"Is my data safe" gets answered with reassurance too often. More useful is a map: when an AI reads your Google Ads account, exactly three parties could see something, they see different things, and different rules govern each. Once the map is clear, the controls become obvious.
The three-party map: connector, AI vendor, model
The pipeline runs: Google Ads → connector → your AI client → the model.
| Party | Sees | Retains |
|---|---|---|
| Connector (AdCopilot) | What each tool call returns | Your name and email, one encrypted refresh token, the connection record, a ledger entry per call, the workspace's business profile; audit reads cached for up to an hour, a saved audit's findings for 180 days |
| AI vendor (OpenAI, Anthropic) | The whole conversation, tool results included | Per your plan's retention and training policy |
| The model | The conversation in its context window | Nothing between conversations, unless the vendor trains on your tier |
Each row deserves its own honest paragraph.
What flows through the connector — and what it retains
When you ask "which search terms wasted money last month", the connector calls Google's API with your OAuth grant, receives the rows, and hands them to your AI client. What AdCopilot keeps is bounded, and the full inventory, with how long each record is kept, is on the privacy policy:
- Who you are: the name and email Google confirms when you sign in, so a connector is tied to the account that authorised it.
- One credential: an encrypted Google refresh token — the thing that lets it act on your OAuth grant. Never your password; no party in this pipeline ever holds your password.
- Your connection record: which AI-client connection is yours.
- A ledger entry per call — an audit trail: which tool, which account, success or refusal, the reason, the timestamp. The record that access happened — not the rows that came back. Kept for 180 days.
- Your workspace's business profile: the business details and budget you give it, the first campaign it built, a log of decisions and a note on the last session, so the next conversation starts where the last one stopped. Kept until the workspace owner deletes it.
- A short-lived cache: an audit's reads, held for up to an hour, and the account summary your assistant opens with, for 10 minutes, so a repeat does not ask Google twice.
- Saved audit results: when an audit's results are saved to your dashboard, each finding keeps its description, the changes it suggests and up to 10 example rows, such as search terms, keywords, ad group and campaign names, landing-page URLs, cost and conversions. Kept for 180 days, then deleted.
- The server's system log: each Google Ads request's account ID and the text of the query that ran, and the full content of any request Google rejected, such as the keywords or ad text it tried to set. Kept until the server's routine log rotation removes it.
The other rows your assistant reads pass through live and are not kept by the connector once the response completes. The security page states this retention posture as a commitment, alongside scoping and revocation.
What the AI vendor sees: conversations, under plan rules
The larger share of the privacy question lives one hop downstream, and it is the hop people forget. Everything the agent read into your conversation — the tables, the search terms, the client name you typed — sits in your chat history with OpenAI or Anthropic, governed by the plan you hold, not by the connector.
Both vendors publish the rules. OpenAI describes consumer-side usage in how your data is used and the business-side defaults in its enterprise privacy commitments. Anthropic's are in the consumer terms update and its training policy article. Policies move; the links above are the current word, and this page was checked against them in August 2026.
Training: what the majors say, by plan type
The pattern, as of this writing, is consistent across both vendors:
- Consumer plans (ChatGPT Free/Plus, Claude Free/Pro/Max): whether conversations train models rides on a toggle in data or privacy settings — offered at sign-up, changeable after, and worth checking before the first connected session.
- Work and API tiers (ChatGPT Business/Enterprise, Claude Team/ Enterprise, both APIs): excluded from training by default, with contractual retention terms.
The practical rule falls out directly: if your ads data is commercially sensitive or belongs to clients, run agent work on a work-tier plan, or set the consumer opt-out before connecting anything.
What never leaves Google at all
Some worries can be closed completely:
- Your Google password. OAuth exists so that it never transfers — you authenticate with Google, and Google issues the connector a scoped, revocable token.
- Payment details. AdCopilot exposes no billing tools, so cards and payment profiles are simply outside what any conversation can reach.
- Anything outside the scopes you granted. Each Google product is connected on its own grant — Google Ads, and Analytics, Search Console or Tag Manager only if you connect them — not Gmail, not Drive. Scope is enforced by Google, not promised by the vendor.
- Accounts you exclude. A connector can be scoped to specific customer IDs, making off-limits accounts unreachable rather than merely unmentioned.
Reducing exposure: the four controls worth using
- Choose the plan deliberately. The AI vendor's tier is the biggest single variable in this whole map — set training and retention there.
- Scope the connector. Limit it to the accounts the work needs; agencies can scope per member, with each seat individually revocable.
- Keep identifiers out of prompts. The agent reads account data by itself — you rarely need to paste customer lists or personal data into the chat, and the habit of not doing so costs nothing.
- Revoke when idle. Access withdraws in one click from your Google account's security page, and a reconnect restores the same seat later. A connector that is off sees nothing.
Mapped this way, the question stops being "is it safe" and becomes three smaller, answerable ones — what does each party hold, under what rule, controlled by which switch. The connector's own answers, stated as commitments rather than defaults, are on the security and data page.