Spendqo, Inc. ("Spendqo," "we," "us," or "our") provides a service that lets you connect advertising platforms to AI assistants through the Model Context Protocol (MCP) and an optional in-app AI agent. This Privacy Policy explains how we collect, use, store, and share information when you use our marketing website, web application, and related services (collectively, the "Service").
By using the Service, you agree to this Privacy Policy. If you do not agree, do not use the Service. For questions, contact us at [email protected].
We collect the following categories of information:
We use collected information to:
When you connect Google Ads, you authorize Spendqo via Google OAuth using scopes such as https://www.googleapis.com/auth/adwords (Google Ads API) together with openid, email, and profile so we can identify the Google account you connected.
Depending on the tools you use, we may access Google user data and Google Ads account data such as customer IDs, campaign structure, ad groups, ads, and performance metrics. We access this data only to provide features you request through Spendqo and compatible MCP clients (for example, listing accessible accounts or searching campaigns).
After you connect, we may call Google's OpenID userinfo endpoint once and store a limited identity snapshot (subject id, email, and/or name) with your connection metadata so Connections can show which Google account is linked. We do not use Google Sign-In as Spendqo's login method.
We store OAuth tokens encrypted at rest. We store connection metadata, operational logs, and—when enabled—encrypted, time-limited copies of advertising API / MCP response data as described in this policy, solely to provide Service features you request (including remote MCP, the in-app agent, usage history, audit, and support). We do not sell Google user data or use it for advertising unrelated to your use of the Service.
You may disconnect Google Ads in your Spendqo dashboard at any time. Disconnecting removes stored OAuth tokens and the identity snapshot for that connection. You may also revoke Spendqo's access in your Google Account permissions at https://myaccount.google.com/permissions.
Spendqo's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Google user data is used only to provide or improve user-facing features you request, for security and abuse prevention, to comply with applicable law, or with your consent. Human access to Google user data is limited to what is necessary for these purposes (for example, support at your request, security investigations, or legal compliance).
We do not use Google user data for serving advertisements, sell Google user data to third parties, or use it for purposes unrelated to the Service's functionality.
We do not use your Google Ads or other Google user data to train or fine-tune general-purpose AI models.
For more information, see the Google API Services User Data Policy at https://developers.google.com/terms/api-services-user-data-policy.
When you connect LinkedIn Ads, you authorize Spendqo via LinkedIn OAuth. Depending on the scopes you approve, we may access (a) LinkedIn advertising account data via Marketing API scopes such as r_ads, r_ads_reporting, rw_ads, and r_organization_admin (account identifiers, campaigns, creatives, reporting metrics, and organization name/website lookups needed for supported MCP tools), and (b) limited member identity via Sign In with LinkedIn using OpenID Connect scopes openid, profile, and email.
After you connect, we may call LinkedIn's OpenID Connect userinfo endpoint once and store a limited identity snapshot (subject id, email, and/or name) with your connection metadata so the Connections page can show which LinkedIn member account authorized the ads connection. We do not use Sign In with LinkedIn as Spendqo's login method, and we do not market LinkedIn OpenID Connect as identity verification.
We use LinkedIn data only to provide features you request, store OAuth tokens encrypted at rest, and retain connection metadata, operational logs, and encrypted MCP/API response payloads as described in this policy. Advertising account administration and reporting data we store is retained no longer than one year, consistent with LinkedIn Marketing API data storage requirements. We do not sell LinkedIn data, and we do not use LinkedIn Content to target advertisements to individuals.
You may disconnect LinkedIn in Spendqo at any time. Disconnecting deletes that connection's OAuth tokens and stored identity snapshot. You may also revoke Spendqo's access through your LinkedIn account settings. To request deletion of other LinkedIn-derived data we retain, email [email protected].
When you connect Reddit Ads, you authorize Spendqo via Reddit OAuth. Depending on the scopes you approve (such as adsread and identity), we may access Reddit advertising data including businesses, ad accounts, campaigns, ad groups, ads, audiences, and reporting needed for supported MCP tools, and may receive your Reddit username and account id to show which Reddit account you connected.
After you connect, we may call Reddit's identity API once and store a limited identity snapshot (account id and/or username) with your connection metadata for the Connections dashboard. We do not use Reddit as Spendqo's login method.
We use Reddit data only to provide features you request, store OAuth tokens encrypted at rest, and retain connection metadata, operational logs, and encrypted MCP/API response payloads as described in this policy. We do not sell Reddit data.
You may disconnect Reddit in Spendqo at any time. Disconnecting removes stored OAuth tokens and the identity snapshot for that connection. You may also revoke access through your Reddit account or application permissions.
When you connect Meta Ads, you authorize Spendqo via Facebook Login OAuth. Depending on the scopes you approve (such as ads_read, business_management, pages_show_list, and email), we may access Meta advertising data including ad accounts, campaigns, ad sets, ads, creatives, and performance insights across Meta technologies (including Facebook and Instagram placements) needed for supported MCP tools, and may receive your Meta user id, name, and/or email to show which Meta account you connected.
After you connect, we may call Meta's Graph /me endpoint once and store a limited identity snapshot with your connection metadata for the Connections dashboard. We do not use Meta Login as Spendqo's login method.
We use Meta data only to provide features you request, store OAuth tokens encrypted at rest, and retain connection metadata, operational logs, and encrypted MCP/API response payloads as described in this policy. We do not sell Meta data.
You may disconnect Meta in Spendqo at any time. Disconnecting removes stored OAuth tokens and the identity snapshot for that connection. You may also revoke access through your Facebook account settings or Meta Business integrations.
When you connect Microsoft Advertising, you authorize Spendqo via OAuth using the sign-in method that matches your ads.microsoft.com account: Microsoft account sign-in (Microsoft Entra ID OAuth with scopes such as openid, offline_access, and https://ads.microsoft.com/msads.manage), or Google account sign-in (Google OAuth with profile and email scopes only).
Google sign-in for Microsoft Advertising is separate from connecting Google Ads in Spendqo. It does not grant the Google Ads API scope and is not described in the Google Ads user data section above.
Depending on the tools you use, we may access Microsoft Advertising data such as customer and account identifiers, campaigns, ad groups, ads, keywords, audiences, conversion goals, reporting metrics, and related account structure needed for supported MCP tools.
After you connect, we may call Microsoft Advertising User/Query once and store a limited identity snapshot (user id, username, name, and/or email) with your connection metadata so Connections can show which Microsoft Advertising user authorized the connection. We do not use Microsoft or Google sign-in for Microsoft Advertising as Spendqo's login method.
We use Microsoft Advertising data only to provide features you request, store OAuth tokens encrypted at rest, and retain connection metadata, operational logs, and encrypted MCP/API response payloads as described in this policy. We do not sell Microsoft Advertising data.
You may disconnect Microsoft Advertising in Spendqo at any time. Disconnecting removes stored OAuth tokens and the identity snapshot for that connection. You may also revoke access through your Microsoft account app permissions or, if you connected with Google sign-in, your Google Account permissions at https://myaccount.google.com/permissions.
Spendqo exposes an MCP endpoint that compatible assistants (such as Claude, ChatGPT, Cursor, or VS Code) can call after you authenticate with Clerk. Spendqo brokers API requests to advertising platforms and may retain encrypted tool/API response data as described above. We do not control how third-party assistants process, display, or retain prompts, tool outputs, or conversation history beyond what Spendqo stores.
When you use Spendqo's in-app AI agent, conversation content and tool results may be sent to the model provider you configure (bring-your-own Anthropic API key) for real-time inference to generate responses. We do not use your advertising platform data or chat content to train or fine-tune general-purpose AI models.
Review the privacy policies of any third-party AI client you connect to Spendqo. Data those clients retain is governed by their terms, not this policy.
We use trusted service providers to operate the Service. They process data on our behalf under contractual obligations:
| Provider | Purpose |
|---|---|
| Clerk | User authentication and session management |
| Supabase | Database hosting for connections, encrypted tokens, operational logs, encrypted MCP/API response payloads, chat, and related Service data |
| Vercel | Application hosting and website analytics |
| Anthropic | AI inference for the in-app agent when you supply your own Anthropic API key (BYOK) |
| OAuth and Google Ads API (when you connect Google Ads); Google OAuth sign-in for Microsoft Advertising (when you connect with Google) | |
| OAuth, LinkedIn Marketing/Advertising APIs, and Sign In with LinkedIn using OpenID Connect for connection identity (when you connect LinkedIn) | |
| OAuth and Reddit Ads API (when you connect Reddit) | |
| Meta | OAuth and Meta Marketing API (when you connect Meta Ads) |
| Microsoft | OAuth and Microsoft Advertising API (when you connect Microsoft Advertising with a Microsoft account) |
OAuth access and refresh tokens are encrypted at rest using industry-standard symmetric encryption. Tokens are decrypted only on our servers to perform API requests you authorize.
Stored MCP and advertising API response payloads are redacted for obvious secrets, encrypted at rest, and associated with your user and (when applicable) organization identifiers. Human access is limited to support, security, and compliance needs.
Internal gateway endpoints that proxy provider APIs require a shared secret and are not exposed to end users. We apply access controls, monitor for abuse, and follow security practices appropriate to the sensitivity of the data we process.
No method of transmission or storage is completely secure. If you believe your account has been compromised, contact us at [email protected] and disconnect affected providers.
We retain account and connection data while your account is active and as needed to provide the Service. When you disconnect a provider, we delete that connection record (including OAuth tokens and any stored platform identity snapshot such as email or username) and update connection status. Encrypted MCP/API response payloads for that connection are kept for a short grace period (30 days) so that reconnecting after a temporary disconnect does not erase recent history; if you do not reconnect, those payloads are then deleted. Payloads may also expire earlier under the retention periods below.
Operational usage metadata is retained for a limited period for security, billing, and product analytics, then deleted or aggregated.
Encrypted MCP/API response payloads are retained by default for up to six months. For LinkedIn advertising account administration and reporting data, retention does not exceed one year. Expired payloads are deleted automatically.
In-app chat messages and artifacts are retained while your account (or organization workspace) remains active unless you delete them or request deletion.
We may retain certain records longer where required by law or to resolve disputes.
To request account deletion or purge of stored advertising data, email [email protected].
Depending on your location, you may have rights to access, correct, delete, or export personal data, or to object to or restrict certain processing.
You can disconnect advertising platforms in the Spendqo web app and revoke OAuth access with each platform directly. To request account deletion or exercise privacy rights, email [email protected]. We will respond within the timeframes required by applicable law.
We and our subprocessors may process data in the United States and other countries. Where required, we rely on appropriate safeguards for cross-border transfers.
The Service is not directed to children under 16, and we do not knowingly collect personal information from children. Contact us if you believe we have collected such information.
We may update this Privacy Policy from time to time. We will post the updated policy on this page with a revised "Last updated" date. Material changes that affect how we use advertising platform data will be reflected here before or when those changes take effect, and where required we will obtain your consent.
Continued use of the Service after an update constitutes acceptance of the revised policy.
Spendqo, Inc.
Email: [email protected]
For OAuth or advertising data questions, reference this Privacy Policy URL when contacting us.