Last updated: September 1, 2026
AdAgnt is operated by VueDooh Technologies LLP ("AdAgnt", "we", "us"). AdAgnt is an MCP (Model Context Protocol) server, REST API and web dashboard that lets AI assistants manage advertising campaigns on your behalf, on ad accounts you connect. This policy describes every category of data the service collects, why it is processed, who receives it, how long it is kept, and the controls you have. It is written to reflect the service's current tools — 359 tools across Google Ads, Meta Ads, LinkedIn Ads, TikTok Ads, Amazon Ads, AppLovin, Reddit Ads and X Ads, plus revenue integrations and the AdAgnt Intelligence Layer.
Account data. Your email address, plan tier, and account identifiers. Sign-in uses one-time codes sent to your email — we never collect or store a password for AdAgnt. We keep customer-support correspondence you send us.
Usage and diagnostic data. For each tool call: the tool name, the arguments needed to execute it, timestamps, success/error status, request identifiers, and quota counters. Server logs include IP addresses and technical metadata used for security, debugging, billing and abuse prevention. We do not receive your full conversation with an AI assistant — only the structured tool calls the assistant sends to our API, which can include text you asked it to use (for example, ad copy or keywords).
Ad platform connection data. When you connect an ad platform, we store the OAuth access and refresh tokens (or, for AppLovin, the API Report Key you paste) needed to act on your behalf, along with connection status, granted scopes, and connected-account metadata such as account IDs, names and currencies. We never collect or store your password for any ad platform. All tokens and keys are encrypted at rest with AES-256-GCM.
Campaign, creative and targeting data. When tools run against a connected account we process what those tools read and write: campaign, ad group / ad set / line item and ad structures; budgets, bids and schedules; keywords, negative keywords and search terms; targeting settings (audiences, locations, demographics, interests, communities, placements, devices); ad copy, headlines, descriptions and landing-page URLs; creative asset metadata and assets you upload for campaign creation.
Performance and reporting data. Metrics fetched to answer your requests: spend, impressions, clicks, conversions, conversion value, revenue, ROAS, CPA/CPC/CPM/CTR and similar, at account, campaign, ad group, ad, keyword, search-term, community and placement level; plus derived analyses such as wasted-spend findings, anomaly explanations, creative-fatigue scores, benchmarks and budget recommendations.
Revenue-source data. If you connect a revenue source (Google Analytics 4, Shopify, Stripe or Klaviyo), we process order, transaction and event data from it — amounts, timestamps, currencies and attribution identifiers — solely to compute revenue attribution ("true ROAS"), campaign verdicts and A/B test results for you. This can include data about your customers' transactions. We process it as your service provider, use it for no other purpose, and never use it for advertising of our own.
Automation data. Monitors you configure (metric, threshold, filters), scheduled briefs and their delivery email addresses, A/B tests, saved strategy notes, autopilot settings, and the record of proposed, approved, rejected or executed actions in the approval queue.
Sandbox data. New accounts start in sandbox mode, which operates entirely on simulated data. Nothing in sandbox mode contacts a live ad platform, and no real spend or real customer data is involved.
We use the data above to: authenticate you and secure your account; connect to the platforms and revenue sources you authorize; execute the tool calls you or your AI assistant initiate; run monitors, scheduled briefs and approved autopilot actions you configured; compute analyses, reports and recommendations; enforce plan quotas and operate billing; provide support; detect and prevent fraud and abuse; and comply with legal obligations. We do not sell your data, we do not use your data to train AI models, and we do not access connected accounts except to serve a request you initiated or an automation you explicitly configured.
Ad platforms you connect. Tool calls are executed against the APIs of Google Ads, Meta, LinkedIn, TikTok, Amazon Ads, AppLovin, Reddit and X, as applicable — reading the data described above and writing the changes you approve. Each platform's own privacy policy governs its side.
Your AI assistant. Tool results (campaign data, metrics, analyses, confirmations) are returned to the AI client that called us — for example ChatGPT or Claude — where they appear in your conversation. The assistant provider's privacy policy governs what happens there.
Service providers. We use a small set of infrastructure providers to run AdAgnt: cloud hosting for our servers and encrypted database, encrypted off-site backup storage, transactional email delivery (sign-in codes and scheduled briefs), and — when paid plans launch — a payment processor, which handles your payment details itself; we never see card numbers. Each processes data only as needed to provide its service to us.
Legal. We may disclose information if required by law or legal process, to enforce our terms, or to protect the rights, safety or security of AdAgnt, our users or the public.
Account data and automation settings: while your account is active, then deleted on account deletion. OAuth tokens and API keys: until you disconnect the platform, revoke access, or delete your account — disconnecting deletes the stored token immediately. Cached campaign structures and performance data: while your account is active, refreshed and replaced as tools run. Tool-invocation and server logs: up to 90 days, for security, debugging and abuse prevention. Billing and legal records: as required by law. Encrypted backups: rotated automatically, with any copy of deleted data purged within at most 30 days (14 days on-site, 30 days off-site).
You can, at any time: disconnect any ad platform or revenue source from the dashboard (this deletes its stored token); revoke AdAgnt's access from the platform's own security settings; delete monitors, scheduled briefs, A/B tests and pending autopilot actions; and disconnect the AI assistant from AdAgnt in the assistant's own connector settings. You can also email privacy@adagnt.com to request access to, correction of, export of, or deletion of your data — we verify the request against your account email and honor it within 30 days. Because sign-in is by one-time email code, there is no AdAgnt password to manage or leak.
All traffic is TLS-encrypted. Platform tokens, API keys and backups are encrypted at rest (AES-256-GCM). Access to production systems is limited to key-based administrative access. Write tools execute exactly once per approved request and are never auto-retried. Report vulnerabilities to security@adagnt.com.
AdAgnt is operated by VueDooh Technologies LLP (Bengaluru, India), and our servers and service providers may process data in other countries. Where required, we use appropriate safeguards for cross-border transfers.
AdAgnt is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children.
We will update this policy as the service changes — including when new platforms or tools are added — and revise the "Last updated" date above. Material changes will be notified by email or an in-product notice.
VueDooh Technologies LLP · support@adagnt.com · adagnt.com