Security

Data Privacy & Security

Understand how your advertising data is protected when using Ad Superpowers with AI assistants like Claude and ChatGPT.

The Bottom Line

  • Your advertising data is processed, then released. Ad Superpowers keeps it only for the response it generates. Workflows and skills you write yourself are saved so you can reuse them, until you delete them. Model training is governed by the policy of whichever AI provider you use, linked below.
  • Your credentials stay with you. OAuth tokens are encrypted and stored in Ad Superpowers' database, not shared with Anthropic or OpenAI.
  • Read-only by default. MCP tools only read data from ad platforms - they can't modify campaigns unless you explicitly use write tools.
  • More controlled than alternatives. Using MCP is safer than copy-pasting data into AI tools or uploading CSVs with unclear privacy policies.

How Your Data Flows

When you ask Claude about your advertising data, here's exactly what happens:

1

Your Request

You ask Claude "Show me my Meta campaign performance"

2

MCP Request

Claude calls Ad Superpowers via MCP with your API key

3

Platform Query

Ad Superpowers uses your stored OAuth token to fetch data from Meta

4

Response

Data returns through MCP to Claude, which formats your answer

What's stored where:

  • Ad Superpowers: Your encrypted OAuth tokens, API keys, usage logs, and any workflows or skills you create. We do not retain your ad data long term. API responses are cached briefly (1 minute to 6 hours), and workflow run logs record how many parameters a run used, not the parameters themselves.
  • Claude/Anthropic: Processes your conversation in memory to generate responses. Retention and training are governed by Anthropic's own policy, linked below.
  • Ad Platforms: Your actual ad data lives here (Meta, Google, etc.). We only read it when you ask.

AI Training Policies

Claude

Claude (Anthropic)

  • Training policy: see Anthropic's own documentation
  • Ad Superpowers caches the tool results it returns for 1 minute to 6 hours, then releases them. That window is ours, not Anthropic's
  • Retention controls beyond that are set by your own Anthropic plan; see their documentation below
Anthropic Privacy Policy
ChatGPT

ChatGPT (OpenAI)

  • Training policy for Plus and Team: see OpenAI's own documentation
  • MCP is only available on Plus (requires opt-in)
  • Free tier may use data for training (opt out in settings)
OpenAI Data Controls FAQ
Gemini

Gemini (Google)

  • Training policy for Gemini Advanced: see Google's own documentation
  • Gemini CLI supports MCP natively
  • Free tier conversations may be reviewed for quality
Gemini Privacy Hub

Model-Agnostic Tools (Cursor, n8n, Antigravity)

Some MCP-compatible tools let you choose which AI model to use. The data privacy policy depends on which model you configure:

Cursor
Cursor IDE

Uses Claude or GPT-4 - check the respective provider's policy

n8n
n8n

Configurable backend - you choose which AI API to connect

Antigravity
Antigravity

Uses Gemini by default - Google's privacy policy applies

Tip: When using model-agnostic tools, always check which AI provider is configured and review their specific data policies.

Safer Than the Alternatives

Many marketers are already using AI to analyze client data - but often in less controlled ways:

MethodData ControlTraining RiskVisibility
Ad Superpowers + MCP Full control Governed by your AI plan See every tool call
Copy/paste into ChatGPT (free) No control May be used Manual only
Upload CSVs to random AI tools Unknown Unknown None
Share spreadsheets via email Limited None No audit trail

Our Security Measures

Data Protection

  • All OAuth tokens encrypted at rest with authenticated encryption (AES-128-CBC with HMAC-SHA256)
  • TLS 1.2 or higher for all connections
  • We do not retain your ad data long term. API responses are cached briefly (1 minute to 6 hours), and workflow run logs record how many parameters a run used, not the parameters themselves. Workflows and skills you create are kept until you delete them.
  • GDPR compliant - export or delete your data anytime

Access Control

  • OAuth 2.0 with minimal required scopes
  • Read-only access by default
  • Revoke platform access anytime from dashboard
  • Administrative actions on our platform are logged.

For Agencies Managing Client Data

If you're an agency using Ad Superpowers with client ad accounts, here's what you should know:

  • Training is governed by your own AI plan. We operate no models ourselves, so client data only ever reaches the AI tool you connect. What that vendor does with it is set by your agreement with them, not by us.
  • You control which accounts are connected. Only platforms you explicitly authorize can be accessed.
  • Full transparency. You can see exactly which MCP tools are called and what data is requested.
  • Check your AI vendor's plan tiers. For highly sensitive clients, the privacy terms that matter are the ones in your agreement with the AI vendor. Compare their plans before you connect the account.

Consider updating your client agreements to mention AI-assisted analysis if you haven't already - it's becoming standard practice in the industry.

Learn More

Still have questions about data privacy?

We're happy to discuss your specific security requirements.

Contact Us

Cookies on this site

We use analytics cookies to see how the site is used. They load only if you accept, and you can change your choice at any time. Read our privacy policy.