Privacy policy
Last updated: 4 August 2026
UA Copilot is a media-buying assistant for Google Ads, operated by Cleanor Research Labs L.L.C-FZ (hello@cleanor.app, support: support@cleanor.app). This page describes what the service stores, why, and how to get it back or remove it. It is written from the actual contents of the database rather than from a template.
What we store
- Your account. The email address you sign in with, and the name, avatar and locale your Google account returns at sign-in. Used to show who you are and who is in a workspace.
- Your workspace and its projects. Project names, notes, naming rules and settings.
- Conversations. The messages you exchange with the copilot, so a chat can be reopened. Their retention is yours to set per project, including deleting them on a schedule; the default is to keep them until you delete them.
- Project memory. Facts, hypotheses and results, either typed by you, extracted from a conversation with your confirmation, or read off a finished creative test.
- Creatives and files. Images, videos, banners and ad copy generated or uploaded, plus documents you add to a project.
- Advertising data. Campaign, ad group, ad and asset metrics read from the Google Ads accounts you connect, kept as a reporting store so screens and reports do not re-query Google for every view.
- Access to your ad accounts. When you connect Google Ads we store a refresh token, encrypted, so the service can read metrics and make the changes you confirm.
- Operational records. A change log of actions taken (who did what and when), token usage for billing, and API keys you create for the data API.
What we do not store
No payment card data (there is no self-serve payment flow). No tracking pixels, no advertising cookies, no analytics on this site. The only cookie is the session cookie that keeps you signed in.
Google user data
Signing in requests openid, email and profile: your
address and display name, nothing else. Connecting an ad account requests
https://www.googleapis.com/auth/adwords, which is what lets the service read your
campaign data and apply changes you confirm. Publishing a video to your channel, if you use
that, requests youtube.upload and youtube.readonly.
UA Copilot's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google Ads data is used only to operate the features you see in your own workspace. It is never sold, never used for advertising, and never used to train a model.
Where it lives, and who else sees it
Everything is stored on Cloudflare infrastructure (D1 databases and R2 object storage) used by this service alone. Data crosses to third parties in exactly three cases:
- Google, to read your advertising data and to make the changes you confirm.
- The language model provider (Google Gemini, and OpenRouter as a fallback), when you ask the copilot to generate or analyse something. The prompt carries the project context needed for that request; it is not used to train those models under their API terms.
- A webhook you configure yourself, if you point an automation or a data subscription at one.
Nothing is sold, and there is no advertising network in the product.
Who can see your data inside the service
A workspace is the boundary. People you invite see that workspace and nothing else; the client role sees only reports and results. Cleanor Research Labs L.L.C-FZ staff have technical access to the database for support and maintenance, which is the honest answer for a service of this size.
Getting your data out, and deleting it
- Projects, chats, memory items and files can each be deleted from the interface at any time.
- Deleting a project removes its accounts, creatives and memory with it.
- Disconnecting a Google account removes the stored refresh token.
- To export everything at once, open Profile settings from the account menu and press Download my data: one JSON file with your account, workspaces, projects, conversations, memory and creatives. Advertising metrics are a copy of your Google Ads data and stay with Google.
- To close the account, use Close this account in the same place. It deletes your conversations, memory, creatives and connections immediately. If you are the last owner of a workspace that still has projects, delete them or hand ownership over first, so nobody else's work disappears with you. Anything you would rather have done by hand goes to support@cleanor.app and is completed within 30 days.
You can also revoke the service's access to your Google account at any time at myaccount.google.com/permissions.
Retention
Conversations follow the per-project retention you choose; everything else is kept until you delete it or your account is closed. Backups of the database are kept for operational recovery and rotate out.
Who is responsible
The data controller is Cleanor Research Labs L.L.C-FZ, the company behind Cleanor Labs. General questions go to hello@cleanor.app; anything about your data, an export or a deletion goes to support@cleanor.app and is answered within 30 days.
Changes
If this policy changes materially, the date at the top changes and, if you have an account, you will be told inside the product.