Last updated: 24 September 2026
This policy covers Nama Marketing MCP, the tool described on its own page. It is separate from the policy covering this website, which is about namasoft.com and nothing else.
The tool is used by Namasoft’s staff and by Namasoft’s partners — companies in Egypt, Kuwait and Saudi Arabia that work with us. Namasoft runs its own copy of the tool, and each partner runs its own copy on its own computers. Each person connects their own Google, Meta and LinkedIn accounts to the copy they use. Namasoft runs no outside service that takes part in its work.
Below, the business means whoever runs the copy in question: Namasoft for its own copy, or the partner for theirs.
Namasoft and its partners
Each copy is separate. A partner’s copy connects the partner’s own accounts, and it keeps what it stores on the partner’s own computers. None of it is sent to Namasoft, and Namasoft cannot reach a partner’s copy, its records, or the accounts it connects. For the data in its own copy, the partner is responsible, and a request about it goes to that partner first.
What Namasoft provides to each copy is the program itself and the Google, Meta and LinkedIn app details it signs in through, unless a partner uses an app of its own. That is why Google, Meta and LinkedIn show Namasoft’s name when a partner’s staff connect their accounts.
What Google data it reaches
Connecting Google asks for one permission, the Google Ads scope
https://www.googleapis.com/auth/adwords. It allows the tool to read and manage
the Google Ads accounts that the signed-in person can already reach, on that
person’s behalf.
It requests nothing else. The tool has no access to Gmail, Drive, Contacts, Calendar, Photos or any other Google service, and beyond the sign-in itself it does not read the Google profile.
What Meta data it reaches
Connecting Meta signs in with Facebook; Threads has its own sign-in. The tool asks only for the permissions of the features an installation has turned on, and which of the following it reaches depends on that:
- Facebook Pages the person manages: their posts, the comments and reactions on them, and their performance figures. It can publish and schedule posts, reply to comments and hide them, and read and answer messages sent to the Page through Messenger.
- Instagram business accounts linked to those Pages: their posts, reels and stories, the comments on them, and their performance figures. It can publish, reply to comments and hide them, and read and answer direct messages.
- Ad accounts: campaigns, ad sets, ads and their creatives, budgets, spend, performance figures and existing audiences. It can create ads and campaigns, change them, and pause them, including ads that promote an app.
- Product catalogs: the products in them and their details, which it can add to and update.
- WhatsApp Business accounts: the business phone numbers, the message templates, and conversations with people who write to the business on WhatsApp. It can send replies and approved template messages.
- Threads profiles the person manages: their threads, the replies to them and their performance figures. It can post, reply and change reply settings.
Meta’s own sign-in asks which Pages, Instagram accounts, ad accounts and businesses to share, and the tool only reaches the ones chosen there. It does not read the person’s own Facebook or Instagram profile beyond their name and ID, their friends, their personal messages or their personal posts.
What LinkedIn data it reaches
Connecting LinkedIn signs in with the person’s LinkedIn account. As with Meta, the tool asks only for the permissions of the features an installation has turned on:
- Company Pages the person administers: the Page’s name, its posts, the comments on them, and their performance and follower figures. It can publish posts to the Page and reply to comments on the Page’s posts. It cannot hide or delete a comment, and it does not delete posts.
- Ad accounts the person can reach in LinkedIn Campaign Manager: campaigns, their status, budgets and bids, and their spend and performance figures. It can pause and resume campaigns and change their budgets and bids. It does not delete campaigns.
- The person’s own profile, only their name and member ID, so the tool can show who is connected.
It does not read the person’s connections, messages, feed or personal posts, and it does not post on the person’s own profile.
No new reach
None of these connections grants new reach. Somebody who cannot see an advertising account, a Page or an Instagram account already cannot see it through this tool either.
People who contact the business
When someone comments on the business’s Pages, Instagram or Threads posts, or sends it a message on Messenger, Instagram or WhatsApp, the tool can read what they wrote, the name and profile ID Meta shows with it, and on WhatsApp their phone number. It uses these only to answer that person and to moderate the business’s own posts.
When someone comments on the business’s LinkedIn Page posts, the tool can read what they wrote and the name LinkedIn shows with it, again only to answer them.
This data is not used to build a profile of anyone and is not added to any advertising audience. The tool does not upload lists of people’s personal details to Meta or LinkedIn to build audiences. It keeps none of it, except that a reply the tool sends is recorded in the activity log. For Meta, that record includes what the reply answered. For LinkedIn, it keeps only the IDs of the comment and of the member who wrote it, never their name or their words, as LinkedIn’s data storage rules require.
What it does with that data
It reads performance figures, posts, comments and messages and returns them in answer to the question that was asked. Where changes have been deliberately enabled for a person, it can also make the changes listed above — Google Ads budgets, bids and keywords; Meta ads, posts, replies and catalog products; LinkedIn Page posts, replies, and campaign status, budgets and bids — within limits an administrator sets beforehand. New posts are held unpublished by default until someone publishes them. LinkedIn has no draft of its own, so a LinkedIn post is held by the tool and sent only when someone publishes it.
The data is not used to build a profile of anyone, is not used for advertising beyond the business’s own campaigns that the tool manages, and is not sold. It is not shared between Namasoft and its partners, or between one partner and another.
Who else sees it
This is the disclosure that matters most. The tool is an MCP server, and it is driven by Claude, made by Anthropic. Google, Meta and LinkedIn data the tool retrieves — including comments and messages from the people above — is returned to the Claude client the person is running, so that Claude can answer with it. That data is therefore processed by Anthropic under Anthropic’s own terms, exactly as any other material typed into Claude would be.
Meta also offers its own ads MCP server. Where a person’s Claude uses it, Claude talks to Meta directly, and that data passes between Meta and Anthropic without going through this tool.
Nobody else receives it. The tool carries no analytics and no telemetry, and involves no third party besides Google, Meta, LinkedIn and Anthropic.
Where credentials and records are kept
Everything the tool stores stays on the computer it runs on, in its application
folder — beside the program, or under %APPDATA% on Windows and ~/.config
elsewhere. Those files are written so that only the account running the tool can
read them, where the operating system supports that.
- Each person’s connections. The tokens Google, Meta and LinkedIn issue when a person connects, and when they expire, are kept in a local database, one set per person. For LinkedIn this includes the permissions granted and the person’s own name. Page access tokens are fetched from Meta when a request needs one and are never stored.
- Sign-in. Each person signs in to the tool’s management page with their own username and password, and their AI client connects with a personal access token. Passwords and tokens are stored only as one-way hashes.
- Settings. The OAuth client details, the Google developer token and the Meta
and LinkedIn app credentials belong to the installation, not to a person, and are kept in a
config.jsonfile. - An activity log. The same database records every change the tool was asked to make: who asked, the time, the account, the request — including the text and media address of a post, or the text of a reply and what it answered — what it replaced, the outcome, and whether it was only a dry run. It exists so a change can be traced afterwards.
Posts, comments, messages and reports read from Google, Meta or LinkedIn are passed to the AI client and not kept. None of what a partner’s copy reads or stores is transmitted to Namasoft, and none of it leaves that copy’s machine other than to the AI client, as described above.
How long it is kept
A Google connection stays valid until it is revoked. A Meta connection expires by itself after about 60 days, and the person reconnects to renew it. Any of them can be revoked at any time. A LinkedIn connection renews itself while it is in use, for up to a year from sign-in, after which the person signs in again. The activity log stays on the machine until an administrator removes it.
How to disconnect and delete your data
- The Disconnect buttons on the tool’s management page delete the stored Google, Meta or LinkedIn token straight away.
- To revoke the tool’s access at the other end as well, remove it from your Google account permissions, or from Settings → Business integrations on Facebook, or from the apps and websites settings in Threads, or from Settings → Data privacy → Permitted services on LinkedIn.
- To delete your account on the tool, ask the administrator of the copy you use. For Namasoft’s own copy you can also write to the address below. Deleting an account removes its connections, tokens and sessions. Entries in the activity log are kept, as the record of changes made to the business’s advertising accounts and Pages.
- If you commented on or messaged a business that uses the tool and want a reply it recorded about you removed, ask that business. For Namasoft, write to the address below. If you cannot reach a partner, write to us too and we will pass your request on, though Namasoft cannot delete anything from a partner’s copy itself.
Limited use and platform terms
Nama Marketing MCP’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Its use of data received from Meta follows the Meta Platform Terms and Meta’s Developer Policies.
Its use of data received from LinkedIn follows the LinkedIn API Terms of Use, including LinkedIn’s data storage requirements for the Marketing APIs.
Changes
If we change how this tool handles Google, Meta or LinkedIn data, this page and the date at the top change with it.
Contact
Email: marketing.mcp@namasoft.com Post: Namasoft, Villa 7, Elhadid W Elsolb Street (off Elfalah Street), Lebanon Square, Mohandessin, Giza, Egypt
The terms this tool is provided under sit alongside this policy.