Skip to content
Ads Audit
Legal

Privacy Policy

Last updated: 2026-08-01

1. Who this applies to

This policy describes how Ads Audit (“we,” “us”) handles information when you create an account, sign in, connect a Google Ads account, or otherwise use the Ads Audit application.

[TODO — owner input required before public launch: legal entity name and registered address for this section.]

2. Information we collect

Account information. Name, email address, organization name, and a securely hashed password when you register directly (rather than through an invitation).

Authentication data. Session identifiers stored in an HTTP-only cookie, and, if you connect Google, an OAuth token issued by Google that Ads Audit uses to call the Google Ads API on your behalf. We do not receive or store your Google account password.

Google Ads data.After you authorize a connection, we read account structure, campaigns, ad groups, keywords, search terms, ads and assets, budgets, and conversion data through the Google Ads API. Google Ads exposes a single OAuth scope covering both read and write access — Ads Audit’s own code contains no function that creates, updates, deletes or otherwise modifies anything in your Google Ads account. Every request Ads Audit makes to the Google Ads API is a read request.

Usage and log data. Basic technical logs (timestamps, request outcomes, error information) needed to operate and secure the service. Log entries are structured to avoid storing tokens, passwords, or full page content.

3. How we use this information

Google Ads data is used to run the audit you request: evaluating account data against a fixed set of rules, producing findings and a decision queue, computing an account score, and presenting that output back to you and members of your organization. Account and authentication data is used to operate login, sessions, and product communication such as verification and password-reset emails.

We do not sell personal information, and we do not use Google Ads data obtained through OAuth for advertising or for any purpose unrelated to providing the audit you requested.

4. Security

Data is isolated per organization at the database level. Sessions use HTTP-only, same-site cookies. Sensitive values (password hashes, OAuth tokens) are never written to application logs in plain form. Traffic to the application is served over HTTPS.

5. Data retention

We retain account information for as long as your account is active. Audit history is retained so you can compare results over time; you can request deletion at any point (see §8).

[TODO — owner input required: exact retention periods per data category before public launch.]

6. Disconnecting Google

You can disconnect a Google Ads connection from within the application at any time. Once disconnected, Ads Audit stops making requests to the Google Ads API using that connection’s credentials. You can also revoke Ads Audit’s access directly from your Google Account’s security settings.

7. Cookies and sessions

Ads Audit uses a single essential, HTTP-only session cookie to keep you signed in. We do not use third-party advertising or tracking cookies on the application itself.

8. Your rights and contact

You can request access to, correction of, or deletion of your account information at any time by contacting us. Depending on your location, additional rights may apply under local data protection law.

Contact: [email protected]

[TODO — owner input required: dedicated data-protection contact, if required under applicable law in your jurisdiction.]

9. Third-party infrastructure

Ads Audit runs on infrastructure operated by third parties, including our hosting provider and, for transactional email (account verification, password reset, team invitations), an email delivery provider. These providers process data solely to deliver the service on our behalf and do not use it for their own purposes.

10. Changes to this policy

We may update this policy as the product changes. Material changes will be reflected by updating the “Last updated” date above.