← Back to home

Privacy Policy

Last updated: June 3, 2026

Orvix Meta Ads MCP (“Orvix”, “we”, “us”) is a Model Context Protocol (MCP) server that lets you manage your Meta (Facebook & Instagram) advertising from an AI assistant such as Claude. This policy explains what we process and why. The short version: we are stateless and store no copy of your data or access tokens.

What we process

  • Facebook Login & your Meta access token. When you connect, you authenticate with Facebook and grant ads permissions (ads_management, ads_read, business_management). We receive a Meta access token scoped to those permissions.
  • We do not store that token on our servers. It is encrypted inside the OAuth token issued to your MCP client (e.g. Claude) and used only transiently, per request, to call the Meta Marketing API on your behalf.
  • Ad data.When you ask your assistant to read or change campaigns, we relay that request to Meta’s Graph API and return the result to your client. We do not retain copies of your campaigns, insights, or creatives.
  • Technical logs. Our hosting provider processes standard request logs (timestamps, status codes, error diagnostics) for reliability and abuse prevention. These do not contain your Meta access token in plaintext.
  • No accounts, passwords, analytics cookies, or ad tracking.

How we use it

Solely to perform the ad-management actions you request through your AI assistant — listing accounts, reading campaigns and insights, and (when you confirm) pausing, resuming, adjusting budgets, or creating campaigns, ad sets, and ads. We do not use your data for advertising, profiling, or model training.

Who we share it with

  • Meta Platforms — your requests act on your own ad accounts via the Meta Graph API.
  • Your MCP client (e.g. Anthropic / Claude) — the encrypted access token is held by your client, not by us.
  • Vercel — our hosting and infrastructure provider.

We do not sell your data or share it with anyone else.

Retention

We persist no personal data. Issued tokens are short-lived — access tokens last about one hour and refresh tokens up to 60 days — and expire automatically. MCP session state is held in memory only and is discarded when the connection ends.

Revoking access & deleting data

Because we store nothing, you can fully end our access at any time by removing the app in Facebook → Settings & Privacy → Settings → Business Integrations, and by removing the connector in your AI client. See our Data Deletion page for details.

Security

All traffic is served over HTTPS. Tokens are encrypted with AES-256-GCM inside the OAuth artifacts we issue, so your Meta access token is never exposed to your client in plaintext.

Children

The service is intended for advertisers and is not directed to anyone under 18.

Changes

We may update this policy; the “last updated” date above will change accordingly. We operate in accordance with the Meta Platform Terms and Developer Policies.

Contact

Questions or requests: support@orvix.co.th.

© Orvix. Terms · Data Deletion