Security.
How we protect your data — and what stays in your control.
Adwiser connects to your Google Ads account with read-only access by default. This page sets out the data we process, the controls that protect it, and the choices that remain yours. Security and procurement teams can request our full documentation at security@adwiserai.com.
Four things that define how we handle your data.
We connect through Google OAuth and read your account. Making changes requires you to explicitly turn on write permissions — and changes can require your approval.
Google privacy-filters its reporting before we receive it, so the integration does not ingest end-user PII. We hold your aggregate campaign data, not your customers' identities.
Anonymized, aggregated insights improve recommendations. You can opt out anytime — your data won't contribute, and your recommendations draw only on your own account.
Every provider in our stack — hosting, storage, and AI — maintains SOC 2 Type II and ISO 27001 certification. We layer our own controls on top.
How we access your account
Adwiser connects to your Google Ads account using Google OAuth. You control what Adwiser can do in your account settings:
- In analysis-only mode — the default — Adwiser reads your reporting data to identify performance improvements and makes no changes to your account.
- You may optionally allow Adwiser to apply changes — such as adjusting bids, budgets, keywords, or campaign settings. When enabled, changes can be configured to require your approval first.
This permission is controlled entirely by you and can be changed at any time. You can revoke Adwiser's access from your own Google account whenever you like. We access no other systems — no CRM, no internal tools, no customer databases.
We don't process end-user personal data
Google Ads reporting is aggregate by design — it reports counts, rates, and totals, not records of individual people. Wherever a slice of data is narrow enough that it could identify someone, Google withholds or aggregates it before it reaches us, as the data controller:
- Low-volume search termsare grouped into “Other” for privacy before we can see them.
- Audience and demographic reporting is withheld when a segment is too small.
- Google applies minimum-user thresholds that prevent transmission of data about individuals.
Because we rely solely on Google's data and inherit these platform-level privacy controls, the integration does not ingest end-user personally identifiable information. Google also blocks advertisers from passing PII into the platform, so personal data is filtered on both ends.
How Adwiser learns (and your control over it)
Adwiser improves your recommendations using two layers:
- Your-account learning — Adwiser retrieves and reasons over your own account's data to tailor recommendations to you. This is always private to you and never shared.
- Aggregated Insights — Adwiser derives aggregated, anonymized patterns that recur across many accounts (for example, which keyword patterns tend to waste budget in a given context) to improve the quality of recommendations.
We do not train or fine-tune AI models on customer data.These benchmarks include only patterns that appear across a minimum threshold of accounts — no individual customer's data is ever exposed to another customer.
Your control: Aggregated Insights are enabled by default. You can opt out at any time in your settings — in which case your data does not contribute to the benchmarks and your recommendations draw only on your own account. Unlike the underlying ad platforms, which offer no opt-out, this is always your choice. Enterprise customers may also disable it contractually.
Infrastructure & certifications
Adwiser is built on independently certified infrastructure — every provider in our stack maintains SOC 2 Type II and ISO 27001 certification — and we layer our own encryption, access controls, and privacy safeguards on top. Application compute and data storage are hosted in the European Union (Frankfurt).
Encryption
- In transit: all data is encrypted using TLS 1.2 or higher.
- At rest: all stored data is encrypted using AES-256.
Sub-processors
We use a limited set of trusted sub-processors and notify customers in advance of material changes. Our AI processing uses Anthropic's Claude API: data sent to Claude is aggregate, non-PII campaign data, is never used to train their models, and is automatically deleted within 7 days.
The full, current list with processing locations lives on our Subprocessors page.
Data retention & deletion
We retain your account data for up to 2 years of historical depth while you are a customer, to inform your recommendations. You can request deletion at any time. We remove customer data from production systems within 30 days of a deletion request or account termination and remove it from the retrieval index; residual copies in encrypted backups are purged within their 30-day rotation. Aggregated, anonymized benchmarks contain no identifiable customer data and are not subject to deletion.
Compliance & documentation
Our practices align with GDPR. We're happy to complete standard security questionnaires (CAIQ, SIG-Lite) for prospective customers. The following are available on request:
- Data Processing Agreement (DPA)
- Information Security Policy
- Data Retention & Deletion Policy
Email security@adwiserai.com and we'll share them with your security team.
Contact
For security questions, to report a vulnerability, or to request documentation: