AdPilot
UKENStart for free

Privacy Policy

Last updated: September 11, 2026 · Data controller: Individual entrepreneur (FOP) Balabuiev Yevhen Serhiiovych · inbox@adpilot.com.ua

This is an English translation provided for convenience. The Ukrainian version at adpilot.com.ua/privacy.html is the binding text; in case of any discrepancy the Ukrainian version prevails.

1. General provisions

1.1. This Policy sets out how personal data and other data of users of the AdPilot service (adpilot.com.ua) is processed, and forms an integral part of the Public Offer Agreement.

1.2. The controller (owner) of personal data is Individual entrepreneur (FOP) Balabuiev Yevhen Serhiiovych (Фізична особа-підприємець Балабуєв Євген Сергійович), tax ID RNOKPP (individual taxpayer registration number) 3343307994, registered address Ukraine, 03115, Kyiv, Mykhaila Kotelnykova St., e-mail inbox@adpilot.com.ua ("we", the "Controller").

1.3. This Policy is based on the Law of Ukraine "On Personal Data Protection" (the "Law"), in particular Articles 6, 8, 10, 11, 12, 14, 24 and 29, and — for data obtained through the official Google connection — on the Google API Services User Data Policy, including the Limited Use requirements.

1.4. The Service is intended for businesses. We do not knowingly collect data of persons under 18 years of age.

2. Definitions

  • Customer — a person who has registered an account in the Service.
  • Cabinet — the Customer's personal area in the Service.
  • Ads Account — the Customer's Google Ads account connected to the Service.
  • Algorithms — software algorithms, machine-learning models and generative language models (AI technologies) that produce findings, recommendations, reports and autopilot decisions.
  • Processor — a person we instruct to process data to the extent required for the Service to operate (Art. 10 of the Law).

3. What data we process

CategoryContentsPurposeBasisRetention
Registration datae-mail address, password hash, interface language, registration date, plan statuscreating the account, login, invoicing, service correspondenceperformance of the Agreementterm of the Agreement
Session dataIP address (stored in full, shown partly masked in the Cabinet), browser and device details, login timelogin security, detection of unauthorised access, list of active sessionsperformance of the Agreement, legitimate interest in securityup to 30 days from session creation
Google Ads accessAds Account identifier, access refresh token (stored encrypted)reading statistics and making the changes instructed by the Customerconsent given in Google's interface and performance of the Agreementuntil access is revoked by the Customer
Ads Account datacampaigns and their settings, daily metrics (cost, conversions, CTR, CPC, CPA, ROAS), search terms, products and product feed, conversions, account balancedaily checks, recommendations, reports, autopilotperformance of the Agreementterm of the Agreement
Business profileinformation gathered from the Customer's public website pages and product feed: brands, assortment, prices, line of businessso that findings and negative keywords match the Customer's real assortmentperformance of the Agreement, legitimate interest in service qualityterm of the Agreement
Delivery channelsTelegram chat identifier, optionally the Customer's own bot token, e-mail addresses for reports (confirmed by code)sending daily, weekly and monthly reports and alertsperformance of the Agreementuntil the channel is removed by the Customer
Referral datapersonal code, records of visits and registrations through itrunning the referral programmeperformance of the Agreementterm of the Agreement
Interface stateflags for hints already shown and the product tour completed; in browser local storage — the e-mail address for the "remember me" featureso the interface does not repeat hintslegitimate interest in usabilityterm of the Agreement or until the browser is cleared
Support requeststhe text and attachments the Customer sends ushandling the requestperformance of the Agreementup to 3 years

3.1. We do not process special categories of data (Art. 7 of the Law), do not collect payment card details (these are handled by the payment provider) and do not ask for the Customer's Google password.

4. Ads Account data and the business profile

4.1. Access to the Ads Account is granted only through the official Google connection with the Customer's explicit consent given in Google's own interface. AdPilot requests only the Google permissions listed in clause 4.5 and does not read any other Google services.

4.2. The access token is stored encrypted. The Customer may revoke access at any time — in the security settings of the Google account (myaccount.google.com/permissions) or via the "Disconnect" button in the Cabinet. After revocation the Service stops all work with the Ads Account.

4.3. The business profile is built from publicly available pages of the Customer's website and from the Customer's product feed. We do not collect personal data of the Customer's website visitors in this way.

4.4. Ads Account data is: not sold; not used to display our own or anyone else's advertising; not disclosed to third parties other than the processors listed in Section 6; not used for the benefit of another customer; not used to train models.

4.5. Google user data we access and why. When the Customer signs in with Google or connects an Ads Account, AdPilot asks for the following Google permissions:

  • Basic profile (openid, email, profile) — the Customer's Google e-mail address, name and avatar. Used only to create and sign the Customer in to their AdPilot account and to send service e-mails.
  • Google Ads (https://www.googleapis.com/auth/adwords) — reading reports (campaigns, ad groups, keywords, search terms, products, conversions, spend) of the Ads Account the Customer explicitly selected, and making the changes the Customer approved or enabled in the Cabinet: negative keywords, pausing products/ads with no sales, bid and budget adjustments. Every change is logged in the Cabinet and can be reverted by the Customer.
  • Google Sheets and Google Drive files created by AdPilot (https://www.googleapis.com/auth/spreadsheets, https://www.googleapis.com/auth/drive.file) — only to create spreadsheet reports on the Customer's own Google Drive when the Customer asks for one in the AdPilot chat. AdPilot cannot see or modify any other files on the Customer's Drive.
  • Google Merchant Center (https://www.googleapis.com/auth/content) — reading the Customer's Merchant Center accounts and product listings (title, brand, price, availability, product links) to build the product catalogue that AdPilot uses for product-level checks and negative keywords, so the Customer does not have to provide a feed URL manually. AdPilot does not edit product listings.
  • Google Analytics, read-only (https://www.googleapis.com/auth/analytics.readonly) — reading GA4 sessions, key events and revenue per campaign for the property the Customer selected, to compare them with Google Ads data and detect tracking gaps. No user-level or personal data of the Customer's website visitors is stored.
  • Google Search Console, read-only (https://www.googleapis.com/auth/webmasters.readonly) — reading search performance (queries, clicks, impressions) of the Customer's verified site to compare organic and paid search demand.

Google user data is stored on the Service's server in Ukraine (see Section 8), is used solely to provide the features described above to the Customer who granted the access, is never sold, never used for advertising or for training AI models, and is deleted when the Customer revokes access or deletes their account. The Customer may revoke access at any time as described in clause 4.2.

5. Google API Services — Limited Use

AdPilot's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

6. Who receives the data

6.1. To provide the services we engage the following processors:

  • Anthropic PBC (USA) — receives Ads Account metrics, search terms and the business profile so that the Algorithms can generate recommendations and report texts. The Customer's registration data and access tokens are not transferred.
  • Telegram Messenger (Bot API) — receives the text of a report or alert and the chat identifier in order to deliver the message.
  • E-mail provider — receives the recipient address and the text of the message in order to deliver service e-mails and reports.
  • Hosting provider — Hosting Ukraine LTD; the server is located in Kyiv, Ukraine.
  • Payment provider — once payments are enabled, receives the data required to process a payment; card details are handled on its side and are not passed to us.

6.2. We may replace a processor with another of the same kind by updating this list on this page. We also disclose data to authorised public bodies where such an obligation is expressly established by law.

6.3. Cross-border transfer. Transfers to Anthropic PBC and Telegram involve processing outside Ukraine, in particular in the United States of America. Such transfer is made under Art. 29 of the Law as necessary for the performance of an agreement concluded for the benefit of the data subject, and on the basis of the Customer's consent given when accepting the offer. By acceding to the offer the Customer consents to such transfer; without it the generation of recommendations and the delivery of reports via Telegram are technically impossible.

7. Automated processing and the Algorithms

7.1. Part of the processing is automated: daily checks, generation of findings and recommendations, report texts and autopilot decisions.

7.2. Autopilot makes changes in the Ads Account only within the settings and limits configured by the Customer. The Customer may switch autopilot off at any time, every action is recorded in the "Operations" log and may be undone. Changes proposed in the chat are executed at the Customer's instruction in the chat; for actions that affect spend or results, AdPilot warns about the consequences and asks again before executing.

7.3. The output of the Algorithms may be inaccurate. Final decisions about the Ads Account are taken by the Customer; the limits of liability are set out in the Public Offer Agreement.

7.4. Material the Customer sends into the chat and the responses of the Algorithms are stored in the Cabinet so that the history of requests can be reviewed.

8. Where and for how long data is stored

8.1. Data is stored on a server in Ukraine (Kyiv). Backups are made regularly, are kept with the same hosting provider and are deleted once their retention period expires.

8.2. We keep data for the term of the Agreement and for the periods stated in the table in Section 3. After the Agreement ends, data is deleted or anonymised, except for data we are required by law to keep (in particular accounting records).

8.3. After the trial period ends the Cabinet switches to read-only mode — the Customer's data is not deleted as a result.

8.4. On a request sent to inbox@adpilot.com.ua from the address given at registration we delete the Customer's data within 30 calendar days (allowing for the time needed to refresh backups).

9. Data security

9.1. In accordance with Art. 24 of the Law we apply the following measures: data is transmitted only over secure channels (HTTPS/TLS); passwords are stored only as hashes; Google access tokens are encrypted; the session cookie carries the HttpOnly attribute and a separate mechanism protects against cross-site request forgery; access to servers and to the database is restricted to those who need it to provide the services; actions in the Ads Account are logged.

9.2. No system is absolutely secure. If we detect an incident that creates a risk to the Customer's rights, we will notify the Customer at the e-mail address given at registration and describe the measures taken.

10. Cookies and local storage

10.1. On the public pages of adpilot.com.ua we use no analytics, advertising or tracking scripts and set no cookies.

10.2. In the Cabinet only strictly necessary cookies are used: the session cookie (30-day lifetime, HttpOnly, not readable by page scripts) and an auxiliary cookie that protects forms against cross-site request forgery. In addition, browser local storage may hold the e-mail address for the "remember me" feature and flags for hints already shown.

10.3. Deleting these items in the browser settings logs the user out of the Cabinet.

11. Customer rights

11.1. Under Art. 8 of the Law the Customer has the right to: know the sources, the place of processing and the purposes of processing of their data; obtain access to their data and a copy of it; demand correction of inaccurate data; demand deletion of data or restriction of its processing, in particular where processing is unlawful; withdraw consent; object to processing; know to whom the data has been disclosed; protect their rights by applying to a court or to the Ukrainian Parliament Commissioner for Human Rights.

11.2. Without contacting us the Customer can: change profile details, end active sessions, remove report delivery channels, switch autopilot off, revoke access to the Ads Account, and unsubscribe from e-mails via the link in an e-mail.

11.3. A request under clause 11.1 is sent to inbox@adpilot.com.ua. We respond within 30 calendar days and may ask the requester to confirm their identity so that data is not disclosed to an unauthorised person.

12. Notice of inclusion in the database

12.1. In accordance with Art. 12 of the Law we notify the Customer of the inclusion of their personal data in the Service's personal data database, of the controller, of the composition and purpose of the collection and of the persons to whom the data is transferred, by the Customer's acceptance of this Policy at registration.

13. Changes to this Policy

13.1. We may update this Policy. The new version is published on this page; the date of the last update is shown at the top of the document.

13.2. Changes that materially affect the scope of processing or the list of processors will be notified by e-mail at least 14 calendar days before they take effect.

14. Contact

14.1. For any question about data processing write to inbox@adpilot.com.ua. Service e-mails are sent from noreply@adpilot.com.ua, which does not accept replies.