OpenLabor Privacy Policy
Last updated: September 14, 2026
OpenLabor provides AI employees that carry out tasks for you and your team using your instructions and the apps you choose to connect. This policy explains how OpenLabor handles personal information and connected-app data when you use openlabor.ai and its services. Contact hello@openlabor.ai with privacy questions or requests.
If you use OpenLabor through a company workspace, your organization controls the work it asks OpenLabor to perform and who can access that workspace. Contact your workspace administrator about your organization's instructions, sharing choices and retention needs; you can also contact us directly about OpenLabor's handling of your information.
1. Information we collect
Account and billing information: your name, email address, profile details, workspace membership, subscription and transaction records. Our payment provider processes payment details. If you choose Google sign-in, our authentication service receives the identity information you authorize, such as your name, email address and profile image. Signing in does not by itself grant access to your Google Ads data.
Workspace content: messages, prompts, uploaded files, instructions, connected-app results, generated reports and other materials you or your team provide or create through AI employees. If you use voice or calling features, this may also include audio, call metadata, transcripts and recordings associated with those features.
Connected-app information: authorization tokens, connection status, account identifiers and the records needed for the integration and task you enable. The data depends on the app and permissions you approve; for example, messaging integrations may process messages and attachments. The next section describes Google Ads specifically.
Service and device information: IP addresses, browser and device information, page visits, feature interactions, errors, usage counters and security logs. Cookies and local storage also support sign-in, preferences and analytics.
2. Google Ads data and permissions
Connecting Google Ads is optional. After you authorize access through Google's OAuth screen, the connector discovers advertising accounts you can access, including clients of manager accounts, and lets you select an advertising account. We receive account and manager identifiers, account names, currency and timezone, campaign identifiers, names, status, budgets and performance metrics: impressions, clicks, spend, conversions and conversion value for the requested dates. For campaign management, we also process ad groups, bids, ad text, landing-page URLs, keywords and targeting settings.
We use these records to list accounts, retrieve campaign reports, answer your advertising-performance questions and generate the analyses you request from your AI employee. Reports can appear in your workspace conversations and files. Authorized workspace members may see them according to workspace roles and sharing settings.
The Google Ads connector requests the https://www.googleapis.com/auth/adwords permission for reporting and campaign management. At your request, an AI employee can create Search campaigns, ad groups, ads and keywords, change budgets and statuses, or remove campaigns, ads and keywords. These actions are validated and sent directly to Google Ads on your behalf without an additional in-app confirmation. New campaigns, ad groups and ads are created paused; your employee can activate them through a subsequent action. Activation and budget changes can affect your advertising spend. This connector does not request Gmail messages, Drive files or Calendar events.
We store action details, the selected account, the employee identifier, request identifiers, execution status and results in your workspace to provide an activity history and prevent duplicate execution. These records remain with workspace data and can be included in a deletion request. Earlier proposals and their approval or rejection records may also remain in the history; they are not automatically executed by this change. Disconnecting Google Ads stops future access but does not undo changes already applied in Google Ads or remove existing workspace records.
We receive access and refresh tokens to maintain the connection and refresh access when needed; we do not receive your Google password. Account discovery can read account metadata before you select an account. Campaign reporting uses the selected account.
3. Meta Ads data and permissions
Connecting Meta Ads is optional. After you authorize access through Meta's Facebook Login screen, the connector lists the ad accounts the authorizing Meta user can reach and lets you select one. We receive ad account identifiers, names, currency, timezone, account status and the owning business name; campaign, ad set, ad and creative identifiers, names, status, objectives, budgets and targeting settings; and performance metrics for the dates you request: spend, impressions, reach, frequency, clicks, click-through rate, cost per click and the conversion actions Meta returns.
We use these records to list ad accounts, retrieve performance reports, answer your advertising questions and produce the analyses you ask your AI employee for. Reports can appear in your workspace conversations and files, visible to authorized workspace members according to workspace roles and sharing settings.
The Meta Ads connector requests ads_management and ads_read, which it cannot operate without, and business_management and pages_show_list, which it will operate without in a reduced form. ads_read retrieves performance reports. ads_management creates and changes campaigns, ad sets, ad creatives and ads in the ad account you select, at your request. business_management lists ad accounts owned by your Business portfolio; without it, only personally owned accounts appear. pages_show_list lists the Facebook Pages the authorizing user administers, so an ad creative can name the Page it is published from; without it, you supply the Page identifier yourself. These permissions are used only for the advertising account you connect. This connector does not request Page content, messages, or personal profile data beyond the identity Meta returns with the authorization.
At your request, an AI employee can create campaigns, ad sets, ad creatives and ads, upload ad images, change budgets and statuses, and delete campaigns. These actions are validated and sent directly to Meta on your behalf without an additional in-app confirmation. Every campaign, ad set and ad is created paused; activation is always a separate action. Activation and budget changes can affect your advertising spend.
We receive a long-lived access token to maintain the connection. Meta issues no refresh token, so the connection is renewed by exchanging the existing token before it expires, approximately every sixty days; when renewal is no longer possible the connection is marked as needing reconnection. We do not receive your Meta password.
We store action details, the selected ad account, the employee identifier, request identifiers, execution status and results in your workspace to provide an activity history and prevent duplicate execution. Disconnecting Meta Ads stops future access but does not undo changes already applied in Meta or remove existing workspace records. To revoke OpenLabor's authorization entirely, remove OpenLabor from your Meta account's Business Integrations settings.
4. X Ads data and permissions
Connecting X Ads is optional. After you authorize access through X's OAuth screen, the connector lists the ad accounts the authorizing X user can reach and lets you select one. We receive ad account identifiers, names, timezone, business identifier and approval status; funding instrument identifiers and their currency; campaign, line item, promoted tweet and targeting criterion identifiers, names, status, budgets, objectives and placements; and performance metrics for the dates you request: billed spend, impressions, clicks and engagements.
We use these records to list ad accounts, retrieve performance reports and produce the analyses you ask your AI employee for. Reports can appear in your workspace conversations and files, visible to authorized workspace members according to workspace roles and sharing settings.
The X Ads connector uses read and write access to the X Ads API for the ad account you select. At your request, an AI employee can create and change campaigns, line items and targeting criteria, promote existing tweets as ads, stop promoting them, and change budgets and statuses. These actions are validated and sent directly to X on your behalf without an additional in-app confirmation. Campaigns and line items are created paused; activation is always a separate action. Activation and budget changes can affect your advertising spend. Promoting a tweet makes an existing public post into an advertisement; it does not create, edit or delete posts.
We receive an OAuth access token and token secret to maintain the connection. These do not expire on a schedule; they remain valid until you disconnect or X or you revoke them. We do not receive your X password.
We store action details, the selected ad account, the employee identifier, request identifiers, execution status and results in your workspace to provide an activity history and prevent duplicate execution. Disconnecting X Ads stops future access but does not undo changes already applied in X Ads or remove existing workspace records. To revoke OpenLabor's authorization entirely, remove OpenLabor from your X account's connected apps settings.
5. How we use information
We use account and service information to operate OpenLabor, authenticate users, manage workspace access, process billing, provide support, diagnose faults, prevent abuse and communicate about the service. Usage analytics help us understand which features work and where the product needs improvement.
We process your workspace content and connected-app data to carry out your instructions, maintain task context, produce responses and deliver the features you enable. Connecting an app does not authorize us to use its data for unrelated purposes.
6. AI processing and Google Limited Use
When you ask an AI employee to analyze connected data, relevant task context and results may be sent to the AI model provider configured for that employee to produce the response. For example, a Google Ads report may be processed by an AI provider to explain campaign performance. Generated answers may be saved in your conversation history. The provider used depends on the selected model, service configuration and any provider account you connect yourself.
OpenLabor does not use Google, Meta or X user data, or your private workspace content, to train general-purpose AI models or models for other customers. AI processing of Google data is for your requested features, not for building an independent training dataset. If you connect your own provider account, its account settings and terms also apply to processing by that provider.
Our handling of Google API data follows the Google API Services User Data Policy, including its Limited Use requirements. We do not sell Google user data, use it for OpenLabor's own advertising or unrelated third-party advertising profiles, or use it to determine creditworthiness. These restrictions also apply to information derived from that data. Campaign management is performed only for the advertising accounts you connect, at your request, including through the instructions you give your AI employee.
Access to Google data by OpenLabor personnel is limited to situations such as support you authorize, investigating security issues or abuse, or complying with applicable law. Google data is not made available to personnel for unrelated browsing or marketing.
7. Sharing and service providers
We do not sell your personal information. Service providers process information needed to deliver OpenLabor: for example, Cloudflare for hosting and storage, Clerk for authentication, Stripe for payments, and the AI providers used to execute your tasks. Depending on the features you use, communications, integration, support, analytics and error-monitoring providers also process the information necessary for those functions.
Data from connected advertising accounts, including Google Ads, Meta Ads and X Ads, may be processed by our hosting and AI providers to deliver the connected features you authorize. We do not transfer it to advertising networks, data brokers or resellers. Transfers are limited to delivering those features, security needs, legal obligations, or a business transfer with the prior consent required by Google's policy.
Your instructions may involve sharing task output with a teammate or sending it to a destination you choose. People who receive an exported report or shared copy may retain it independently. Other connected services handle information under their own policies as well as the permissions you grant them.
8. Storage and security
We use HTTPS for data transmission, authenticated access and workspace access controls. The direct Google Ads, Meta Ads and X Ads connectors store encrypted authorization tokens in workspace-scoped storage; connection metadata identifies the employee and the selected advertising account. Tokens are not included in the reports returned to AI employees and are not shared with the AI model providers that process your requests.
Report results, conversations and files can be stored as workspace content so you can revisit your work. Our infrastructure and service providers may process information in countries other than where you live. No online service can guarantee absolute security; contact us promptly if you suspect unauthorized access.
9. Retention, disconnection and deletion
We keep account and workspace information for as long as needed to provide the service and retain the work you choose to keep. Retention depends on the type of record, your workspace's use of the service, deletion requests and any applicable billing, legal or security requirements; there is no single retention period for all records.
To stop a direct advertising connection for an employee, open that employee's Apps tab, select Google Ads, Meta Ads or X Ads and disconnect it. This removes its stored tokens and pending authorization sessions. To revoke OpenLabor's Google authorization across connections, remove OpenLabor from your Google Account's third-party connections page. Revocation prevents future authorized access; it does not delete reports already saved in OpenLabor.
You can request deletion of connected Google data, saved reports, conversations or your account by emailing hello@openlabor.ai. Identify the account or workspace and the information you want removed; do not send passwords or tokens. We may verify your identity and authority over a shared workspace before acting. Disconnecting an app and deleting previously imported data are separate actions.
Some records may need to remain for legal obligations, billing disputes, fraud prevention or security. Copies may also remain in backups until those backups are removed or expire. If an exception affects your request, we will explain it. Copies you exported or shared with another service must also be managed with that recipient.
10. Cookies, analytics and your choices
OpenLabor uses browser storage for authentication, preferences and service operation. We use analytics and error-monitoring tools, including PostHog and Sentry, to understand usage and diagnose problems. You can turn off OpenLabor analytics in Settings → Account → Preferences. Browser controls also let you remove or restrict cookies and local storage, although this may affect sign-in and other features.
You choose which apps to connect and can review their permissions before authorizing them. Depending on your location, you may have rights to access, correct, delete or obtain a copy of personal information, object to certain processing, or withdraw consent. Contact hello@openlabor.ai to exercise these rights. We aim to respond within 30 days and will tell you if more time or information is needed.
11. Changes and contact
We will update this page when our practices change and revise the date above. If we introduce a new use of Google data, we will provide notice and obtain any additional consent required before that use begins. For questions, data-access requests or deletion requests, contact the OpenLabor team at hello@openlabor.ai.