The context layer
See it in action
See it on your account
Thirty minutes on your own account.
Get a free audit
By role
By industry
TRUST/SECURITY

Security.
How we protect your data — and what stays in your control.

Adwiser connects to your Google Ads account with read-only access by default. This page sets out the data we process, the controls that protect it, and the choices that remain yours. Security and procurement teams can request our full documentation at security@adwiserai.com.

LAST UPDATED · JUNE 30, 2026
At a glance

Four things that define how we handle your data.

Read-only by default.

We connect through Google OAuth and read your account. Making changes requires you to explicitly turn on write permissions — and changes can require your approval.

No end-user personal data.

Google privacy-filters its reporting before we receive it, so the integration does not ingest end-user PII. We hold your aggregate campaign data, not your customers' identities.

You control aggregated learning.

Anonymized, aggregated insights improve recommendations. You can opt out anytime — your data won't contribute, and your recommendations draw only on your own account.

Certified infrastructure.

Every provider in our stack — hosting, storage, and AI — maintains SOC 2 Type II and ISO 27001 certification. We layer our own controls on top.

01

How we access your account

Adwiser connects to your Google Ads account using Google OAuth. You control what Adwiser can do in your account settings:

  • In analysis-only mode — the default — Adwiser reads your reporting data to identify performance improvements and makes no changes to your account.
  • You may optionally allow Adwiser to apply changes — such as adjusting bids, budgets, keywords, or campaign settings. When enabled, changes can be configured to require your approval first.

This permission is controlled entirely by you and can be changed at any time. You can revoke Adwiser's access from your own Google account whenever you like. We access no other systems — no CRM, no internal tools, no customer databases.

02

We don't process end-user personal data

Google Ads reporting is aggregate by design — it reports counts, rates, and totals, not records of individual people. Wherever a slice of data is narrow enough that it could identify someone, Google withholds or aggregates it before it reaches us, as the data controller:

  • Low-volume search termsare grouped into “Other” for privacy before we can see them.
  • Audience and demographic reporting is withheld when a segment is too small.
  • Google applies minimum-user thresholds that prevent transmission of data about individuals.

Because we rely solely on Google's data and inherit these platform-level privacy controls, the integration does not ingest end-user personally identifiable information. Google also blocks advertisers from passing PII into the platform, so personal data is filtered on both ends.

03

How Adwiser learns (and your control over it)

Adwiser improves your recommendations using two layers:

  • Your-account learning — Adwiser retrieves and reasons over your own account's data to tailor recommendations to you. This is always private to you and never shared.
  • Aggregated Insights — Adwiser derives aggregated, anonymized patterns that recur across many accounts (for example, which keyword patterns tend to waste budget in a given context) to improve the quality of recommendations.

We do not train or fine-tune AI models on customer data.These benchmarks include only patterns that appear across a minimum threshold of accounts — no individual customer's data is ever exposed to another customer.

This mirrors how the ad platforms themselves operate. Google states it uses event data “aggregated across advertisers, for the overall benefit of advertisers,” while “advertiser-specific event data isn't shared with other advertisers.”

Your control: Aggregated Insights are enabled by default. You can opt out at any time in your settings — in which case your data does not contribute to the benchmarks and your recommendations draw only on your own account. Unlike the underlying ad platforms, which offer no opt-out, this is always your choice. Enterprise customers may also disable it contractually.

04

Infrastructure & certifications

Adwiser is built on independently certified infrastructure — every provider in our stack maintains SOC 2 Type II and ISO 27001 certification — and we layer our own encryption, access controls, and privacy safeguards on top. Application compute and data storage are hosted in the European Union (Frankfurt).

PROVIDER
ROLE
CERTIFICATIONS
Supabase
Database & storage
SOC 2 Type II, ISO 27001, HIPAA, PCI DSS
Fly.io
Application hosting
SOC 2 Type II, ISO 27001 data centers
Vercel
Frontend delivery
SOC 2 Type II, ISO 27001
Anthropic (Claude)
AI processing
SOC 2 Type II, ISO 27001, ISO 42001, HIPAA
05

Encryption

  • In transit: all data is encrypted using TLS 1.2 or higher.
  • At rest: all stored data is encrypted using AES-256.
06

Sub-processors

We use a limited set of trusted sub-processors and notify customers in advance of material changes. Our AI processing uses Anthropic's Claude API: data sent to Claude is aggregate, non-PII campaign data, is never used to train their models, and is automatically deleted within 7 days.

The full, current list with processing locations lives on our Subprocessors page.

07

Data retention & deletion

We retain your account data for up to 2 years of historical depth while you are a customer, to inform your recommendations. You can request deletion at any time. We remove customer data from production systems within 30 days of a deletion request or account termination and remove it from the retrieval index; residual copies in encrypted backups are purged within their 30-day rotation. Aggregated, anonymized benchmarks contain no identifiable customer data and are not subject to deletion.

08

Compliance & documentation

Our practices align with GDPR. We're happy to complete standard security questionnaires (CAIQ, SIG-Lite) for prospective customers. The following are available on request:

  • Data Processing Agreement (DPA)
  • Information Security Policy
  • Data Retention & Deletion Policy

Email security@adwiserai.com and we'll share them with your security team.

09

Contact

For security questions, to report a vulnerability, or to request documentation:

Related legal
Privacy Policy
What data we touch when you use Adwiser, and what we do with it.
Subprocessors
The third-party providers we use to deliver the Service.