AI Transparency
Self-assessment, last reviewed July 24, 2026. We re-assess this page with every feature release that could change it.
1. Our role in one sentence
Ad Superpowers is a deterministic tool server (MCP) for ad platforms. We are not a provider or deployer of an AI system under the EU AI Act. The AI Act obligations that apply to the assistant you use (Claude, ChatGPT, or another) rest with its provider and with you as its user.
That is not a loophole. It is how the law allocates responsibility: rules follow the party that builds or operates the AI system. We build the safe rails it runs on.
2. What is and is not AI in our product
Our product contains no AI model. Nothing in our backend or dashboard performs inference, and we never train models on your data. Every component behaves the same way every time:
| Component | What it is | AI? |
|---|---|---|
| MCP tools (40) | Deterministic API calls to the ad platforms, with fixed schemas and input validation | No |
| Skills (120+) | Static expert knowledge in text form, served exactly as written | No |
| Workflow templates | Static, pre-written analysis templates | No |
| Client profiles | An encrypted database for business context, scoped to your organization | No |
| Write confirmations | Rule-based confirmation steps before anything changes on an ad platform | No |
| Your AI assistant (Claude, ChatGPT, ...) | The AI system in the workflow. Provided by its vendor, connected and operated by you under your own agreement | Yes, yours |
We enforce this in our engineering process: an automated check in our test suite fails the build if any AI model integration is added to production code. Adding AI to the product can only happen as a deliberate decision that re-triggers the assessment behind this page.
3. Our risk classification under the EU AI Act
The EU AI Act sorts AI systems into four risk levels: unacceptable, high, limited (transparency), and minimal. Because our product is not an AI system, it does not fall into any of these categories. In the terms of the European Commission's framework, the product sits outside the pyramid entirely, comparable to any other business software.
Where the Act does touch us, we comply:
- AI literacy (Article 4): we use AI systems internally to build the product and maintain a documented AI literacy practice for that use.
- Transparency (Article 50): assessed and documented as not applicable to us. We operate no chatbot, generate no synthetic content, and perform no emotion recognition. We re-assess on every release.
- Value-chain cooperation (Article 25(4)): if your use of an AI system together with our tools ever qualifies as high risk, we have cooperation terms prepared to support the compliance of that system's provider.
Three product commitments keep this classification stable, recorded in our architecture decision records: no AI model in the product, no skills or workflows built for high-risk uses listed in Annex III of the Act (such as targeting job advertisements), and no co-branding of any AI assistant under our name.
4. Where your data goes
When you use Ad Superpowers, data flows like this:
- You give an instruction to your AI assistant, under your own agreement with its vendor.
- Your assistant calls our servers, hosted in the EU (Amsterdam, with data stores in Frankfurt and Belgium), which validate the request and your permissions.
- Our servers call the ad platforms you connected (Meta, Google, LinkedIn, TikTok) and return the result to your assistant.
One consequence deserves to be stated plainly: anything our tools return to your assistant, including ad metrics and the client profiles you store with us, passes through your AI vendor's infrastructure, which may process data outside the EU depending on the vendor and plan you chose. We recommend business or API plans with a data processing agreement and no training on your inputs. Our own processing is covered in our privacy policy and data privacy documentation.
5. What we do voluntarily
No AI Act obligation requires the following. We do it because agencies run real budgets through AI, and that deserves guardrails:
- Write operations require explicit confirmation. Your assistant cannot silently change campaigns or spend budget.
- Strict organization isolation: your assistant can only ever reach data belonging to your own organization.
- Encryption of OAuth tokens and stored client profiles at rest, TLS in transit.
- EU-hosted infrastructure for our own processing, with a published sub-processor list.
- We never use your data to train AI models, ours or anyone else's.
- Risk management practices aligned with the NIST AI Risk Management Framework, and the voluntary principles of the EU AI Pact.
6. What stays your responsibility
Because you choose and operate the AI assistant, some duties stay on your side of the line:
- Your agreement with your AI vendor, including its data processing terms and where it processes data.
- Reviewing AI output before acting on it, especially write operations. See our Terms of Service (section 7.3).
- Disclosure duties for AI-generated ad creative under Article 50(4) of the AI Act, such as realistic AI-generated imagery of people, and the AI-disclosure settings of the platforms you publish to.
- AI literacy of your own team when working with AI assistants (Article 4).
- Not using the Service for practices the AI Act prohibits, or for targeting job advertisements without a separate compliance agreement with us. See our Terms of Service (section 6).
7. Changes and contact
We keep a dated record of every change to this page. Questions about our AI Act position, or a due diligence questionnaire we can help with? Email contact@adsuperpowers.ai.
| Date | Change |
|---|---|
| July 24, 2026 | First publication, based on our EU AI Act self-assessment of July 24, 2026 (post Digital Omnibus). |