Skip to content
Back to homepage

Privacy Policy

Last updated: 26 July 2026Version 1.4לקריאת המסמך בעברית

1. Who we are

adsecrets (the "Service", "we", "us") is a service for managing, reporting on, and analyzing Google Ads accounts, operated by Oryan Cooper, sole proprietor (Osek Murshe), business ID 316612696, Zadok Halevy 18, Kiryat Ekron, Israel.

Privacy contact: privacy@adsecrets.io

The Service is offered through two interfaces: a dashboard at app.adsecrets.io, and a remote MCP endpoint at mcp.adsecrets.io (which lets you connect the Service to a chat client such as Claude). This policy applies to both.

Our marketing sites (adsecrets.io, adsecrets.co.il) are public content sites and are not part of the product. Data collection there differs materially — see §14.

2. Scope of this policy

This policy describes what data we collect, how we use it, who we share it with, how we protect it, and how long we keep it. It includes an explicit disclosure of how we handle data received from Google APIs.

3. What data we collect

3.1 Account data

Your email address, name, and sign-in credentials. Authentication is handled by a secure authentication provider (Supabase Auth). If you sign in with Google, we receive only your email address, name, and profile picture from it.

3.2 Your Google Ads authorization

When you connect your Google Ads account, you complete Google's own consent screen and grant us the https://www.googleapis.com/auth/adwords scope. We store an encrypted refresh token that lets us access the accounts you approved.

We never ask for, and never receive, your Google password.

3.3 Your Google Ads data (read access)

Depending on your plan and the permissions enabled for you, the Service can read the following from your Google Ads account:

  • Performance and reporting data — campaigns, ad groups, ads, keywords, budgets, bidding strategies, impression share, and breakdowns by device / country / hour.
  • Search terms — the actual queries end users typed that triggered your ads (see §6; this category receives specific treatment).
  • Keyword ideas — aggregated market data from Google, based on keywords or a URL you provide.
  • Billing / invoice data — invoice numbers, dates, service period, currency, and amounts (subtotal / tax / total) for your Google Ads account (see §7).
  • Change history — metadata about changes to the account: what changed, when, and through which interface. This report does not reveal who made a change — we deliberately do not select the user's email address field from Google.
  • Free-form reporting queries (GAQL) — if this permission is enabled for you, the Service can run read-only free-form reporting queries against your Google Ads data. See §6.

Importantly, we do not pull this data on an ongoing basis. We read it only when you ask us to. See §4.1.

3.4 AI analyst conversation history

If you use the AI analyst, we store the conversation (your messages and the responses) so that you can return to it. Important: responses and data displayed in a conversation — which may include search-term text, billing data, or (where connected) Google Analytics or Search Console metrics (§3.7) — are retained as part of that conversation history. See §11 regarding retention and deletion.

3.5 Usage data and operational logs

Operational logs and usage metrics (for abuse prevention, troubleshooting, and billing). We do not write secrets, tokens, or passwords to logs.

3.6 What we do not collect

  • We do not collect a billing address or payment instrument for your Google Ads account — Google does not provide them to us, and we do not ask for them.
  • We do not collect precise location data, end-user identifiers, or personal profiles of people who saw your ads. The geographic breakdown we display is aggregated at country level only.
  • We do not request and do not need "special categories" of personal data — health, racial or ethnic origin, political opinions, religious belief, sex life, or biometric data. The Service is not designed for such data, and our terms of service prohibit submitting it (including in the analyst's free-text field).
  • We do not run any third-party analytics tooling, advertising pixels, or tracking cookies inside the product. See §14.

3.7 Your Google Analytics and Search Console data (read access)

If you choose to, you can separately connect a Google Analytics 4 (GA4) property and/or a Google Search Console site. Each is its own Google consent screen: connecting GA4 grants us the https://www.googleapis.com/auth/analytics.readonly scope; connecting Search Console grants us the https://www.googleapis.com/auth/webmasters.readonly scope. Both scopes are read-only — the Service never writes to, and cannot change, your GA4 property or your Search Console site.

Depending on your plan and the permissions enabled for you, the Service can read the following:

  • Google Analytics 4 — site-behavior and traffic metrics, aggregated at the property level: sessions, users, engagement, events, traffic sources and channels, landing pages, and revenue/conversion metrics. This category is more end-user-adjacent than your Google Ads data — the metrics can include page paths and event names from your own website — so we treat it with the same care as §3.6: what we read is the aggregated reporting data your GA4 property already computes, not individual visitors' raw records, and we do not attempt to identify any end user from it.
  • Google Search Console — organic-search performance: the search queries that led to your site, pages, clicks, impressions, click-through rate, and average position.
  • Property and site discovery — to let you pick which GA4 property or Search Console site to connect, we list the properties/sites your Google account has access to, using the same read-only authorization.

Currency: where a Google Analytics metric represents revenue, it is shown in the property's own configured currency — which is not necessarily ₪ (Israeli new shekel).

As with your Google Ads data, we do not pull this data on an ongoing basis — we read it only when you ask us to (§4.1). We do not store the report rows themselves: GA4 and Search Console figures are streamed to you at the moment of the request and are not persisted in our database. What we do store is your connection selection — which property or site you chose to connect — exactly as we store which Google Ads accounts you connected, and it is deleted the same way (on disconnect or account deletion, §11.1–§11.2).

3.8 The Google account behind each connection

When you connect any Google product (Google Ads, Google Analytics 4, or Google Search Console), the same Google consent screen also grants us the standard `openid` and `email` scopes. From these we store two facts about the Google account you connected: a stable account identifier (the OpenID sub) and that account's email address. We use them only for connection management: (a) to show, next to each connection, which Google account it uses, so you can tell your connected accounts apart; and (b) to recognize when a product you are connecting uses an account you have already connected, so we update the existing authorization instead of creating a duplicate. This is the email of your own connected Google account — it is not an end user's email, and it is distinct from the "who made a change" field that we deliberately do not collect (§3.3). We store it only for as long as the connection exists, and delete it when you disconnect that account or delete your account (§11.1–§11.2). It is never sent to the AI model provider (§6), never written to logs, and never sent to any analytics or advertising tool (§14).

4. How we use your data

Solely to provide and improve the Service for you: to display reporting and analysis, to run AI analyses at your request, to make changes to your account that you have approved (§7), to provide support, to prevent abuse, and to handle billing. Where you connect Google Analytics 4 and/or Google Search Console (§3.7), we use that data for the same purpose: read-only reporting and AI-analyst insight across your Ads, Analytics, and organic-search data, plus letting you discover and select which properties/sites to connect. We never write to, and never modify, any Google Analytics or Search Console setting — there is no write capability for these products, unlike the Google Ads write capability described in §7.

We do not sell your data. We do not use it for advertising, retargeting, or interest-based advertising. We do not use it for credit-worthiness purposes. And we do not use your Google Ads data to train AI models, and neither does any provider we send it to on your behalf.

4.1 Pull-on-request only

We read from your Google Ads account only when you explicitly ask us to — never automatically.

This is an architectural constraint of the product, not a marketing promise: we operate no scheduled fetch, no background refresh, no cron, and no "just in case" prefetch. In practice:

  • A report is fetched when you open or refresh it.
  • The analyst fetches when you ask it a question.
  • The remote MCP connection fetches when a tool is called from your chat client.

What this means for your privacy: we do not stockpile or continuously harvest your Google Ads data in the background. When you are not using the Service, we are not touching your account. Every read we perform is the result of an action you initiated.

Data freshness: because we fetch from Google Ads at the moment you ask, the reporting you see is not delayed by more than 24 hours relative to the source at Google. If we ever introduce a caching layer that would delay reporting beyond 24 hours, we will disclose that prominently, as required by the Google Ads API policies.

4.2 Google Ads data is reported separately

The Service reports on Google Ads data and, where you choose to connect them, Google Analytics 4 and Google Search Console data (§3.7) — the first non-Google-Ads sources the Service supports. Consistent with the Google Ads API policies, your Google Ads data is reported separately from your Analytics and Search Console data: they appear in distinct reports/sections and are never merged into a single figure that would obscure which platform a metric came from. If we add further non-Ads data sources in future, the same separation will apply to them.

5. Google API Services — Limited Use (mandatory disclosure)

adsecrets's use and transfer of information received from Google APIs to any other app will adhere to the [Google API Services User Data Policy](https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

Specifically, and consistent with that policy (verified against the live source, 2026-07-16):

  • We limit our use of data received from Google exclusively to providing or improving user-facing features that are prominent in the Service's user interface.
  • We do not transfer this data to third parties except: (a) to provide or improve user-facing features that are visible and prominent — with the user's consent (the only transfer of this kind in our Service is to the AI analyst; see §6.4); (b) for security purposes; (c) as required by law; or (d) as part of a merger or acquisition, following notice and explicit prior consent.
  • We do not sell or transfer user data to advertising platforms, data brokers, or information resellers. In particular: your Google Ads data is never transferred to advertising platforms such as Meta/Facebook, and never enters any analytics tool. See §14.
  • We do not allow humans to read the data, unless: you give your affirmative agreement; it is necessary for security purposes (for example, investigating a bug or abuse); it is required by law; or the data is aggregated and used for internal operations. See §10.

These commitments apply equally to Google Analytics and Google Search Console data we read on your behalf where you connect them (§3.7) — the same Limited Use requirements govern all data we receive from Google APIs, regardless of which Google product it comes from.

Where you connect an external client to our hosted MCP endpoint (§6.6), that is your own transfer to a provider you chose, not a transfer by us; our Limited Use commitments above continue to govern all data we receive from Google APIs regardless.

6. The AI analyst and transfers to the AI model provider

Our AI sub-processors are the AI model providers configured for your accountAnthropic (the Claude model) and/or Google LLC (the Gemini model, via Google's paid Gemini API), depending on the feature and the model set for your account. Which provider receives your data depends on the feature and the model configured for your account; the disclosure you consent to names both. This transfer occurs only on the analyst path — that is, only when you initiate an analysis. The regular dashboard and the remote MCP connection do not send data to either provider.

6.1 Reporting data and search terms

"When you use the AI analyst, the Google Ads reporting data for the account you select — which may include search-term text (the actual queries end users typed that triggered your ads) — is sent to our AI sub-processor (Anthropic and/or Google, depending on the feature and the model configured for your account) to produce the analysis shown back to you. Search terms are provided by Google only in aggregate, above Google's privacy threshold; we do not attempt to re-identify individual users."

6.2 Free-form GAQL queries

If free-form reporting queries (GAQL) are enabled for your account, the Service — or the analyst acting on your behalf — can run read-only queries across a broad range of reporting fields in your Google Ads account, and their results may be sent to the AI model provider to produce the analysis. These queries are strictly read-only: GAQL cannot be used to modify data.

6.3 Billing / invoice data

"If you use the invoices report via the analyst, your Google Ads account's billing data — invoice numbers, dates, and amounts (subtotal / tax / total) — may be sent to our AI sub-processor (Anthropic and/or Google, depending on the feature and the model configured for your account) to produce the analysis. Billing data is your own account's only and does not include a billing address or payment instrument."

6.4 The boundaries

  • The transfer happens only if you choose to use the analyst. The analyst is a separate feature that you invoke yourself. If you do not use it, no data from your account is sent to either provider.
  • The provider processes on our behalf. Anthropic processes as an organization under its Commercial Terms (not a consumer account); the default under those terms is that content submitted through the API is not used to train models, and we do not opt into any feedback or data-sharing programme that would change this. Google processes via the paid Gemini API: on the paid tier Google does not use your prompts or responses to train its models or improve Google's products.
  • Retention. At Anthropic, content is retained for up to 30 days and then deleted; content flagged by Anthropic's automated safety systems may be retained for up to 2 years. At Google, Gemini API content on the paid tier is logged only for a limited period to detect and prevent abuse, and is not used for training.
  • Data-processing agreements with SCCs are in force with both. Anthropic's Data Processing Addendum is automatically incorporated into its Commercial Terms and includes Standard Contractual Clauses (SCCs): anthropic.com/legal/data-processing-addendum. Google's use is governed by the Gemini API Additional Terms and Google's Data Processing Addendum for Products Where Google is a Data Processor (business.safety.google/processorterms), which incorporates the SCCs.
  • We never send your refresh token, or any other secret, to either provider.
  • The change-history report does not include the identity of who made a change, and therefore never transfers it (§3.3).

6.5 Google Analytics and Search Console data

If you have connected Google Analytics 4 and/or Google Search Console (§3.7), running the analyst also sends your GA4 site-behavior and traffic data (such as traffic, on-site behavior, and conversions) and/or your Search Console data (such as organic search queries and page performance) to the AI model provider configured for your account, to produce the analysis you asked for — only with your active consent, under the exact same consent mechanism, versioned disclosure, and immediate-revocation terms described in §6.1–§6.4 for your Google Ads data: the transfer happens only if you choose to use the analyst; neither provider trains on it; retention is as described in §6.4 (Anthropic up to 30 days, up to 2 years if flagged by its automated safety systems; Google's paid Gemini API logs only for a limited abuse-prevention period); and you can withdraw your consent at any time, which stops the analyst immediately (analyses you already received are kept).

Because this added a new data category to what the analyst discloses, it triggered the same material-change mechanism described in §15: your consent to the earlier, Ads-only disclosure does not carry over automatically — the Service requires you to re-confirm under the updated disclosure (naming these Analytics/Search Console categories) before it will send this data to Anthropic on your behalf.

6.6 The hosted MCP endpoint and clients you connect (Line A)

adsecrets offers a hosted MCP endpoint (mcp.adsecrets.io) that lets you connect an external AI or chat client of your choice — for example Claude or ChatGPT — so it can read your Google Ads data (and your Google Analytics / Search Console data, where you have connected them) to answer your questions. This is a different path from the AI analyst in §6.1–§6.5, and the difference matters:

  • In §6.1–§6.5, our AI model provider (Anthropic or Google/Gemini) acts as our sub-processor — we send data to it, on your consent, to run a feature we operate.
  • Here, the recipient is a client you choose, connect, and control. When you connect an external client, that client — and the AI model provider behind it — receives the data it requests. That flow runs to your chosen provider, under your control; we are not a party to your relationship with that provider and do not control what it does with the data. You should review that provider's own terms and privacy policy. We tell you this plainly at the moment you connect, and record that you saw it.
  • How you connect and authenticate. You connect either by signing in with Google (OAuth) or by creating an MCP API key that authenticates you to our endpoint. The Google authorization underneath is always your own stored, encrypted Google credential — no Google token is ever handed to the external client (that is our red line, §8). The key identifies you to us; it does not give the client your Google credential.
  • This path is read-only. Through the MCP endpoint a connected client can pull reports and data; it cannot change your Google Ads account.
  • Revocation. You can revoke an MCP API key or disconnect at any time. Revocation takes effect immediately: the next call from that client fails. Keeping your API key confidential is your responsibility, the same as any password.
  • What we log. We keep operational logs about MCP calls (such as which tool was called and when, and for which of your accounts) for abuse-prevention, troubleshooting, and billing, exactly as described in §3.5. We do not write your API key, Google tokens, or other secrets to logs, and we do not store the report data returned to your client as part of these logs.
  • Our own commitments still apply. Whatever you do with a connected client, on our side the Limited Use commitments in §5 continue to govern every piece of data we receive from Google APIs.

7. Making changes to your Google Ads account

"With your consent and only after your explicit in-app approval, the system can make changes to your Google Ads account — for example, adding negative keywords — using the authorization you granted to Google (an encrypted refresh token). We do not make changes without your approval, and we never use one account's authorization to touch another. Change proposals may be generated with the help of the analyst (see the AI analyst section, §6)."

How this works in practice:

  1. 1The Service (or the analyst) proposes a change — for example, wasteful search terms worth excluding.
  2. 2The proposal is shown to you for review. Nothing is written to your account at this stage.
  3. 3Only after you explicitly approve is the change applied — using your authorization, in your account.

The adwords scope you grant includes write permission. Our controls — explicit approval, a draft-first default, and double confirmation — are what ensure we never use it unless you asked us to.

Status as of 2026-07-16: the write capability is built but not enabled for external customers. It is off by default and requires per-account enablement. This section is published in advance so that the policy covers the capability from the moment it is switched on — not retroactively. If you do not see the feature in the product, it is not active on your account.

8. Our red line

  • We never give a customer programmatic access to a Google Ads account without their own OAuth.
  • No "API over API" and no token passthrough. Your refresh token is never returned to you, never handed to a third party, and never written to logs.
  • No cross-customer access. One customer's authorization is never used to reach another's account.
  • Your refresh token is decrypted server-side solely in order to call Google itself — the party that issued it.

9. Third parties (sub-processors)

The providers below process data on our behalf only, under our instructions. A data processing agreement (DPA) is in force with each of them; the specific agreement is named in the table:

ProviderRoleWhat it processesAgreement in force
Google Cloud (Cloud Run, me-west1 — Israel)Hosting and running the ServiceAll Service dataCloud Data Processing Addendum — automatically incorporated into the terms of service
Supabase Pte. Ltd (Singapore)Authentication and databaseAccount data, connection records, conversation historyDPA signed and submitted 2026-07-16 (version Supabase+DPA+260601.pdf); Irish governing law, forum: the courts of Ireland; SCCs Module Two (controller→processor) and Module Three (processor→sub-processor)
AnthropicModel provider for the AI analyst (the Claude model)Reporting data sent for an analysis you initiated, including Google Analytics and Search Console data where connected (§6, §6.5)Commercial Terms; DPA automatically incorporated, including SCCs
Google LLCModel provider for the AI analyst (the Gemini model, paid Gemini API)Reporting data sent for an analysis you initiated, including Google Analytics and Search Console data where connected (§6, §6.5)Gemini API Additional Terms; Google's Data Processing Addendum for Products Where Google is a Data Processor, which incorporates the SCCs
ResendTransactional email (account verification)Your email addressDPA automatically incorporated into the terms of service
CloudflareDNS for our domainsDNS records only — does not proxy user traffic and does not process customer dataData Processing Addendum — automatically incorporated into the terms of service (§6.1)

Google itself is not a "third party" with respect to your Google Ads data — it is the source of that data and the owner of the platform. (Where your account is configured to use the Gemini model, Google LLC acts as a distinct AI sub-processor for that transfer, as listed in the table above and in §6 — a separate role from Google-as-data-source.)

Note: the analytics and advertising providers used on our marketing sites (§14) are deliberately not in this table. They do not touch the product and do not process any customer data or Google Ads data.

9.1 International transfers and where your data lives

Your most sensitive data — your account details and your encrypted refresh tokens — is stored in the European Union and does not leave it. Our compute runs in Israel. Only two paths leave for the United States: transactional email delivery, and an AI analysis that you initiate. Both are covered by Standard Contractual Clauses (SCCs).

ProviderWhere the data is storedWhat lives there
SupabaseFrankfurt, Germany 🇩🇪 (eu-central-1) — European UnionAccount details, the encrypted refresh tokens, conversation history
Google CloudTel Aviv, Israel 🇮🇱 (me-west1)Running the Service (the compute layer)
ResendUnited States 🇺🇸Your email address only
AnthropicUnited States 🇺🇸Reporting data sent for an analysis you initiated, including Google Analytics and Search Console data where connected (§6, §6.5), up to 30 days
Google (Gemini)United States 🇺🇸Reporting data sent for an analysis you initiated (where your account uses the Gemini model), including Google Analytics and Search Console data where connected (§6, §6.5); logged for a limited abuse-prevention period only

Both US transfers on the analyst path (Anthropic and Google/Gemini) are covered by Standard Contractual Clauses (SCCs) — see §6.4.

An important distinction between contracting entity and storage location: the entity we contract with at Supabase is Supabase Pte. Ltd in Singapore (65 Chulia Street, OCBC Centre), and the DPA's governing law is Irish — but the data itself sits in Frankfurt. Entity ≠ data location.

Resend states explicitly: "All account data, including email metadata, logs, and API records, is stored in the United States* regardless of the sending region you select."*

These transfers are made under the data processing agreements listed in §9, including SCCs where they apply.

10. Staff and operator access

Authorized staff may access metadata about your account (plan, usage, connected Google Ads account identifiers) for support, billing, and security purposes — for example, diagnosing a bug or investigating abuse. Such access is logged and audited. This is one of the explicit exceptions under Google's Limited Use requirements. Staff cannot access your refresh token — it is not exposed in any administrative interface.

11. Retention and deletion — what actually happens

It is important to understand the distinction between two actions:

11.1 Disconnecting your Google account ("Disconnect")

  • We revoke the authorization at Google and delete the encrypted refresh token — immediately.
  • We delete the connection records for your ad accounts, and, where connected, your Google Analytics 4 property and Google Search Console site selections (§3.7).
  • What disconnecting does NOT delete: your AI analyst conversation history (§3.4) — which may contain search-term text or billing data that was displayed in a conversation — remains, as do your account details and logs. Disconnecting Google stops future access to your Google Ads data; it does not erase what was already shown in past conversations. To remove those as well, delete your account (§11.2).

11.2 Deleting your account

Account deletion is immediate and irreversible. As soon as you confirm, we revoke your authorizations at Google and delete the refresh tokens, the account connections, your AI analyst conversation history, your account details, and your sign-in identity.

There is no waiting period, no "recycle bin", and no restore. Once you confirm, we cannot bring the account or the data back — even if you ask us to. If you are unsure, consider disconnecting (§11.1) instead of deleting: that stops our access to your Google Ads account while leaving your adsecrets account in place.

You can do this from within the product, or by contacting privacy@adsecrets.io.

Residual copies: after deletion from live systems, copies may survive in encrypted backups for up to 7 days, after which they are removed in the normal backup rotation. Backups are not accessible for routine operations and are not used to restore a deleted account.

11.3 Other retention

  • Operational logs — up to 30 days, after which they are deleted automatically.
  • Our own invoices and accounting records — retained as required by Israeli law (including tax law), even after account deletion. These contain no Google Ads data.
  • At the AI model provider — content sent to the analyst is retained by Anthropic for up to 30 days (and up to 2 years if flagged by automated safety systems); where your account uses the Gemini model, Google logs it only for a limited abuse-prevention period. See §6.4.

11.4 Conversation history retention (1-year policy)

"Your AI analyst conversation history is retained while your account is active. A conversation with no activity for 12 months* is deleted automatically, together with all of its messages, in a nightly cleanup. A conversation you are still using is kept in full — including messages older than 12 months — because deleting part of a live thread would destroy the context the analyst reads. Deleting your account deletes all history immediately, regardless of age (§11.2)."*

12. Your rights

You have the right to access, correct, delete, and port your data, and to withdraw the authorization you granted to Google at any time — from within the product, or directly on your Google account's "Third-party apps" page. To exercise these rights: privacy@adsecrets.io. We respond within the period required by law.

12.1 Disassociating your campaigns from the Service

In line with the Google Ads API policies, if you notify us that you wish to disassociate your Google Ads campaigns from the Service, we will provide you with the ability to do so within 3 business days of receiving that notice. In practice you can do this immediately and yourself, using "Disconnect" in the product (§11.1); contacting us is an alternative route, not a precondition.

13. Security

  • Encryption at rest: refresh tokens are encrypted at the application layer using Fernet (AES-128-CBC + HMAC), with rotatable keys held in Google Secret Manager. The token is stored as a single copy and decrypted only at the point of use, server-side.
  • Encryption in transit: TLS across all communication paths.
  • Access control: multi-tenant isolation; authorization data is not reachable through the public API surface; the database does not log token writes.
  • No system is perfectly secure. In the event of a security incident requiring notification, we will notify you and the relevant authorities as required by law.

14. Cookies, analytics, and advertising — the product / marketing-site split

This is a material distinction. Please read it.

This section is about analytics and advertising tools running on our own websites (cookies, pixels, tags). It is unrelated to the Google Analytics 4 property or Google Search Console site you may connect as a customer (§3.7) — that is your own data, read on your behalf inside the authenticated product using your own Google authorization; it is not a tracking tool embedded in our sites, and §14's rules about our own marketing-site tags do not describe it.

14.1 In the product (app.adsecrets.io and mcp.adsecrets.io)

We use strictly necessary cookies only, required for session management and security.

As of 2026-07-16, and verified in code: the product loads no third-party analytics tooling, no advertising pixel, and no tracking cookie — no Google Analytics, no Meta/Facebook Pixel, nothing.

This is deliberate, not incidental: no tracking tag may ever run inside the authenticated product. A pixel inside the dashboard would hand a commercial third party information about customer accounts and activity — which would be incompatible with our Limited Use commitment (§5) and with our promise that we do not transfer data to advertising platforms.

14.2 On the marketing sites (adsecrets.io, adsecrets.co.il)

Our public marketing sites — the brand, pricing, and content pages — are a separate environment from the product.

14.3 The rule that must never be broken

Your Google Ads data, your account identifiers, and your billing amounts are never sent to any analytics or advertising tool — not in a page_path, not as an event, not as a custom property, not in any other way. This rule applies also if and when we add any analytics in the future.

15. Changes to this policy

We will update this policy as the Service changes. We will notify you of material changes, and where a change concerns how we use or transfer data received from Google APIs, we will ask you to consent to the updated policy before it applies to you, as required by the Google API Services User Data Policy. The "Last updated" date at the top always reflects the version in force.

Change log:

  • 1.4 — 2026-07-26: Added Google LLC (the Gemini model, paid Gemini API) as a second AI analyst sub-processor alongside Anthropic. The active recipient depends on the AI model configured for your account; the disclosure now names both. Updated §6 (title + intro), §6.1–§6.5 (both providers, and Gemini's paid-tier no-training basis + abuse-logging retention), §9 (sub-processor table row + the Google-as-source clarification), §9.1 (international-transfers table row + SCCs), and §11.3 (retention). Because this adds a new recipient, it is a material change: consent to the prior disclosure does not carry over — tenants re-confirm under the updated disclosure before any data is sent to Gemini.
  • 1.3 — 2026-07-19: Added §6.6 — the hosted MCP endpoint (Line A): clients the tenant connects, the tenant-controlled nature of that transfer, MCP API keys, read-only scope, revocation, and logging; plus a §5 pointer. Prospective disclosure ahead of external enablement.
  • 1.2 — 2026-07-19: Added §3.8 — the connected Google account's stable identifier (sub) and email address, collected via the standard openid/email scopes for connection labeling and duplicate prevention only. Not a new use or transfer of Google reporting data — no re-consent required.
  • 1.1 — 2026-07-18: Added Google Analytics 4 and Google Search Console data categories (§3.7, §3.4, §4, §4.2, §5, §6.5, §9, §9.1, §14).
  • 1.0 — 2026-07-17: First published version.

16. Contact

privacy@adsecrets.io · Oryan Cooper, sole proprietor (Osek Murshe), business ID 316612696, Zadok Halevy 18, Kiryat Ekron, Israel.