Privacy policy
Last updated: 22 July 2026 · Applies to upbuild.app and the Upbuild connector service
Upbuild is a hosted MCP (Model Context Protocol) connector that lets you query your own advertising and analytics accounts from AI assistants such as Claude and ChatGPT. This policy explains what we process, why, and what we deliberately do not do. It also serves as the privacy policy for the Upbuild OAuth applications registered with Google and Meta.
Who we are
Upbuild is a product of Uptimal. Two companies in the same group are involved, each with a defined role:
- Uptimal FZCO (Dubai, United Arab Emirates) provides the service and is the controller for your account, subscription and billing data, site analytics and contact form submissions.
- Madtechers SLU, trading as Uptimal (CIF B01878834, Calle Viladomat 208, P.5 Pta.1, 08029 Barcelona, Spain), holds the Meta application behind Upbuild and is the entity that receives and processes Meta Platform Data when you connect a Meta ad account, on your behalf and on your instructions.
Both companies trade as Uptimal. Any privacy request can be sent to [email protected] and we route it to the right entity internally.
What we process, and why
- Identity. Your Google account id, email and basic profile (and, if you link it, your Meta user id) identify your connection, your trial and your subscription. Legal basis: contract performance.
- OAuth tokens. Access and refresh tokens for the platforms you connect are stored encrypted, server-side, in Cloudflare KV. They are never exposed to the AI assistant, to your browser, or to third parties. Legal basis: contract performance.
- Platform data in transit. When you ask a question, the connector fetches the requested data (for example a Google Analytics report or a Google Ads query) and returns it to your assistant. Responses may be cached briefly to keep conversations fast, then discarded. We do not build a copy of your marketing data.
- Usage metering. We log which tools are called, when, and by which connection (in Cloudflare D1) to enforce trials and subscriptions, prevent abuse and operate the service. Legal basis: contract performance and legitimate interest.
- Billing. Payments are processed by Stripe. We never see or store your full card details. Legal basis: contract performance and legal obligation.
- Contact form. If you submit the form on upbuild.app we store your name, email, company and message to reply to you. Legal basis: consent.
What we deliberately do not do
- We request read-only scopes wherever the platform offers them. The connector cannot modify campaigns, tags, budgets or audiences.
- Your data is never used to train models, ours or anyone else's.
- We never sell or rent personal data or platform data.
- We do not show ads on upbuild.app and we do not run third-party advertising trackers on it.
OAuth scopes we request
Google: Tag Manager (readonly), Analytics (readonly), Display & Video 360, Campaign Manager 360 trafficking and reporting (read use), Google Ads (read use), plus openid, email and profile for sign-in. Meta (optional): ads_read only. Snapchat (optional): read-only marketing scopes via Snapchat Business OAuth. TikTok (optional): authorization runs through TikTok’s official for-Business MCP server; the grant is platform-wide by TikTok’s design, and Upbuild enforces a server-side read-only allowlist that blocks all write operations before they reach TikTok. TikTok authorizations expire every 30 days and are re-requested through the connector. Adobe (optional): an OAuth Server-to-Server credential that you create in your own Adobe Developer Console; it is stored encrypted, used only for read (GET) calls to Adobe Analytics and Adobe Experience Platform Tags, and deleted when you disconnect. You can review and revoke access at any time from your Google Account connections or your Meta Business integration settings.
Meta Platform Data
Connecting a Meta ad account is optional. When you do, Madtechers SLU receives an access token limited to ads_read and uses it only to run the reports you ask for inside your own AI assistant session. Meta Platform Data is processed on your behalf and on your instructions.
Specifically, Meta Platform Data is:
- requested only when a question you ask needs it, and returned into your own assistant session;
- never sold, licensed or shared with data brokers, and never transferred to anyone outside the subprocessors listed below;
- never used for advertising, audience building, profiling, credit or eligibility decisions, or to train machine learning models;
- never pooled or combined with another customer's data.
Storage: access tokens are encrypted at rest in Cloudflare KV. Report responses are cached briefly, typically for minutes, to respect Meta rate limits; Upbuild is not a long-term store of your Meta data.
Revoking access and deleting Meta data
You can stop the processing at any time, from either side:
- Disconnect Meta on the Upbuild connect hub. The stored token is deleted and any cached responses expire within minutes.
- Or revoke Upbuild inside Facebook, under Settings and privacy, Settings, Business integrations, which invalidates the token at source.
To have any remaining records deleted, email [email protected] with the subject "Meta data deletion", from the address on your Upbuild account. We action verified requests within 30 days and confirm by email. This section is the data deletion instructions page for the Upbuild Meta application: https://upbuild.app/privacy#data-deletion.
Use of Google user data (Limited Use disclosure)
Upbuild's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the user-facing features described here: answering the questions you ask through your AI assistant. It is not used for advertising, not sold, and not used to train models.
Cookies and analytics
Upbuild uses Google Analytics 4 with Google Consent Mode v2 in its advanced configuration. Until you accept, and whenever you decline, no analytics cookies are set and no persistent identifiers are stored: the site sends only anonymous, cookieless measurement pings that Google processes in aggregate. If you accept, first-party analytics cookies (_ga, _ga_*) are set to recognize returning visits; they expire after at most 24 months and are never used for advertising. All advertising consent signals (ad_storage, ad_user_data, ad_personalization) remain permanently denied: this site runs no advertising or remarketing. You can change or withdraw your choice at any time via Cookie preferences in the footer.
Subprocessors
| Provider | Purpose |
|---|---|
| Cloudflare | Hosting (Workers), encrypted token storage (KV), usage metering (D1) |
| Anthropic PBC | Claude, when you connect Upbuild there: the answers you ask for, including any Meta Platform Data, are delivered into your own Claude session |
| OpenAI LLC | ChatGPT, when you connect Upbuild there: the answers you ask for, including any Meta Platform Data, are delivered into your own ChatGPT session |
| Microsoft Corporation | Copilot Studio, when you connect Upbuild there: the answers you ask for, including any Meta Platform Data, are delivered into your own Copilot Studio agent |
| Google LLC (Gemini Enterprise) | Gemini Enterprise, when you connect Upbuild there: the answers you ask for, including any Meta Platform Data, are delivered into your own Gemini Enterprise session |
| Sign-in and the Google marketing APIs you connect | |
| Meta Platforms | Optional Meta Ads sign-in and Marketing API |
| Google Analytics | Privacy-configured site analytics under Consent Mode v2; cookieless until consent |
| Snap Inc. | Optional Snapchat Ads sign-in and Marketing API |
| TikTok (ByteDance) | Optional TikTok Ads authorization via TikTok’s official for-Business MCP server |
| Adobe | Optional Adobe Analytics and Adobe Experience Platform Tags APIs, via a credential from your own Adobe organization |
| Stripe | Subscriptions, checkout and customer portal |
Retention
- Tokens: until you disconnect, revoke access, or your account is deleted.
- Response cache: brief, typically minutes.
- Metering and billing records: as long as needed for the service and for legal and accounting obligations.
- Contact form submissions: until resolved, plus a reasonable follow-up period, unless you ask us to delete them earlier.
Your rights
Under the GDPR and equivalent laws you can request access, rectification, erasure, restriction, portability, and object to processing. Write to [email protected]. You can also lodge a complaint with your local supervisory authority. Disconnecting the connector and revoking access in Google or Meta immediately invalidates stored tokens; ask us to delete the associated records at any time.
International transfers
Our providers may process data outside the EEA. Where they do, transfers rely on adequacy decisions or standard contractual clauses put in place by those providers. The same applies between the two group companies named above, one established in Spain and one in the United Arab Emirates.
Changes
We will post any material change to this page and update the date above. Significant changes affecting connected users will also be communicated through the service.