Privacy policy
Last updated: 15 September 2026
1. Who is the data controller
Novion Sancho Léonard, sole trader (entrepreneur individuel) registered under SIREN 106 059 884, whose registered office is at 22 chemin de Condrine, 33720 Illats, France.
For any question or request about your data: contact@adsnalytic.com.
2. What Adsnalytic does, and why that matters for your data
Adsnalytic is an MCP server. It lets an advertiser connect an ad account and talk about it in plain language from their own AI assistant: Claude, ChatGPT or another compatible client.
Three consequences follow, and they matter more than anything below:
- The conversation does not happen on our site. It happens inside your AI assistant.
- Your advertising data therefore passes through whoever makes that assistant. When you ask a question, our server queries the advertising API, formats the answer, and sends it back to your assistant, which shows it to you. What that maker (Anthropic, OpenAI or another) does with that content is governed by their privacy policy and by your contract with them, not by us. We can neither control it nor answer for it.
- We keep none of your advertising data. The figures are read on demand and passed straight back. Nothing is stored on our side. There is no database of your campaigns, your spend or your conversions.
3. What we process
3.1 The waiting list, before launch
If you sign up to the waiting list on adsnalytic.com:
| Data | Why |
|---|---|
| Your email address | to tell you when we open |
Which form you used (hero or footer) | to know which page convinces |
| Your user agent, truncated to 500 characters | to tell a visitor from a bot |
Legal basis: your consent. Retention: until launch, or until you ask us to delete it. Where: a Postgres database hosted by Supabase.
For the record: an earlier version of the form asked for a phone number and a country. Those fields are no longer collected and nothing is written to them any more, but values already recorded remain in the rows concerned. They are deleted on request, like the rest.
3.2 Connecting an ad account
When you connect your account, you go through the advertising platform's official OAuth flow (Google, then Meta). You grant us an access authorisation. We never see your password and we never ask you for one.
| Data | Why | Where |
|---|---|---|
| The access and refresh token issued by the platform | to query your account on your behalf | encrypted at rest in a Postgres database |
| Your email address, as the platform passes it to us | to trace calls, and to tie a write confirmation to the person who asked for the preview | never stored in the database |
Legal basis: performing the service you asked for.
Two architecture choices limit what we hold, and you can check both in the code:
- There is no users table. We create no account on our side, and your identity is derived from your token on every request, never cached.
- The confirmation token for a write is not stored. It is computed by cryptographic signature and expires after fifteen minutes.
3.3 Cookies, trackers, analytics
None. The site sets no cookie, uses no Google Analytics, no Plausible, no PostHog, no measurement tool of any kind, and writes nothing to your browser's local storage. There is no banner to accept, because there is nothing to accept.
(Checkable: the site's only third-party dependencies are its host and its database.)
4. What we do not do
- We do not sell any data.
- We do not share your advertising data with any third party, apart from the technical processors listed in section 6.
- We do not train any AI model on your data. We train no models at all.
- We do not combine data from different advertisers.
- We write nothing to your ad account without an explicit request from you in the conversation, preceded by a costed preview that you approve. A recommendation from the assistant is not an authorisation.
5. Google user data, and Google's Limited Use policy
Adsnalytic's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
For data obtained through the Google Ads API, concretely:
- it is used only to provide the user-facing features described in section 2 — reading and analysing your own ad account from your AI assistant;
- it is not sold, and it is not used for advertising of any kind;
- it is not used to train any AI model, ours or anyone else's;
- no human at Adsnalytic reads it, except where you explicitly ask us to look at something to help you, where it is necessary to investigate a bug or abuse, or where the law requires it;
- it is not transferred to anyone, with one exception, stated plainly rather than buried: the answers you ask for are returned to the AI assistant you chose, because that is where the conversation happens and that is the whole point of the product. You trigger that transfer with each question, and section 2 explains what it means.
6. Processors
| Processor | Role | Where the data sits |
|---|---|---|
| Vercel | hosting for the site and the MCP server | functions served from Paris (cdg1) |
| Supabase | Postgres database: waiting list, and tokens encrypted at rest | Ireland (eu-west-1) |
| Google Ads API, and OAuth provider | on their own platform, under your contract with them | |
| Meta | Marketing API, and OAuth provider | on their own platform, under your contract with them |
Not in this table, and not by oversight: whoever makes your AI assistant. They are not our processor. You are the one with a contract with them, and you are the one who chooses to send them your questions. See section 2.
7. Your rights
Under the GDPR you have rights of access, rectification, erasure, restriction, objection and portability.
Two things you can do right now, without writing to us:
- Revoke our access to your ad account, at any time, from the security settings of your Google or Meta account. Access stops immediately.
- Ask for your data to be deleted. See the dedicated page, delete your data.
For everything else: contact@adsnalytic.com. We answer within one month. You can also lodge a complaint with the CNIL, the French data protection authority.
8. Transfers outside the European Union
Your data stays in the European Union. Both processors that host it are configured on European regions: Supabase's Postgres database is in Ireland (eu-west-1), and the Vercel functions that serve the site and the MCP server run from Paris (cdg1).
Vercel Inc. and Supabase Inc. are nonetheless companies incorporated in the United States. A transfer therefore remains possible in the course of their operations, and it is then covered by the European Commission's standard contractual clauses, which form part of their data processing terms.
Google and Meta are not hosts. They are the advertising platforms whose accounts you authorise us to read. Your campaign data is already with them, under the contract you signed with them. We read it. We do not transfer it there.
9. Security, and how sensitive data is protected
The most sensitive thing we hold is the access token to your ad account. We hold no campaign data at all, so there is nothing else to protect — see section 3.2.
9.1 Encryption
- In transit. Every connection is encrypted. The site and the MCP server are served over HTTPS only. The connection between the server and its database is TLS 1.3.
- At rest. Access and refresh tokens are encrypted before they are written to the database, with Fernet (AES-128-CBC with HMAC-SHA256 authentication). The database never sees a token in clear. Our host's own disk encryption sits underneath, and is not what we rely on.
- The encryption key is derived from a secret held in the runtime environment. It is not in the source code, not in the repository, and not in the database. Someone reading a database dump cannot decrypt a single token.
9.2 Access control
- No human at Adsnalytic reads your advertising data, except where you explicitly ask us to look at something to help you, where it is necessary to investigate a bug or abuse, or where the law requires it. This is stated in section 5 and it is the rule.
- Tokens are never displayed in any interface, ours or anyone else's.
- Access to the production environment is limited to the data controller named in section 1. Adsnalytic has no employees and no contractors: there is no one else to grant access to.
9.3 Isolation between advertisers
One advertiser's data cannot appear in another's response. Identity is re-derived from the token on every single request — never read from a session, never cached between two calls — and the storage key is built from that identity. This is not a convention: it is enforced in code and covered by an automated test that fails the build if it breaks.
9.4 What we never write down
- We never log a complete OAuth response, which would contain a refresh token. Logs record the type of an error, never its payload.
- No secret is stored in the source code.
- Connection strings, keys and tokens never appear in an error message shown to a user.
9.5 Deletion, and revocation
- You can cut access instantly, without asking us, from the security settings of your Google or Meta account. The token we hold becomes useless at that moment.
- Disconnecting a platform from our connections page deletes the stored token.
- See section 7 and the delete your data page.
9.6 If something goes wrong
If a breach affecting your data occurred, we would notify the CNIL within 72 hours and tell you directly where the regulation requires it. Our exposure is deliberately small: we store no campaign, spend or conversion data, so a breach of our database would expose encrypted tokens and nothing else.
10. Changes
Any change to this document is published on this page, with its date. If a change is substantial we tell you by email, where we have your address.