Data Security

How we protect your data

atomicAds connects to the platforms you already buy on and runs checks against what it finds there. This is what we take, what we do with it, and what we will never do.

Principles

Four rules we hold ourselves to

  • You authenticate, we never hold passwords

    You sign in to DV360, Meta, The Trade Desk and the rest yourself, through each platform’s own OAuth flow. We never ask for, store or transmit your platform passwords, and nobody shares a login.

  • Read-scoped by default

    A new connection can read. It cannot change anything until you grant write access, per platform and per seat, and you can revoke that at any time from inside the platform or from atomicAds.

  • Nothing is written back without approval

    Renaming a line item, adjusting pacing or pausing a placement can all run behind an approval step. Every write-back is logged with what changed, when, and who approved it.

  • One client’s data never touches another’s

    Data is separated per client. Rules, taxonomies and reports are scoped to the account they belong to, so one client’s convention can never be applied to another’s campaigns.

What we handle

The data we take, and the data we don’t

We take campaign operations data. We do not take the things people usually worry about.

What we take

  • Campaign, insertion order, line item and creative metadata, including names
  • Delivery and spend figures, and the KPIs reported alongside them
  • Budget and pacing settings as the platform holds them
  • Your own budget records where you connect them, such as an IO, Prisma or Pipedrive
  • Account and user details for the people on your atomicAds team

What we don’t

  • End-user personally identifiable information
  • Raw audience or customer lists
  • Your platform passwords — authentication happens on the platform
  • Payment card details — billing runs through our payment provider
Practices

How it is handled day to day

  • In transit and at rest

    Traffic runs over TLS. Stored data sits behind encryption, firewalls and intrusion detection, on servers located in India as set out in our privacy policy.

  • Access inside AtomicAds

    Access to customer data is limited to the people who need it to run your account, and administrative access is logged.

  • Retention and deletion

    Data is kept while your account is active or as long as we are legally required to keep it. You can request deletion at any time by writing to legal@atomicads.ai.

FAQ

What security teams ask us

Anything not covered here, write to legal@atomicads.ai and we’ll answer it properly.

Contact us
Do you store our platform passwords?

No. You authenticate directly with each platform through its own sign-in, and we hold a revocable token rather than a credential. There are no shared logins and nothing to leak.

Can atomicAds change our campaigns on its own?

Only where you have granted write access, and you can require an approval step on top of that. Every change is logged with who approved it, so there is always an answer to “who did this”.

How is one client’s data kept away from another’s?

Data is separated per client, and rules, taxonomies and reports are scoped to the account they belong to. This matters most for agencies running competing advertisers in the same seat.

Where is our data stored?

On servers located in India, as set out in our privacy policy.

Do you handle end-user personal data?

No. We work with campaign operations data — names, settings, delivery and spend. We do not ingest end-user PII or raw audience lists.

How do we get our data deleted?

Write to legal@atomicads.ai. Data is otherwise retained while your account is active or as long as we are legally required to hold it.

Questions your security team needs answered

Send us the questionnaire. We’ll fill it in properly rather than pointing you at a page, and we’ll tell you plainly where we don’t yet have an answer.

Contact us

TLS

In transit, encrypted at rest, read-scoped by default