ADS WORKSPACE
Privacy Policy
Effective September 12, 2026
Ads Workspace is a controlled personal beta operated by Asahi Ryo (individual) for connecting selected Google Ads accounts, running evidence-backed audits, and reviewing narrowly defined account changes. This policy explains how the service handles Google user data and related account information.
Data the service accesses
- A stable Google account identifier returned through OpenID Connect, used to bind an authorization to the correct person.
- Google Ads customer identifiers, account names, manager relationships, currency, time zone, account status, and the reporting fields needed for the selected audit.
- Campaign, ad-group, keyword, performance, and conversion evidence returned by fixed read-only Google Ads queries.
- For a separately enabled and explicitly approved change, the exact affected resource and its before, requested, accepted, and verified states.
The service never asks for or stores a Google password or passkey. Short-lived Google access tokens are used server-side and are not persisted.
How data is used
Google data is used only to connect accounts selected by an authorized organization administrator, run the requested audit, show evidence and limitations, prepare reviewable recommendations, verify approved actions, provide tenant-authorized support, and keep the service secure. It is not sold, used for advertising or credit decisions, or used to train a general-purpose AI model.
Use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
The optional model-analysis path and Google Ads mutation workers are not enabled in this beta. Enabling either later requires an updated release gate and, if data use changes, an updated notice and consent.
Storage and service providers
Refresh grants are encrypted before storage. Ads Workspace uses Vercel to run the web application and Supabase for authentication and database storage. These providers process data only to operate the service. Authorized support views are scoped and sanitized; they do not expose credentials, OAuth identity, raw provider responses, or account evidence.
Retention
- Audit, approval, change, support, and schedule evidence: 365 days.
- Terminal invitations, notifications, and unused setup attempts: 30 days.
- Retired encrypted refresh-grant versions: 7 days.
- Minimal completed deletion and revocation receipts: 365 days.
Active or unresolved work is not deleted only because it reached an age limit; it is retained until it can be reconciled safely.
Your controls
Organization Owners and Admins can export the organization’s customer-readable data, unlink an Ads account, reconnect or retire a Google authorization, and request organization deletion. A user can also revoke Google access from their Google Account. Deletion waits for any uncertain provider effect or grant revocation to be resolved, then removes tenant data while retaining only the minimal receipts described above.
Security and contact
The service uses tenant authorization checks, encrypted credentials, bounded provider requests, immutable approval evidence, and disabled-by-default mutation flags. No system can promise absolute security. Privacy, deletion, and support requests should be sent to support@adkick.site, the operator support address also shown on the Google consent screen.