Security
You are handing us OAuth tokens to accounts that spend money and to channels that post under your name. Here is what we do with them.
Tokens
Tokens for your connected accounts are encrypted at rest. They are used to pull performance, to create campaigns you build, and to publish posts you send, nothing else.
Disconnecting a platform revokes our access to it. See Connecting accounts.
Access
Access is scoped per workspace. Members of one workspace cannot see another workspace's data, connections, or campaigns.
Workspace members come in two roles. An admin can invite teammates and manage the workspace; a viewer has read-only access. Invites go out by email and are bound to the invited address.
History
Every change made to your ad accounts is logged under History, including what changed and when. If a campaign is not what you expected, that is where you look first.
Campaigns you create live can be set to land paused, so they exist in your ad account correctly configured and spend nothing until you switch them on yourself. See Ad campaigns.
Authentication
Ads.haus is passwordless. Sign-in uses a one-time emailed link, so we never store a password.
One consequence worth knowing: corporate mail scanners sometimes pre-open links in incoming email. Because a sign-in link is single-use, a scanner that opens it first will consume it, and the link will be dead by the time you click. If that happens, request a fresh one. If it happens every time, your mail provider is the culprit.
Getting in touch
Questions, or a security issue to report? Email info@nebula.haus.