Skip to main content
Adspirer never sees your ad platform passwords. All authentication uses OAuth 2.1 with — the same standard used by banking apps.

Authentication: OAuth 2.1 with PKCE

When you connect an ad platform (Google Ads, Meta, LinkedIn, TikTok), Adspirer uses OAuth 2.1 with PKCE — the same standard used by banking apps and enterprise software.

What This Means

  • Your passwords stay with Google/Meta/Amazon/LinkedIn/TikTok. Adspirer never receives, stores, or transmits your login credentials. (ChatGPT Ads has no login — you paste an OpenAI Advertiser API key, which Adspirer stores encrypted and never exposes to the AI client.)
  • PKCE prevents interception. Every authentication generates a cryptographic proof that only your specific session can complete. Even if someone intercepts the authorization code, they can’t use it.
  • Scoped permissions. You authorize exactly what Adspirer can do — read campaign data, create ads, manage budgets. Nothing more.
  • Meta approved access. Adspirer has Meta approved Ads Management Standard Access, meaning Meta has verified the app’s use of their Marketing API. Meta’s account enforcement systems (security reviews, restrictions, account disabling) operate independently from Adspirer and are governed by Meta’s own Community Standards and policies.
  • Google agency-level approval. Google reviewed and classified Adspirer as an agency, full-service ad platform for the Google Ads API and granted Standard Access — verifying how Adspirer uses the API and lifting the daily operations cap. (This is the Google Ads API “external full-service” classification — not the separate Google Partners program.)
  • Reviewed by the AI platforms. Adspirer’s Claude connector is Anthropic verified, meaning Anthropic has reviewed it for quality and security. Its Cursor plugin is Verified by Cursor, and the same listing powers Grok Bot. Its ChatGPT plugin is reviewed and published by OpenAI. Install from those listings rather than adding a custom connector by URL.

Token Lifecycle

AI client tokens are stored only as hashes and are refreshed automatically. If a token expires or is revoked, your AI client prompts you to re-authenticate.

API Key Authentication

For remote servers, Docker containers, and CI/CD pipelines where browser-based OAuth isn’t possible, Adspirer supports Personal Access Tokens (API keys).

How API Keys Work

  1. You generate a key from the Adspirer dashboard at adspirer.ai/keys
  2. The key starts with sk_live_ and is shown once — copy it immediately
  3. Adspirer stores a SHA-256 hash of the key — the raw token is never stored
  4. On each request, the server hashes the provided token and looks up the hash in the database

API Key Security Properties

Revoking API Keys

Revoke a key instantly from adspirer.ai/keys. Revoked keys return a 401 error on the next request. The key record is preserved for audit trail (revocation timestamp visible in admin).

API Keys vs OAuth

What Data Adspirer Accesses

Reads:
  • Campaign names, statuses, budgets
  • Performance metrics (spend, conversions, CPA, ROAS, CTR)
  • Keywords, ad copy, targeting settings
  • Asset metadata (image/video dimensions, file sizes)
Writes (with your confirmation):
  • Create campaigns (always created PAUSED)
  • Update budgets and bids
  • Pause or resume campaigns
  • Add keywords, ad copy, or extensions
Never accesses:
  • Your ad platform login credentials
  • Billing/payment information (credit cards, bank accounts)
  • Personal data beyond what’s shown in ad account settings
  • Data from other ad accounts you haven’t explicitly connected

Campaign Safety

Every write operation has built-in safety:
  • Campaigns created PAUSED — You review before any money is spent
  • User confirmation required — Your AI assistant asks before budget-affecting actions
  • No automatic retries — If a campaign creation fails, it reports the error instead of retrying
  • Read-before-write — Research and validation always happen before creation

Revoking Access

You can disconnect Adspirer at any time:
  1. From Adspirer: Visit adspirer.ai and disconnect the platform
  2. From the ad platform: Revoke access in your platform’s security settings:
Revoking from either side immediately stops all tool access.
  1. API Keys: Visit adspirer.ai/keys and click Revoke on any active key. The key is invalidated immediately.

Infrastructure Security

Data Handling & Compliance

Adspirer is operated by BETSONAGI LLC, d/b/a Adspirer, a United States company. This section summarizes how customer data is stored, protected, shared, retained, and deleted. The Privacy Policy is the governing document.

Data Location

All customer data is stored and processed in the United States, on Google Cloud Platform (us-central1). Every subprocessor listed below processes data in the United States. Where international transfer safeguards are required, we use appropriate mechanisms such as Standard Contractual Clauses.

Security Controls

Subprocessors

The advertising platforms you connect (Google, Meta, LinkedIn, TikTok, Amazon, Microsoft) and the AI client you use are connected at your direction with your own authorization. They are not Adspirer subprocessors.

AI and Data Use

  • Adspirer does not use your data to train AI models, and AI model providers we use are not permitted to train on it.
  • Adspirer does not sell your data or use it for advertising.
  • Adspirer does not receive your full conversations with your AI client, only the tool requests it sends.

Retention and Deletion

After you leave: when you delete your account or ask us to delete your data, everything is deleted within 90 days, including tool call logs and backups. The only exception is billing and legal records we are required to keep. To request deletion, email support@adspirer.com. See Privacy Policy, Section 4.

Incident Response

If we learn of a security incident that affects your personal data, we notify affected users without undue delay and as required by law. When an incident involves data received through a partner AI platform, we also notify that platform within the time its terms require. For Meta’s Muse connector platform, that is within 48 hours. See Privacy Policy, Section 6.

Government and Third-Party Requests

We disclose user data only in response to a valid, legally binding request, such as a subpoena, court order, or warrant. We review each request for legal validity and scope, challenge requests that are overbroad or unlawful, and disclose only the minimum data needed. Where the law allows, we notify the affected user first. No government has direct or bulk access to Adspirer data. To submit a request, email support@adspirer.com with the subject line “Legal Process Request”. Include the signed legal process, the requesting authority and an official contact, the account the request concerns, and the specific data and date range sought. We verify every requester and do not respond to informal or incomplete requests. The full requirements are in Privacy Policy, Section 3.

Data Processing Addendum

Business, agency, and enterprise customers can request a Data Processing Addendum (DPA) at support@adspirer.com.

FAQ

No. Your data is isolated to your Adspirer account. No data is shared between users, used for training, or sold to third parties.
No. All campaigns are created PAUSED, and budget changes require explicit user confirmation. Even autonomous agents (like Codex) follow this rule.
Your ad campaigns continue running normally — they’re managed by Google/Meta/LinkedIn/TikTok, not by Adspirer. You just can’t make changes via AI until the service recovers. Downtime does not affect live campaigns.
Last modified on October 5, 2026