• LivePostclickAudits the page behind your ad, then designs and builds a better one.Coming soonPPC.io AgentsDoes the Google Ads work your team repeats every week.
    See both in action →Postclick MCPUse casesPostclick login
  • Are you a brand or an agency?

    Brand Click here →Agency Click here →
    $3,000 a month, whatever you spend →
  • Free toolsAudits, calculators and scripts.Landing page examplesReal pages, scored, 54 industries.BlogPractical Google Ads and AI.The AI PlaybookMy book for PPC pros, free.
    Free Google Ads audit with Stewart →
  • About UsAbout
Postclick Let's talk Talk
Let's talk
Our AI Tools PostclickLivePPC.io AgentsComing soonHire us

Are you a brand or an agency?

Brand Click here →Agency Click here →
Free toolsLanding page examplesBlogThe AI Playbook
Free Google Ads audit with Stewart
About Us
Postclick→ Let's talk

Security and Data Policy

Last Updated: Oct 1, 2026

This policy covers the PPC.io app, which Digital Tapas Ltd (trading as PPC.io) runs. It explains what we read from your Google Ads account, what we change, who else handles your data, how long we keep it and how you remove it. Our Privacy Policy covers this website and everything else.

The short version

  • We read your Google Ads data so the app can find search terms that waste money.
  • We only change negative keywords, and only after an owner or admin on your team presses send.
  • We never sell your data, never use it for advertising and never use it to train AI models.
  • You can disconnect Google Ads at any time. We then revoke our access with Google.

What we read from Google Ads

You connect Google Ads through Google’s own sign-in screen. We ask for one permission, https://www.googleapis.com/auth/adwords. Google requires that permission for any app that reads or edits an account.

With it, the app reads:

  • campaigns, ad groups, keywords, ads and asset groups
  • search terms, with their impressions, clicks, cost and conversions
  • daily campaign figures: cost, clicks, impressions, conversions, conversion value, calls and impression share
  • conversion actions, location targets and disapproved ads
  • your existing negative keywords and negative keyword lists
  • account change history

We use this data for one purpose: to show you what your account spends, flag search terms that waste money and propose negatives to block them. We refresh it every hour while your account stays connected.

What we change in Google Ads

The app only writes negative keywords. It can add them to an ad group, a campaign, a shared negative list or the whole account. It does not create or edit campaigns, ads, budgets, bids or targeting.

Nothing changes on its own. The app proposes negatives and a person on your team reviews them. Only an owner or admin of your organisation can send them to Google Ads. We record who sent each change, and you can download every batch of changes as a CSV.

Signing in

You can sign in with email and a password, or with Google. Signing in with Google shares only your name, email address and profile picture. It gives us no access to your Google Ads account. That needs the separate connection described above.

How we protect your data

  • Your Google Ads refresh token is encrypted in our database and never shown in the app. We create short-lived access tokens from it as each request needs them, and we never save those.
  • We check that each Google sign-in response matches the request we sent. We reject it if it does not.
  • Passwords are hashed with bcrypt. We never store them in readable form.
  • You can switch on two-factor authentication with any authenticator app. Recovery codes come with it.
  • Each organisation has owners, admins and members. Members can review proposals but cannot send changes to Google Ads.
  • We limit sign-in and two-factor attempts to five a minute, to slow down password guessing.
  • You can sign out of every other session from your account settings.
  • Our error monitoring strips passwords and email addresses before anything is logged.

Who else handles your data

We use a small number of companies to run the app. Each one only gets what it needs to do its job.

CompanyWhat it receives
Google
Google Ads API and Google sign-in
Your requests to your own account
Laravel Cloud
Hosts the app and its database
Everything stored in the app
Anthropic
AI that reviews search terms
Search terms, their figures, campaign names, keywords, ad copy and the business notes you enter
OpenAI
Backup AI if Anthropic is unavailable
The same as Anthropic
Typesafe
First-pass sorting of search terms
Search terms, their figures, campaign names, keywords and ad copy
Firecrawl
Reads your public website so the AI understands your business
Your website address
Postmark
Sends account and report emails
Your name, email address and the content of each email
Stripe
Takes payments
Billing details. We never see your full card number.
Laravel Nightwatch
Error and performance monitoring
Technical logs, with passwords and email addresses removed

We do not share your Google Ads data with anyone else, unless the law requires it.

AI and your data

The app uses AI to judge whether a search term wastes money and to explain why. We send the AI providers only the data in the table above. We do not use your Google Ads data to train any AI model, ours or anyone else’s.

We delete the full text of every AI request and response after 90 days. We keep the cost of each request, with no content attached.

Google API Services User Data Policy

PPC.io’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In practice, that means:

  • We use Google Ads data only to provide and improve the features you see in the app.
  • We do not sell it, and we do not use it for advertising.
  • We do not use it to train AI models.
  • Our team does not read your account data unless you ask us to, for example to help with a support question, or unless security or the law requires it.

How long we keep your data

DataHow long
Google Ads dataWhile your account stays connected to an organisation
Full text of AI requests and responses90 days
Log of our calls to the Google Ads API365 days
Daily account snapshots for alerts60 days
A deleted organisation and everything in itRemoved for good 30 days after you delete it

Disconnecting and deleting

  • Disconnect Google Ads. Disconnect the account in the app. We delete the stored token and revoke our access with Google. If someone in your organisation connected another account with the same Google login, that access stays until you disconnect it too.
  • Delete an organisation. We cancel its subscription, stop its jobs and hide it at once. After 30 days we delete it for good, with its projects, accounts, Google Ads data and AI content. We revoke every Google Ads connection it held.
  • Delete your user account. Go to your account settings. If you own an organisation, delete it or hand it to someone else first.

You can also revoke our access at any time from your Google Account permissions page.

Reporting a security problem

If you find a security problem in the app, email us at michael@ppc.io. Please give us a chance to fix it before you tell anyone else. For privacy questions or data requests, use the same address.

Company Home

Products

  • Postclick
  • Postclick MCP
  • PPC.io Agents Coming soon
  • Pricing

Company

  • About us
  • Blog
  • Contact

Services

  • AI PPC Management
  • For brands
  • For agencies
  • PPC by Industry
  • Google Ads Agency

Resources

  • Free PPC Tools
  • Landing Page Examples

Social

  • LinkedIn
  • YouTube
Copyright © 2026 PPC.io
Privacy Policy Terms of service Security and data Refund Policy
1 Finds what loses the sale 2 Designs a better page 3 Builds the one you pick

Postclick is live

Turn more ad clicksinto customers.

Audit the page behind your ad, then turn the findings into stronger design directions.

✦

Paste a valid landing page URL.