Security
Purpose-limited access, explicit actions, recoverable outcomes.
AqiMeta separates browser interaction from server-side credentials and records task state needed to prevent unsafe retries.
Server-side credentials
Application secrets and authorized platform tokens are not embedded in the Chrome extension.
Defined browser access
The extension uses explicit host permissions and does not request unrestricted access to every website.
No private UI automation
AqiMeta does not simulate Ads Manager clicks or depend on private webpage interfaces.
Persistent task state
Creation progress, object IDs, and error context support user-visible recovery and reconciliation.
Transient image originals
Original uploads are forwarded for processing and are not retained as a permanent cross-account media library.
Controlled revocation
Users can disconnect an authorized account and request deletion of associated service data.
Responsible disclosure
Report a security concern directly to our team.
Please include a concise description, affected surface, reproduction steps, and potential impact. Do not include live access tokens, passwords, or unrelated personal information.
security@aqimeta.com