Privacy Policy
PPCAdvisor ("we", "us") is an advertising-creative management service operated by RVK Holdings LLC. This policy explains what we collect, why, and the choices you have. It applies to the PPCAdvisor web application and its connected-assistant (MCP) endpoint.
Information we collect
- Account information — when you sign in with Google we receive your name, email address, and profile picture. We never see or store a password.
- Advertising data — when you connect your Google Ads account we access, at your direction, your campaigns, asset groups, ad copy, creative images, extensions, and performance metrics, and (if connected) Merchant Center product feed data. We store copies of this data to power analysis, editing, and reporting for your workspace.
- Uploaded content — creative images and copy you upload or generate in the app.
- Usage & log data — standard server logs (IP, user agent, timestamps) for security and reliability.
How we use Google user data
AI features and connected assistants
- Creative tagging and copy suggestions are generated with Anthropic's Claude models. Only the creative content needed for the feature (e.g. an image to tag, existing ad copy to improve) is sent, under contractual terms that prohibit training on it. Google user data — raw or aggregated/anonymized — is never used to develop, improve, or train generalized AI/ML models, by us or by any third party we send it to.
- If you connect an AI assistant (Claude, ChatGPT) via our MCP endpoint, that assistant can read your workspace's advertising data after you explicitly approve it on our consent screen. Assistant access is read-only — it can never edit, publish, or spend — and you can revoke it anytime in the app.
How we share information
We do not sell your data, raw or aggregated. We share it only with the service providers required to run PPCAdvisor: hosting infrastructure, Anthropic (AI features), and Resend (email, if enabled) — each bound to process it only for us and only to provide the features you use. We may disclose information if required by law.
Security
OAuth refresh tokens are encrypted at rest; session and API tokens are stored only as cryptographic hashes; all traffic is TLS; access is isolated per workspace. Our full security overview is available on request at the address below.
Data retention & deletion
Retention. Your change history, decisions, plans and measured outcomes are kept for the life of your workspace (they are your record). Operational logs — assistant call logs, AI usage detail, audit events, email recipients — are kept for 90 days, then deleted or rolled up into totals. Invoices and payment records are kept for 7 years as required by tax law.
Export. Admin → Your data → Request export gives you everything in your workspace as a machine-readable bundle (JSON, Parquet and CSV, plus your original creatives) with a published schema, within minutes; the download link lasts 7 days.
Disconnecting Google revokes Kleos's grant at Google immediately and deletes the stored tokens. You can also revoke access at myaccount.google.com/permissions.
Deleting your workspace (Admin → Your data) freezes it immediately — API keys, assistant grants and Google access are revoked and billing is cancelled — then erases every row and file after a 30-day grace period during which you can cancel. Our processors are instructed to delete too (Stripe customer deleted; invoices retained by law). You receive a deletion certificate listing what was erased and what was retained and why. Deleted data may persist in encrypted backups for up to 30 days and is never restored to production. Individual users can delete just themselves; their name on the workspace's shared history is replaced with a pseudonym. Requests made by email to the address below are honoured within 30 days.
Contact
Questions or deletion requests: privacy@rvkholdings.com.