AdvisorPPC MCP Connector
Privacy Policy
Last updated: July 24, 2026
The AdvisorPPC MCP Connector ("the Connector," "we," "us") is an OAuth-secured remote Model Context Protocol (MCP) server that connects your own Google Ads and Meta Ads accounts to ChatGPT. This policy explains what data the Connector handles, why, where it goes, how it is protected, and the choices you retain. Questions can be sent to support@advisorppc.com.
1. What the Connector does
When you authorize a supported platform, the Connector lets ChatGPT, acting on your instructions:
- Authenticate to an account you control using the provider's official OAuth flow.
- Read account structure, settings, performance data, and other information needed for the tool you request.
- Write only bounded eligible changes after the required confirmation. Public examples include pausing or enabling an eligible Google Ads campaign, updating its budget, and creating a paused Meta campaign draft.
The Connector does not make unrestricted or unattended changes to advertising accounts.
2. Connected platforms
The ChatGPT app submission candidate represents these advertising platforms:
- Google Ads
- Meta Ads (Facebook and Instagram advertising)
You choose which platform to connect. The Connector cannot reach an advertising account that your connected identity is not authorized to access. Other provider integrations are not represented as part of the public ChatGPT submission unless they are added to the published tool surface after separate technical and provider approval.
3. Data we collect and handle
- AdvisorPPC account data. Your login email, subscription or entitlement status, and workspace identifiers.
- OAuth credentials. Access tokens and, when supplied by a provider, refresh tokens scoped to permissions you granted. We do not receive or store your Google or Meta password.
- Advertising account metadata. Account IDs and names, manager and business relationships, campaigns, ad groups or ad sets, ads, keywords, audiences, budgets, conversion settings, and related configuration.
- Search-query and advertising text. Google Ads search terms or search-query text, keyword text, ad copy, and campaign names returned for a requested analysis. Search-query text can reflect text entered by individual searchers, so users should avoid unnecessarily reproducing it outside the requested workflow.
- Performance data. Impressions, clicks, cost, conversions, value, and similar figures for the account and date range requested.
- Client workspace data. Client names, websites, industries, monthly budgets, account-to-client mapping IDs, roles and notes, CRM-style client notes, and other context a user enters into AdvisorPPC. When a user asks ChatGPT to retrieve client details, responsive fields can be included in the tool result.
- Tool request data. Structured arguments ChatGPT sends to a Connector tool, such as an account ID, campaign ID, date range, requested status, budget, or client lookup.
- Operational records. Timestamps, tool name, user or workspace identifier, and success or error status needed for security, billing, debugging, and abuse prevention. We aim to keep logs free of unnecessary account-data content.
We collect only what is needed to operate the Connector. We do not buy or enrich advertising-account data with data-broker records.
4. Where data goes
Data moves only as needed to perform the workflow or meet legal and operational obligations:
- ChatGPT and OpenAI. When you use the Connector in ChatGPT, ChatGPT sends structured tool requests to AdvisorPPC. AdvisorPPC sends responsive tool results back to ChatGPT for OpenAI to process and display in your conversation. Depending on the tool, a result may contain advertising metrics, campaign settings, Google Ads search-query text, or client workspace and CRM-style notes. AdvisorPPC does not include OAuth tokens or provider secrets in tool results. OpenAI's retention, use, and processing of information received in ChatGPT are governed by your ChatGPT plan and settings and OpenAI's applicable terms and privacy policy.
- Google and Meta. We send authorized API requests to the connected provider to retrieve data or perform a confirmed eligible action.
- Infrastructure providers. Hosting, database, monitoring, and security vendors process data only as needed to operate the service under contractual or confidentiality obligations.
- Legal requirements. We may disclose limited information when required by valid legal process or to protect users, the service, or others from fraud, abuse, or security threats.
5. Why we use data and the limits we accept
We use the data above to authenticate users, run requested Connector tools, return results to the user's ChatGPT conversation, perform confirmed actions, maintain security and reliability, provide support, and enforce plan entitlements.
- We do not sell your data.
- We do not expose one customer's data to another customer. Access controls bind stored credentials and workspace records to the authorized user or workspace.
- AdvisorPPC does not use Connector data to train its own AI or machine-learning models. OpenAI's handling of data sent to ChatGPT is controlled by OpenAI's terms and the user's ChatGPT plan, workspace, and data-control settings; AdvisorPPC cannot make a separate training promise on OpenAI's behalf.
- We do not use connected advertising data to build unrelated advertising profiles.
- Google API data. AdvisorPPC's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
6. How data is stored and protected
- Encrypted in transit. Connector, provider, and ChatGPT traffic uses HTTPS/TLS.
- Protected at rest. Stored OAuth credentials use the application's credential-encryption layer. Access is restricted to service processes that need the credentials for authorized requests.
- Customer isolation. Credentials and workspace records are resolved for the authenticated AdvisorPPC user or workspace.
No internet-connected service can promise zero risk. We minimize the data held and apply safeguards proportionate to the Connector's function.
7. OAuth scopes and revocation
The provider consent screen shows the permissions requested before you approve them. You can revoke Google or Meta access from the provider's account settings. Where AdvisorPPC shows a disconnect control, you can also use it to remove the stored connection. Provider-side revocation stops future authorized API access after the provider applies it.
8. Retention and deletion
- Short-lived authorization records. Provider OAuth state expires after 10 minutes and can be used only once. Connector authorization codes also expire after 10 minutes and can be redeemed only once.
- OAuth credentials are retained while needed to operate the connection. They are removed from the live service when you use an available AdvisorPPC disconnect control or when we complete a valid deletion request. Revoking access at Google or Meta makes the provider credential unusable but does not by itself guarantee immediate deletion of the stored AdvisorPPC record.
- Public ChatGPT read calls do not persist provider response bodies or tool arguments in the Connector's tool-call log. Bounded write, billing, and security records can retain the tool name, user or workspace identifier, timestamp, result status, and the minimum information needed to audit the action.
- Meta deletion requests. Meta can POST a signed request to our automated Meta data deletion endpoint. After verifying Meta's signature, we remove the matching live Meta credential, Meta account mappings, and Meta-specific operational records. The status receipt stores a random confirmation code, completion status, and timestamps; it does not store the raw Meta user ID.
- Other deletion requests can be sent to support@advisorppc.com. We will delete data we control unless law or a legitimate security, billing, or dispute-resolution need requires limited retention.
Deleting AdvisorPPC data does not delete copies already sent to ChatGPT or held by Google or Meta. Those services apply their own retention and deletion controls.
9. Your rights
Depending on your location, you may have rights to access, correct, export, delete, restrict, or object to processing of personal data, and to withdraw consent. Contact us to exercise a right concerning data controlled by AdvisorPPC. Use the relevant provider's controls for data controlled by OpenAI, Google, or Meta.
10. Changes to this policy
If we make a material change, we will update the date above and provide additional notice where appropriate.
11. Contact
Questions, security reports, data requests, or deletion requests can be sent to support@advisorppc.com. Do not send passwords, OAuth tokens, or API secrets by email.