Who this policy applies to
M3Pilot AI is the application identified in this policy. The organization that provides your account administers its deployment and is the primary contact for requests concerning your account and its connected business data.
Data we access or collect
- Application identity: login email, display name, assigned role, account status and security activity needed to authenticate users and enforce permissions.
- Connection data: OAuth tokens, granted scopes, connection status and platform account identifiers. Tokens are stored server-side in encrypted form and are not shown in the interface.
- Google Ads data: authorized customer-account identifiers and names, campaign and ad-group configuration, keywords and reported search terms, ads and creative metadata, budgets, bidding settings, conversion definitions and available delivery and performance metrics for the selected period.
- Meta Ads data: authorized ad-account identifiers, names, currency and status, plus campaign, ad-set, ad, creative and available delivery and performance data. M3Pilot AI requests ads_read and does not request ads-management or lead-retrieval permission.
- User-created business content: saved settings, reporting periods, recommendation decisions, comments, conversation history and knowledge-base content that authorized users choose to add.
- Optional integrations: when separately connected, limited business data from services such as HubSpot. M3Pilot AI is configured to read aggregated deal information and does not access HubSpot Contacts.
- Technical data: timestamps, error diagnostics and security records needed to operate, protect and troubleshoot the service.
How we use data
- Authenticate users and keep each connection tied to its authorized application user.
- Retrieve, cache and display the advertising data the user asks to review.
- Generate audits, comparisons, reports and decision-support recommendations.
- Maintain user settings, saved analysis and a record of human decisions.
- Protect the service, diagnose failures and prevent unauthorized access.
M3Pilot AI does not sell connected-platform data, use it to serve ads, or use it to build advertising profiles unrelated to the user's requested analysis. Google user data is used in accordance with the Google API Services User Data Policy, including its Limited Use requirements.
Service providers and disclosures
Data may be processed by infrastructure providers that host the application and its protected storage. When an authorized user invokes an AI feature, the minimum relevant context for that request may be sent to the configured OpenAI service to generate the requested analysis. Connected-platform APIs receive only the requests needed to retrieve authorized data or manage the connection.
We may also disclose information when required by law, to protect the security and rights of users or the service, or as part of an approved organizational transition. We do not permit a service provider to use connected advertising data for its own advertising purposes.
Storage, retention and security
OAuth credentials are encrypted at rest and kept server-side. Application data is protected through authenticated access and role-based controls. No system can guarantee absolute security, so administrators should grant access only to appropriate users and remove access promptly when it is no longer needed.
Connection credentials are retained while the connection is active. Saved snapshots, settings, recommendations and user content are kept while needed for the deployment's reporting and operational history, or until they are deleted by an authorized administrator, subject to security, legal and backup-retention needs.
Your choices and rights
You can disconnect Google Ads or Meta Ads in M3Pilot AI, and you can revoke the application directly in your Google or Meta account. You may ask the administrator who issued your M3Pilot AI account to provide access to, correct, export or delete data associated with you, subject to applicable law and legitimate retention obligations. Detailed steps are available on the Data Deletion page.
Changes and contact
We update this policy when data practices or platform requirements change and show the current revision date above. Direct privacy questions and requests to the organization administrator who issued your account, using your organization's normal support channel.