Adbrick Medya Dijital Hizmet Teknoloji Anonim Şirketi (“AdBrick”, “we”, “our”, “us”) operates AdBrick AI, an agency-operated paid-media control plane available at https://adbrick.ai and the product application at https://dev.adbrick.ai.
This Privacy Policy explains what information AdBrick AI collects, including information received through Google, Meta, and TikTok authorizations; how we use, store, disclose, retain, and protect it; and how an authorized user can disconnect a platform or request deletion.
1. Who this policy covers
- Authorized operators and members invited to a tenant in AdBrick AI.
- People who connect advertising or measurement platforms to a tenant.
- Visitors to our public website pages (such as this Privacy Policy and Terms).
AdBrick AI is a business product. Access to tenant workspaces is invitation-based and authenticated. We do not offer open public self-signup for client advertising accounts.
2. Information we collect
2.1 Account and membership information
- Name, email address, role/membership, and organization/tenant identifiers.
- Authentication and access-control signals used to verify authorized operators.
- Support communications and operational contact details.
2.2 Client operating context
- Business and media-operating information entered in onboarding/settings (for example offer, markets, budget bands, naming rules, conversion definitions, and guardrails).
2.3 Platform connection and advertising data
- OAuth access and refresh credentials, granted permissions, connection status, and selected account or asset identifiers.
- Google Ads customer/account details, campaigns, ad groups, assets, keywords, search terms, recommendations, conversion settings, budgets, status, and performance metrics.
- GA4 account/property identifiers and names, the authorizing Google account email, access-binding information, and key-event or measurement configuration.
- Meta Business, ad account, Page, pixel, and catalog identifiers and names, advertising configuration, and performance data. We store a non-reversible operator-correlation value rather than a raw Meta user ID where applicable.
- TikTok Business Center connection metadata and OAuth credentials. The current TikTok integration is connection-only as described in Section 3.4.
2.4 Technical and security data
- IP address, device/browser information, timestamps, and request logs.
- Security, audit, and incident records for material actions and connection events.
2.5 Product, AI, and operational records
- Chat sessions and messages, prompts, model responses, read-only platform tool results, recommendations, and user feedback.
- Model selection, processing status, token-usage and cost metadata, error details, and redacted diagnostic traces.
- Plans, approvals, execution manifests, changes, rollback information, and audit records.
- Browser-stored preferences such as active tenant, locale, and model/depth selection.
We receive information directly from authorized users, their organization, connected platforms, authenticated identity services, and automatically from use of the service. AdBrick AI does not request Meta lead-retrieval permission and is not designed to ingest lead-form personal information.
3. Platform OAuth scopes and permissions we request
We request only permissions used by an operator-selected connection and the product capabilities described below. Google and Meta names are the exact values configured by AdBrick AI. TikTok API for Business uses provider-configured products rather than a fixed consumer-style scope list in our authorization request.
3.1 Google Ads
OAuth scope:
https://www.googleapis.com/auth/adwords(Google Ads API / AdWords scope)
This allows AdBrick AI to:
- Read Google Ads account, campaign, ad group, asset, keyword, and performance data.
- Prepare recommendations and, only after human approval, execute permitted mutations such as status, budget, keyword, or campaign-structure changes on connected accounts.
3.2 Google Analytics 4 (GA4)
OAuth scopes:
openidhttps://www.googleapis.com/auth/userinfo.emailhttps://www.googleapis.com/auth/analytics.readonlyhttps://www.googleapis.com/auth/analytics.manage.users.readonly
This allows AdBrick AI to:
- Identify the consenting Google account email.
- Discover and read GA4 accounts/properties the operator can access.
- Verify property access/admin binding and read key-event or measurement configuration needed for readiness.
The current GA4 integration uses Analytics Admin API reads for property discovery, access verification, and key-event readiness. It does not currently retrieve GA4 performance reports. Browser consent banners and end-user consent collection remain the client’s responsibility; AdBrick AI cannot prove browser consent behavior through API reads alone.
3.3 Meta (Facebook Login for Business / Marketing API)
Meta permissions are configured in our Facebook Login for Business configuration and granted during Meta’s consent screen (including any Business Manager / ad account assets the operator selects or creates there):
ads_managementbusiness_managementpages_show_listpages_read_engagementcatalog_management
This allows AdBrick AI to:
- Receive a system-user token scoped to the Business Manager / ad accounts / Pages / pixels / catalogs selected in consent.
- Discover and map those assets to a tenant.
- Read Meta advertising and related asset data for analysis and recommendations.
- Execute permitted advertising changes only after human approval.
We intentionally do not request leads_retrieval or other
lead-PII retrieval permissions. Lead form personal data is out of scope for AdBrick AI.
3.4 TikTok
AdBrick AI uses the TikTok API for Business authorization flow for its registered
Business Center application. Our current implementation does not send a separate OAuth
scope parameter. Authorized products or permissions are controlled by
TikTok’s app configuration and may be returned by TikTok with the token response.
The current TikTok integration only:
- Registers the selected Business Center connection for a tenant.
- Stores the connection metadata and access/refresh credentials securely.
- Does not currently call TikTok Marketing API reporting or mutation endpoints.
If TikTok reading or mutation capabilities are enabled later, we will update this policy and the TikTok app review/configuration before using the connection for those purposes. Material mutations will remain subject to human approval.
4. How we use information
We use information only as needed to:
- Authenticate and maintain the connection for the selected tenant.
- Show account health, readiness, and operating context to authorized operators.
- Analyze connected Google Ads and Meta data and generate user-requested recommendations inside AdBrick AI.
- Execute human-approved Google Ads or Meta media changes on connected accounts.
- Provide AI-assisted chat and analysis as described in Section 5.
- Keep audit, security, incident, and compliance records.
- Provide support and protect the service against abuse.
- Meet legal obligations and enforce our Terms.
Human approval: material spend-affecting or structural advertising mutations require an authorized human approval step before execution.
5. AI-assisted processing
When an authorized operator uses AdBrick AI’s Lab, chat, analysis, or recommendation features, relevant business context, the operator’s message, and selected read-only results from connected advertising platforms may be included in a prompt sent to the model provider selected for that session. This is done only to return the requested analysis or operate the user-facing feature.
Our primary model infrastructure is Google Cloud Vertex AI. AdBrick AI can also be configured to use Anthropic or OpenAI models. If one of those providers is enabled and selected, the relevant prompt content is processed by that provider on our behalf. We do not use connected platform data to train general-purpose AI or machine-learning models. Material advertising actions proposed by AI require authorized human approval.
6. Google API Services User Data Policy — Limited Use
AdBrick AI’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- We use Google user data only to provide or improve user-facing features of AdBrick AI that are prominent in the application.
- We do not sell Google user data.
- We do not use or transfer Google user data for advertising, retargeting, data brokerage, credit-worthiness, or lending purposes.
- We transfer Google user data only to service providers acting on our behalf when necessary to provide a prominent user-facing feature, for security, or where required by law.
- We do not allow humans to read Google user data unless the user has affirmatively agreed to the specific access, it is necessary for security or legal compliance, or it is required for support requested by the user, and then only under appropriate access controls.
- We do not use Google user data to train general-purpose AI or machine-learning models.
7. Storage, security, and tenancy
- Platform OAuth and system-user credentials are stored in Google Cloud Secret Manager, not in public pages or browser bundles.
- Operational records are stored in access-controlled Google Cloud services, including Firestore and BigQuery.
- Data is tenant-scoped. Operators can access only tenants they are authorized for.
- We use HTTPS/TLS in transit, cloud encryption at rest, least-privilege service identities, authenticated product access, audit records, and server-side authorization checks.
- For Meta Graph API server calls, we use app-secret proofing and other server-side controls where applicable.
Our product workloads are currently configured primarily in Google Cloud European regions for operational storage and compute. Vertex AI may use a global endpoint. Cloudflare hosts and protects the public website.
8. Disclosure and service providers
We do not sell personal information or connected advertising-account data. We disclose information only to:
- Google Cloud Platform for hosting, storage, identity/security infrastructure, and Vertex AI inference.
- Cloudflare for public-site hosting, delivery, and security.
- Anthropic or OpenAI only when the corresponding model integration is enabled and selected for a user-facing AI feature.
- The platforms you connect (Google, Meta, TikTok, etc.), as needed to perform the authorized actions.
- Professional advisers or authorities when required by law or to protect rights, safety, and security.
- A successor entity in a corporate transaction, under continued confidentiality/privacy obligations.
We do not share connected platform data with other AdBrick tenants. Agency operators act only within authorized tenant memberships.
9. Retention
- Short-lived OAuth authorization state is designed to expire after approximately 10 minutes.
- Operational incident records are normally retained for 30 days; Meta privacy-request status records are normally retained for 90 days.
- Connection metadata and encrypted credentials are retained while a connection is active. Disconnecting marks the product connection revoked and prevents routine use, but does not by itself immediately erase every Secret Manager version or audit record.
- Chats, plans, approvals, execution and connection audits, and redacted telemetry are retained while needed to provide the service, preserve accountability for advertising actions, resolve disputes, maintain security, and meet legal obligations.
A verified deletion request starts our manual deletion process for active credentials and personal information. We delete or de-identify information unless retention is required for security, fraud prevention, legal claims, accounting, or another legal obligation. Provider-side data remains subject to the connected provider’s own retention practices.
10. Your choices, disconnect, and deletion
- Disconnect or revoke: depending on the platform and current product version, an authorized operator can disconnect in AdBrick AI settings, revoke access in Google Account permissions, Meta Business Integrations/app settings, or TikTok authorization settings, or contact us for assistance.
- Access / correction / deletion: depending on your location, you may request access, correction, deletion, or export of personal data.
- How to request: email privacy@adbrick.ai from an authorized address. Describe the tenant, connected platforms, and the request type.
Revoking access at a provider prevents future provider access but does not automatically delete AdBrick audit records. To request deletion of information held by AdBrick, follow our public Data Deletion Instructions. We verify the requestor’s authority before deleting tenant or platform-connection information and respond within applicable legal time limits.
11. Cookies, local storage, and public-site requests
The public adbrick.ai site does not currently use optional analytics cookies. Cloudflare may process IP address and request information to deliver and protect the site, and the site requests its web font from Google Fonts. The authenticated product uses browser local storage for functional preferences such as active tenant, locale, and model/depth selection. If optional analytics or advertising cookies are introduced, we will update this notice and obtain consent where required.
12. Legal bases and international transfers
Where applicable, we process information to perform our agreement, follow an operator’s authorization, pursue legitimate interests in operating and securing a B2B service, comply with law, or based on consent. Data may be processed in Turkey, the EU/EEA, the United States, or other locations where our providers operate. We use appropriate contractual, organizational, and technical safeguards for cross-border transfers where required.
13. Privacy rights
Depending on applicable law, including Turkey’s KVKK or the GDPR, an individual may have rights to request access, correction, deletion, restriction, objection, portability, or information about processing and transfers. Requests may be sent to privacy@adbrick.ai. We may ask for information needed to verify identity, authority, and tenant membership.
14. Children’s privacy
AdBrick AI is a B2B service and is not directed to children under 18. We do not knowingly collect children’s personal data.
15. Changes to this policy
If we change how we access, use, store, or share Google, Meta, TikTok, or other platform user data in a material way, we will update this Privacy Policy and, where required, obtain new consent before using the data for a new purpose.
16. Contact
Adbrick Medya Dijital Hizmet Teknoloji Anonim Şirketi
Esentepe Mah. Kore Şehitleri Cad. No:48-50 İç Kapı No:2
Şişli/İstanbul, Turkey
Privacy: privacy@adbrick.ai
Legal: legal@adbrick.ai
This page is publicly available at https://adbrick.ai/privacy and is linked from our homepage and Terms.