How we protect your data
atomicAds connects to the platforms you already buy on and runs checks against what it finds there. This is what we take, what we do with it, and what we will never do.
Four rules we hold ourselves to
You authenticate, we never hold passwords
You sign in to DV360, Meta, The Trade Desk and the rest yourself, through each platform’s own OAuth flow. We never ask for, store or transmit your platform passwords, and nobody shares a login.
Read-scoped by default
A new connection can read. It cannot change anything until you grant write access, per platform and per seat, and you can revoke that at any time from inside the platform or from atomicAds.
Nothing is written back without approval
Renaming a line item, adjusting pacing or pausing a placement can all run behind an approval step. Every write-back is logged with what changed, when, and who approved it.
One client’s data never touches another’s
Data is separated per client. Rules, taxonomies and reports are scoped to the account they belong to, so one client’s convention can never be applied to another’s campaigns.
The data we take, and the data we don’t
We take campaign operations data. We do not take the things people usually worry about.
What we take
- Campaign, insertion order, line item and creative metadata, including names
- Delivery and spend figures, and the KPIs reported alongside them
- Budget and pacing settings as the platform holds them
- Your own budget records where you connect them, such as an IO, Prisma or Pipedrive
- Account and user details for the people on your atomicAds team
What we don’t
- End-user personally identifiable information
- Raw audience or customer lists
- Your platform passwords — authentication happens on the platform
- Payment card details — billing runs through our payment provider
How it is handled day to day
In transit and at rest
Traffic runs over TLS. Stored data sits behind encryption, firewalls and intrusion detection, on servers located in India as set out in our privacy policy.
Access inside AtomicAds
Access to customer data is limited to the people who need it to run your account, and administrative access is logged.
Retention and deletion
Data is kept while your account is active or as long as we are legally required to keep it. You can request deletion at any time by writing to legal@atomicads.ai.
What security teams ask us
Anything not covered here, write to legal@atomicads.ai and we’ll answer it properly.
Contact usDo you store our platform passwords?
No. You authenticate directly with each platform through its own sign-in, and we hold a revocable token rather than a credential. There are no shared logins and nothing to leak.
Can atomicAds change our campaigns on its own?
Only where you have granted write access, and you can require an approval step on top of that. Every change is logged with who approved it, so there is always an answer to “who did this”.
How is one client’s data kept away from another’s?
Data is separated per client, and rules, taxonomies and reports are scoped to the account they belong to. This matters most for agencies running competing advertisers in the same seat.
Where is our data stored?
On servers located in India, as set out in our privacy policy.
Do you handle end-user personal data?
No. We work with campaign operations data — names, settings, delivery and spend. We do not ingest end-user PII or raw audience lists.
How do we get our data deleted?
Write to legal@atomicads.ai. Data is otherwise retained while your account is active or as long as we are legally required to hold it.
Questions your security team needs answered
Send us the questionnaire. We’ll fill it in properly rather than pointing you at a page, and we’ll tell you plainly where we don’t yet have an answer.
TLS
In transit, encrypted at rest, read-scoped by default

