Security and data
What Adrails stores, how credentials are protected, what the AI model sees, and how to have your data deleted.
This page sums up how Adrails handles your data. The Privacy Policy is the reference; the Security page explains the boundaries in more depth.
What Adrails stores
- Your account and workspace: name, email address, profile picture, sessions, roles and invitations.
- Ad platforms: the access token and its expiry, ad account details, and campaigns, ad sets, ads and their figures. Image and video files fetched from Meta are not stored.
- Integrations: the data each one reads (see Integrations). Shopify customer email addresses are turned into a one-way fingerprint before they are stored. For Google Drive, only the identifiers, names and types of files, not their content.
- Tracking: the events your site sends. Customer emails and external ids are stored only as keyed hashes; phone numbers are not stored. See Set up tracking.
- Your work: conversations, prompts, the agent's tool activity, and every approval.
How credentials are protected
- Tokens and API keys of Meta, Google and every integration are encrypted at rest with AES-256-GCM, with a key kept outside the database.
- They are never placed in what the agent reads.
- Disconnecting an integration revokes the authorization with the provider when it allows it, and deletes the stored credential. Removing a Meta profile erases its access token.
What the AI model sees
To answer, Adrails sends the AI provider your request, the relevant conversation, workspace instructions and the results of the tools it used, which can include advertising figures and aggregated commerce figures. Integration tokens, private keys and passwords are never sent to the model.
An AI answer or proposal can be wrong. Review it before you act. Adrails never treats an AI answer as an approval: changes to your ad accounts wait for a person, as Approvals and undo explains.
Retention
- Your data is kept while your account or workspace is active.
- Disconnecting stops future reads. Data already imported stays until you ask for deletion.
- Webhook payloads are deleted after 30 days.
- Deleted data can remain in backups until they expire on the normal backup cycle.
Delete your data
Follow Data deletion: email support with the subject Data deletion request, from the email address you use for Adrails, naming the workspace or ad account if you can. Never send an access token, password or key. Adrails verifies your identity and authority, then deletes the data and confirms within 30 days.
You can also revoke Adrails' access at any time:
- Meta: from your Facebook or Meta business settings.
- Google: from your Google Account permissions, at
myaccount.google.com/permissions.
Revoking stops future access. It does not by itself delete what was already imported: ask for deletion for that.
Watch for
- Only owners and administrators can connect or disconnect sources.
- A client report link shows figures to anyone who has it. Revoke links you no longer need: see Client reports.
- Keep the tracking server key on your server only.
