Skip to main content

AskMyAds legal

Privacy policy

This policy explains the data AskMyAds needs to provide its Google Ads service and its Meta features (pending Meta approval), including its handling of Google API data and Meta Platform data.

Effective 21 August 2026

1. Who we are and what this covers

AskMyAds is provided by OrcDev (Uros Miric), trading as AskMyAds. In this policy, “AskMyAds,” “we,” and “us” refer to that service provider. This policy covers the AskMyAds website, account and workspace, billing, support, Google Ads, and Meta features.

AskMyAds is in its founding pilot. Features described below may be introduced in stages. Where a feature is not yet available, this policy states the data-handling conditions that must be in place before we enable it.

2. Data we collect

Account, workspace, and security data

You may sign in with a magic link, Google, or an email and password. We collect the email address used to sign in, account and workspace identifiers, workspace name and membership, and authentication records. When you choose Google sign-in, we request OpenID, email, and profile information and may receive a Google account identifier, email and verification status, name, and profile image. Short-lived Google identity access and ID tokens are used only during the sign-in callback and are not persisted; we do not store a Google identity refresh token or granted identity scopes. Google sign-in authenticates your AskMyAds account and does not connect Google Ads. If you set a password, we store only a salted scrypt hash of it, never the password itself, and when you set or change it we check it against known breaches by sending a partial hash prefix to the Have I Been Pwned range API; the full password never leaves AskMyAds.

Security records may include session timestamps, IP address, browser or device user agent, verification status, and rate-limit events. We also keep messages and information you choose to send to support.

Business profile data

You may provide information about your business, including its name, offerings and prices, audience, service area, differentiators, exclusions, notes, and up to three website URLs. If you ask AskMyAds to start from a website, we fetch only the public HTTPS pages you enter and extract text to prepare and save a structured profile. We do not store the raw extracted page text. A successfully fetched profile is immediately available to the assistant, and you can review or edit its fields at any time.

Google connection and Google Ads data

If you choose to connect Google Ads, Google sends us an OAuth authorization grant rather than your Google password. We process consent and granted-scope metadata, connection status, and refresh or revocation events. Short-lived Google Ads access tokens are used only in the server request path and are not persisted. The only Google Ads OAuth credential we store is the refresh token, encrypted at rest. The Google Ads permission does not provide your Google profile or email address.

With your authorization, AskMyAds may access the Google Ads accounts you select and their customer IDs, names, currency and timezone; campaigns, ad groups, ads and assets; budgets, bidding, network and geographic settings; keywords, match types, negative keywords and search terms; conversion configuration; policy and disapproval status; and performance metrics segmented by time, device, and geography. Search terms or ad content may contain personal data entered by third parties, so you should connect only accounts you are authorized to manage.

We use those records to run a read-only Waste Scan, calculate deterministic waste figures from account metrics, explain findings, produce reports, meter the plan’s managed ad spend, and, only when management features are available and you explicitly approve a proposal, carry out and verify that approved change.

Meta connection and Meta ads data

Meta features are pending Meta's App Review and are not yet generally available. If you choose to connect Meta where access has been granted, Meta sends us an OAuth authorization grant rather than your Facebook password. We store one long-lived Meta access token, encrypted at rest the same way as Google credentials, together with consent and granted-scope metadata and connection status. Meta tokens cannot be silently renewed: when the token expires (about every 60 days), the connection is marked expired and nothing is read until you reconnect. The Meta permission does not provide your Facebook profile beyond what asset discovery requires.

With your authorization, AskMyAds may access the Meta ad accounts you select and their names, currency and timezone; campaigns, ad sets and ads with their targeting settings, budgets and delivery metrics segmented by placement; the Facebook Pages you manage and their linked Instagram professional accounts; the performance of your organic Instagram reels (plays, reach, saves, shares); and whether your Meta pixel or Conversions API event sources are active. We read the status of conversion measurement, never the underlying event payloads about your customers.

We use those records to run a read-only Waste Scan for Meta, rank your own reels against your account's own history, meter the plan's managed ad spend, and, only when you explicitly approve a proposal or approve a budget-capped Boost Policy, carry out and record the approved change. Every action taken under a policy you approved is individually logged and reversible, and a policy can be paused at any time.

Billing and service data

We keep your selected plan, price, currency, subscription status, billing period, Stripe customer and subscription identifiers, and checkout or invoice events needed to operate billing and resolve disputes. Stripe receives and processes payment-method details. We do not receive or store your full card number.

We may also keep product records generated for your workspace, including normalized raw scan snapshots; derived findings and the private evidence that supports them; waste totals; reports; recommendations; approvals; projected or verified savings; and audit records. Private evidence can include a limited subset of matching search terms, normalized keyword text, and Google Ads entity identifiers. It remains inside authenticated workspace views and exports and is excluded from public report links and AI narrative processing. When conversational or campaign-management features are enabled, product records can also include messages and the result of approved actions.

Website data

We process ordinary request and security logs and use strictly necessary cookies or similar storage for sign-in, session protection, preferences, and abuse prevention. We do not use Google user data for advertising cookies, retargeting, or interest-based advertising.

AskMyAds runs one optional third-party measurement service: Vercel Web Analytics. It stays off until you accept measurement in the consent banner, and it records nothing before you do. You can change or withdraw that choice at any time from the same banner, and withdrawing stops collection immediately.

When accepted, we record page views for our public pages only - the home page, the pricing, Waste Scan, how-it-works, agents and blog pages, and the contact, privacy, terms, data-processing, and data-deletion pages. Page views are never recorded inside your dashboard, on shared report links, or on the sign-in and verification pages, and query strings and URL fragments are removed before anything is sent. No custom events are sent to Vercel at all. Vercel Web Analytics sets no cookies and we do not use it to build a profile of you.

The same acceptance turns on our own first-party measurement, which never leaves AskMyAds. We then store, under an opaque identifier in a first-party cookie: which public page you landed on, the campaign parameters (utm_source, utm_medium, utm_campaign, utm_content) and the Google click identifier (gclid, wbraid or gbraid) in the link you followed, the hostname of the site that referred you, and which call to action you pressed. If you go on to create an account, that first visit is linked to your workspace and we record the milestones that follow as events: workspace created, Google Ads connected, account selected, scan started, succeeded or failed, report shared, checkout started, subscription started, and each change proposed, applied, failed or undone. Every event carries only its name, its time and a closed set of labels; none carries the content of your account or your ads. Google Ads data is never used for website analytics.

A legacy browser preference cannot turn any of this on - the consent banner is the only thing that can. Withdrawing in the banner deletes the first-party records held under your identifier at once, and the retention and deletion terms below bound everything else.

3. Google API data and Limited Use

Google sign-in and Google Ads connection are separate authorization flows with separate callbacks. Google sign-in requests only openid email profile and uses the callback /api/auth/callback/google to authenticate your AskMyAds account. It does not request Google Ads access.

If you separately connect Google Ads, AskMyAds requests only the Google Ads OAuth scope https://www.googleapis.com/auth/adwords, using the separate callback /api/google/callback. It is the single Google Ads API scope and can technically permit both reading and managing an authorized Ads account. A Waste Scan uses read operations only. AskMyAds does not use mutation paths for a scan, and it does not make a campaign change unless the relevant management feature is available and the workspace user has explicitly approved that proposal.

AskMyAds’ use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use Google user data only to provide or improve the prominent, user-facing AskMyAds features described in this policy.

  • We do not sell, resell, rent, or disclose Google user data to data brokers or information resellers.
  • We do not use or transfer it to serve ads, retarget people, build advertising profiles, conduct surveillance, or make credit or lending decisions.
  • We do not mix one customer’s Google Ads data into another customer’s workspace, reports, recommendations, or model context.
  • We do not use Google user data to train a general-purpose AI model, and we do not permit a processor to do so.
  • Humans may access specific Google user data only with your affirmative permission for support, when necessary to investigate security or abuse, when required by law, or in aggregated form for lawful internal operations.

We will update this policy and obtain any consent Google or applicable law requires before using Google user data for a new purpose.

4. How and why we use data

  • Provide sign-in, workspace isolation, billing, support, business profiles, scans, reports, and other features you request.
  • Authenticate Google API calls, maintain a connection you authorized, and detect a revoked or expired grant.
  • Calculate findings from real account metrics and maintain an auditable record of recommendations, approvals, and results.
  • Protect accounts, prevent abuse, troubleshoot failures, and keep the service reliable.
  • Administer subscriptions, refunds, tax and accounting records, and comply with legal obligations.
  • Improve user-facing AskMyAds features using feedback and aggregated or de-identified operational data.

Depending on the data and applicable law, we process it to perform our contract with you, on the basis of your OAuth consent, to comply with law, or for legitimate interests such as security, fraud prevention, and service reliability where those interests are not overridden by your rights.

5. How we protect your data: security, encryption, and token handling

We protect all data we hold, including sensitive Google user data obtained through Google APIs, with layered technical and organizational security measures. All data moves over encrypted connections (HTTPS/TLS) between your browser, AskMyAds, and Google, and between AskMyAds and its managed database. All stored data, including Google Ads account data such as campaign settings, metrics, and search terms, is held in a managed database that encrypts data at rest. OAuth credentials receive an additional layer: authenticated, per-record envelope encryption (AES-256-GCM) with encryption keys stored separately from the database and rotated on a documented schedule. Access to stored data is restricted by authentication, workspace-scoped authorization on every query, and least-privilege server-side paths; security procedures include audit records, dependency and secret-management practices, monitoring, and incident-response procedures proportionate to the data. Sensitive data is retained only as long as needed for the purposes in this policy and is then deleted; the specific retention periods, the automatic deletion schedules, and how to request deletion are in section 7 and on the data deletion page.

Google identity access and ID tokens are discarded after the sign-in callback and are not stored in the linked account record. AskMyAds does not request an offline Google identity refresh token. We will not enable the separate Google Ads connection unless its only stored OAuth credential - the Ads refresh token - is encrypted at rest using authenticated, per-record encryption with encryption keys kept separately from the database. It is decrypted only in the server-side Google Ads API-call path. OAuth credentials are never rendered to the browser, included in product analytics, sent to an AI model, or intentionally written to application logs.

Access is limited to authorized service paths and workspace-scoped queries. We use encrypted transport, access controls, audit records, dependency and secret-management practices, and incident-response procedures proportionate to the data. If Google reports that a grant is expired, revoked, or otherwise unusable, we stop using it, remove the encrypted refresh token from active storage, and require a new authorization before further access. We also send a service email to the AskMyAds account owner and retain limited pending, attempt, and delivery timestamps so a temporary email outage can be retried. The notification does not include Google Ads account data. No online service can promise absolute security.

6. When we share data

If you connect an external AI agent to AskMyAds over the Model Context Protocol, that agent receives, at your direction, the data its granted tools return: campaign settings, performance figures, Waste Scan findings, your saved business context, and proposal contents. Confirmation codes are never sent to the agent. You can revoke a connected agent at any time in Settings, and how that agent handles what it receives is governed by its own provider's terms.

We share only what is necessary with service providers acting for us, under confidentiality and data-protection terms. Categories may include cloud hosting, a managed database, transactional email and support, security and error monitoring, and, when analysis features are enabled, an AI inference provider limited to producing the requested user-facing result.

AI Gateway narrative processing

When a Waste Scan requests a Claude narrative, AskMyAds sends only a derived, aggregate finding packet through Vercel AI Gateway to the inference provider selected by the gateway for the configured Anthropic Claude model. The packet contains completeness, currency, the deterministic report total, and each finding’s known check identifier, affected-entity count, classification, severity, and discriminated monetary aggregates. Claude orders those checks and selects the overview and one rationale for each check verbatim from fixed, rule-bound AskMyAds-authored options. Claude cannot write, edit, combine, or paraphrase report prose. Output must cover every supplied check exactly once and match an approved option bound to that check. Deterministic application code remains the sole authority for dollar figures, classifications, and next steps. Claude cannot write campaign instructions or make campaign changes. The packet excludes Google OAuth credentials and access tokens, raw search terms, Google Ads customer, campaign, ad group, keyword, ad, and asset identifiers, and the scan’s private evidence records.

Vercel AI Gateway routes the packet to the selected inference provider and returns the model result to AskMyAds. This processing is subject to Vercel’s AI Product Terms and the applicable selected provider terms. Each request enables the Gateway controls for zero data retention and no prompt training, so the Gateway restricts routing to providers covered by both controls. If no eligible provider is available, AskMyAds uses the deterministic fallback instead of sending the packet through an ineligible route. AskMyAds does not submit the packet as model feedback or use it to train an AskMyAds model.

Those request controls govern inference-content routing and handling. Applicable Vercel and selected-provider terms still govern any permitted service, security, billing, abuse-prevention, or legal-compliance processing. See Vercel’s current AI Gateway provider-options documentation.

Business profile and assistant processing

When you choose “Fetch from website,” AskMyAds sends the text extracted from only the public HTTPS pages you entered through Vercel AI Gateway to the inference provider selected for the configured Claude model. Claude prepares structured business-profile fields; website text is treated as untrusted data, never instructions. If fetching or distillation fails, AskMyAds shows an error and you can retry or complete the profile manually. Raw extracted page text is not saved to your workspace.

After a successful website fetch or after you save manual edits, the profile fields and source URLs are sent through Vercel AI Gateway with each Ask conversation so the business context is always available to the assistant. Unsaved edits are not exposed to the assistant. The same zero-data-retention and no-prompt-training Gateway controls described for scan narrative processing apply to website distillation and assistant requests. AskMyAds does not submit business-profile data as model feedback or use it to train an AskMyAds model.

Stripe processes checkout, payments, invoicing, refunds, and payment fraud controls. Its processing is also governed by the Stripe privacy policy. We may disclose limited data to professional advisers, regulators, or authorities when reasonably necessary to establish or defend legal claims, protect users or the service, or comply with law.

Business customers can review AskMyAds’ public data processing agreement template. The execution copy identifies the parties and current subprocessor schedule before it is accepted. Contact us to execute it.

7. Retention, disconnection, and deletion

Your saved business profile, including its source URLs and saved fields, is retained while your workspace is active and needed to provide the feature. It is included in your workspace data export and deleted with your account. Raw website text fetched to prepare a profile is not stored.

Normalized raw Google Ads metric snapshot payloads are stored in AskMyAds’ private managed database for no more than 90 days, then deleted from active payload storage. Limited capture, size, integrity, and purge metadata may remain in its associated snapshot retention record. Derived findings, their private supporting evidence, reports, recommendations, approval and execution records, savings calculations, and audit records may be retained while your account is active and afterward only as long as needed to provide the service, secure the system, resolve disputes, or meet legal obligations.

Optional first-party measurement records are kept for at most 90 days unless linked to a workspace, and Google advertising click identifiers are removed after 90 days in every case. Campaign parameters, the referring hostname, the landing page and the lifecycle events attached to a workspace may be retained only as needed during that account’s lifecycle, are included in your data export, and remain available for verified deletion. These records are not built from Google Ads API user data.

A linked Google identity-provider record and the associated account profile are kept while your AskMyAds account remains active and needed. No Google identity OAuth token is retained. The separate encrypted Google Ads OAuth refresh token is kept only while the Ads connection is authorized, usable, and needed. Disconnecting stops AskMyAds’ future Ads API access, deletes that token from active storage, and clears the saved advertiser selection even if Google does not confirm remote revocation. If confirmation fails, the connection remains blocked until you remove AskMyAds manually in Google Account connections and acknowledge that removal. Detecting an expired, revoked, or otherwise unusable Ads grant also removes the stored refresh token. Revoking access in Google does not by itself delete your AskMyAds account or Google Ads data already received by AskMyAds; use our deletion process for that.

Account and billing records follow the same necessity principle, although transaction, tax, fraud-prevention, and legal records may be retained for a period required by law. Backup remnants are isolated from ordinary use and disappear through secure rotation. Details and request steps are on the data deletion page.

8. International processing

AskMyAds and its service providers may process data in countries other than yours. Privacy rules and government-access standards can differ across countries. Where applicable law requires a transfer safeguard, we use an approved legal mechanism and supplementary protections appropriate to the data and provider.

9. Your choices and rights

Depending on where you live, you may have rights to access, correct, export, or delete personal data; restrict or object to processing; withdraw consent; receive portable data; and complain to a data protection authority. Withdrawing Google Ads OAuth consent stops future Ads API access but does not affect processing already lawfully completed. Removing the existing Google sign-in grant may require you to authorize basic profile access again the next time you sign in with Google, but it does not delete your AskMyAds account, active sessions, or stored product data. A magic-link sign-in remains available for the account email.

You can change or withdraw your measurement choice at any time from the consent banner, and withdrawing takes effect immediately. To request deletion of identifiable first-party measurement records linked to your account, follow the verified deletion instructions or contact privacy support.

You can review or revoke Google access at any time from your Google Account connections. You may also disconnect inside your AskMyAds workspace. The European Data Protection Board provides an overview of GDPR data-subject rights.

To exercise a right, use the request instructions or contact privacy support. We may verify that you control the relevant account before disclosing or deleting data.

10. Business use and children

AskMyAds is a business advertising service and is not directed to children. You must be at least 18, or the age required to enter a binding contract where you live, and authorized to act for the connected business and Google Ads account. We do not knowingly collect personal data from children through the service.

11. Changes and contact

We may update this policy as the product, providers, or law changes. We will post the new effective date and give additional notice when a change materially affects your rights. Before using Google user data for a new purpose, we will provide the disclosure and obtain the consent required by Google policy or applicable law.

Questions, DPA requests, and privacy requests can be sent to support@askmyads.ai. The service provider is OrcDev (Uros Miric), trading as AskMyAds.