Security
How MyAd protects credentials, data and account access.
Connections
- OAuth2 only — we never see or store your Google or Meta password.
- AES-256-GCM encryption for credentials and refresh tokens at rest.
- Read-only by default. Write access requires explicit approval or enabling autonomous mode.
- Revoke access any time from your Google or Meta account settings, or from MyAd.
Data handling
- Ad data is never used to train AI models.
- Ad data is never shared with competitors.
- Ad data is never sold to third parties.
- Least-privilege access controls with per-account scoping for API keys.
Application security
- All traffic is served over TLS 1.2+.
- Infrastructure runs on Cloudflare’s edge with DDoS protection and WAF.
- Secrets are stored in Cloudflare’s encrypted secret store, never in source control.
- Mutating actions are rate-limited and written to an immutable audit trail.
Compliance
- GDPR-aligned data processing; a DPA is available on request.
- Data residency can be discussed for Enterprise customers.
- Sub-processors are listed in the privacy policy.
Reporting a vulnerability
Email security@myad.si. We acknowledge reports within one business day.