Sign inFree AI Analysis

Trust & access

How do we access your accounts?

We never ask for your password. Through Meta’s and Google’s official permission systems, with only the access needed, revocable at any time.

Frequently asked questions

How does YUEN connect to my ad account?

Through the official OAuth consent screens of Google Ads and Meta: you approve with your own account, and YUEN receives only ad read/manage and page-statistics permissions. Your password never reaches YUEN at any step.

How do I revoke YUEN's access?

With one click in Portal → Connections → "Remove connection". The access key is deleted immediately and revoked on the Google/Meta side as well; ownership of the account always stays with you.

Where and how are access keys stored?

Keys are stored encrypted with AES-256-GCM in the EU (Frankfurt); only the server reads them and nothing reaches the browser. Every client's data is isolated at row level; AI recommends, a human approves each change, and every action is logged.

How the connection is made

Four steps. Your password never reaches us in any of them.

  1. 1

    You click “Connect”

    In the client portal, with your own account. We enter nothing.

  2. 2

    Meta’s / Google’s own screen opens

    Your password is entered there; YUEN never sees it. That screen belongs to the platform, not to us.

  3. 3

    Permissions are listed one by one

    Only ad read/manage and page statistics. You approve.

  4. 4

    A limited key is issued

    Stored encrypted, kept only on the server, revoked with one click.

Your password never reaches YUEN at any step. This is Meta’s and Google’s official method for agencies.

What we see, what we never see

What we can access

  • Campaigns, budgets, targeting
  • Performance data: spend, reach, clicks, conversions
  • Ad creatives and copy
  • Page statistics: followers, reach, engagement
  • Only the account you connected

What we can never access

  • Your password
  • Your personal profile, messages, friends
  • Your payment method / card
  • The identities of your followers (Meta gives this to no one)
  • Your other, unconnected accounts

Corporate note: We work through “Partner” in Meta Business Manager and “Manager account link” in Google Ads. Ownership stays with you; you can remove YUEN with one click.

Security layers

  1. 01

    Password-free access (OAuth)

    Your password never reaches us; the platform’s own permission system is used.

  2. 02

    Limited scope

    Only the permissions needed for the job are requested, nothing more.

  3. 03

    Encrypted key storage

    Access keys are stored encrypted in the EU (Frankfurt); only the server reads them, nothing goes to the browser.

  4. 04

    Client isolation

    Every client’s data is separated at row level; no client can see another, an expert sees only assigned accounts.

  5. 05

    Human approval

    AI produces recommendations, an expert approves the change. No automatic changes.

  6. 06

    Full audit trail

    Every change records who, when and why; you see it in your portal.

  7. 07

    One-click revocation

    You remove access from the portal; the key is deleted and revoked on the platform side too.

  8. 08

    Data use

    Your data is never sold or shared; personal data categories are kept for at most 24 months. YUEN may use de-identified, aggregated statistics to improve the service and its recommendation rules; identifiable client data is never used for model training.

Our infrastructure runs on Supabase and Vercel, both SOC 2 certified. We have described our own processes on this page.

Technical security

For your IT team: where and how data is protected, in one sentence each.

  • Encrypted token storage

    Google and Meta access keys are encrypted with AES-256-GCM; the key lives only in the server environment.

  • Row-level security (RLS)

    Each client sees only its own data, each expert only assigned clients; the rule is enforced in the database.

  • Server-side business logic

    All writes and API calls run on the server; no secrets reach the browser.

  • HTTPS

    All traffic is TLS-encrypted; HSTS enabled.

  • Least privilege

    Only the scopes needed for the job are requested; Drive is read-only, Ads write access only on an active plan.

  • Service-account method (Drive)

    Clients do not connect a Google account; the shared folder is the only source of authority and access ends when sharing is removed.

  • Weekly backups; daily as we grow

    An automatic database backup runs every Sunday at 03:00 and is kept for 8 weeks in encrypted private storage.

  • Access and change logs

    Every change records who, when, what and why; visible in the client portal.

Details and retention periods: Privacy Policy · Data deletion.

For corporate clients

A two-page “Security and Data Processing Summary” for your legal and IT teams: access model, see/never-see table, retention and deletion periods, technical layers, sub-processors (Supabase, Vercel, Google, Meta, Anthropic).

The English PDF is a translation; the Turkish version is the binding text and is available at /guvenlik.

Back to services