Security and access
What Operax asks Google and Meta for, what it can do with it, and what it cannot do at all.
What access Operax asks for
| Platform | Permission requested | Why |
|---|---|---|
| Google Ads |
| Read campaigns, search terms, keywords, ads, budgets and results; apply the changes you approve. Google offers a single permission for Google Ads. It always includes the ability to make changes; there is no read-only version. Operax enforces read-only on its own servers: on a read-only connection, the code path that sends changes to Google is blocked. |
| Google Ads (revenue feedback) |
| Send the value of jobs you actually won back to Google, so its bidding learns from revenue instead of from form fills. Asked for separately, and only when you turn on revenue feedback or customer-list matching. Declining it changes nothing else. |
| Meta (read-only audit) |
| Read campaigns, ad sets, ads and results. This is all a read-only Meta connection asks for. Lead forms are not captured while a connection is read-only. |
| Meta (managed) |
| Apply the changes you approve, and receive the leads people submit through your Facebook and Instagram lead forms. Requested only when you switch Meta to managed access, in a second sign-in you can decline. |
Read-only and managed connections
A read-only connection can be analysed and reported on, and nothing else. Every path that would send a change to Google or Meta is refused on our servers before it reaches the platform.
A managed connection can also apply the changes you approve. You choose per connection, and you can switch back to read-only at any time. You can remove Operax’s access entirely from your Google Account permissions page or your Meta Business settings at any time; Operax will then show the connection as disconnected.
What the AI can do
- Change a campaign budget
- Pause a campaign
- Add negative keywords so your ads stop showing on searches that never convert
- Add keywords
- Rewrite responsive search ad headlines and descriptions
- Turn on a paused campaign it created
- Adjust a Google Ads target cost per conversion (target CPA) or target return on ad spend (target ROAS)
What the AI cannot do
- Access your payment methods or billing details in Google Ads or Meta.
- Create or remove users on your ad accounts.
- Act at all on a read-only connection.
- Exceed a guardrail you set.
- Act while the kill switch is on.
- Turn on something it created without that being approved as its own change.
- Send your data to other advertisers, or use it to train models for other customers.
- Operax reports on Local Services, Smart, Shopping, Display and Video campaigns but does not change them.
- Retail (Shopping and feed-based Performance Max) campaigns are reported, not managed.
Guardrails
Guardrails compare against what your ad accounts report, not against numbers written by the AI.
- A daily spend ceiling and a monthly spend ceiling for the whole account.
- A maximum budget change per step, so no single action can move a budget by more than a set percentage.
- A maximum number of actions per day.
- An approval threshold in money: anything above it always asks, whatever else is switched on.
- Protected brand terms, so your own name is never blocked or bid away.
- Quiet hours for anything that contacts a customer.
A spend ceiling is a limit Operax enforces on itself. It is not a hard stop inside Google or Meta: an ad platform can spend more than a daily budget on a given day, and no software outside the platform can prevent that.
Approvals, rollback and the kill switch
An approval shows the change, the evidence behind it, what it expects to happen and how it will be undone. Approving is one click; so is undoing it afterwards, because the previous state was captured before the change was sent.
The kill switch stops every AI action for your whole account immediately. Rollback keeps working while it is on, so switching it off is never a trap.
How your data is handled
- OAuth tokens are encrypted at rest with Fernet; nobody reads them out of the database by eye.
- Your data is used to provide the service to you, and is not sold.
- The AI providers we use receive the campaign data needed to write a proposal. It is not used to train their models. The sub-processors are named in the Privacy Policy.
- You can ask for your data to be deleted, and it is deleted.
- Operax’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- The full detail is in the Privacy Policy.
Limits of our responsibility
Your ad spend is yours: it is charged by Google and Meta directly to your payment method, and Operax cannot see or control it. What Operax is responsible for, and what it is not, is set out in the Terms of Service.
Start with a free, read-only audit
Connect Google Ads, pick the account, and see what we find. No card. We do not change anything in your account.