Privacy Policy
What we collect, what we never store, where it runs, who else touches it, and how to take the access back. Everything here describes what the software actually does — you can check most of it yourself.
Who we are
AdCopilot is operated by Atromx Intelligence Private Limited (CIN U62099AP2026PTC126398), India, trading as Atromx Intelligence, registered office R.S. No. 21-10, D.No. 36-3-48, near Sampath Vinayaka Temple, Tanuku, West Godavari, Andhra Pradesh 534211, India. AdCopilot is a hosted Google Ads MCP connector: it lets an AI assistant you already use read, and when you ask it change, the Google Ads accounts you grant it. For data-protection purposes we are the controller of the account data described below.
For anything about this policy, your data, or a request to delete it, write to support@adcopilot.cloud. For company or commercial matters, support@atromx.com.
What we collect
Only what the service cannot run without.
| What | Why | Kept for |
|---|---|---|
| Your name and email | To identify your connector and contact you about it. | Until you close the account. |
| A Google refresh token | Issued by Google when you sign in. It is what lets the connector call the Google Ads API as you. Encrypted at rest. | Until you withdraw access or close the account. |
| Your connector address | The private URL you paste into your AI client. It is a credential. | Until rotated or switched off. |
| An audit record per call | Which tool ran, against which account ID, whether it succeeded, and when. This is how “what did it do on Tuesday” is answerable, and how refusals are proven. | For the life of the account. |
| Optional: a developer token or manager account ID | Only if you choose to supply your own instead of using ours. | Until you remove it. |
| Anything you type into the pilot form | To answer your enquiry. | In our email, until it is no longer needed. |
What we never collect or keep
- Your Google password. You authenticate with Google directly. We never see it and could not receive it.
- Your advertising data. Campaigns, search terms, spend and conversions are read live from Google when you ask, passed to your AI client, and not stored by us. The audit record notes which account was touched, never the rows that came back.
- Training data. Nothing you do here trains any model. We do not have a model to train.
- Cookies and analytics. This website sets no cookies and runs no analytics, tag manager or tracking script of any kind. You can verify it: nothing on adcopilot.cloud returns a
Set-Cookieheader, and the page source contains no third-party script.
Where it runs
The connector, its database and your encrypted credential run on a virtual server operated by Hostinger International Limited in Kuala Lumpur, Malaysia. If you are in the UK or the EEA, that is a transfer outside your region, and there is no adequacy decision covering Malaysia — we would rather state that plainly than leave you to discover it. Ask us if you need contractual terms covering it.
Who else touches it
Two, and only because of choices we made. Google is not on this list: you grant access to your own Google Ads account, and the data moves under your own credential, so Google is your provider rather than our sub-processor.
| Who | What they do | Where |
|---|---|---|
| Hostinger International Limited | Virtual server hosting. The connector, the database and the encrypted credentials sit on a machine they operate. | Kuala Lumpur, Malaysia |
| FormSubmit (formsubmit.co) | Delivers the pilot enquiry form on this website to our inbox. It sees whatever you type into that form; it is not involved in the connector or in any advertising data. | United States |
How it is protected
- Your Google refresh token is encrypted at rest, with the key in a root-owned file outside the database, so a copy of the database alone does not yield a usable credential.
- Connector addresses are never written to request logs. Web-server access logging is switched off for the connector, because the address is itself the credential and a log file is not a place for one.
- Everything travels over HTTPS, and the connector refuses expired, deactivated or out-of-scope requests before any call reaches Google.
- We hold no SOC 2 or ISO 27001 certification. We would rather say so than imply otherwise.
Your rights, and the fastest route to each
- Withdraw access immediately— your Google Account's third-party access page. Removing AdCopilot there revokes the credential at source, without our involvement and without waiting for us.
- Have your data deleted — email support@adcopilot.cloud. We remove your account, your encrypted credential and your audit records.
- Ask what we hold — same address. The honest answer is: the table above and nothing else.
- Object or complain — write to us first, and you retain the right to complain to your local data-protection authority.
Where the UK GDPR or EU GDPR applies, we process your account details and credential to perform our contract with you, and keep the audit record on the legitimate interest of being able to show what a connector did.
Children
AdCopilot is a business tool and is not directed at anyone under 18. We do not knowingly collect their data.
Changes
If this policy changes materially we will update the date at the top and, where the change affects how your data is handled, tell connected accounts by email.