個人情報Legal
Privacy Policy
What Adako collects when you use it, why, where it goes, and how to delete it.Last updated 11 September 2026
In short
- Adako reads your ad accounts to answer the requests you and your AI assistant make. It changes them only through proposals you approve.
- Platform tokens and advertiser keys are encrypted, stay on our servers and are never sent to your AI assistant.
- We do not sell your data, use it to advertise, or use it to train AI models.
- No analytics or advertising cookies. Only the cookies needed to sign you in.
- To delete your data, follow Deleting your data or write to privacy@adako.ai.
This summary helps you find your way. The numbered sections below are what apply.
1. Who we are
Adako (adako.ai) is operated by [Legal entity name], [Registered address], [Country] (“Adako”, “we”, “us”). We are the controller of the personal data described in this policy.
This policy covers the adako.ai website, the Adako web app, the MCP endpoint at adako.ai/mcp and API access with Adako keys (together, the “Service”). It does not cover the ad platforms or AI assistants you connect. Their own privacy policies apply to them.
If you use Adako for an organisation, for example an agency managing client accounts, that organisation decides which ad accounts are connected and why. Where the law treats us as its processor for that data, we process it only on its instructions and under our Terms of Service. Write to privacy@adako.ai for a data processing agreement.
2. What we collect
We collect what the Service needs to work. It comes from you, from the platforms you connect, and from the requests your AI assistant makes.
Your account
- Name, email address and password. The password is stored only as a salted one-way hash.
- If you sign in with Google: your Google account ID, name, email address, profile picture and the sign-in tokens Google issues.
- Settings: your write policy (direct or inbox), locale and time zone.
Sessions and security
- Session records with the IP address and browser user agent of each sign-in, and when the session expires.
- Short-lived cookies used while you sign in and connect platforms (see Cookies).
Connected ad platforms
- For each platform login: the platform’s user ID, a display name (your Google account email, your Meta profile name or the ChatGPT Ads account name), the permissions granted, the connection status and the last error the platform returned.
- The access and refresh tokens Google and Meta issue, or the ChatGPT Ads advertiser key you paste. These are encrypted (see Security).
- For each ad account the login can reach: account ID, name, currency, time zone, manager relationship, and which account you made active or primary.
- A record of each time a stored token is decrypted: the purpose, the request and the time. It never contains the token.
Ad account data read on request
When a tool runs, Adako fetches what it needs from the platform and returns it to the AI assistant that asked. That can be campaigns, ad groups and ad sets, ads, keywords, search terms, audience names and sizes, budgets, bids, conversion actions and performance metrics. We do not keep a copy of your ad accounts. Some responses are cached for up to 10 minutes to avoid repeat calls, and parts of the data are kept in the tool-call and proposal records described below.
Adako’s tools do not read or upload the members of customer lists. Audience tools see only names, types, IDs and approximate sizes.
Tool calls
Every tool call is recorded: the tool name, time, duration, status and error code, the ad account, the AI client or API key that made it, a hash of the arguments, and the arguments themselves with tokens, secrets and email addresses removed. Arguments can include campaign names, budgets, keywords, URLs and ad copy.
Proposals
Every change is stored as a proposal: the full request, the preview (what changes, before and after), the decision (approved or rejected, when, where, and any reason you gave), the result the platform returned, and a read-back of the object afterwards.
AI clients and API keys
- AI clients you authorise: the client’s registration details (its name, redirect addresses and the metadata it publishes), the scopes you approve on the consent screen, and the access and refresh tokens issued to it.
- API keys: the name you give, the first characters, a hash of the key, its permissions, expiry and revocation time. The full key is shown to you once and never stored.
Billing and usage
- Your plan, subscription status and billing period, the Stripe customer and subscription IDs, and task counts for each period.
- Payments run through Stripe. Card details go to Stripe directly. Adako never sees or stores full card numbers.
Images you supply
When you ask for an ad built from an image URL, Adako downloads the image, checks it and uploads it to the ad platform. We do not keep the image after the request.
Logs and support
- Our hosting provider records requests to the Service: IP address, time, URL and user agent. Our application logs record events with tokens and secrets redacted.
- Messages you send us, and our replies.
What we do not collect
No analytics or advertising trackers, no third-party cookies, no fingerprinting. The fonts on this site are served from adako.ai, so loading a page sends nothing to a third party.
3. How we use it
We use personal data only for the purposes below. The legal basis applies where the GDPR or UK GDPR applies to you.
| Purpose | Legal basis |
|---|---|
| Create your account, sign you in and keep sessions secure | Contract |
| Connect ad accounts and run the tools you and your AI assistant call | Contract |
| Preview, execute exactly once and read back the changes you approve | Contract |
| Count tasks, enforce plan limits, bill you and keep tax records | Contract; legal obligation |
| Keep an audit trail, rate-limit requests, detect abuse and investigate incidents | Legitimate interests: keeping the Service and your ad accounts secure |
| Answer support requests | Contract; legitimate interests |
| Tell you about security issues, billing problems and changes to our terms | Contract; legitimate interests |
| Improve the Service with aggregated statistics, such as which tools fail most often | Legitimate interests: a reliable product |
| Comply with the law and respond to lawful requests | Legal obligation |
We do not:
- sell or rent personal data, or share it for cross-context behavioural advertising;
- use your data or your ad account data to advertise to you or anyone else;
- use your data or your ad account data to train or improve AI or machine-learning models;
- make decisions about you by automated means that have legal or similarly significant effects;
- let people at Adako read your ad account data, except with your permission (for example in a support request), to investigate security incidents or abuse, or where the law requires.
4. Your AI assistant
You use Adako through an AI assistant you choose: Claude, ChatGPT, Cursor, Claude Code or another MCP client. When the assistant calls a tool, the result goes back to it. That includes campaign names, metrics, search terms, ad copy and anything else the tool returns. From that point the assistant’s provider processes the data under its own terms and privacy policy, including whether conversations are stored or used for training.
If you approve the identity scopes on the consent screen, the assistant also receives your Adako user ID, name and email address.
You decide which assistants to connect and what they may do. To cut one off, remove Adako from the assistant’s connector settings, revoke its API key on the Keys page, or ask us at privacy@adako.ai to revoke its authorisation. Platform tokens are never sent to an assistant.
5. Data from ad platforms
Adako connects to an ad platform only when you connect it, and uses what it receives only to provide the features you use in Adako.
Google Ads
When you connect Google Ads, Adako asks for the Google Ads API scope (https://www.googleapis.com/auth/adwords) and your basic identity (openid, email). With them Adako:
- reads the Google Ads accounts your login can reach, and their campaigns, ad groups, ads, keywords, search terms, audiences, budgets, bids, conversion actions and performance metrics;
- creates and changes those objects only when you approve a proposal. New campaigns are always created paused;
- reads your Google account ID and email address to label the connection.
Google user data is stored and shared only as this policy describes: tokens encrypted on our servers, account details in our database, and tool results returned to the AI assistant you connected. We transfer it to others only as needed to provide the Service, for security, to comply with the law, or as part of a merger or acquisition with your prior consent. We do not sell it, use it for advertising, use it to determine credit-worthiness or for lending, or use it to train AI models. People at Adako read it only with your permission, for security, to comply with the law, or in aggregated form for internal operations.
Adako’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can remove Adako’s access at any time on the Connections page, or in your Google Account at myaccount.google.com/connections.
Meta
When you connect Meta, Adako uses Facebook Login for Business with the ads_read, ads_management and business_management permissions. With them Adako:
- reads your Meta user ID and name, the businesses and ad accounts you grant, and their campaigns, ad sets, ads, creatives, audience names and sizes, and insights;
- creates and changes those objects, and uploads ad images, only when you approve a proposal. New campaigns are always created paused.
We do not sell, license or purchase Meta Platform Data. We delete it on request as described in Deleting your data. You can remove Adako at any time on the Connections page, or in Facebook under Settings and privacy → Settings → Business integrations.
ChatGPT Ads
ChatGPT Ads connects with an advertiser API key that you create and paste into Adako. We store it encrypted and use it to read the account, its campaigns, ads and performance, and to make the changes you approve. Removing the key from Adako does not revoke it at the platform. Delete or rotate it in ChatGPT Ads Manager to retire it everywhere.
Adako is independent. It is not affiliated with, endorsed or sponsored by Google, Meta or OpenAI.
6. Who we share it with
We share personal data only in the cases below, or otherwise with your permission.
Service providers
These companies process data on our behalf, under contracts that limit them to providing their service to us.
| Provider | What they do | Where |
|---|---|---|
| Vercel Inc. | Hosting, serverless functions and request logs | United States and a global edge network |
| Supabase Inc. | Managed Postgres database where Adako’s records are stored | European Union (Ireland) |
| Stripe | Subscriptions, payments, invoices and tax | United States, European Union and other Stripe locations |
We update this list before a new provider starts processing personal data.
Platforms and assistants you connect
We send Google, Meta and OpenAI the requests you make through Adako, including the changes you approve and the images you supply, and we return results to the AI assistants you connect. They handle that data under their own terms.
Legal and safety
We disclose data when the law requires it, or when it is necessary to protect the rights, property or safety of our users, the public or Adako, for example to stop fraud or abuse. Where the law allows, we tell you first.
Business transfers
If Adako is part of a merger, acquisition or sale of assets, data may transfer to the new owner under this policy. We will tell you before that happens. Google user data transfers only with your prior consent.
7. Cookies
Adako sets only the cookies it needs to work. There are no analytics, advertising or third-party cookies, so there is nothing to opt out of.
| Cookie | Purpose | Lifetime |
|---|---|---|
| Session | Keeps you signed in | Until you sign out or the session expires |
| Sign-in and authorisation | Protects sign-in and AI client authorisation against forged requests | Cleared when the step completes or expires |
| Platform connection | Ties a Google or Meta connection to the browser that started it | 10 minutes |
Stripe hosts checkout and the billing portal and sets its own cookies there, for example for fraud prevention, under Stripe’s privacy policy.
8. Security
- Traffic to and from Adako is encrypted with TLS.
- Platform tokens and advertiser keys are encrypted with AES-256-GCM under a separate data key for each connection, which is itself encrypted with a master key. A token is decrypted only for the call that needs it, each decryption is recorded, and tokens are never sent to AI clients or written to logs.
- Passwords and API keys are stored as hashes.
- Access to production systems and data is limited to the people and services that need it.
- Every change is a proposal you approve, and new objects are created paused.
No system is perfectly secure. If a breach affects your personal data, we will tell you and the relevant authorities as the law requires. Report vulnerabilities to security@adako.ai.
9. How long we keep it
| Data | How long |
|---|---|
| Account, settings, connections, ad account records, proposals, tool-call records, token-decryption records, API keys, AI client authorisations and support messages | While your account is open |
| Platform tokens and advertiser keys | Until you disconnect the platform, when they are erased at once |
| Connection and ad account records of a disconnected platform | Kept, marked revoked, until you delete your account or ask us to remove them |
| Cached platform responses and rate-limit counters | From a few minutes up to a day |
| Hosting request logs | A short period set by our hosting provider, no more than 30 days |
| Billing records | As long as tax and accounting law requires |
When you delete your account, we delete your personal data within 30 days. The exceptions are billing records we must keep, and data we need for an open security investigation or legal claim. Deleted data can remain in encrypted database backups until the normal backup cycle overwrites it.
10. Your rights
Wherever you live, you can ask us to:
- give you a copy of your personal data in a portable format;
- correct data that is wrong;
- delete your data (see Deleting your data);
- stop processing it for a purpose you object to.
You can also disconnect a platform on the Connections page, revoke API keys on the Keys page and change your write policy in Settings at any time.
EEA, UK and Switzerland
Under the GDPR and UK GDPR you also have the right to restrict processing, to object to processing based on legitimate interests, to withdraw consent where we rely on it, and to lodge a complaint with your local data protection authority. We would welcome the chance to resolve your concern first.
California and other US states
California residents have the right to know what personal information we collect, use and disclose; to delete and correct it; to opt out of its sale or sharing; to limit the use of sensitive personal information; and not to be discriminated against for exercising these rights. Residents of other US states with privacy laws have similar rights.
In the past 12 months we collected these categories of personal information, for the purposes in How we use it, and disclosed them for business purposes to the service providers in Who we share it with: identifiers (name, email address, IP address, account IDs); commercial information (plan and payment history); internet or other electronic network activity (tool calls, session and request logs); and sensitive personal information limited to account login credentials, used only to sign you in. We do not sell or share personal information, and have not done so in the past 12 months.
How to make a request
Email privacy@adako.ai from the address on your Adako account. We may ask you to confirm your identity. We answer within one month, or 45 days for California requests, and tell you if we need longer. An authorised agent can make a request for you with your signed permission.
11. Deleting your data
You can remove Adako’s access to a platform, or delete everything Adako holds about you.
Disconnect a platform
- Sign in and open Connections.
- Choose Disconnect next to Google Ads, Meta or ChatGPT Ads.
Adako erases the stored tokens at once, deactivates the ad accounts and asks Google or Meta to revoke its access. A ChatGPT Ads key cannot be revoked from outside the platform: delete or rotate it in ChatGPT Ads Manager.
You can also remove Adako from the platform side: in your Google Account at myaccount.google.com/connections, or in Facebook under Settings and privacy → Settings → Business integrations.
Delete your account
- Email privacy@adako.ai from the address on your Adako account, with the subject “Delete my account”.
- We confirm the request and cancel any paid subscription.
- Within 30 days we delete your account, connections, tokens, ad account records, proposals, tool-call records, API keys and AI client authorisations, and email you when it is done.
Self-service deletion in Settings is coming soon. Deleting your Adako data does not change your ad accounts: campaigns and ads Adako created stay exactly as they are, paused or live.
To delete only the data Adako received from Meta, say so in your email. We delete it as soon as reasonably possible and confirm when it is done.
12. International transfers
[Legal entity name] is based in [Country]. Adako’s database is hosted in the European Union (Ireland), and our hosting and payment providers also process data in the United States and other countries. When personal data leaves the EEA, the UK or Switzerland, we rely on an adequacy decision, such as the EU–US Data Privacy Framework for certified recipients, or on the European Commission’s Standard Contractual Clauses and the UK Addendum.
13. Children
Adako is a business tool for people aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has given us personal data, write to privacy@adako.ai and we will delete it.
14. Changes to this policy
We update this policy when our practices change. The date at the top shows the current version. If a change materially affects how we use your data, we email you before it takes effect.
15. Contact
Privacy questions and requests: privacy@adako.ai. Everything else: support@adako.ai. Security reports: security@adako.ai.
Post: [Legal entity name], [Registered address], [Country].