Security
You are handing us OAuth tokens to accounts that spend money and to channels that post under your name. Here is what we do with them.
Tokens
Tokens for your connected accounts are encrypted at rest. They are used to pull performance, to create campaigns you build, and to publish posts you send, nothing else.
Disconnecting a platform revokes our access to it. See Connecting accounts.
Access
Access is scoped per workspace. Members of one workspace cannot see another workspace's data, connections, or campaigns.
Workspace members come in two roles. An admin can invite teammates and manage the workspace; a viewer has read-only access. Invites go out by email and are bound to the invited address.
History
Every change made to your ad accounts is logged under History, including what changed and when. If a campaign is not what you expected, that is where you look first.
Campaigns you create live can be set to land paused, so they exist in your ad account correctly configured and spend nothing until you switch them on yourself. See Ad campaigns.
Authentication
Ads.haus is passwordless. Sign-in uses a six-digit code emailed to you, so we never store a password. Codes expire after ten minutes and only work on the screen that requested them.
We moved from emailed links to codes because corporate mail scanners pre-open links in incoming email and used up single-use sign-in links before anyone clicked them. A code in the email body has nothing for a scanner to open.
Getting in touch
Questions, or a security issue to report? Email info@nebula.haus.