Security

AdPilot connects to your Google Ads account, so we treat security as the product — not an afterthought. Here’s how your data and your account are protected, in plain language.

Your Google connection is encrypted

When you connect Google Ads, we never see or store your Google password. Google gives us a limited access token instead, and we store it encrypted at the application level with AES-256-GCM — the same class of encryption banks use. Even someone with a copy of our database could not read it without a separate key we keep apart.

Encrypted in transit and at rest

Every connection between you and AdPilot is encrypted in transit over TLS (HTTPS). Our database is encrypted at rest by our provider (Neon), so your data is protected on disk as well as on the wire.

Every change is approved by you — and recorded

AdPilot never changes your account on its own. The AI recommends; you decide. Nothing is applied to Google Ads until you click to approve it. Every proposed and applied change is written to a permanent Change History — what changed, the before and after values, who approved it, and when — so you can always see exactly what happened and undo it.

Built-in guardrails

Your one-click approval is the only gate a change passes — no hidden extra steps — and hard limits still apply: campaigns can never be deleted through AdPilot, and shared budgets are never touched. A before-change snapshot is captured every time, every applied change lands in your Change History with one-click Revert, and a full audit log records who changed what, and when — so there is always a way back.

We only use Google data to run the service

AdPilot’s use of information from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. We use your Google Ads data only to provide AdPilot — analysis, recommendations, and reports. We do not sell it and do not use it for advertising of our own. You can revoke AdPilot’s access at any time from your Google account or from AdPilot’s settings.

Payments never touch our servers

Billing is handled entirely by Stripe, a PCI-DSS Level 1 payment provider. Your card details go straight to Stripe — we never see or store them.

Delete your data any time

You can ask us to delete your data at any time. On request we remove your profile, chat history, and Google access tokens, and we strip personal identifiers from the change records we are required to keep for legal reasons. See our Privacy Policy for the full detail.

Found something that looks off, or have a security question? Email junaid@heyadpilot.com. See also our Privacy Policy and Terms of Service.