Privacy Policy
Effective 3 September 2026
This policy covers AdPilot Meta, a separate service operated by Jack Mars ADS.
1. Controller
Jack Mars ADS, Ukraine (“AdPilot”, “we”, “us”) provides an advertising technology service for businesses that choose to connect authorized Meta assets. Contact: hello@adpilot.com.ua.
2. Data we process
- authorization data, such as the authenticated user, business relationship, granted permissions and access status;
- identifiers for authorized Business Portfolios, ad accounts, campaigns, ad sets, ads and creatives;
- advertising configuration, delivery and performance data available through the Meta Marketing API;
- security and audit records, including timestamps, request status and technical diagnostics. Access tokens and secrets are not written to ordinary application logs;
- support communications you send to us.
3. Why we use data
Only to authenticate authorized users, discover permitted assets, provide reporting and diagnostics, prepare client-requested recommendations, secure the service, meet legal obligations and respond to support or deletion requests.
4. Meta Platform Data
Meta Platform Data is processed only for the business that authorized it and only to provide the requested AdPilot service. We do not sell Platform Data, move it between client workspaces, use it for unrelated advertising, or use it to train AdPilot or third-party AI models.
5. MCP and client-selected AI services
An authorized user may work through a compatible MCP client they select. AdPilot returns only data permitted for that authenticated session. If a client enables an external AI provider, that provider processes prompts and responses under the client’s agreement and the provider’s terms. AdPilot does not independently send Meta Platform Data for model training or advertising.
6. Sharing and providers
Data may be disclosed only to infrastructure and security providers required to operate the service, a client-selected integration, or an authority where law requires it. We do not sell personal data.
7. Retention and security
We retain data only while needed to provide and secure the service, resolve disputes and meet legal obligations. Authorization data is removed or rendered unusable after revocation. Valid deletion requests are completed within 30 days unless law requires otherwise. We use least-privilege access, client isolation, encryption in transit and separate protected secret storage.
8. Your choices and rights
You may revoke access through Meta, request access or correction, object to processing, or request deletion. See our Data Deletion Instructions. We may verify your identity and authority over the relevant business.
9. Changes
We may update this policy as the service or legal requirements change. The date at the top identifies the current version.