Security & data

Read by code. Not by people.

No human at ChatWithAds opens your ad accounts. Not for QA, not for support, not ever. Here's how that works, what gets stored, what doesn't, and how to revoke access in five seconds.

Read-only OAuthGDPRAES-256Revoke in 5sSOC 2 in progress
Four commitments

How the data actually moves.

Read by code
No human review · by design

No human at ChatWithAds opens your account. Not for QA. Not for "improving the model." Not for support escalation.

When you reply in the chat, a real person reads your reply. That's a feature. But the ad accounts themselves are read by code. End of list.

Read-only OAuth, always
No write scopes · ever requested

ChatWithAds physically cannot pause campaigns, change bids, edit budgets, or spend a cent of your money. The platforms enforce this. Not us.

When you connect Meta or Google, the consent screen lists read-only scopes. No write permission is requested. No write permission is granted.

Disconnect in five seconds
User-controlled · no offboarding friction

Revoke from Meta Business Settings or your Google account in about five seconds. You don't email us. You don't fill out a form. Your ad-account data is purged from our systems within 24 hours of disconnect.

Meta
Business Settings → Business assets → Connected apps → ChatWithAds → Remove
Google
Account → Security → Third-party apps → ChatWithAds → Remove
Result
Notified instantly. Data deleted within 24 hours.
Encrypted in transit and at rest
AES-256 · TLS 1.3 · region-pinned

AES-256 at rest. TLS 1.3 in transit. Region-pinned. Your data stays in your country's data center, never cross-routed.

Never sold. Never shared. Never used to train models other customers see.

What ChatWithAds never does

Five sentences, never broken.

If any of these five ever changed, this page would change with it. The list is the promise.

  • Never sold to third parties.
  • Never used to train models other customers see.
  • Never written to. No campaign edits, no budget changes, no replies on your behalf.
  • Never reviewed by a human at ChatWithAds.
  • Never retained after disconnect. 24-hour purge, 7-day fully gone.
Data retention

What we keep. For how long.

01When you connect

OAuth tokens (encrypted) and your account IDs are stored. That's it. No copy of your ad data lives on our side. The platforms get read from when you ask a question, then forgotten.

02When the AI answers

The platforms get read, the answer gets processed, the reply gets sent back to your chat. The raw underlying data isn't persisted on our side. The answer text and your question are stored for your chat history (encrypted).

03When you disconnect

OAuth tokens are deleted within minutes. Chat history is deleted within 24 hours. Within 7 days, all traces are gone, no log, no backup, no analytics shadow.

04If you ask for an export

Anytime, email help@chatwithads.com. Chat history, every weekly brief, and every captured event (with Journey) get sent as JSON. Your data is yours to export.

Compliance status

What we have. What we're working on.

What we have today
  • GDPR-compliant data handling
  • CCPA-compliant
  • Region-pinned storage (EU and US)
  • AES-256 at rest, TLS 1.3 in transit
  • Standard data processing agreement (DPA) available on request
In progress

SOC 2 Type II audit is in the observation window now. Report expected H2 2027. We'd rather publish a real audit late than wave a logo at you early.

If you need formal compliance documentation for an enterprise procurement process today, email help@chatwithads.com.

Sub-processors

Who else touches the data.

Hosting
AWS
Region-pinned by customer location
Model layer
Anthropic
Enterprise tier. No training on your data
Auth & infra
Standard SaaS stack
Full list available on DPA request
Security operations

Pen tests. Incident response. Vulnerability program.

Penetration testing

External penetration tested annually. Email us for the current report date under NDA.

Incident response

Customer-affecting incidents disclosed within 72 hours. Post-mortem published within 14 days.

Vulnerability program

Reports get a response within 24 hours, a fix path within 7 days. Email help@chatwithads.com.

Plug in safely. Stay private.

Get started →
FAQ

What security teams ask first.

Within 24 hours of disconnect, your OAuth tokens are revoked and your ad-account-derived data is deleted. Chat history is deleted within 24 hours. Within 7 days, no trace remains in our active systems. Backups are purged on a 30-day rolling window.

Something we didn't cover?

Every security email gets a response within 24 hours. Send the question, the use case, the procurement form. We'll reply with the real answer, not boilerplate.

Ad intelligence through conversation. The reasoning engine for growing brands.

© 2026 ChatWithAds. All rights reserved.