Legal / Platform Connection and Data Access Policy

Platform Connection and Data Access

Version 1.0  ·  Effective September 9, 2026  ·  Last updated September 9, 2026

This policy forms part of the Coretas Terms of Use and is incorporated into them by reference. Where this policy and the Terms of Use conflict on a matter this policy covers, this policy applies.

What happens when you connect Google Ads or Meta Ads to Coretas.

This policy describes what happens when you connect an advertising account to Coretas: what access we ask for, what we do with the data, what stays your responsibility, and how to disconnect.

This policy forms part of the Terms of Use you accepted when you created your account, and you accepted it at the same time. Before your first connection we show you a short summary of what the access involves, so that nothing here comes as a surprise.

1. How the connection works

Coretas connects to Google Ads and Meta Ads through their official APIs, using each platform's own authorisation flow. We never ask for and never store your Google or Meta password.

Once you connect, the flow is:

  1. Coretas reads and analyses the performance history in the accounts you selected.
  2. You get a unified dashboard personalised to your own accounts, rather than a generic template.
  3. Coretas gives you recommendations drawn from that analysis, with the reasoning behind each one.
  4. You build your own media plans and campaigns from those recommendations, in the Coretas dashboard.
  5. When you are ready, and only when you approve it, Coretas publishes what you built to your connected advertising account.

The access Coretas requests is not read-only. It includes permission to create, edit, pause and enable campaigns, ad sets, ad groups, ads and budgets in the account you connect. Coretas needs that access to publish the campaigns and changes you approve.

Nothing is created, paused or edited in your account without your approval. Every change is presented to you for review before it reaches your advertising account, and you approve it or reject it. We do not make silent changes, and we do not run background automations that alter your account without a human approval step.

You can see which accounts are connected, and what access each connection carries, in Settings.

2. What access Coretas asks for, and what it reads

Once connected, Coretas reads performance and configuration data from the account, including campaigns, ad groups and ad sets, ads and creatives, audiences, budgets and bids, keywords and placements, products and feeds, conversions and conversion actions, and the associated performance metrics over time.

Coretas currently reads up to 12 months of history. We may change how much history we read, how often we read it, and which fields we read, at any time and without prior notice.

Coretas does not read, and does not ask for access to, your Google account contents outside the connected advertising account, your Facebook or Instagram personal profile content, or your Meta business assets beyond the ad accounts you select.

3. What Coretas does with it

We use the data to provide the platform to you: to build your unified reporting, to analyse historical performance, to generate insights, recommendations, media plans, campaign structures and advertising components, to answer your questions through Coretas Copilot, and to publish the changes you approve.

We use subprocessors to do this, including cloud hosting and AI model providers. They are listed under Subprocessors.

We do not sell your advertising data. We do not disclose identifiable data about your account to other customers or to third parties, except to the subprocessors needed to run the platform, with your consent, or where required by law. See section 8 of the Terms of Use and the Privacy Statement.

4. What you confirm when you connect

By connecting an advertising account you confirm that:

If you connect an account you are not authorised to connect, you are responsible for the consequences, and we may disconnect it and suspend your access.

5. Advertising platform rules apply to you

Google and Meta impose obligations on us as an API developer, and require us to pass matching obligations to you. By connecting an account you agree that:

If you breach these rules we may have to disconnect your account or suspend your access, including at the instruction of the advertising platform, and we may be required to report the breach to that platform.

6. What stays your responsibility

7. Data accuracy

Coretas reports what the advertising platforms return. Platform data can be incomplete, delayed, modelled, or restated by the platform after the fact, particularly for conversions and attribution. Where numbers differ between Coretas and a platform's own interface, the cause is usually a difference in attribution window, time zone, currency conversion or data freshness. Coretas does not warrant the accuracy or completeness of data it receives from a third-party platform.

8. Disconnecting

You can disconnect any advertising account at any time, in Settings, in one step. You can also revoke Coretas's access from inside Google or Meta directly.

When you disconnect:

Disconnecting does not cancel your subscription and does not make the current billing period refundable. See the Refund Policy.

9. Security of your connection

We store access tokens encrypted, restrict access to them to the systems and personnel that need it, and log their use. If we believe a token has been exposed, we invalidate it and notify you. Report a suspected problem to info@coretas.ai.

Changes to this policy

We may update this policy at any time. Unless the law, or an agreement we have signed with you, requires otherwise, a change takes effect as soon as we post it here, without prior notice to you, and the version on this page is the version that applies. We recommend checking this page from time to time. Prior versions are available on request from info@coretas.ai.

Material changes to the Terms of Use themselves follow the notice process in section 19 of those Terms.