Skip to content
Get MCP AdsGet MCP Ads, home
Start free

Legal

Privacy policy

Last updated 28 August 2026

Get MCP Ads is an MCP gateway published by BENLY HLG. It connects your advertising accounts to an assistant such as Claude, ChatGPT or Cursor. Your advertising data is never stored here. Your account and your encrypted platform tokens are, and they sit in the United States.

What we collect

  • Your account: email address and name, and a password hash if you signed up with one. Sign-in, sessions and password resets are handled by Clerk.
  • Your organisation: its name, who belongs to it, and the invitations you sent. An invitation link is kept only as a hash and cannot be recovered from it.
  • Your advertising connections: the access tokens Meta Ads, Pinterest Ads, Google Ads, TikTok Ads, Search Console and Google Analytics 4 issue when you connect them, encrypted, together with the identifiers of the accounts you ticked as reachable.
  • Your usage: a count of tool calls per month, which is what applies your plan's limit. It holds a count, never a query.

What we never do

  • We do not sell or rent your data. Nothing on this site profiles you and nothing here is used to advertise to you.
  • We do not keep your advertising data. Campaigns, spend and performance are read from the platform on demand and passed straight to your assistant. They are not stored here.
  • We never hand your advertising tokens to the assistant. It calls this gateway, and the gateway calls the platform. No tool returns a token and none is written to a log.

How your tokens are protected

Advertising access tokens are encrypted with AES-256-GCM before they are written to the database. The encryption key is not stored alongside them, so a copy of the database on its own gives no access to your advertising accounts.

Disconnecting a platform deletes the row rather than marking it revoked, and you can withdraw the access separately from that platform's own security settings at any time.

Data that leaves the European Union

3 of the 5 processors below work outside the European Union, in the United States: Vercel, Neon and Clerk. In practice that means the database is hosted in Virginia, the functions that render this site and the dashboard run in Virginia, and your sign-in is handled from the United States.

The rest is served closer. Requests reach the site through an edge location in Paris, the MCP gateway answers from the Cloudflare location nearest to you and requests from Europe are served in Europe, and transactional email is sent from Ireland.

This is a transfer of personal data outside the European Union, and it is written here because a list of processor names on its own lets you assume everything stays in Europe. Each processor's own privacy policy is linked from the table.

Who processes your data

Every company that touches your data on our behalf, what it does, and what it can actually see. Nothing is listed here that the code does not call, and nothing the code calls is left out.

Outside the European Union
What it does
Hosts the website and the dashboard.
Data it can see
Request metadata, and the session of a signed-in user.
Where
Edge in Paris, functions in Virginia (iad1).
Outside the European Union
What it does
PostgreSQL database.
Data it can see
Account, organisation, memberships, invitations, encrypted advertising tokens, usage counters.
Where
AWS us-east-1, Virginia.
Inside the European Union
What it does
Runs the MCP gateway and serves DNS.
Data it can see
Request metadata and the bearer token presented by an MCP client.
Where
Nearest edge location. Requests from Europe are served in Europe.
Outside the European Union
What it does
Sign-in, sign-up, password reset and session management.
Data it can see
Email address, name, password hash, session and device metadata.
Where
United States.
Inside the European Union
What it does
Sends transactional email: invitations and the welcome message.
Data it can see
Recipient email address, and the content of the message.
Where
AWS eu-west-1, Ireland.

What this site stores on your device

Cookies and local storage in one table, because the law does not distinguish them: what counts is reading or writing on your device. The question asked of each one is the same. Is it strictly necessary for the thing you asked for?

One entry out of 7 is not, and that is all you are ever asked about. Everything else is exempt from consent, and there is no advertising cookie, no third-party tracker and no cross-site identifier to be found here.

__session, __client_uat
cookie, set by Clerk
Why it is there
Keeps you signed in, so the dashboard does not ask again on every page.
How long
Until you sign out.
Strictly necessary
Yes, so we do not ask
gma_org
cookie, set by Get MCP Ads
Why it is there
Remembers which organisation you are looking at, when you belong to more than one.
How long
One year.
Strictly necessary
Yes, so we do not ask
oauth state
cookie, set by Get MCP Ads
Why it is there
Ties an advertising platform's authorisation response to the request you started. Without it, the flow cannot be verified.
How long
The duration of the connection flow.
Strictly necessary
Yes, so we do not ask
sidebar:state
cookie, set by Get MCP Ads
Why it is there
Remembers whether you collapsed the sidebar.
How long
One year.
Strictly necessary
Yes, so we do not ask
theme
local storage, set by Get MCP Ads
Why it is there
Remembers whether you chose light or dark.
How long
Until you clear your browser data.
Strictly necessary
Yes, so we do not ask
gma_consent
local storage, set by Get MCP Ads
Why it is there
Remembers your answer about analytics, so we do not ask again.
How long
Six months, then we ask again.
Strictly necessary
Yes, so we do not ask
Vercel Web Analytics
local storage, set by Vercel
Why it is there
Counts page views and where visitors come from. No cookie, no cross-site identifier, no profile.
How long
Aggregated. Nothing identifies a visitor.
Strictly necessary
No, so we ask first

Analytics, and your answer

Vercel Web Analytics counts page views and where visitors arrive from. It sets no cookie, builds no profile and does not follow you to other sites. It does not start until you answer, and no answer means it does not start, so ignoring the question is a refusal.

Your answer is kept in this browser's local storage rather than in a cookie, because setting a cookie to record that you did not want cookies would be a poor joke. It never leaves your device, and we ask again after six months. Answering on this device says nothing about any other one.

How long we keep it

Your account and organisation
For as long as the account exists. Deleting the account removes them, and an organisation left with nobody in it is removed with it.
Advertising access tokens
Until you disconnect the platform, or the platform revokes them. Disconnecting deletes the row rather than marking it revoked.
Advertising data itself
Never stored. Campaigns, spend and performance are read from the platform on demand and passed straight to your assistant.
Usage counters
Thirteen months, so a year-on-year comparison is possible. They hold a count, not a query.
Invitations
Kept as a record of who was invited and when. The link itself is stored only as a hash and is never recoverable.

Your rights

BENLY HLG is the controller of this data. Under the GDPR you may, at any time:

  • Ask what we hold about you, and get a copy.
  • Correct anything that is wrong.
  • Delete your account, which removes it and everything attached to it.
  • Object to a processing, or ask that it be restricted.
  • Complain to your supervisory authority. In France that is the CNIL.

Write to contact@getmcpads.com and we will answer within one month. If the answer does not satisfy you, the CNIL takes complaints at cnil.fr.

Changes to this page

The date at the top is the date this page last changed. The two tables are generated from the record this service runs on, and a test refuses the build if a processor is named here that the code does not call, or if the code calls one that is missing. A machine-readable copy of this page is at /privacy.md.