Privacy Policy
Last updated: June 2026. This policy describes how AdPilot handles your data. Review with counsel before relying on it in your jurisdiction.
Who we are
AdPilot (“we”) operates AdPilot, a tool that lets you plan, create, launch, monitor, and optimize paid advertising campaigns on Google Ads and Meta (Facebook/Instagram) Ads, for ad accounts you explicitly connect. You can use AdPilot directly on this website, and/or through a connected AI assistant (e.g. Claude or ChatGPT) via our connector. Contact: support@doalier.com.
Data we collect
- Account: your email address (for passwordless sign-in).
- Ad-platform authorization: the OAuth access/refresh tokens for the Google and Meta ad accounts you connect, plus the account ids, names, and currencies you select. Tokens are encrypted at rest and never shown back to you or to your AI assistant.
- Ad-account data: via the permissions you grant, we read your ad accounts, campaign/ad-set/ad structure, and performance insights (impressions, clicks, spend, conversions), and we create/update campaigns you set up. We store campaign metadata you create through AdPilot.
- Creatives: ad images/videos you generate or upload, and the prompts used to generate them.
- Operational data: an audit log of mutating actions and a log of external API requests (with credentials redacted) for security and debugging.
- Billing: handled by Stripe; we store a Stripe customer id and subscription status. We never store card numbers.
How we use it
We use your data solely to provide the service: to authenticate you, perform the ad-platform actions you initiate (on the website or via your AI assistant), generate the creatives you request, show you your own campaign performance, enforce spend guardrails, and bill the $5/month subscription. We do not sell your data, do not use it for our own advertising, and do not use ad-account data for any purpose other than performing the operations you initiate and reporting your results back to you.
Meta (Facebook/Instagram) permissions & data
We request the minimum permissions needed to manage ads on accounts you
connect: ads_management and ads_read (and
business_management where applicable). With these we read your
ad-account structure and performance and create/manage the campaigns you set
up. We handle this data in accordance with the
Meta Platform Terms and
Developer Policies.
You can revoke AdPilot’s access at any time in your Meta/Facebook
settings; we also honor Meta’s deauthorize and data-deletion callbacks and
remove the associated data when they fire.
Google permissions & data
We request the Google adwords scope to manage ads on accounts
you connect. Google user data is used and transferred in accordance with the
Google API Services User Data Policy,
including the Limited Use requirements. We access ad-account data only to
perform actions you initiate.
Sub-processors
We share data only with the providers needed to deliver the function you request:
- Google Ads API and Meta Marketing API - to perform the campaign operations you initiate.
- Stripe - subscription billing (no card data stored by us).
- Media generation - only when you generate an image/video, your prompt is sent to the generation service to produce the asset.
- Error monitoring (Sentry) - receives diagnostic error data to keep the service reliable. It is configured to not receive personal data, ad-account data, or tokens.
Retention & deletion
We keep your data while your account is active. You can, at any time from your dashboard: disconnect an ad account (we delete its stored tokens), regenerate your API token, or delete your account and all associated data. Meta-linked data is also deleted when you remove the app or submit a data-deletion request. See Data Deletion.
Security
OAuth tokens are encrypted at rest; all traffic is over HTTPS. Access to the remote connector requires authentication (OAuth or your secret API token).