Privacy Policy
What we collect, what we never store, where it runs, who else touches it, and how to take the access back. Everything here describes what the software actually does — you can check most of it yourself.
Who we are
AdCopilot is operated by Atromx Intelligence Private Limited (CIN U62099AP2026PTC126398), India, trading as Atromx Intelligence, registered office R.S. No. 21-10, D.No. 36-3-48, near Sampath Vinayaka Temple, Tanuku, West Godavari, Andhra Pradesh 534211, India. AdCopilot is a hosted Google Ads MCP connector: it lets an AI assistant you already use read, and when you ask it change, the Google Ads accounts you grant it. For data-protection purposes we are the controller of the account data described below.
For anything about this policy, your data, or a request to delete it, write to [email protected]. For company or commercial matters, [email protected].
What we collect
Only what the service cannot run without.
| What | Why | Kept for |
|---|---|---|
| Your name and email | To identify your connector and contact you about it. The email is the one Google confirms when you sign in, not just the one you typed, so a connector can be tied to the account that actually authorised it — that is what lets us refuse a reconnection from a different Google account. We ask Google for your email address and nothing else about your identity. | Until you close the account. |
| A Google refresh token | Issued by Google when you sign in. It is what lets the connector call the Google Ads API as you. Encrypted at rest. | Until you withdraw access or close the account. |
| Your connection record | Which AI-client connection is yours, tied to your Google sign-in. The connector URL itself is public and the same for everyone — not a secret. | Until you switch it off or withdraw access. |
| An audit record per call | Which tool ran, against which account ID, whether it succeeded, and when. This is how “what did it do on Tuesday” is answerable, and how refusals are proven. | For the life of the account. |
| Optional: a developer token or manager account ID | Only if you choose to supply your own instead of using ours. | Until you remove it. |
| Anything you type into the pilot form | To answer your enquiry. | In our email, until it is no longer needed. |
What we never collect or keep
- Your Google password. You authenticate with Google directly. We never see it and could not receive it.
- Your advertising data. Campaigns, search terms, spend and conversions are read live from Google when you ask, passed to your AI client, and not stored by us. The audit record notes which account was touched, never the rows that came back.
- Training data. Nothing you do here trains any model. We do not have a model to train.
- Cookies and analytics. This website sets no cookies and runs no analytics, tag manager or tracking script of any kind. You can verify it: nothing on adcopilot.cloud returns a
Set-Cookieheader, and the page source contains no third-party script.
Google user data, and the Limited Use rule
AdCopilot’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice that means what the rest of this page already says, stated in Google’s terms: we use your Google Ads data only to provide the features you ask for, we do not use it for advertising, we do not sell or rent it to anyone, we do not transfer it except to the sub-processors named below, and no human at Atromx reads it except where you ask us to help with a specific problem or the law requires it.
Where it runs
The connector, its database and your encrypted credential run on a virtual server operated by Hostinger International Limited in Kuala Lumpur, Malaysia. If you are in the UK or the EEA, that is a transfer outside your region, and there is no adequacy decision covering Malaysia — we would rather state that plainly than leave you to discover it. Ask us if you need contractual terms covering it.
Who else touches it
Two, and only because of choices we made. Google is not on this list: you grant access to your own Google Ads account, and the data moves under your own credential, so Google is your provider rather than our sub-processor.
| Who | What they do | Where |
|---|---|---|
| Hostinger International Limited | Virtual server hosting. The connector, the database and the encrypted credentials sit on a machine they operate. | Kuala Lumpur, Malaysia |
| FormSubmit (formsubmit.co) | Delivers the pilot enquiry form on this website to our inbox. It sees whatever you type into that form; it is not involved in the connector or in any advertising data. | United States |
How it is protected
- Your Google refresh token is encrypted at rest, with the key in a root-owned file outside the database, so a copy of the database alone does not yield a usable credential.
- The connector URL is public and the same for everyone, so its request paths carry no secret. What matters — your Google refresh token — is encrypted and never written to logs or the audit trail.
- Everything travels over HTTPS, and the connector refuses expired, deactivated or out-of-scope requests before any call reaches Google.
- We hold no SOC 2 or ISO 27001 certification. We would rather say so than imply otherwise.
Your rights, and the fastest route to each
- Withdraw access immediately— your Google Account's third-party access page. Removing AdCopilot there revokes the credential at source, without our involvement and without waiting for us.
- Have your data deleted — email [email protected]. We remove your account, your encrypted credential and your audit records.
- Ask what we hold — same address. The honest answer is: the table above and nothing else.
- Object or complain — write to us first, and you retain the right to complain to your local data-protection authority.
Where the UK GDPR or EU GDPR applies, we process your account details and credential to perform our contract with you, and keep the audit record on the legitimate interest of being able to show what a connector did.
Children
AdCopilot is a business tool and is not directed at anyone under 18. We do not knowingly collect their data.
Changes
If this policy changes materially we will update the date at the top and, where the change affects how your data is handled, tell connected accounts by email.