How it keeps you safe
An AI client can misread a request. It can also read a web page or a comment that tells it to do something you never asked for. Marketing MCP is built so that neither can quietly spend your money, publish in your name or delete your work.
This page says what the server does about it. It is the page to read before you decide whether to use Marketing MCP.
The short version
- Every change is a preview first. Nothing is changed until the request is sent a second time, asking for it to be applied.
- A post is a draft unless you asked for it to be published or gave it a time.
- New campaigns and ads start paused. Starting to spend is always a step of its own.
- Limits are set by the administrator. A request cannot raise one, and a request over one is refused, never cut down to fit.
- Deleting and removing need a second, explicit confirmation.
- The platforms' automations are sent switched off unless you ask for one by name.
- Optional abilities are off until an administrator switches each one on.
- Leads, messages and customer records are never stored on the server.
- Everything is in the activity log: what was applied, what was only previewed and what failed.
Every change is a preview first
When you ask your AI client for a change, the server first answers with a preview: what would change, what it is now, and any warning. A preview changes nothing. The AI client shows it to you and asks. Only when you say yes does it send the request again to be applied.
Raise the daily budget of the Spring Sale campaign to 80.
What comes back is a preview: the budget now, the budget asked for, and whether it passes the limits. The budget is still what it was. After you confirm, the change is applied and the activity log has both rows: the preview and the change.
Who checks a preview
A preview is not the same thing on every platform, and it matters that you know which kind you are looking at.
| Where | What a preview is |
|---|---|
| Google Ads | Google checks it. The change is sent to Google marked "check only", so Google itself says whether it is valid, and applies nothing. |
| Sending conversions or a customer list to Google | Google checks it, the same way. |
| Meta Ads: creating, editing, switching on or off, or re-budgeting a campaign, an ad set or an ad | Meta checks it, and applies nothing. |
| Meta Ads: everything else, such as a creative, boosting a post, a lead form, an audience, a customer list, sending conversions, a copy, an automated rule | This server's own check. Meta has not seen it. |
| Facebook and Instagram posts, comments and messages | This server's own check. Meta has not seen it. |
| LinkedIn posts and all of LinkedIn Ads | This server's own check. LinkedIn has not seen it. |
| Watching an account, a lead feed, an alert rule, a budget plan, a scheduled report | Nothing goes to a platform either way. The preview shows what would be saved. |
Three Google Ads actions are the exception to the first row, because Google has no way to check them without doing them: applying a recommendation, dismissing one, and uploading a video. Their preview is this server's own check.
A preview that the platform has not seen can still be refused later
Meta and LinkedIn have no "check only" mode for most things. There the server checks what it can by itself: your permissions, the limits, the length of the text, the media, the schedule. The platform sees the change for the first time when it is applied, and may still refuse it. The server never calls such a preview "validated", and the AI client is told not to either.
A post is a draft unless you ask for it to go live
A published post cannot be un-published: people have seen it. So the safe state for a post is "not published yet", and that is the default.
- Asked for nothing more: the post is held as a draft. You review it on Drafts in the management page and press Publish or Discard there, or ask your AI client to publish it.
- Asked for it to go live: it is published as soon as the request is applied.
- Gave it a time: it is scheduled. Facebook holds a scheduled post itself. Instagram and LinkedIn cannot, so the server holds the post in its own queue and publishes it at that time.
The request decides, not a setting: there is no installation switch that publishes everything or holds everything.
Three things go live at once, because the platform has no held state for them: a Facebook story, a reply to a comment and a reply to a private message. The AI client is told to show you each one and get a clear yes first, and never to reply in bulk.
See Posting and Scheduling.
New campaigns and ads start paused
In a new installation, nothing that the server creates can spend until someone switches it on.
| Platform | What a new thing starts as |
|---|---|
| Google Ads | A campaign is always paused. A keyword, an ad and an ad group are paused too, while the administrator's two switches for them on Safety limits are on, as they are in a new installation. With one of those switches off, a new keyword, or a new ad or ad group, is created enabled unless the request asks for it paused. |
| Meta Ads | A campaign, an ad set and an ad are always paused. A copy is paused. An automated rule is created disabled. |
| LinkedIn Ads | A campaign group is a draft. A campaign and an ad are paused. A lead form is a draft. |
Starting to spend is a step of its own
On Meta Ads and on LinkedIn Ads, exactly one action switches a campaign, an ad set or an ad on. No other request can start spending as a side effect. When that action is previewed, the server:
- checks every budget that would go live against the administrator's limits, including a budget that somebody made above the limit on the platform's own site;
- adds up the daily budgets that would be live on the ad account and checks the total;
- shows the most that could be spent. A daily budget is an average: Meta may spend up to 75% more on one day, and LinkedIn up to 50% more;
- by default, refuses to switch on an ad that you have not had previewed in the last 24 hours.
On Google Ads, enabling a paused campaign, ad or keyword is likewise a request of its own.
Changing many things in one request is possible on all three platforms, for pausing and for budgets. It cannot switch anything on, and it cannot delete.
See Meta Ads, LinkedIn Ads and Google Ads.
Limits come from the administrator
The administrator sets the limits on the Safety limits page: the highest budget, the highest bid, the largest raise in one request, how many posts a person may publish in a day, and more. They are checked on the server for every request.
- A request cannot raise a limit. No wording in a prompt can.
- A request over a limit is refused, not trimmed. You are told the limit; the server does not pick a smaller number for you.
- Lowering is not held back. On Google Ads, a lower budget, bid or target goes through even when it is still above the limit, because refusing it would keep the higher value. On Meta Ads and LinkedIn Ads, a lower budget is never refused for the size of the change, but the new amount must itself be within the highest budget for the account's currency.
- On Meta Ads and LinkedIn Ads, a currency with no limit is not unlimited. Until the administrator sets an amount for an ad account's currency, changes that the limit guards are refused on that account.
- A refusal says where to change it. When a request is refused over a limit or a switch, the answer carries the address of the management page where an administrator changes it.
Every limit and its starting value is on Limits and switches.
Deleting and removing ask twice
Anything that cannot be undone needs two things: the request must ask for it to be applied, and it must carry a separate confirmation. The preview is free, so you can see what would be removed before you confirm. What was removed is kept in the activity log as it was.
- Google Ads campaigns, ad groups and ads cannot be deleted from here at all. Pausing is their off switch. What can be removed, such as a keyword, a negative keyword or an exclusion, asks for the confirmation.
- A published post is deleted one post per request, after it has been read and shown to you. For a Facebook post, hiding it can be undone and is offered first.
- A comment can be hidden, which can be undone. Deleting one is refused until the administrator allows it.
- A draft can be discarded only while nobody has seen it.
- Taking people out of a customer list, and replacing a list, count as removing.
See Editing and deleting and Comments.
The platforms' automations are off unless you ask
Each platform has features that change your ad or widen your audience by themselves. The server sends them switched off, by name, instead of leaving them to the platform's default.
- Meta Ads: creative enhancements, which let Meta rewrite the text or crop and retouch the image, are all sent refused. A request can ask for one by name only where the administrator allows it. Widening the audience beyond your targeting is off unless you ask.
- Google Ads: for a Performance Max campaign, Google's own texts, image retouching, images taken from your landing page, reworked videos and sending clicks to other pages are all sent off. Showing Display or Demand Gen ads to people beyond what you targeted is off unless you ask. Google's reworking of a Demand Gen ad's images and videos is sent off, and there is no way to ask for it from here.
- LinkedIn Ads: audience expansion is off unless you ask. Ads on other companies' apps and sites are off, and can be asked for only where the administrator allows it.
Where a platform gives no switch, the server says so in the preview instead of hiding it. For example, Google may make a video for a Performance Max campaign that has none.
Optional abilities are off until an administrator switches them on
A new installation can post and report. Everything more sensitive is behind a switch that starts off: advertising on Meta and LinkedIn, reading leads, reading and answering private messages, sending customer records to a platform, deleting comments, deleting Instagram posts, letting the server read accounts by itself, and pushing leads to your own system.
Two more controls sit above all of them:
- Write access is per person. A user without May write can read reports and is refused every change. See Users and access.
- Read-only mode refuses every change for everyone. See Server settings.
What the server does by itself
With nobody asking at that moment, the server does only these things:
- publishes a post from the queue at the time you gave it;
- reads the accounts you asked it to watch and keeps their figures, when History is on;
- checks your alert rules. A rule tells you, and does nothing else: it never pauses anything and never changes a budget;
- builds a scheduled report and sends it to you;
- pushes new leads to your organisation's own address, when lead delivery is on.
It never creates, changes, starts or stops an ad by itself. When something it did by itself fails, it tells you on Notifications. A queued post or a report that failed is never sent a second time by itself. A lead feed that could not deliver keeps trying, and the leads are sent when it gets through.
What is never stored
The server passes these on and keeps none of them, not in the database, not in the activity log and not in a log file:
- Leads: the names and contact details that people left in a lead form. The activity log keeps which form was read and how many leads.
- Private messages: neither what people wrote nor your reply. The log keeps ids and the length of a reply.
- Customer records that you send to an advertising platform, and the hashed values made from them. The log keeps counts.
- What listening finds: other people's posts under a hashtag, posts that tag you, and another account's figures.
- LinkedIn commenters' names and words. The log keeps ids.
- Website analytics reports.
Two things are kept, so that you can see what was done:
- A Facebook or Instagram comment that you replied to, hid or deleted through the server is kept in that action's row in the activity log.
- Your own posts, as drafted, published, edited and deleted.
When History is on, the server keeps counts for the accounts you watch: figures per day, never a person. A scheduled report is kept as figures too.
The full list of what an installation stores, for how long, and what deletes it, is in the privacy policy. Your data stays on your own installation: Namasoft does not run it and does not receive it.
What the server enforces, and what it asks of the AI client
It is worth being exact about this.
The server enforces the preview by default, write access, every limit and switch, the separate confirmation for a delete, paused creation, the single action that starts spending, and the automations sent off. An AI client cannot argue its way round any of these: they are checked on the server for every request.
The server asks the AI client to show you each preview and to wait for your yes before applying it, to publish only when you asked, and to pass on warnings. A well-behaved AI client does. But the server cannot see your conversation, so it cannot prove that you were asked. This is why the limits exist: they hold whatever the AI client does.
Everything is in the activity log
Every change is recorded with who made it, when, what was asked, what was there before and what came back. So is every preview and every failure. You read your own on My activity; the administrator reads everyone's on All activity.
See The activity log.