Hướng dẫn xoá dữ liệu người dùng
Cập nhật lần cuối: Đơn vị vận hành: mcp.nguyentatduong.com
Trang này hướng dẫn cách xoá dữ liệu liên quan tới tài khoản Facebook (Meta), TikTok Ads, Google Ads (gồm quảng cáo YouTube), OpenAI Ads, kênh thông báo Telegram hoặc thư mục Google Drive / Google Sheet đã được kết nối vào hệ thống Ads MCP tại mcp.nguyentatduong.com (“Hệ thống”), do mcp.nguyentatduong.com (“Đơn vị vận hành”) vận hành.
1. Dữ liệu nào liên quan tới tài khoản Facebook của bạn
Hệ thống không dùng “Đăng nhập bằng Facebook”. Dữ liệu chỉ phát sinh khi một nhân sự dán access token Meta vào Hệ thống, gồm:
- Access token (và App ID, App Secret nếu có), được lưu mã hoá.
- Danh sách tài khoản quảng cáo và Trang Facebook mà token truy cập được (tên, ID, tiền tệ, múi giờ, danh mục, ảnh đại diện, số người theo dõi).
- Nhật ký các lệnh đã chạy trên những tài khoản và Trang đó (thời gian, tham số, tóm tắt kết quả, địa chỉ IP).
Chiến dịch, chỉ số quảng cáo, bài viết và chỉ số Trang được đọc trực tiếp từ Meta khi có yêu cầu và không được lưu thành kho dữ liệu riêng.
Với TikTok Ads, Google Ads (gồm YouTube) và OpenAI Ads, dữ liệu tương tự gồm: thông tin truy cập (access token, App ID/App Secret, refresh token hoặc khoá service account, API key) được lưu mã hoá, danh sách tài khoản quảng cáo và nhật ký lệnh. Với kênh thông báo Telegram: bot token được lưu mã hoá, chat ID, tên nhóm/kênh, ID chủ đề và nhật ký gửi tin.
Với Google Drive / Google Sheet: khoá service account và API key Google được lưu mã hoá, danh sách thư mục / sheet đã khai báo (mã, tên, cấu hình cột), mã file và mã media đã tải lên tài khoản quảng cáo, đường dẫn tạm và trạng thái các lượt tải video. File ảnh / video không được lưu trên máy chủ của Hệ thống.
2. Cách 1: Tự xoá trong Hệ thống
- Đăng nhập Hệ thống, mở mục Kết nối quảng cáo.
- Chọn kết nối Meta (hoặc TikTok Ads, Google Ads, OpenAI Ads) cần xoá.
- Bấm Thêm → Xoá kết nối, rồi xác nhận.
Kênh Telegram: trong mục Kết nối quảng cáo, mở chế độ xem Telegram, chọn kênh cần xoá → Xoá, rồi xác nhận. Nhân viên xoá được kết nối và kênh do mình tạo; quản trị viên xoá được mọi kết nối và kênh. Quản trị viên cũng có thể khoá hoặc xoá tài khoản nhân sự ở mục Người dùng (nút Thao tác trên dòng của người đó → Khoá tài khoản hoặc Xoá người dùng).
Google Drive: trong mục Kết nối quảng cáo, mở chế độ xem Google Drive, chọn thư mục / sheet → Xoá, rồi xác nhận (nguồn bị gỡ khỏi mọi MCP; file trên Google Drive không bị ảnh hưởng). Service account riêng xoá ở cùng chế độ xem; khoá service account và API key của hệ thống do quản trị viên xoá ở mục Cài đặt → Google Drive hệ thống.
3. Cách 2: Gửi yêu cầu cho Đơn vị vận hành
Gửi email tới địa chỉ liên hệ bên dưới với tiêu đề “Yêu cầu xoá dữ liệu”, kèm theo:
- Tên hoặc ID tài khoản Facebook, ID tài khoản quảng cáo và ID Trang liên quan; hoặc ID nhà quảng cáo TikTok (advertiser ID), ID khách hàng Google Ads (customer ID), ID tài khoản OpenAI Ads; hoặc tên kênh Telegram và chat ID.
- Email tài khoản của bạn trong Hệ thống (nếu có).
- Phạm vi dữ liệu muốn xoá.
Chúng tôi có thể đề nghị bạn xác minh quyền sở hữu tài khoản trước khi xử lý. Yêu cầu được xử lý trong tối đa 30 ngày và bạn sẽ nhận email xác nhận khi hoàn tất.
quản trị viên hệ thống tại mcp.nguyentatduong.com
4. Cách 3: Gỡ quyền truy cập ngay từ nền tảng
- Facebook: vào Cài đặt & quyền riêng tư → Cài đặt → Ứng dụng và trang web (hoặc Tích hợp doanh nghiệp), chọn ứng dụng đã cấp quyền → Gỡ. Tên mục có thể khác nhau theo phiên bản Facebook; có thể mở trực tiếp facebook.com/settings?tab=applications.
- Token của Người dùng hệ thống (System User): trong Meta Business Suite → Cài đặt doanh nghiệp → Người dùng hệ thống, thu hồi token hoặc gỡ tài sản đã gán.
- TikTok Ads: đăng nhập TikTok For Business, mở phần cài đặt uỷ quyền (Business Center → Settings → Authorizations, hoặc trang quản lý ứng dụng nhà phát triển), chọn ứng dụng đã được uỷ quyền → Remove (Gỡ).
- Google Ads (gồm YouTube): nếu kết nối dùng OAuth + refresh token, vào Tài khoản Google → Bảo mật → Quyền truy cập của bên thứ ba (myaccount.google.com/permissions), chọn ứng dụng → Xoá quyền truy cập. Nếu kết nối dùng service account, xoá email service account khỏi Quản trị → Quyền truy cập và bảo mật → Người dùng trong Google Ads (và có thể xoá khoá của service account trong Google Cloud).
- OpenAI Ads: thu hồi (revoke) API key trong trang quản lý OpenAI Ads.
- Telegram: mở @BotFather, gửi lệnh /revoke và chọn bot để vô hiệu hoá bot token; hoặc gỡ bot khỏi nhóm/kênh nhận thông báo.
- Google Drive / Google Sheet: trên Google Drive mở thư mục / sheet → Chia sẻ → xoá email service account của Hệ thống; quản trị viên có thể xoá khoá của service account (Google Cloud → IAM & Admin → Service accounts → Keys) và API key (APIs & Services → Credentials).
Sau khi gỡ, token không còn dùng được: Hệ thống không truy cập được dữ liệu của bạn nữa (hoặc không gửi được tin Telegram) và lần kiểm tra kế tiếp sẽ đánh dấu kết nối hoặc kênh bị lỗi. Để xoá cả dữ liệu đã lưu trong Hệ thống, làm thêm Cách 1 hoặc Cách 2.
5. Dữ liệu nào bị xoá, dữ liệu nào được giữ lại
- Xoá ngay khi xoá kết nối: token hoặc API key (bản mã hoá bị ghi đè bằng dữ liệu rỗng). Kết nối biến mất khỏi giao diện và mọi MCP mất quyền truy cập các tài khoản, Trang của kết nối đó.
- Tên kết nối và danh sách tài khoản quảng cáo, Trang đã đồng bộ được giữ ở trạng thái ẩn cùng bản ghi kết nối đã xoá để đối chiếu nhật ký. Khi bạn gửi yêu cầu theo Cách 2, Đơn vị vận hành xoá hẳn phần dữ liệu này.
- Nhật ký MCP và nhật ký nhân sự là nhật ký kiểm toán chỉ ghi thêm, được giữ tới hết thời hạn lưu (lần lượt 3 và 3 tháng cộng tháng hiện tại) vì lý do bảo mật và pháp lý, sau đó tự động bị xoá vĩnh viễn. Nhật ký không chứa token hay API key.
- Kênh Telegram đã xoá: Hệ thống ngừng gửi tin ngay. Nhật ký gửi tin được giữ theo thời hạn của nhật ký MCP rồi tự động bị xoá.
- Thư mục / sheet Google Drive đã xoá: bị gỡ khỏi mọi MCP ngay, Hệ thống không đọc nữa. Khoá service account và API key bị xoá khỏi Hệ thống khi quản trị viên xoá thông tin xác thực. Đường dẫn tạm cho video bị xoá sau 24 giờ kể từ khi hết hạn, lượt tải video nền sau 30 ngày; mã media đã tải lên được giữ tới khi tài khoản quảng cáo bị xoá khỏi Hệ thống.
- Dữ liệu nằm trên Meta, TikTok, Google (kể cả file trên Google Drive và nội dung Google Sheet), OpenAI hoặc Telegram (kể cả tin nhắn đã gửi vào nhóm/kênh) do các nền tảng đó quản lý; xoá trong Hệ thống không xoá dữ liệu trên nền tảng.
English version
Data Deletion Instructions
Last updated: Operator: mcp.nguyentatduong.com
This page explains how to delete data related to a Facebook (Meta), TikTok Ads, Google Ads (including YouTube ads) or OpenAI Ads account, a Telegram notification channel, or a Google Drive folder / Google Sheet, connected to the Ads MCP system at mcp.nguyentatduong.com (the “System”), operated by mcp.nguyentatduong.com (the “Operator”).
1. What data relates to your Facebook account
The System does not use “Login with Facebook”. Data only exists when a staff member pastes a Meta access token into the System:
- The access token (and App ID, App Secret if provided), stored encrypted.
- The list of ad accounts and Facebook Pages the token can access (name, ID, currency, time zone, category, profile picture, follower count).
- Logs of the requests run on those accounts and Pages (time, parameters, result summary, IP address).
Campaigns, ad metrics, Page posts and Page insights are read directly from Meta on request and are not kept as a separate data store.
For TikTok Ads, Google Ads (including YouTube) and OpenAI Ads the data is similar: credentials (access token, App ID/App Secret, refresh token or service account key, API key) stored encrypted, the list of ad accounts, and request logs. For a Telegram notification channel: the bot token stored encrypted, chat ID, group/channel title, topic ID and the delivery log.
For Google Drive / Google Sheets: the Google service account key and API key stored encrypted, the list of registered folders / sheets (ID, name, column mapping), the file IDs and media IDs already uploaded to ad accounts, temporary links and the status of video uploads. Image / video files are not stored on the System’s server.
2. Option 1: Delete it yourself in the System
- Sign in to the System and open Kết nối quảng cáo (Ad connections).
- Select the Meta (or TikTok Ads, Google Ads, OpenAI Ads) connection to delete.
- Click Thêm (More) → Xoá kết nối (Delete connection) and confirm.
Telegram channels: in Kết nối quảng cáo (Ad connections), switch to the Telegram view, select the channel → Xoá (Delete) and confirm. Staff can delete the connections and channels they created; administrators can delete any connection or channel. Administrators can also lock or delete staff accounts under Người dùng (Users): the actions button on the person’s row → Khoá tài khoản (Lock account) or Xoá người dùng (Delete user).
Google Drive: in Kết nối quảng cáo (Ad connections), switch to the Google Drive view, select the folder / sheet → Xoá (Delete) and confirm (it is removed from every MCP server; files on Google Drive are not affected). Personal service accounts are deleted in the same view; the system service account key and API key are deleted by an administrator under Cài đặt (Settings) → Google Drive hệ thống (System Google Drive).
3. Option 2: Send a request to the Operator
Email the contact address below with the subject “Data deletion request” (“Yêu cầu xoá dữ liệu”), including:
- Your Facebook account name or ID, the related ad account IDs and Page IDs; or your TikTok advertiser ID, Google Ads customer ID or OpenAI Ads account ID; or the Telegram channel name and chat ID.
- Your account email in the System (if any).
- What data you want deleted.
We may ask you to verify that you own the account before processing. Requests are completed within 30 days and you will receive a confirmation email when done.
the system administrator at mcp.nguyentatduong.com
4. Option 3: Revoke access on the platform
- Facebook: go to Settings & privacy → Settings → Apps and websites (or Business integrations), select the app you granted access to → Remove. Menu names may vary between Facebook versions; you can also open facebook.com/settings?tab=applications directly.
- System User tokens: in Meta Business Suite → Business settings → System users, revoke the token or remove the assigned assets.
- TikTok Ads: sign in to TikTok For Business, open the authorization settings (Business Center → Settings → Authorizations, or your developer app management page), select the authorized app → Remove.
- Google Ads (including YouTube): if the connection uses OAuth with a refresh token, go to Google Account → Security → Third-party access (myaccount.google.com/permissions), select the app → Remove access. If it uses a service account, remove the service account email under Admin → Access and security → Users in Google Ads (and optionally delete the service account key in Google Cloud).
- OpenAI Ads: revoke the API key in the OpenAI Ads dashboard.
- Telegram: open @BotFather, send /revoke and pick the bot to invalidate its token; or remove the bot from the notification group/channel.
- Google Drive / Google Sheets: in Google Drive open the folder / sheet → Share → remove the System’s service account email; administrators can delete the service account key (Google Cloud → IAM & Admin → Service accounts → Keys) and the API key (APIs & Services → Credentials).
Once revoked, the token stops working: the System can no longer access your data (or send Telegram messages) and the next check marks the connection or channel as failed. To also delete the data stored in the System, use Option 1 or Option 2.
5. What is deleted and what is kept
- Deleted immediately when a connection is deleted: the token or API key (its encrypted value is overwritten with empty data). The connection disappears from the interface and every MCP server loses access to its accounts and Pages.
- The connection name and the synced list of ad accounts and Pages are kept hidden with the deleted connection record to keep logs consistent. When you send a request under Option 2, the Operator deletes this data permanently.
- MCP logs and staff activity logs are append-only audit logs kept until their retention period ends (3 and 3 months respectively, plus the current month) for security and legal reasons, then deleted permanently and automatically. Logs never contain tokens or API keys.
- Deleted Telegram channels: the System stops sending messages immediately. The delivery log is kept for the MCP log retention period, then deleted automatically.
- Deleted Google Drive folders / sheets: removed from every MCP server immediately and no longer read. The service account key and API key are deleted from the System when an administrator deletes the credentials. Temporary video links are deleted 24 hours after they expire and background video uploads after 30 days; uploaded media IDs are kept until the ad account is removed from the System.
- Data held by Meta, TikTok, Google (including files on Google Drive and Google Sheets content), OpenAI or Telegram (including messages already sent to a group/channel) is managed by those platforms; deleting data in the System does not delete it on the platform.