Privacy Policy
Last updated: August 3, 2026
1. Introduction
ApprovePilot ("we", "us", "our") is an AI-powered advertising operations platform for connected ad platforms. This Privacy Policy explains how we collect, use, store, and protect your information when you use our service.
By using ApprovePilot, you agree to the collection and use of information in accordance with this policy.
2. Google API Services Usage Disclosure
ApprovePilot uses Google OAuth 2.0 to access your Google Ads data. Specifically, we request the following scopes:
openid, email, profile — to identify your account and display your name/email.https://www.googleapis.com/auth/adwords — to read your Google Ads campaign data (impressions, clicks, conversions, budgets, keywords) and to execute approved changes (budget adjustments, keyword pausing, negative keyword additions).
ApprovePilot's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We only access Google Ads data necessary to provide our service (campaign analysis, recommendation generation, and approved changes). We do not use your Google Ads data for advertising, sell it to third parties, or use it for purposes unrelated to ApprovePilot's core functionality.
3. Data We Collect
- Account Information: Email address, display name, and authentication credentials.
- Google Ads Data: Campaign statistics, keyword performance metrics, search term reports, and ad group data (read via Google Ads API).
- OAuth Tokens: Access tokens and refresh tokens necessary to maintain your connection to Google Ads.
- Usage Data: Actions taken within ApprovePilot (proposal approvals, rejections, settings changes).
4. How We Store and Protect Your Data
- Token Encryption: All OAuth tokens (access_token, refresh_token) are encrypted at rest using AES-256-GCM before being stored in our PostgreSQL database.
- Encryption Key Management: Encryption keys are stored separately from the database in secure environment variables and are never logged or exposed in API responses.
- Database Security: We use Row-Level Security (RLS) to ensure users can only access their own data. All data is isolated per user.
- Transport Security: All API communications use TLS 1.2+ (HTTPS). No data is transmitted in plaintext.
- Minimal Retention: We retain your Google Ads performance data only as long as needed to provide analysis and recommendations.
5. How We Use Your Data
- Analyze your Google Ads campaign performance using AI.
- Generate optimization recommendations (proposals).
- Execute approved changes to your Google Ads account.
- Send notifications about new recommendations.
- Provide usage analytics and reporting within the app.
6. Data Sharing
We do not sell, rent, or share your personal data or Google Ads data with third parties, except:
- AI Processing: Anonymized campaign metrics are sent to our AI analysis provider (Anthropic Claude) for generating recommendations. No personally identifiable information is included.
- Infrastructure Providers: We use cloud services (AWS, Cloudflare) for hosting. These providers process data on our behalf under strict data processing agreements.
- Legal Requirements: We may disclose data if required by law or to protect our rights.
7. Your Rights
- Revoke Access: You can disconnect your Google Ads account at any time from Settings. This immediately deletes stored OAuth tokens.
- Data Deletion: You can request complete deletion of your account and all associated data by contacting us.
- Data Export: You can export your proposals and activity history from the dashboard.
- Google Permissions: You can also revoke ApprovePilot's access directly from your Google Account Permissions page.