). Revoking at myaccount.google.com/permissions stops further reads and any further confirmed writes immediately. Assets and any campaign-management changes already made remain in your Google Ads account and are managed there — revoking access or deleting AdsAgent records does not undo a change that already exists in your account, and AdsAgent may not be able to delete or edit it for you.
Retention of Meta and MCP data: Meta connection data is retained while your Facebook authorization remains active and is deleted or anonymized after verified revocation or deletion requests. Cached advertising snapshots (for example ad accounts, products, and performance summaries) are retained while the connection is active and removed on verified deletion requests, typically within thirty (30) days after you revoke access.
MCP OAuth and operational logs (ChatGPT Apps and other connectors): When you connect through an MCP client, the client receives the AdsAgent OAuth credentials needed to maintain your authorized connection. AdsAgent stores authorization metadata and token-verification hashes server-side. Your underlying Meta and Google OAuth tokens are not sent to the AI or MCP client. MCP OAuth refresh tokens expire after thirty (30) days unless you revoke access sooner; revoking the connector or AdsAgent OAuth authorization stops new tool calls immediately.
- Tool-call audit logs (tool name, status, request/response size, hashed identifiers — not full chat transcripts): retained for thirty (30) days, then automatically deleted.
- Error diagnostics (sanitized argument structure and error classification for failed tool calls): retained for fourteen (14) days by default, up to thirty (30) days when needed for abuse or reliability investigation, then automatically deleted.
- Support error reports (bounded diagnostics you explicitly submit or approve for troubleshooting): retained for ninety (90) days, then automatically deleted. The
setup_get_status tool may disclose this retention period for your workspace.
AdsAgent does not store complete ChatGPT or assistant conversation transcripts. On verified deletion requests, we remove or anonymize remaining MCP authorization metadata and cached workspace data within the timelines above unless a longer period is required by law.
5. Google API Services — Limited Use
AdsAgent's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- Google user data is used only to provide and improve the AdsAgent features the user requested.
- We do not sell Google user data, and do not use it for advertising profiles or unrelated commercial purposes.
- We do not transfer Google user data to third parties except as necessary to provide the service, comply with law, or as part of a merger with appropriate notice.
- Humans do not read Google user data except with the user's consent, for security/abuse/legal reasons, or where required and aggregated for internal operations.
- Google user data is used only to provide the features you requested — reading and reporting, the user-confirmed creation of advertising assets (image assets and YouTube video references), and the user-confirmed campaign-management writes (status changes, daily-budget changes subject to a cap, bidding-strategy changes from a small allowlist, and always-paused campaign creation). Every write requires a prepare → Google validate-only dry-run → explicit per-action confirmation, and AdsAgent never deletes any entity. This data is not sold and is not used for advertising profiles or unrelated purposes.
Our use also remains aligned with the Google Ads API terms and best-practices guidance.
6. Cookies and Similar Technologies
AdsAgent uses a small number of strictly-functional cookies to keep you signed in and to defend against cross-site request forgery. We do not run third-party advertising or analytics cookies on the public marketing site.
- access_token, refresh_token — session cookies that prove a logged-in operator after Supabase authentication. Marked HttpOnly + Secure + SameSite=Lax.
- csrf_token — a per-session token used to validate POST submissions on auth and waitlist forms.
- signup_captcha_token — a 10-minute HMAC-signed token that holds the captcha challenge during signup.
Two different "tokens": the access_token / refresh_token cookies above are AdsAgent's own Supabase session cookies (they prove a logged-in operator) and are unrelated to Google. Your Google OAuth refresh token is not stored in any cookie — it is held server-side, encrypted at rest, and is never sent to the browser or to MCP clients. Clearing cookies signs you out of AdsAgent but does not by itself revoke Google access; revoke that at myaccount.google.com/permissions.
Disabling these cookies will prevent sign-in and form submission. Your browser settings let you remove them at any time.
7. Your Privacy Rights (GDPR / UK GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights with respect to personal data adsagents LLC processes about you:
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — ask us to correct inaccurate or incomplete personal data.
- Right to erasure ("right to be forgotten") — request deletion of personal data we hold, subject to legal retention obligations.
- Right to restrict processing — limit how we use your personal data while a request is being investigated.
- Right to data portability — receive your personal data in a structured, machine-readable format and transmit it to another controller.
- Right to object — object to processing where it is based on legitimate interests or used for direct marketing.
- Right to withdraw consent — where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of prior processing.
- Right to lodge a complaint — with your local data protection authority.
Exercise any of these rights by emailing support@adsagent.md with the subject "Privacy Rights Request" and the right you wish to exercise. We respond within thirty (30) days.
8. Your Privacy Rights (California — CCPA / CPRA)
California residents have the right to know what categories of personal information are collected, the purposes of collection, and the right to access, delete, correct, and limit the use of sensitive personal information. adsagents LLC does not sell or share personal information in the sense defined by the CCPA/CPRA, and does not engage in cross-context behavioral advertising on this marketing site.
To submit a verifiable consumer request, email support@adsagent.md with the subject "California Privacy Request". You may designate an authorized agent in writing to make a request on your behalf. Exercising your rights will not result in discriminatory treatment.
9. International Data Transfers
adsagents LLC is established in Wyoming, USA, and may process personal data on infrastructure located in the United States or other jurisdictions. Where personal data of EEA, UK, or Swiss residents is transferred outside those regions, we rely on Standard Contractual Clauses or other lawful transfer mechanisms recognized by the relevant supervisory authority.
10. Children's Privacy
AdsAgent is a B2B service for advertising operators and is not directed at children. We do not knowingly collect personal data from anyone under 16 (or under 13 in the United States, per COPPA). If you believe a child has provided personal data, please contact us and we will delete it.
11. Changes to This Policy
We may update this Privacy Policy as the service evolves or to reflect changes in law. Material changes will be communicated by email to the address on file or by in-product notice at least thirty (30) days before they take effect. The "Last Updated" date at the top of this page reflects the most recent revision.
12. Security and Contact
AdsAgent uses HTTPS, token-based authorization flows, and controlled access to maintain the security of connected ad-account data.
Company: adsagents LLC
Address: 30 N Gould St Ste R, Sheridan, WY 82801
Privacy / data subject requests: support@adsagent.md
General: support@adsagent.md
Phone: +1-346-306-1794