Skip to content

Security

Security & data

How the Zbang Ads audit handles your Google Ads data — read-only access, private workspaces, and operator-controlled retention.

Read-only by design

Zbang Ads reads the Google Ads account you select so it can analyze it. That is the whole job. It never creates, edits, pauses, or deletes campaigns. It never sells your Google Ads data or uses it for unrelated advertising, and it never exposes your connection to other customers.

What we access, and why

When you connect Google, Zbang asks for a short list of scopes. Here is each one and what it is for.

Scope What it's for
openid Confirm the identity of the Google account holder during sign-in and connection setup.
email Link the connected Google identity to the correct private workspace, and show the connected account's email.
profile Read basic profile info to verify the connection belongs to the signed-in user.
Google Ads API (.../auth/adwords) List the accounts you can access and read reporting, campaign, asset, conversion, and product-feed data for the audit. Read-only — never used to create, edit, or delete campaigns.

You're in control

You connect Google yourself, choose the account, and start each audit. Optional AI recommendations are off by default: server-side AI runs only if the operator turns it on. Otherwise your Google Ads analysis stays inside the deployment unless you download the outputs.

Data retention

By default, generated files and workspace artifacts are kept for up to 30 days, then automatically cleaned up. Operators can turn automatic cleanup off entirely — artifacts then persist until they are cleared.

Who processes your data

A small set of subprocessors helps run the audit:

Subprocessor Role
Google Identity and the Google Ads API, used when you connect Google and run an audit.
Railway Application hosting and runtime.
OpenAI Optional AI recommendations — only when AI is enabled.
The deployment database Structured application storage.

Read the full policies

This page is a friendly summary. The authoritative detail — the detailed policy used on the Google OAuth consent screen — lives in the app's own policies.

App privacy policy · App subprocessors