AdCopilotby Atromx

What Data Does the AI Actually See From Google Ads?

Three parties could see your ads data — connector, AI vendor, model — under different retention rules. A map of who sees what, and how to shrink exposure.

Updated 2026-08-10Atromx IntelligenceGoogle Ads · Search, PMax, Display, YouTube, Demand Gen
The short answer

Three parties see three different things. The connector sees what its tools return and retains almost none of it — AdCopilot stores one encrypted Google refresh token plus an audit log of calls, never your performance data. The AI vendor (OpenAI, Anthropic) sees whatever enters the conversation, kept under your plan's retention and training policy. The model sees only the conversation's context. Your Google password and payment details never enter the pipeline at all.

"Is my data safe" gets answered with reassurance too often. More useful is a map: when an AI reads your Google Ads account, exactly three parties could see something, they see different things, and different rules govern each. Once the map is clear, the controls become obvious.

The three-party map: connector, AI vendor, model

The pipeline runs: Google Ads → connector → your AI client → the model.

Party Sees Retains
Connector (AdCopilot) What each tool call returns One encrypted refresh token + audit metadata; no performance data
AI vendor (OpenAI, Anthropic) The whole conversation, tool results included Per your plan's retention and training policy
The model The conversation in its context window Nothing between conversations, unless the vendor trains on your tier

Each row deserves its own honest paragraph.

What flows through the connector — and what it retains

When you ask "which search terms wasted money last month", the connector calls Google's API with your OAuth grant, receives the rows, and hands them to your AI client. That data is in transit through the connector and is not written down there. AdCopilot retains two things only:

  • One credential: an encrypted Google refresh token — the thing that lets it act on your OAuth grant. Never your password; no party in this pipeline ever holds your password.
  • An audit trail of every call: which tool, which account, success or refusal, the reason, the timestamp. The record that access happened — not the advertising data itself.

That is the whole inventory. Campaign metrics, search terms and conversion data pass through live and are gone from the connector when the response completes. The security page states this retention posture as a commitment, alongside scoping and revocation.

What the AI vendor sees: conversations, under plan rules

The larger share of the privacy question lives one hop downstream, and it is the hop people forget. Everything the agent read into your conversation — the tables, the search terms, the client name you typed — sits in your chat history with OpenAI or Anthropic, governed by the plan you hold, not by the connector.

Both vendors publish the rules. OpenAI describes consumer-side usage in how your data is used and the business-side defaults in its enterprise privacy commitments. Anthropic's are in the consumer terms update and its training policy article. Policies move; the links above are the current word, and this page was checked against them in August 2026.

Training: what the majors say, by plan type

The pattern, as of this writing, is consistent across both vendors:

  • Consumer plans (ChatGPT Free/Plus, Claude Free/Pro/Max): whether conversations train models rides on a toggle in data or privacy settings — offered at sign-up, changeable after, and worth checking before the first connected session.
  • Work and API tiers (ChatGPT Business/Enterprise, Claude Team/ Enterprise, both APIs): excluded from training by default, with contractual retention terms.

The practical rule falls out directly: if your ads data is commercially sensitive or belongs to clients, run agent work on a work-tier plan, or set the consumer opt-out before connecting anything.

What never leaves Google at all

Some worries can be closed completely:

  • Your Google password. OAuth exists so that it never transfers — you authenticate with Google, and Google issues the connector a scoped, revocable token.
  • Payment details. AdCopilot exposes no billing tools, so cards and payment profiles are simply outside what any conversation can reach.
  • Anything outside the ads scope. The grant covers Google Ads — not Gmail, not Drive, not Analytics. Scope is enforced by Google, not promised by the vendor.
  • Accounts you exclude. A connector can be scoped to specific customer IDs, making off-limits accounts unreachable rather than merely unmentioned.

Reducing exposure: the four controls worth using

  1. Choose the plan deliberately. The AI vendor's tier is the biggest single variable in this whole map — set training and retention there.
  2. Scope the connector. Limit it to the accounts the work needs; agencies can scope per member, with each seat individually revocable.
  3. Keep identifiers out of prompts. The agent reads account data by itself — you rarely need to paste customer lists or personal data into the chat, and the habit of not doing so costs nothing.
  4. Revoke when idle. Access withdraws in one click from your Google account's security page, and a reconnect restores the same seat later. A connector that is off sees nothing.

Mapped this way, the question stops being "is it safe" and becomes three smaller, answerable ones — what does each party hold, under what rule, controlled by which switch. The connector's own answers, stated as commitments rather than defaults, are on the security and data page.

Frequently asked questions

Will my ads data be used to train ChatGPT or Claude?

Plan-dependent, and both vendors publish the rules. OpenAI may use consumer ChatGPT conversations for training unless you opt out in data controls; business, Enterprise and API traffic is excluded by default. Anthropic, since its August 2025 consumer-terms update, trains on Free, Pro and Max chats only when the model-improvement setting is on — you choose at sign-up and can change it later; Team, Enterprise and API are excluded. On work plans with default settings, the practical answer is no.

Does the connector store my performance data?

No. AdCopilot reads your account live through Google's API and passes results straight to your AI client — nothing about campaigns, costs or conversions is retained on the connector. What it stores: one encrypted Google refresh token, and an audit trail recording each call's tool, account, success or refusal, reason and timestamp. The metadata of access is kept; the advertising data is not.

Can I use this under an NDA or client confidentiality agreement?

Treat the AI vendor's plan as the deciding variable, because the conversation is where client data lives. A work-tier plan with training excluded and short retention typically fits confidentiality obligations the way any SaaS processor does — but that is your call and possibly your client's. Scoping the connector to only the permitted accounts keeps the boundary mechanical rather than behavioural.

The offer

Try it on your own account for a week

The full set of tools for the week, so you can see what it actually does — and it still cannot delete anything. No cost, no card, no contract: you connect your own Google account and can withdraw the access whenever you like.

  • Up to 5 accounts
  • One week
  • Full tools
  • No card
Keep reading