← Back

Security and privacy

What the AdLoop server enforces before an AI changes anything in your ad accounts, where your data lives, who processes it and when we delete it.

What the server enforces

These rules aren't instructions to the AI that it could skip. The AdLoop server enforces them on every call, whichever AI assistant is asking.

Preview first, then the change

Every change starts as a preview. It is applied only after you confirm it in the chat. Without that confirmation, nothing changes.

A test run is mandatory

The server refuses a real change until the same preview has gone through one test run. For Google Ads, Google checks the test run through its validation interface and executes nothing.

New workspaces start in test mode

While "Allow dry-run only" is on, nothing is applied for real. Switching test mode off takes an explicit confirmation, and we log when and by whom.

Budget limit

The server refuses daily budgets above your limit, whatever the AI suggests. Agencies can set a separate limit per client.

No runaway bids

A single change can at most double an existing bid.

New things start paused

New Google Ads campaigns and ads, and everything new on Reddit Ads, are created paused. They go live only when you enable them.

Known budget traps blocked

The server refuses new campaigns that combine broad match keywords with manual bidding, and ads or sitelinks whose landing page can't be reached.

Removal needs a second confirmation

Permanently removing something takes a second confirmation. Pausing is always the recommended route.

Keys with limited rights

API keys can be limited to read-only, to single clients and to chosen tool groups. A read-only key can't even create a preview.

Change log

Every write is logged: what, when, for which client and with what result. So you can always show your clients what was changed.

The safety layer is open source (MIT). You can read every one of these rules in the code. See the code on GitHub

Where your data lives

AdLoop runs no AI model of its own. Your data goes to the AI assistant you connect yourself, and to no other AI provider.

MCP server Hetzner, Falkenstein data centre (Germany)
Dashboard and database Laravel Cloud, AWS Frankfurt region (EU)
Campaign and analytics data Passed through, never stored
Google and Reddit access tokens Encrypted with authenticated encryption (libsodium)
AI app sign-in OAuth 2.1 with PKCE. Refresh tokens are stored only as a hash.
Account Two-factor sign-in available, roles for team members

Subprocessors

The complete, binding list is in § 7 of the DPA. We announce changes in advance.

Hetzner Online GmbH

Runs the MCP server

Germany

Laravel Cloud (Laravel LLC, including the Cloudflare edge)

Hosts the dashboard and database

USA, processing in the EU (Frankfurt)

Plus Five Five, Inc. (Resend)

Sends transactional emails

USA, EU-US Data Privacy Framework and standard contractual clauses

Google Ireland Limited

Website analytics on the marketing pages, only with consent

Ireland (EU)

Google and Reddit are not subprocessors: you connect your accounts with your own authorization. Payments are handled by Link (Stripe) as merchant of record. Card details never reach us.

When we delete

Data Deleted after
Change log 24 months
Usage counters (call counts only, no content) 24 months
Previews that were never applied 7 days
Revoked or expired AI app connections 30 days
Campaign and analytics data Never stored
When you delete your account Access tokens deleted at once and access revoked at Google and Reddit. Backups expire after 30 days at most.

Deletion runs automatically every night. Every period in detail is in the privacy policy. Read the privacy policy

Contracts

Data processing agreement (DPA)

Under Art. 28 GDPR, version 1.3. It applies from sign-up without a signature, and you can save it as a PDF for your records and your clients'.

View the DPA and save it as PDF →

Security questions

For questions from your privacy review, or to report a vulnerability, write to the founder directly.

daniel@getadloop.com
Start free Read the docs