Privacy Policy
Last updated: August 17, 2026. Compliant with GDPR and Google API Services User Data Policy.
1. Google User Data Accessed and Collected
When you use AdCTO, we access and process specific Google user data depending on the permissions you grant via Google OAuth 2.0:
- Google Account Information (Sign-In): When you sign in or authenticate via Google (
openid,.../auth/userinfo.email,.../auth/userinfo.profile), we access and store your Google Account email address, full name, and profile identifier solely to authenticate your account and manage your AdCTO profile. - Google Ads Account Data: When you connect your Google Ads account via
https://www.googleapis.com/auth/adwords, we access campaign structures, ad groups, keyword configurations, search terms, quality scores, and aggregated performance metrics (impressions, clicks, cost/spend, conversions, CPA, and ROAS).
2. Strict Read-Only API Access & Purpose of Use
AdCTO uses the official Google Ads API solely in read-only mode (GAQL SELECT queries). The retrieved data is used exclusively for:
- Generating automated audit reports of your advertising account.
- Calculating potential budget waste (e.g., broad match inefficiencies, keyword cannibalization).
- Displaying performance and optimization insights within your AdCTO dashboard.
Security & Non-Mutation Guarantee: Our application performs zero automated mutations. We cannot and do not create, pause, edit, modify, or delete your campaigns, keywords, ads, or bidding strategies.
3. Google API Services User Data Policy (Limited Use Disclosure)
AdCTO's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. Data Storage, Sharing, and AES-256 Encryption
- No Selling or Sharing: We do not share, sell, rent, or transfer your Google Ads data or Google user data to any third-party data brokers, advertising networks, or external AI models for generalized training.
- Data Encryption: We never store or have access to your Google account password. When you connect via OAuth 2.0, authorization tokens are securely encrypted using AES-256 symmetric encryption and stored in our protected PostgreSQL database. All data transfers use TLS/HTTPS encryption.
5. GDPR Right to be Forgotten, Revocation & Data Deletion
In compliance with GDPR and global privacy standards, you maintain complete ownership and control of your data:
- Revoking Access: You can revoke AdCTO's access to your Google Ads and Google Account at any time directly through your Google Account Security Permissions or within your AdCTO Settings page.
- Data Deletion: Upon revocation or when you delete your AdCTO account, all OAuth tokens, retrieved performance metrics, and audit history are permanently and irreversibly purged from our databases.
6. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at: [email protected].