Privacy Policy
Last updated July 25, 2026
This Privacy Policy explains how AdPilot(“AdPilot”, “we”, “us”), a product of Cruq AI, collects, uses, and protects information when you use our advertising management platform at adpilot.cruq.ai(the “Service”).
Information we collect
- Account information. When you sign up, our authentication provider (Clerk) processes your name, email address, and organization membership.
- Connected ad accounts. When you connect a Meta (Facebook/Instagram) or Google Ads account, we receive OAuth access and refresh tokens and your ad account identifiers. Tokens are stored encrypted at rest (AES-256-GCM) and are used only to perform actions you request.
- Advertising data. To provide reporting and let the assistant manage campaigns, we read campaign structures and performance metrics (impressions, clicks, spend, conversions) from the platforms you connect, and we store campaigns you create through the Service.
- Chat content. Messages you send to the AI assistant are processed to fulfill your requests.
- Technical data. Standard logs (IP address, timestamps, error diagnostics) needed to operate and secure the Service.
How we use information
- To create, manage, and optimize the ad campaigns you direct.
- To display analytics and generate recommendations.
- To authenticate you and keep your workspace’s data isolated.
- To operate, secure, debug, and improve the Service.
We do not sell your personal information or your advertising data, and we do not use it for advertising to you.
Google API Services — Limited Use
AdPilot’s use and transfer of information received from Google APIs adhere to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained from the Google Ads API is used solely to provide and improve user-facing features within the Service, is not transferred to third parties except as necessary to provide the Service or as required by law, and is not used for advertising or sold.
Meta Platform Data
Data received from Meta’s platforms (the Marketing API and Instagram Graph API) is used only to provide the campaign management and reporting features you request, in accordance with the Meta Platform Terms and Developer Policies. We retain Meta Platform Data only as long as needed to provide the Service and delete it upon disconnection or account deletion.
Sub-processors
We rely on the following service providers to operate the Service:
- Vercel — application hosting.
- Neon — managed PostgreSQL database.
- Clerk — authentication and organization management.
- OpenRouter and the AI model providers it routes to — processing assistant requests.
- Meta and Google — the advertising platforms you connect.
Data retention & deletion
You can disconnect any ad account at any time, which revokes and deletes the associated stored tokens. To delete your account and associated data, contact us at adpilot@cruq.ai. We delete or anonymize data when it is no longer needed to provide the Service, unless retention is required by law.
Security
We encrypt platform credentials at rest, scope every data access to your organization, transmit data over TLS, and require approval before any action that would spend money. No method of transmission or storage is completely secure, but we work to protect your information using industry-standard measures.
Your rights
Depending on your location, you may have rights to access, correct, export, or delete your personal data. To exercise these rights, contact adpilot@cruq.ai.
Changes
We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above.
Contact
Questions about this policy? Email adpilot@cruq.ai.
