← Trust Center

Toffu and your ad accounts: what your agency connected

Your agency uses Toffu, an AI marketing assistant, to analyze and report on your advertising. This page explains exactly what Toffu can and cannot do with the accounts they connected.

What Toffu can access

  • Read your ad campaigns, ad accounts, and performance results on Meta (Facebook / Instagram) and Google Ads.
  • Read your Google Analytics and Search Console data.
  • It accesses only the accounts your agency selects, through Google's and Meta's official APIs.

What Toffu cannot do

  • It cannot change anything you did not approve. Meta connects read-only by default; making changes requires your agency to deliberately enable management access, and even then every change is proposed for approval first.
  • On Google Ads, it cannot make any change without explicit approval (Google has no read-only option, so changes are governed by the approval step below).
  • It never uses your data to train AI models. This is contractual, in Toffu's Data Processing Agreement.
  • It does not share your data with other clients or sell it.

How changes are controlled

  1. Toffu proposes a specific change for review.
  2. Nothing is sent to the ad platform until it is approved.
  3. Every change Toffu makes is logged and can be reviewed.
  4. An approved change can be reverted to its previous values.

Certifications

Toffu is SOC 2 Type II certified and GDPR compliant. Access is governed by SSO and role-based access control.

Questions

Security questions or a request for Toffu's policies and SOC 2 report: security@toffu.ai. Full detail: toffu.ai/trust-center.

Toffu AI, Inc. This summary is provided for transparency and does not modify any agreement between you and your agency or Toffu.