> ## Documentation Index
> Fetch the complete documentation index at: https://help.autoady.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Protect access and understand data use

> Check who can access your workspace, protect credentials and report links, and find the applicable data policy.

Start with the access you control: team permissions, provider connections, client credentials, and shared report links. For AutoAdy’s stated data collection, processing, and privacy terms, read the current [Privacy Policy](https://www.autoady.io/privacy-policy).

## Review who can access the work

1. In **Settings → Team**, review each person’s role and assigned accounts. [Edit or remove access](/workspace/team#update-or-remove-access) when responsibilities change.
2. Check website permissions separately. A website viewer cannot manage its collection or keys; a team account grant does not automatically grant every website. [Manage website access](/websites/manage).
3. Review external clients in **Settings → AI & Agents → AutoAdy API keys**. Revoke unused manual keys or **Connected apps** OAuth connections. A credential acts with its AutoAdy identity’s access. [Manage credentials](/developers/authentication#replace-or-revoke-access).

Client workspaces organize work; they are not an additional access boundary. [Workspace structure](/workspace/structure) explains the relationships.

## Protect credentials and shared links

* Store API keys and server credentials in private settings or a secret store. Keep them out of browser code, repositories, screenshots, and support messages.
* If an AutoAdy key is exposed, **Revoke** it immediately, then replace it in the client before resuming work. An expired key also needs replacement or reconnection.
* Anyone with a complete client-report link can view that report without signing in. Open and check the report before sharing, and send it only to the intended recipients.
* The [Email Agent address](/agent/email) is a secret credential. Treat it as carefully as an API key.

For a website server key, follow [the rotation steps](/websites/manage#rotate-a-server-key); its old key stops working immediately.

## Understand which service handles the work

The [Privacy Policy](https://www.autoady.io/privacy-policy) describes data used to provide AutoAdy and sharing with service processors. For your work, these are the practical distinctions:

| Information | What it is used for | Your control |
| - | - | - |
| Connected account and ad data | Reading performance and carrying out supported work on the authorized account. | Provider connection choices, team permissions, and action approvals. |
| Submitted Agent prompts and creative material | The requested AI analysis or production task. | Choose the AI billing/provider mode and the material you submit. |
| Tracked website events | Website reporting and configured event delivery. | Installed script, consent state, collection controls, and destination settings. |
| API and server credentials | Authenticating a client or server task. | Keep secrets private; revoke an API connection or rotate a website server key. |
| Shared client-report links | Giving the link’s recipient access to its saved report. | Review the snapshot and share the complete link only with intended recipients. |

Model-provider keys pay for eligible internal AI work; AutoAdy API keys authenticate external clients to AutoAdy. They are different credentials.

With your own OpenAI or Claude key selected, eligible Agent text uses that provider connection and billing. With AutoAdy credits selected, work uses AutoAdy’s supported credit flow. Check the chosen mode and the provider’s terms before submitting sensitive material. [Connect and choose an AI provider](/agent/ai-providers).

For a tracked website, collection depends on its installed script and consent state. [Install tracking with consent](/websites/install); ownership verification alone does not mean visitor events are being collected.

## Request help with privacy or account data

Email [contact@autoady.io](mailto:contact@autoady.io) with your account email and the request you need help with. Use [Request account deletion](/workspace/account-deletion) for the existing deletion-request entry, or the [Privacy Policy](https://www.autoady.io/privacy-policy) for data-rights contact information. Sending a request is separate from its confirmation and completion.

For formal privacy terms and data-rights information, use the published policy linked above.

*Last reviewed: October 5, 2026.*


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.