Security and privacy
What the AdLoop server enforces before an AI changes anything in your ad accounts, where your data lives, who processes it and when we delete it.
What the server enforces
These rules aren't instructions to the AI that it could skip. The AdLoop server enforces them on every call, whichever AI assistant is asking.
Preview first, then the change
Every change starts as a preview. It is applied only after you confirm it in the chat. Without that confirmation, nothing changes.
A test run is mandatory
The server refuses a real change until the same preview has gone through one test run. For Google Ads, Google checks the test run through its validation interface and executes nothing.
New workspaces start in test mode
While "Allow dry-run only" is on, nothing is applied for real. Switching test mode off takes an explicit confirmation, and we log when and by whom.
Budget limit
The server refuses daily budgets above your limit, whatever the AI suggests. Agencies can set a separate limit per client.
No runaway bids
A single change can at most double an existing bid.
New things start paused
New Google Ads campaigns and ads, and everything new on Reddit Ads, are created paused. They go live only when you enable them.
Known budget traps blocked
The server refuses new campaigns that combine broad match keywords with manual bidding, and ads or sitelinks whose landing page can't be reached.
Removal needs a second confirmation
Permanently removing something takes a second confirmation. Pausing is always the recommended route.
Keys with limited rights
API keys can be limited to read-only, to single clients and to chosen tool groups. A read-only key can't even create a preview.
Change log
Every write is logged: what, when, for which client and with what result. So you can always show your clients what was changed.
The safety layer is open source (MIT). You can read every one of these rules in the code. See the code on GitHub
Where your data lives
AdLoop runs no AI model of its own. Your data goes to the AI assistant you connect yourself, and to no other AI provider.
| MCP server | Hetzner, Falkenstein data centre (Germany) |
|---|---|
| Dashboard and database | Laravel Cloud, AWS Frankfurt region (EU) |
| Campaign and analytics data | Passed through, never stored |
| Google and Reddit access tokens | Encrypted with authenticated encryption (libsodium) |
| AI app sign-in | OAuth 2.1 with PKCE. Refresh tokens are stored only as a hash. |
| Account | Two-factor sign-in available, roles for team members |
Subprocessors
The complete, binding list is in § 7 of the DPA. We announce changes in advance.
Hetzner Online GmbH
Runs the MCP server
Germany
Laravel Cloud (Laravel LLC, including the Cloudflare edge)
Hosts the dashboard and database
USA, processing in the EU (Frankfurt)
Plus Five Five, Inc. (Resend)
Sends transactional emails
USA, EU-US Data Privacy Framework and standard contractual clauses
Google Ireland Limited
Website analytics on the marketing pages, only with consent
Ireland (EU)
Google and Reddit are not subprocessors: you connect your accounts with your own authorization. Payments are handled by Link (Stripe) as merchant of record. Card details never reach us.
When we delete
| Data | Deleted after |
|---|---|
| Change log | 24 months |
| Usage counters (call counts only, no content) | 24 months |
| Previews that were never applied | 7 days |
| Revoked or expired AI app connections | 30 days |
| Campaign and analytics data | Never stored |
| When you delete your account | Access tokens deleted at once and access revoked at Google and Reddit. Backups expire after 30 days at most. |
Deletion runs automatically every night. Every period in detail is in the privacy policy. Read the privacy policy
Contracts
Data processing agreement (DPA)
Under Art. 28 GDPR, version 1.3. It applies from sign-up without a signature, and you can save it as a PDF for your records and your clients'.
View the DPA and save it as PDF →Security questions
For questions from your privacy review, or to report a vulnerability, write to the founder directly.
daniel@getadloop.com