Privacy Policy

Google Ads MCP · last updated 28 September 2026

This policy covers the Google Ads MCP service operated by Synatix GmbH at https://sea-ads-mcp-816321498820.europe-west4.run.app. It supplements the Synatix GmbH privacy policy, which applies to our website and business generally.

1. Controller

Synatix GmbH, Deisterstraße 20, 31785 Hameln, Germany. Register: Amtsgericht Hannover, HRB 203142. VAT ID: DE260044147. Managing directors: Fabian Simon, Dennis van der Zwaag. For privacy questions, including access, correction, deletion, portability or objection, contact us via the contact form at synatix.com/kontakt.

2. Who this applies to

The service is for employees of Synatix GmbH and its group companies who sign in with a synatix.com Google account. It is not offered to the general public.

3. Google user data we access

DataScopeWhy
Your email address and the fact your account belongs to our Workspace domain openid, email To identify you, restrict access to our domain, and attribute activity to you
Your Google Ads accounts and their reporting data https://www.googleapis.com/auth/adwords To answer the reporting questions you ask

We act strictly within your own permissions. The service reads only what your Google account can already read, and it performs no write operations of any kind.

4. What we store, and for how long

StoredWhereRetention
Your email addressGoogle Cloud Firestore, EU region (Frankfurt) Until your authorisation is withdrawn or your account is removed
The Google refresh token representing your authorisation Firestore, EU region Until withdrawn; deleted on request
A cached index of which Ads accounts sit under which manager account Firestore, EU regionRefreshed at least every 24 hours
Session tokens issued by this service to your AI client Firestore, EU regionAccess tokens 8 hours; refresh tokens until revoked
Operational logs (time, path, HTTP status, error type) Google Cloud Logging, EU regionPer Google Cloud defaults, currently 30 days
We do not store your reporting data. Campaign, keyword, search-term and spend figures are fetched from Google when you ask a question, passed to your AI assistant, and not written to our storage. Credentials are never written to logs.

5. Who receives the data

Your AI assistant

This is the point of the service, and the most important thing to understand: the reporting data you request is returned to the MCP client you connect — for example Claude, operated by Anthropic. That provider then processes it under its own terms and privacy policy. Only data returned by the questions you ask is sent. Choose what you ask for accordingly, and use only clients your employer has approved.

Processors

We do not sell or rent personal data, and we do not use it for advertising or profiling.

6. Limited Use

Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we do not use Google user data to develop, improve or train generalised artificial intelligence or machine learning models, and we do not transfer it except as described above or where required by law.

7. Legal basis

Processing is based on Art. 6(1)(b) GDPR (performance of the employment-related use of a tool provided to you), Art. 6(1)(f) GDPR (our legitimate interest in operating and securing an internal reporting tool), and your consent to the Google authorisation itself, which you may withdraw at any time under Art. 7(3) GDPR.

8. Withdrawing access and deleting data

9. Security

Traffic is TLS-encrypted end to end. The service runs with a dedicated identity that can read only the specific secrets it needs, rather than broad project access. Credentials are held in Google Secret Manager with EU-pinned replication, are never written to logs, and are never sent to the AI client. Access to the stored data is limited to the service itself and to named administrators.

10. Your rights

You have the right of access, rectification, erasure, restriction, data portability and objection, and the right to lodge a complaint with a supervisory authority. For Synatix GmbH that is the data protection authority of Lower Saxony (Landesbeauftragte für den Datenschutz Niedersachsen).

11. Changes

We will update this page when the service changes and revise the date above. Material changes affecting how Google user data is handled will also be communicated to users directly.