1. Scope
This policy applies to authorized internal users who connect a Google Ads account to the application for keyword research and content planning.
2. Google data we access
With the user's authorization, the application may process OAuth credentials, Google Ads customer or manager account identifiers, keyword queries, keyword ideas and historical keyword metrics returned by the Google Ads API. Historical metrics may include average monthly searches, monthly search history, competition indicators and bid ranges.
3. How we use the data
- Authenticate requests expressly authorized by an internal user.
- Retrieve keyword-planning information requested by that user.
- Display research results for human-reviewed SEO and editorial planning.
- Diagnose service errors and protect the application from misuse.
Google user data is not used for advertising profiles and is not sold.
4. Storage and retention
OAuth client credentials and the authorized refresh token are stored as encrypted Cloudflare Worker secrets and are not exposed in the browser or source code. Short-lived access tokens are requested when required and are not intentionally persisted by the application server. The Worker does not maintain a database of returned keyword metrics. The browser-based workspace may save project inputs and results locally in the authorized user's browser until that user clears the records or browser storage.
5. Sharing and processors
We do not sell Google user data. Data is transmitted only as needed to Google for OAuth and Google Ads API services and to Cloudflare for secure application hosting and request delivery. We may disclose information if required by applicable law or to protect the security and integrity of the service.
6. Security
We use HTTPS, restricted internal access, secret storage, limited OAuth permissions and human review. No internet service is risk-free; authorized users must keep their Google and company credentials secure.
7. User control and deletion
An authorized user may revoke the application's Google access from their Google Account permissions. Requests to remove stored OAuth authorization or locally managed application records may be sent to qyuanmachine@gmail.com. We will remove or replace the corresponding server-side secret when a valid request is confirmed. Browser-local records can also be deleted from the application's record controls or by clearing site data.
8. Google API Services User Data Policy
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
9. Changes and contact
We may update this policy when the application or legal requirements change. Material changes will be published on this page. Questions may be sent to qyuanmachine@gmail.com.