Privacy Policy
Last updated: 25 September 2026
GoPilot (“GoPilot”, “we”, “us”) is an online platform that helps businesses build landing pages with AI, publish them on their own domains, and prepare Google Ads campaigns. This policy explains what information we collect, how we use it, and the choices you have. Questions: kevinong0203@gmail.com.
1. Information we collect
Your account
- Your email address and password (passwords are stored hashed by our authentication provider, never in plain text).
- Basic records of when you signed up and last signed in.
Content you create or upload
- Landing pages, the business details you enter, chat instructions, saved versions and publishing settings.
- Photos and PDF files you upload.
- Domains you add, Google Ads campaign plans, and Growth settings (such as a Facebook Pixel ID, Google Tag Manager ID, SEO text and FAQs).
- If you choose to use your own Anthropic API key, that key (stored encrypted).
Usage information
- How many AI requests you make and their size (tokens), so we can apply fair-use limits and understand costs.
- Technical logs (such as IP address, browser type and error messages) kept by our hosting providers for security and troubleshooting.
2. Google user data (Google Ads)
If you choose Connect Google Ads, you sign in with Google and grant GoPilot access to your Google Ads account (scope https://www.googleapis.com/auth/adwords) and your email address. We use this access only to provide features you ask for:
- to list the Google Ads accounts you can use, with their name, ID and currency, so you can choose one;
- when you click Post to Google Ads account, to create the campaign you prepared in GoPilot (budget, ad group, ads, keywords, negative keywords, locations, languages, callouts and sitelinks) in your account, paused;
- to read the status of campaigns created through GoPilot, so GoPilot can show whether they are paused or live.
GoPilot never turns campaigns on: you publish them yourself inside Google Ads. We do not read your billing or payment information, and we do not access campaigns GoPilot did not create except to list your accounts.
We store the Google sign-in token encrypted, only to perform the actions above. We do not sell Google user data, use it for advertising, or use it to train AI models, and humans at GoPilot do not read it unless you ask us for help, it is needed for security, or the law requires it. You can disconnect at any time in GoPilot (Google Ads → Disconnect), which revokes our access and deletes the token, or from your Google Account’s security settings.
GoPilot’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
3. How we use information
- To run GoPilot: build, store, publish and host your pages, and prepare your ads.
- To generate content with AI when you ask (see section 4).
- To keep accounts secure, prevent abuse and apply usage limits.
- To answer your support requests and send important service messages (such as sign-up confirmation).
We do not sell your personal information.
4. AI processing
When you ask GoPilot to build or change a page, write ads, or suggest SEO text and FAQs, the relevant content (your instructions, business details, page, and uploaded files) is sent to Anthropic’s Claude API to produce the result. Anthropic processes it as our service provider under its commercial terms. If you use your own Anthropic API key, the request is made with your key under your agreement with Anthropic.
5. Service providers we share information with
- Supabase: database, file storage and sign-in.
- Vercel: hosting of GoPilot and of published pages, including SSL certificates for your domains.
- Anthropic: AI generation (Claude).
- Google: when you connect Google Ads.
These providers process information only to provide their services to us. We may also disclose information if required by law or to protect the rights and safety of our users and GoPilot.
6. Pages you publish and their visitors
We host the pages you publish. If you add a Facebook (Meta) Pixel, Google Tag Manager, or other tracking to your page, those services may collect information about your visitors under their own policies. You are responsible for telling your visitors about this and for any consent your local law requires.
7. Keeping and deleting information
- We keep your information while your account is active.
- You can delete pages, files and domains in GoPilot at any time.
- To delete your account and all its content, email kevinong0203@gmail.com. We delete it within 30 days, except where we must keep something by law.
8. Security
We use HTTPS, access controls on our database, and encryption for stored secrets such as Google sign-in tokens and API keys. No system is perfectly secure, so please use a strong password and tell us about any concern.
9. Your choices and rights
You can access and update your content in GoPilot, disconnect Google Ads, remove your API key, and ask us for a copy or deletion of your personal information by emailing us. Depending on where you live (for example under Malaysia’s PDPA), you may have further rights.
10. Children
GoPilot is a business tool and isn’t intended for anyone under 18.
11. Changes
We may update this policy. We’ll change the date above and, for important changes, let you know in GoPilot or by email.