1. Introduction
This Privacy Policy (“Policy”) explains how Automads.ai (“Automads,” “we,” “us,” or “our”), as the data controller for the services we offer, collects, uses, discloses, and otherwise processes personal information.
“You” means the individual using our services. “Services” means our website at automads.ai, the Automads web application, our APIs, and related support and communications channels.
By using the Services, you acknowledge this Policy. Our Terms of Service govern your use of the Services and apply together with this Policy.
2. Scope and third parties
This Policy covers automads.ai, the Automads web application, APIs, and related communications from us.
Meta (Facebook). When you connect a Meta Ads account, Automads processes advertising-related data on your behalf to provide the features you request. Meta’s own terms and policies also apply; this Policy does not replace them.
Company and workspace scope. Access to connected data is scoped to the authenticated user and the company or workspace that user is authorized to access. MCP tools only process data from accounts connected for that company or workspace.
Payments. Card and bank details are collected and processed by our payment provider. In our own systems we typically retain identifiers and subscription metadata (such as plan, status, and billing period references), not your full card number.
Third-party AI clients. If you use Automads through an MCP or similar connector in an application such as ChatGPT, Claude, or Cursor, that application’s provider processes data under its policies. Automads receives individual API or tool requests with the parameters needed to perform that action—we do not receive your full conversation with the third-party app by design of that connector. References to third-party brands do not imply that those companies endorse Automads.
3. Information we collect
We collect the following categories of information, described in everyday terms:
- Account and workspace. Email address, login credentials (passwords stored in a non-reversible form), profile details such as name, display name, language, and notification preferences, how you signed up (for example email or Google), company or workspace name, onboarding or survey responses, branding you upload (such as a logo URL), internal account identifiers, and timestamps.
- Subscription and billing. Plan status, billing periods, trials or access codes, and references to your customer and subscription record in the payment system. If checkout collects tax or business-registration identifiers required for billing or compliance, that information may be collected during checkout and processed through the payment provider.
- Meta Ads integration. Secured tokens and connection metadata, granted permissions, ad account structure and campaigns, ad sets, ads, creative assets and previews, performance metrics, transcriptions or text extracted from creatives, tags (including AI-suggested tags), and sync status and error information.
- MCP connector. Credentials we issue so AI clients can connect, OAuth tokens for those clients, and technical logs of API use (such as type of operation, tool category, success or failure, timing, and error summaries) for security, rate limits, reliability, and support.
- MCP audit logs. We store MCP request audit records in McpRequestLog, including request metadata such as operation type, tool category, status, timing, and error summaries for security monitoring, abuse prevention, troubleshooting, and compliance.
- Tool and API parameters. Per request, identifiers and filters needed for reporting or listing (for example ad account, optional campaign, ad set, or ad, and date ranges)—not a standing copy of your full chat in another application.
- Product analytics. A product analytics service may receive identifiers (for example email as a user key), workspace or company identifiers, and events about feature usage (such as authentication, integrations, MCP-related steps, subscription lifecycle, in-app navigation, and creative analytics usage). Some features—for example assistant-style chat in the web app—may send portions of text you type to analytics for measurement and product improvement.
- Cookies and similar technologies. Session and authentication cookies (including to complete MCP OAuth in the browser), analytics cookies or storage as configured for our analytics tools, and any cookies used on the marketing site, consistent with our cookie notice where we provide one.
- Server and operations. Standard server logs such as IP address, browser or device type, requested paths, and timestamps. Internal error alerts to our team may include limited account or request context to diagnose issues.
- Support. Information you send to support@automads.ai and transactional emails we send to you.
- Abuse prevention. Signals such as email domain or similar attributes used to enforce access rules and prevent abuse.
4. How we use information
We use personal information to:
- Operate, provide, maintain, and improve the Services;
- Authenticate users, secure the platform, enforce limits, and prevent abuse;
- Connect and synchronize Meta data and deliver reporting, creative, and MCP-related features;
- Bill and collect payments and meet tax or compliance obligations where applicable;
- Respond to support requests and send service-related messages; where we send optional promotional communications, we provide a way to opt out;
- Conduct analytics and product improvement as described in Section 3;
- Comply with law, enforce our terms, and protect rights, safety, and integrity.
5. How we share information
We may share personal information with:
- Service providers that assist in hosting, email delivery, analytics, payments, and other functions, subject to appropriate safeguards;
- Meta, as needed to provide connected advertising features you enable;
- Meta Graph API flow. For connected advertising features, we send request parameters to the Meta Graph API and receive account structure, creative assets, and performance metrics required to deliver the specific feature you request;
- Authorities or others when required by law, legal process, or to protect rights, safety, and security;
- Successors in connection with a merger, acquisition, financing, reorganization, or sale of assets, with notice where required by law.
We share personal information only as described in this Policy and with recipients who are bound to use it consistently with this Policy or as the law allows.
6. International transfers
Your information may be processed in countries other than where you live. Where required, we use appropriate safeguards—such as standard contractual clauses approved by relevant regulators—for transfers of personal data. Details can be provided on request.
7. Retention
We retain personal information for as long as your account is active and as needed to provide the Services. After you close your account or request deletion, we delete or anonymize personal information within a reasonable period, unless a longer retention period is required or permitted by law (for example tax, accounting, or dispute resolution).
When you disconnect Meta, we stop new synchronization; we may retain certain Meta-related data for a limited period for backup, security, and legal compliance before deletion, consistent with our technical and legal obligations.
Operational and API logs are retained for a period appropriate for security, troubleshooting, and legal requirements. Analytics data is retained according to our analytics provider’s settings and our configuration.
McpRequestLog retention. MCP audit logs stored in McpRequestLog are retained for up to 12 months, unless a longer retention period is required for legal obligations, fraud investigations, or active disputes.
8. Security
We implement reasonable technical and organizational measures designed to protect personal information, including encryption in transit (HTTPS), access controls, and reliance on reputable vendors. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
OAuth token protection. OAuth tokens are stored using encryption at rest, limited by role-based access controls, and handled under credential lifecycle controls (such as expiration, revocation, and rotation where supported) to reduce unauthorized access risk.
9. Your rights and choices
Depending on your location, you may have rights to access, correct, delete, or export personal information, or to object to or restrict certain processing. To exercise these rights, contact us at support@automads.ai. Where the product offers in-app settings for account or integration management, you may also use those controls.
You may disconnect your Meta Ads integration in the product; doing so stops further sync as described in Section 7. Where the product allows, you may regenerate or rotate MCP credentials.
If we send promotional email, you can opt out using the link in those messages or by contacting us. For analytics, choices may depend on your browser, device, and region; contact us if you need help understanding available options.
Additional rights under laws such as the GDPR or U.S. state privacy laws may apply based on your jurisdiction. We will respond to valid requests in line with applicable law.
10. Children
The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, please contact us at support@automads.ai.
11. AI-assisted features
Some features use automation or machine learning—for example tagging, transcriptions, or assistants. These features support your use of the Services and are not intended to produce solely automated decisions with legal or similarly significant effects concerning you without human involvement where such involvement is required by law.
12. Changes to this Policy
We may update this Policy from time to time. We will post the updated version on this page and change the “Last updated” date above. If we make material changes, we may provide additional notice (for example by email or an in-product message) where appropriate. Your continued use of the Services after the effective date of an update constitutes your acceptance of the revised Policy, except where applicable law requires a different approach.
13. Contact
Questions about this Privacy Policy: support@automads.ai
