Data Privacy & Security
Understand how your advertising data is protected when using Ad Superpowers with AI assistants like Claude and ChatGPT.
The Bottom Line
- Your advertising data is processed, then released. Ad Superpowers keeps it only for the response it generates. Workflows and skills you write yourself are saved so you can reuse them, until you delete them. Model training is governed by the policy of whichever AI provider you use, linked below.
- Your credentials stay with you. OAuth tokens are encrypted and stored in Ad Superpowers' database, not shared with Anthropic or OpenAI.
- Read-only by default. MCP tools only read data from ad platforms - they can't modify campaigns unless you explicitly use write tools.
- More controlled than alternatives. Using MCP is safer than copy-pasting data into AI tools or uploading CSVs with unclear privacy policies.
How Your Data Flows
When you ask Claude about your advertising data, here's exactly what happens:
Your Request
You ask Claude "Show me my Meta campaign performance"
MCP Request
Claude calls Ad Superpowers via MCP with your API key
Platform Query
Ad Superpowers uses your stored OAuth token to fetch data from Meta
Response
Data returns through MCP to Claude, which formats your answer
What's stored where:
- Ad Superpowers: Your encrypted OAuth tokens, API keys, usage logs, and any workflows or skills you create. We do not retain your ad data long term. API responses are cached briefly (1 minute to 6 hours), and workflow run logs record how many parameters a run used, not the parameters themselves.
- Claude/Anthropic: Processes your conversation in memory to generate responses. Retention and training are governed by Anthropic's own policy, linked below.
- Ad Platforms: Your actual ad data lives here (Meta, Google, etc.). We only read it when you ask.
AI Training Policies
Claude (Anthropic)
- Training policy: see Anthropic's own documentation
- Ad Superpowers caches the tool results it returns for 1 minute to 6 hours, then releases them. That window is ours, not Anthropic's
- Retention controls beyond that are set by your own Anthropic plan; see their documentation below
ChatGPT (OpenAI)
- Training policy for Plus and Team: see OpenAI's own documentation
- MCP is only available on Plus (requires opt-in)
- Free tier may use data for training (opt out in settings)
Gemini (Google)
- Training policy for Gemini Advanced: see Google's own documentation
- Gemini CLI supports MCP natively
- Free tier conversations may be reviewed for quality
Model-Agnostic Tools (Cursor, n8n, Antigravity)
Some MCP-compatible tools let you choose which AI model to use. The data privacy policy depends on which model you configure:
Uses Claude or GPT-4 - check the respective provider's policy
Configurable backend - you choose which AI API to connect
Uses Gemini by default - Google's privacy policy applies
Tip: When using model-agnostic tools, always check which AI provider is configured and review their specific data policies.
Safer Than the Alternatives
Many marketers are already using AI to analyze client data - but often in less controlled ways:
| Method | Data Control | Training Risk | Visibility |
|---|---|---|---|
| Ad Superpowers + MCP | Full control | Governed by your AI plan | See every tool call |
| Copy/paste into ChatGPT (free) | No control | May be used | Manual only |
| Upload CSVs to random AI tools | Unknown | Unknown | None |
| Share spreadsheets via email | Limited | None | No audit trail |
Our Security Measures
Data Protection
- All OAuth tokens encrypted at rest with authenticated encryption (AES-128-CBC with HMAC-SHA256)
- TLS 1.2 or higher for all connections
- We do not retain your ad data long term. API responses are cached briefly (1 minute to 6 hours), and workflow run logs record how many parameters a run used, not the parameters themselves. Workflows and skills you create are kept until you delete them.
- GDPR compliant - export or delete your data anytime
Access Control
- OAuth 2.0 with minimal required scopes
- Read-only access by default
- Revoke platform access anytime from dashboard
- Administrative actions on our platform are logged.
For Agencies Managing Client Data
If you're an agency using Ad Superpowers with client ad accounts, here's what you should know:
- Training is governed by your own AI plan. We operate no models ourselves, so client data only ever reaches the AI tool you connect. What that vendor does with it is set by your agreement with them, not by us.
- You control which accounts are connected. Only platforms you explicitly authorize can be accessed.
- Full transparency. You can see exactly which MCP tools are called and what data is requested.
- Check your AI vendor's plan tiers. For highly sensitive clients, the privacy terms that matter are the ones in your agreement with the AI vendor. Compare their plans before you connect the account.
Consider updating your client agreements to mention AI-assisted analysis if you haven't already - it's becoming standard practice in the industry.
Learn More
Still have questions about data privacy?
We're happy to discuss your specific security requirements.
Contact Us