Security & privacy

Encrypted credentials and secrets that never leave the server

Access tokens to ad platforms are the most sensitive data in the service. They are encrypted, used only on the server and never shown to anyone — including the AI.

What it does

Tokens from Google, Meta and other providers are stored encrypted with the service key. API keys, dashboard link tokens, invitation tokens and backup codes are stored only as hashes, so even a database copy would not reveal them.

Logs are written without request bodies containing secrets, AI requests are scanned for secret patterns before sending, and provider error messages that may contain identifiers are not shown or stored — only error codes.

Why it helps

  • A leaked database copy does not expose working credentials.
  • No secrets in logs, exports or AI context.
  • Security by design rather than by policy.

How to set it up

  1. Nothing to configure.
  2. Rotate API keys periodically and revoke unused ones.

Good to know

  • Values shown once (API keys, links) cannot be recovered later — create new ones if lost.
  • Disconnecting a platform also revokes access on the provider's side.
Ace, the AdAce Ads mascot

Try it on your own accounts

Create a workspace, connect Google or Meta in a couple of clicks and see your accounts clearly. Changes follow your approvals or the policy you configure.

Create your workspace