Legal
Privacy policy
Last updated 28 August 2026
Get MCP Ads is an MCP gateway published by BENLY HLG. It connects your advertising accounts to an assistant such as Claude, ChatGPT or Cursor. Your advertising data is never stored here. Your account and your encrypted platform tokens are, and they sit in the United States.
What we collect
- Your account: email address and name, and a password hash if you signed up with one. Sign-in, sessions and password resets are handled by Clerk.
- Your organisation: its name, who belongs to it, and the invitations you sent. An invitation link is kept only as a hash and cannot be recovered from it.
- Your advertising connections: the access tokens Meta Ads, Pinterest Ads, Google Ads, TikTok Ads, Search Console and Google Analytics 4 issue when you connect them, encrypted, together with the identifiers of the accounts you ticked as reachable.
- Your usage: a count of tool calls per month, which is what applies your plan's limit. It holds a count, never a query.
What we never do
- We do not sell or rent your data. Nothing on this site profiles you and nothing here is used to advertise to you.
- We do not keep your advertising data. Campaigns, spend and performance are read from the platform on demand and passed straight to your assistant. They are not stored here.
- We never hand your advertising tokens to the assistant. It calls this gateway, and the gateway calls the platform. No tool returns a token and none is written to a log.
How your tokens are protected
Advertising access tokens are encrypted with AES-256-GCM before they are written to the database. The encryption key is not stored alongside them, so a copy of the database on its own gives no access to your advertising accounts.
Disconnecting a platform deletes the row rather than marking it revoked, and you can withdraw the access separately from that platform's own security settings at any time.
Data that leaves the European Union
3 of the 5 processors below work outside the European Union, in the United States: Vercel, Neon and Clerk. In practice that means the database is hosted in Virginia, the functions that render this site and the dashboard run in Virginia, and your sign-in is handled from the United States.
The rest is served closer. Requests reach the site through an edge location in Paris, the MCP gateway answers from the Cloudflare location nearest to you and requests from Europe are served in Europe, and transactional email is sent from Ireland.
This is a transfer of personal data outside the European Union, and it is written here because a list of processor names on its own lets you assume everything stays in Europe. Each processor's own privacy policy is linked from the table.
Who processes your data
Every company that touches your data on our behalf, what it does, and what it can actually see. Nothing is listed here that the code does not call, and nothing the code calls is left out.
- What it does
- Hosts the website and the dashboard.
- Data it can see
- Request metadata, and the session of a signed-in user.
- Where
- Edge in Paris, functions in Virginia (iad1).
- What it does
- PostgreSQL database.
- Data it can see
- Account, organisation, memberships, invitations, encrypted advertising tokens, usage counters.
- Where
- AWS us-east-1, Virginia.
- What it does
- Runs the MCP gateway and serves DNS.
- Data it can see
- Request metadata and the bearer token presented by an MCP client.
- Where
- Nearest edge location. Requests from Europe are served in Europe.
- What it does
- Sign-in, sign-up, password reset and session management.
- Data it can see
- Email address, name, password hash, session and device metadata.
- Where
- United States.
- What it does
- Sends transactional email: invitations and the welcome message.
- Data it can see
- Recipient email address, and the content of the message.
- Where
- AWS eu-west-1, Ireland.
What this site stores on your device
Cookies and local storage in one table, because the law does not distinguish them: what counts is reading or writing on your device. The question asked of each one is the same. Is it strictly necessary for the thing you asked for?
One entry out of 7 is not, and that is all you are ever asked about. Everything else is exempt from consent, and there is no advertising cookie, no third-party tracker and no cross-site identifier to be found here.
- Why it is there
- Keeps you signed in, so the dashboard does not ask again on every page.
- How long
- Until you sign out.
- Strictly necessary
- Yes, so we do not ask
- Why it is there
- Remembers which organisation you are looking at, when you belong to more than one.
- How long
- One year.
- Strictly necessary
- Yes, so we do not ask
- Why it is there
- Ties an advertising platform's authorisation response to the request you started. Without it, the flow cannot be verified.
- How long
- The duration of the connection flow.
- Strictly necessary
- Yes, so we do not ask
- Why it is there
- Remembers whether you collapsed the sidebar.
- How long
- One year.
- Strictly necessary
- Yes, so we do not ask
- Why it is there
- Remembers whether you chose light or dark.
- How long
- Until you clear your browser data.
- Strictly necessary
- Yes, so we do not ask
- Why it is there
- Remembers your answer about analytics, so we do not ask again.
- How long
- Six months, then we ask again.
- Strictly necessary
- Yes, so we do not ask
- Why it is there
- Counts page views and where visitors come from. No cookie, no cross-site identifier, no profile.
- How long
- Aggregated. Nothing identifies a visitor.
- Strictly necessary
- No, so we ask first
Analytics, and your answer
Vercel Web Analytics counts page views and where visitors arrive from. It sets no cookie, builds no profile and does not follow you to other sites. It does not start until you answer, and no answer means it does not start, so ignoring the question is a refusal.
Your answer is kept in this browser's local storage rather than in a cookie, because setting a cookie to record that you did not want cookies would be a poor joke. It never leaves your device, and we ask again after six months. Answering on this device says nothing about any other one.
How long we keep it
- Your account and organisation
- For as long as the account exists. Deleting the account removes them, and an organisation left with nobody in it is removed with it.
- Advertising access tokens
- Until you disconnect the platform, or the platform revokes them. Disconnecting deletes the row rather than marking it revoked.
- Advertising data itself
- Never stored. Campaigns, spend and performance are read from the platform on demand and passed straight to your assistant.
- Usage counters
- Thirteen months, so a year-on-year comparison is possible. They hold a count, not a query.
- Invitations
- Kept as a record of who was invited and when. The link itself is stored only as a hash and is never recoverable.
Your rights
BENLY HLG is the controller of this data. Under the GDPR you may, at any time:
- Ask what we hold about you, and get a copy.
- Correct anything that is wrong.
- Delete your account, which removes it and everything attached to it.
- Object to a processing, or ask that it be restricted.
- Complain to your supervisory authority. In France that is the CNIL.
Write to contact@getmcpads.com and we will answer within one month. If the answer does not satisfy you, the CNIL takes complaints at cnil.fr.
Changes to this page
The date at the top is the date this page last changed. The two tables are generated from the record this service runs on, and a test refuses the build if a processor is named here that the code does not call, or if the code calls one that is missing. A machine-readable copy of this page is at /privacy.md.