••HireOtto
Product ⌄Solutions ⌄
ProductGoogle AdsReport, analyze and make account changesLinkedIn AdsAnalyze and operate Campaign ManagerTag ManagerInspect measurement infrastructureSearch ConsoleAnalyze organic search performanceGoogle AnalyticsConnect acquisition to on-site outcomes
SolutionsAgenciesMore leverage across client accountsIndependent marketersMove faster without another hireIn-house teamsAnswers without another reporting cycle
How it worksPricing
Connect a server ↗
ProductGoogle AdsLinkedIn AdsTag ManagerSearch ConsoleGoogle AnalyticsSolutionsAgenciesIndependent marketersIn-house teamsHow it worksPricingConnect a server ↗
Privacy Policy

Our Privacy Policy

This policy explains what HireOtto collects, why we use it, who receives it, how long we keep it, and the controls available to you.

Last updated September 1, 2026

Who we are

HireOtto is operated by HIREOTTO TECHNOLOGIES LLP (“HireOtto,” “we,” “us,” or “our”).

HireOtto provides remote Model Context Protocol (“MCP”) servers and related tools for advertising, analytics, search, and measurement workflows. Supported services include Google Ads, LinkedIn Ads, Google Tag Manager, Google Search Console, and Google Analytics 4.

If you have questions or want to exercise a privacy right, email suyash@hireotto.com.

1) Scope and service summary

  • This policy covers the HireOtto website, accounts, subscriptions, support channels, remote MCP servers, temporary exports, and supported connections to Google, LinkedIn, AI clients, and other services you choose to use.
  • Google Tag Manager, Google Analytics 4, and Google Search Console are currently read-only. Google Ads and LinkedIn Ads support reporting and supported actions initiated by the user through an MCP-compatible client.
  • We treat Google user data under the Google API Services User Data Policy, including its Limited Use requirements. Those additional restrictions are set out in Section 4.

2) How HireOtto works with ChatGPT, Codex, and other AI clients

You may use HireOtto through ChatGPT, Codex, or another MCP-compatible AI client, assistant, or automation tool that you choose.

  • Your selected client decides when to call a HireOtto tool and sends the structured tool inputs and task-specific data needed for that request. HireOtto does not retrieve, reconstruct, or independently access your full conversation history.
  • Tool inputs may include the task you requested, the connected account or resource you selected, report parameters, proposed settings, or content needed for a supported action.
  • HireOtto uses those inputs to retrieve information from, or perform a user-directed action in, the relevant connected platform. Requested results are returned to you through your selected AI client.
  • OpenAI or another client provider may process, display, retain, or use information under its own terms and privacy policy. HireOtto does not control the client provider’s data practices.

3) Data we collect and why we use it

A. HireOtto account and authentication data

  • Categories: name, email address, HireOtto user and organization identifiers, account status, consent records, authentication records, plan, entitlements, and connected-profile identifiers.
  • Purposes: create and secure your account, authenticate requests, apply the correct plan and permissions, maintain your connections, communicate about the service, and prevent misuse.

B. MCP tool inputs and task data

  • Categories: structured tool-call inputs and task-specific data explicitly supplied by your selected client, such as account or resource identifiers, dates, filters, report fields, draft settings, and content for a supported action.
  • Purposes: validate and complete the request, retrieve the requested result, preview or perform a supported user-directed action, and return the result through your selected client.
  • HireOtto does not request or receive your full conversation history. We do not store raw tool inputs in ordinary MCP logs.

C. Google user data accessed through Google APIs

  • We request permissions only for the Google services you choose to connect:
    • Google Ads: https://www.googleapis.com/auth/adwords, for reporting and supported user-directed Google Ads actions.
    • Google Tag Manager: https://www.googleapis.com/auth/tagmanager.readonly, to read accounts, containers, workspaces, tags, triggers, variables, folders, and related configuration. Current Tag Manager access is read-only.
    • Google Search Console: https://www.googleapis.com/auth/webmasters.readonly, to read sites, sitemaps, URL inspection information, and search-performance data.
    • Google Analytics: https://www.googleapis.com/auth/analytics.readonly, to list accessible accounts and properties and read standard, comparison, realtime, and configuration reports. Current Google Analytics access is read-only.
    • Google identity: OpenID and basic email/profile permissions may be used to identify the Google account you connected and support authentication.
  • Categories: OAuth tokens; Google account and resource identifiers; Google Ads reporting, campaign, ad group, keyword, ad, budget, conversion, and settings data; Tag Manager configuration; Search Console sites, sitemaps, inspection and performance data; and Google Analytics properties, configuration, metrics, dimensions, events, acquisition, landing-page, conversion, and realtime data.
  • Purposes: provide the report, configuration inspection, export, preview, or supported user-directed action you request. Reporting and configuration results are not stored as part of your HireOtto account profile or in ordinary MCP logs.

D. LinkedIn Ads data accessed through LinkedIn authorization

  • Categories: OAuth tokens, authorized-member and ad-account identifiers, account roles, campaign groups, campaigns, ad sets, creatives, media assets, targeting entities, audience estimates, reporting metrics, aggregate professional-demographic reporting, and supported settings.
  • Purposes: identify accessible advertising accounts; provide requested reporting, analysis, exports, drafts, previews, and supported user-directed LinkedIn Ads actions; and return the result through your selected client.
  • LinkedIn Ads reporting and configuration results are not stored as part of your HireOtto account profile or in ordinary MCP logs.

E. Subscription, billing, plan, and credit data

  • Categories: billing name and email, payment-provider customer and transaction identifiers, subscription status, plan, amount, currency, payment-method type, limited payment-method details such as card brand or last four digits when provided by the payment processor, invoices, refunds, and credit allocation and consumption records.
  • Purposes: administer trials and subscriptions, apply entitlements, measure credit usage, process payments and refunds, provide billing support, maintain accounting records, and prevent billing abuse.

F. Support messages and feedback

  • Categories: emails and other messages, attachments you choose to provide, feedback, feature requests, and troubleshooting details.
  • Purposes: answer questions, investigate issues with your permission, improve user-facing features, and maintain a record of the resolution.

G. Temporary reports and exports

  • Categories: temporary CSV files, reports, and signed download links generated at your request.
  • Purposes: deliver the requested report or export. These files are not added to your stored account profile and expire automatically as described in Section 10.

H. Website analytics and cookies

  • Categories: IP address, device and browser information, pages viewed, referring URLs, timestamps, cookie identifiers, and similar website-use data.
  • Purposes: operate and secure the website, understand traffic and site performance, and improve website content. Website analytics is separate from MCP-service telemetry and is not used to build advertising audiences or retarget users.

I. MCP operational and security metadata

  • Categories: HireOtto user ID, connected-account ID, tool name, timestamp, and credit usage.
  • Purposes: authenticate and meter requests, enforce plan limits, diagnose reliability problems, maintain request isolation, investigate security incidents, and prevent abuse.
  • Ordinary MCP logs do not contain raw tool inputs, tool outputs, or connected-platform report results.

4) Google API Services User Data Policy and Limited Use

HireOtto’s use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements:

  • Purpose-limited: We use Google user data only to provide or improve user-facing features, such as showing requested reports or configuration and performing supported account actions when you request them.
  • No advertising or sale: We do not sell Google user data or use it for advertising, retargeting, or interest-based or unrelated behavioral profiling.
  • No transfers except:
    • to provide or improve the user-facing features you request, with your consent;
    • for security purposes, such as investigating abuse or a bug;
    • to comply with applicable law; or
    • as part of a merger, acquisition, or sale of assets only after obtaining your explicit prior consent.
  • No human access to Google user data unless:
    • you give affirmative consent for a specific support case;
    • access is necessary for security, abuse, or bug investigation;
    • access is required by law; or
    • the data, including derivations, is aggregated and de-identified and used for internal operations in accordance with applicable privacy law.
  • Personnel and providers: We require employees, contractors, agents, and service providers that handle Google user data to comply with these obligations.

5) Credentials and payment information

Do not submit passwords, API keys, access tokens, authentication links, MFA codes, one-time passwords, full payment-card numbers, CVVs, or other authentication secrets through an AI-client or plugin conversation.

  • Google and LinkedIn authorization takes place through the provider’s secure OAuth flow. HireOtto does not collect your Google or LinkedIn password.
  • Paddle and PayPal process card and other payment credentials under their own terms and privacy policies. HireOtto does not receive full card numbers, CVVs, or complete payment credentials.
  • HireOtto may receive the limited billing and transaction information described in Section 3(E).

6) Categories of data recipients

We disclose data only as needed for the purposes described in this policy:

  • Your selected AI or MCP client: requested advertising or analytics results are returned through the client you chose, at your direction.
  • Connected platforms: Google, LinkedIn, and another platform you deliberately connect receive the identifiers, parameters, content, or instructions required to retrieve data or perform the user-requested action.
  • Service providers: providers supporting hosting, databases, authentication, security, website analytics, email, customer support, error handling, file delivery, and payments may process the data needed to perform their services for HireOtto.
  • Professional advisers and authorities: advisers, courts, regulators, law-enforcement bodies, or other authorities may receive information when reasonably necessary to obtain advice, protect rights and security, or comply with law.
  • Business-transaction recipients: a buyer, investor, successor, or adviser may receive permitted information in connection with a financing, merger, acquisition, reorganization, or sale. The stricter consent requirement in Section 4 applies to Google user data.

OpenAI and other AI-client providers process information under their own terms and privacy policies. Payment providers process payment information under their own terms and privacy policies.

7) No sale, advertising, or unrelated profiling

  • HireOtto does not sell personal data, Google user data, LinkedIn Ads data, tool inputs, or connected-platform results.
  • HireOtto does not use this information for advertising, retargeting, or unrelated behavioral profiling.
  • HireOtto does not use one customer’s connected-platform data to make decisions for, or provide reports to, another customer.

8) Storage, security, and location

We use administrative, technical, and physical safeguards designed to protect data, including encryption at rest for OAuth tokens, least-privilege access controls, and operational logging.

  • No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
  • Data may be processed on infrastructure operated by service providers and may be stored or processed outside your state or country, subject to applicable safeguards.

9) Website analytics and MCP telemetry are separate

Website analytics concerns visits to HireOtto websites, such as pages viewed, browser information, referring URLs, IP address, timestamps, and cookies. It helps us understand and improve the website.

MCP telemetry concerns operation of authenticated HireOtto tools. It is limited to the metadata listed in Section 3(I) and does not include raw tool inputs, outputs, or connected-platform report results in ordinary logs.

10) Retention and deletion timelines

We use the following retention periods unless a longer period is required to comply with law, resolve a dispute, prevent fraud, enforce an agreement, or investigate a specific security incident. When data is no longer required, we delete it or de-identify it.

Data categoryRetention period
OAuth tokens and connected-account identifiersWhile the connection is active. Active tokens are deleted within 3 business days after disconnection, platform revocation, account deletion, or a verified deletion request. Residual backup copies may remain for up to 30 days.
HireOtto account and authentication dataWhile the account is active, then deleted or de-identified within 30 days after account closure or a verified deletion request, except for records that must be retained for legal, security, billing, or dispute purposes.
Google and LinkedIn reporting or configuration resultsProcessed for the requested task and returned through the selected client. They are not retained in the HireOtto account profile or ordinary MCP logs. A temporary export follows the export period below.
Subscription, payment, refund, and invoice recordsUp to 8 years after the relevant transaction or the end of the customer relationship when needed for accounting, tax, legal, fraud-prevention, or dispute records.
Plan, entitlement, and credit-usage recordsWhile the account is active and for up to 24 months after account closure. Records included in accounting or dispute documentation may be retained for up to 8 years.
MCP request, operational, and security metadata30 days. Records tied to a specific security incident, abuse investigation, or legal dispute may be retained until the matter is resolved and any required legal period ends.
Temporary CSV and report exportsOnly for the delivery window selected or configured for the request, typically 30 minutes and never longer than 24 hours.
Support messages and identifiable feedbackUp to 24 months after the last interaction. De-identified feedback may be retained longer to improve the service.
Website analytics dataUser-level and event-level website analytics data is retained for up to 14 months, subject to the analytics provider’s treatment of aggregated reports.
Website cookiesUntil they expire or you delete them. Google Analytics cookies used by the website may persist for up to 24 months.
Backups and deletion lagResidual copies of deleted data may remain in protected backups for up to 30 days before being overwritten or deleted, unless a longer period is legally required.

11) Your controls and choices

  • Disconnect Google: disconnect the relevant HireOtto profile where available or revoke HireOtto through Google Account → Security → Third-party connections.
  • Disconnect LinkedIn: disconnect the relevant HireOtto profile where available or remove HireOtto through LinkedIn’s permitted-services or connected-app settings.
  • Delete your HireOtto account: email suyash@hireotto.com. There is currently no self-service account-deletion control.
  • Access, correct, or delete data: subject to applicable law, email suyash@hireotto.com to request access, correction, deletion, or a copy of your personal data.
  • Marketing emails: use the unsubscribe link in a marketing email. Service, security, billing, and transactional messages may still be sent.
  • Cookies: control or delete cookies through your browser or device settings. HireOtto does not currently offer a separate cookie preference centre.
  • AI client: you control which compatible client you use and can remove or disconnect the HireOtto server through that client’s settings.

12) Children’s privacy

HireOtto is not directed to children under 13, and we do not knowingly collect personal data from children under 13.

13) Changes to this policy

We may update this policy from time to time. If a change is material, we will update the “Last updated” date and provide additional notice where required by law.

Contact us

For privacy questions or requests, contact:

HIREOTTO TECHNOLOGIES LLP
Email: suyash@hireotto.com

••HireOtto

MCP servers for performance marketers.

ProductGoogle Ads MCPLinkedIn Ads MCPTag Manager MCPSearch Console MCPGoogle Analytics MCPPricing
SolutionsAgenciesIndependent marketersIn-house teams
CompanyDocsBlogContactTermsPrivacyRefunds
© 2026 HireOtto. Built for marketers who would rather do the work.