This policy describes what happens when you connect an advertising account to Coretas: what access we ask for, what we do with the data, what stays your responsibility, and how to disconnect.
This policy forms part of the Terms of Use you accepted when you created your account, and you accepted it at the same time. Before your first connection we show you a short summary of what the access involves, so that nothing here comes as a surprise.
1. How the connection works
Coretas connects to Google Ads and Meta Ads through their official APIs, using each platform's own authorisation flow. We never ask for and never store your Google or Meta password.
Once you connect, the flow is:
- Coretas reads and analyses the performance history in the accounts you selected.
- You get a unified dashboard personalised to your own accounts, rather than a generic template.
- Coretas gives you recommendations drawn from that analysis, with the reasoning behind each one.
- You build your own media plans and campaigns from those recommendations, in the Coretas dashboard.
- When you are ready, and only when you approve it, Coretas publishes what you built to your connected advertising account.
The access Coretas requests is not read-only. It includes permission to create, edit, pause and enable campaigns, ad sets, ad groups, ads and budgets in the account you connect. Coretas needs that access to publish the campaigns and changes you approve.
Nothing is created, paused or edited in your account without your approval. Every change is presented to you for review before it reaches your advertising account, and you approve it or reject it. We do not make silent changes, and we do not run background automations that alter your account without a human approval step.
You can see which accounts are connected, and what access each connection carries, in Settings.
2. What access Coretas asks for, and what it reads
Once connected, Coretas reads performance and configuration data from the account, including campaigns, ad groups and ad sets, ads and creatives, audiences, budgets and bids, keywords and placements, products and feeds, conversions and conversion actions, and the associated performance metrics over time.
Coretas currently reads up to 12 months of history. We may change how much history we read, how often we read it, and which fields we read, at any time and without prior notice.
Coretas does not read, and does not ask for access to, your Google account contents outside the connected advertising account, your Facebook or Instagram personal profile content, or your Meta business assets beyond the ad accounts you select.
3. What Coretas does with it
We use the data to provide the platform to you: to build your unified reporting, to analyse historical performance, to generate insights, recommendations, media plans, campaign structures and advertising components, to answer your questions through Coretas Copilot, and to publish the changes you approve.
We use subprocessors to do this, including cloud hosting and AI model providers. They are listed under Subprocessors.
We do not sell your advertising data. We do not disclose identifiable data about your account to other customers or to third parties, except to the subprocessors needed to run the platform, with your consent, or where required by law. See section 8 of the Terms of Use and the Privacy Statement.
4. What you confirm when you connect
By connecting an advertising account you confirm that:
- you own the account, or you are authorised by its owner to connect it and to grant Coretas the access described above,
- if the account belongs to a client of yours, you have that client's permission to connect it and to share its data with Coretas,
- you have the consents and legal basis needed for us to process any personal data in the account, and
- connecting the account does not breach any agreement you have with the advertising platform or with a third party.
If you connect an account you are not authorised to connect, you are responsible for the consequences, and we may disconnect it and suspend your access.
5. Advertising platform rules apply to you
Google and Meta impose obligations on us as an API developer, and require us to pass matching obligations to you. By connecting an account you agree that:
- you will comply with the terms, policies and advertising rules of each advertising platform you connect, including the Google Ads Terms and Conditions, Google Ads policies, the Google Ads API Terms and Conditions, and the Meta Platform Terms, Advertising Standards and Business Tools Terms,
- you will comply with applicable law in the advertising you create and publish, including law on advertising claims, consumer protection, data protection and marketing consent,
- you will not use Coretas to access, manage or extract data from any advertising account other than one you own or are authorised to manage,
- you will not use Coretas to circumvent a platform's rate limits, policy enforcement, review processes or account restrictions, and
- you will not extract advertising platform data through Coretas in order to build or train a competing product, or to resell that data.
If you breach these rules we may have to disconnect your account or suspend your access, including at the instruction of the advertising platform, and we may be required to report the breach to that platform.
6. What stays your responsibility
- Your advertising spend. All of it, including spend from campaigns and changes published through Coretas after you approved them. See section 4 of the Terms of Use.
- Your advertising content. Its accuracy, legality, and compliance with platform policy, including copy and creative that Coretas generated and you approved.
- Your account. Your billing relationship with the advertising platform, your account structure outside Coretas, and any action the platform takes against your account.
- Reviewing before approving. Budgets, targeting, bids and copy, on every change you approve.
- Your own records. Keep your own record of the data held in your advertising accounts, and be able to run your accounts without Coretas. Platform APIs can change or be withdrawn, and access can be suspended for reasons outside our control.
7. Data accuracy
Coretas reports what the advertising platforms return. Platform data can be incomplete, delayed, modelled, or restated by the platform after the fact, particularly for conversions and attribution. Where numbers differ between Coretas and a platform's own interface, the cause is usually a difference in attribution window, time zone, currency conversion or data freshness. Coretas does not warrant the accuracy or completeness of data it receives from a third-party platform.
8. Disconnecting
You can disconnect any advertising account at any time, in Settings, in one step. You can also revoke Coretas's access from inside Google or Meta directly.
When you disconnect:
- we stop reading from the account immediately,
- our access tokens for it are invalidated,
- campaigns already live in that account keep running, because they live in your account and not ours. They are yours, and they remain your responsibility. If you want them paused, pause them in the platform they run on, and
- data already ingested is retained and deleted in line with the Cancellation and Billing Policy and the Privacy Statement.
Disconnecting does not cancel your subscription and does not make the current billing period refundable. See the Refund Policy.
9. Security of your connection
We store access tokens encrypted, restrict access to them to the systems and personnel that need it, and log their use. If we believe a token has been exposed, we invalidate it and notify you. Report a suspected problem to info@coretas.ai.
Changes to this policy
We may update this policy at any time. Unless the law, or an agreement we have signed with you, requires otherwise, a change takes effect as soon as we post it here, without prior notice to you, and the version on this page is the version that applies. We recommend checking this page from time to time. Prior versions are available on request from info@coretas.ai.
Material changes to the Terms of Use themselves follow the notice process in section 19 of those Terms.