MadderHelp Request early access

What Madder does with your data

Madder reads campaigns, metrics and account names, writes only the changes you approve, encrypts your platform token, and never sees passwords or cards.

Checked 6 Sep 2026

Three minutes to read. This is the disclosure Meta and Google require of an app that uses their ad data.

Before you start#

  • Nothing. This applies from the moment you connect an account.

1. What Madder reads#

From each connected ad account:

  • the account's id, name, currency and timezone;
  • campaigns, ad sets and ads: names, status, objective, daily budget;
  • daily delivery metrics: spend, impressions, clicks, leads, and the cost per lead derived from them;
  • the id of the user who granted access and the permissions granted.

Madder reads nothing outside the ad accounts you granted. It does not read your Facebook profile, posts, friends, Gmail, or anything on a Google account beyond Google Ads.

2. What Madder writes#

Only proposals you approved: create a paused campaign, pause, resume, raise or lower a daily budget. One more write exists: Create my Pixel in the tracking wizard creates (or finds) a web dataset in your Meta ad account, one per account, so you can paste the snippet. Every write is recorded against the person who approved it.

3. What Madder never reads#

  • Your platform password. You sign in on Meta's or Google's own page; Madder receives a token, not a password.
  • Card numbers, payment methods, invoices or spending limits on any platform.
  • Data from ad accounts you did not grant.

4. How the token is protected#

The platform token is encrypted with AES-256-GCM before it is stored. It is never logged, never sent to your browser, never placed in a link. The web app and the agent cannot read it back; only the executor that applies approved changes and syncs metrics can, and only in memory. A server without the encryption key refuses to start.

5. How long things are kept#

  • Run history (the agent's step-by-step journal and its events): purged after 30 days.
  • Proposals and approvals: kept as your audit trail while the workspace exists.
  • Metrics and campaign facts: kept while the account is connected; kept after a disconnect unless you ask for deletion.
  • The token: retired when you disconnect the account — no read or write uses it again — and deleted when you ask for your data to be deleted.

6. Who at Madder can see what#

Madder staff use a read-only database role. It cannot write, approve, or read the encrypted token. Staff access is for support and incident work only. No one at Madder can spend on your behalf.

7. Platform rules Madder follows#

Madder's use of Meta data is governed by the Meta Platform Terms and its use of Google data by the Google API Services User Data Policy, including the Limited Use requirements. Madder does not sell platform data and does not use it for advertising other than yours.

If it doesn't work#

  • You want a copy of what Madder holds — write to hello@madder.ai from the email on your account.
  • You want it gone — see Delete your data or disconnect.