This policy covers the PPC.io app, which Digital Tapas Ltd (trading as PPC.io) runs. It explains what we read from your Google Ads account, what we change, who else handles your data, how long we keep it and how you remove it. Our Privacy Policy covers this website and everything else.
The short version
- We read your Google Ads data so the app can find search terms that waste money.
- We only change negative keywords, and only after an owner or admin on your team presses send.
- We never sell your data, never use it for advertising and never use it to train AI models.
- You can disconnect Google Ads at any time. We then revoke our access with Google.
What we read from Google Ads
You connect Google Ads through Google’s own sign-in screen. We ask for one permission, https://www.googleapis.com/auth/adwords. Google requires that permission for any app that reads or edits an account.
With it, the app reads:
- campaigns, ad groups, keywords, ads and asset groups
- search terms, with their impressions, clicks, cost and conversions
- daily campaign figures: cost, clicks, impressions, conversions, conversion value, calls and impression share
- conversion actions, location targets and disapproved ads
- your existing negative keywords and negative keyword lists
- account change history
We use this data for one purpose: to show you what your account spends, flag search terms that waste money and propose negatives to block them. We refresh it every hour while your account stays connected.
What we change in Google Ads
The app only writes negative keywords. It can add them to an ad group, a campaign, a shared negative list or the whole account. It does not create or edit campaigns, ads, budgets, bids or targeting.
Nothing changes on its own. The app proposes negatives and a person on your team reviews them. Only an owner or admin of your organisation can send them to Google Ads. We record who sent each change, and you can download every batch of changes as a CSV.
Signing in
You can sign in with email and a password, or with Google. Signing in with Google shares only your name, email address and profile picture. It gives us no access to your Google Ads account. That needs the separate connection described above.
How we protect your data
- Your Google Ads refresh token is encrypted in our database and never shown in the app. We create short-lived access tokens from it as each request needs them, and we never save those.
- We check that each Google sign-in response matches the request we sent. We reject it if it does not.
- Passwords are hashed with bcrypt. We never store them in readable form.
- You can switch on two-factor authentication with any authenticator app. Recovery codes come with it.
- Each organisation has owners, admins and members. Members can review proposals but cannot send changes to Google Ads.
- We limit sign-in and two-factor attempts to five a minute, to slow down password guessing.
- You can sign out of every other session from your account settings.
- Our error monitoring strips passwords and email addresses before anything is logged.
Who else handles your data
We use a small number of companies to run the app. Each one only gets what it needs to do its job.
| Company | What it receives |
|---|---|
| Google Google Ads API and Google sign-in | Your requests to your own account |
| Laravel Cloud Hosts the app and its database | Everything stored in the app |
| Anthropic AI that reviews search terms | Search terms, their figures, campaign names, keywords, ad copy and the business notes you enter |
| OpenAI Backup AI if Anthropic is unavailable | The same as Anthropic |
| Typesafe First-pass sorting of search terms | Search terms, their figures, campaign names, keywords and ad copy |
| Firecrawl Reads your public website so the AI understands your business | Your website address |
| Postmark Sends account and report emails | Your name, email address and the content of each email |
| Stripe Takes payments | Billing details. We never see your full card number. |
| Laravel Nightwatch Error and performance monitoring | Technical logs, with passwords and email addresses removed |
We do not share your Google Ads data with anyone else, unless the law requires it.
AI and your data
The app uses AI to judge whether a search term wastes money and to explain why. We send the AI providers only the data in the table above. We do not use your Google Ads data to train any AI model, ours or anyone else’s.
We delete the full text of every AI request and response after 90 days. We keep the cost of each request, with no content attached.
Google API Services User Data Policy
PPC.io’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice, that means:
- We use Google Ads data only to provide and improve the features you see in the app.
- We do not sell it, and we do not use it for advertising.
- We do not use it to train AI models.
- Our team does not read your account data unless you ask us to, for example to help with a support question, or unless security or the law requires it.
How long we keep your data
| Data | How long |
|---|---|
| Google Ads data | While your account stays connected to an organisation |
| Full text of AI requests and responses | 90 days |
| Log of our calls to the Google Ads API | 365 days |
| Daily account snapshots for alerts | 60 days |
| A deleted organisation and everything in it | Removed for good 30 days after you delete it |
Disconnecting and deleting
- Disconnect Google Ads. Disconnect the account in the app. We delete the stored token and revoke our access with Google. If someone in your organisation connected another account with the same Google login, that access stays until you disconnect it too.
- Delete an organisation. We cancel its subscription, stop its jobs and hide it at once. After 30 days we delete it for good, with its projects, accounts, Google Ads data and AI content. We revoke every Google Ads connection it held.
- Delete your user account. Go to your account settings. If you own an organisation, delete it or hand it to someone else first.
You can also revoke our access at any time from your Google Account permissions page.
Reporting a security problem
If you find a security problem in the app, email us at michael@ppc.io. Please give us a chance to fix it before you tell anyone else. For privacy questions or data requests, use the same address.
Our AI Tools








