Privacy Policy
Effective: August 11, 2026 · Contact: ops@leakstop.dev
The short version: we collect the minimum needed to audit your Google Ads spend, we keep it only as long as each feature needs, we never sell it, we never share one customer's data with another, and our software never modifies your ad account. Deletion is one email away.
1. Who we are
LeakStop ("we") operates leakstop.dev — an auditing service for Google Ads advertisers. Data controller contact: ops@leakstop.dev.
2. What we collect, why, and for how long
2.1 This website
This site loads no third-party scripts, no analytics, and sets no tracking cookies. If you email us, we receive what you send.
2.2 Free CSV waste-audit
- What: the search-terms / change-history CSV files you upload, and the audit report computed from them.
- Why: to generate your waste report. Files are processed for this purpose only.
- Retention: audits are deleted after 24 hours. If you unlock the full report with your email, that audit is kept for 30 days so the links we email you keep working — this is disclosed again at the exact moment you unlock.
2.3 Email (report unlock)
- What: your email address, your consent record, and summary numbers of your audit (never the search-term text itself — our outbound email is structurally incapable of carrying it).
- Why: to send you the full report and 2–3 follow-up emails about what we found. That's the whole sequence — it stops by itself.
- Opt-out: every email carries a one-click unsubscribe that works without login. Unsubscribing stops everything immediately, and we erase the address 30 days after opt-out.
2.4 Google Ads data (connected accounts)
When you connect a Google Ads account you authorize the
https://www.googleapis.com/auth/adwords scope via Google's own consent screen. What we then do:
| Data | Purpose | Notes |
|---|---|---|
| Search terms & metrics | Waste detection (query bleed, n-gram waste) | Read-only nightly sync of your own account |
| Campaign / ad-group metrics | Budget-creep & anomaly detection, savings ledger baselines | Aggregated per day |
| Change history | The AI-activity watchdog change-log | Attribution of automated changes |
- Zero write access in practice: our software makes no mutate calls to your account. Every change is your click, in Google's own interface.
- Tokens: your OAuth refresh token is encrypted at rest and never exposed to the browser.
- Revocation: disconnecting an account deletes its tokens immediately; you can also revoke access anytime at myaccount.google.com/permissions. Synced data is deleted when the connection is removed.
- No cross-customer sharing: your account data is visible only inside your own workspace. We do not sell or resell Google Ads data. Ever.
Google API Limited Use disclosure. LeakStop's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide the auditing features you see; we do not use it for advertising, do not sell it, and do not allow humans to read it except with your consent, for security, or where required by law.
2.5 Browser extension (optional)
- What: the extension authenticates with a scoped key (stored hashed on our side) and reports only its version string and boolean selector-health flags (whether page elements were found) — no page content, no URLs, no personal data.
- Retention: telemetry is purged after at most 13 months (enforced by a scheduled job, not a promise).
2.6 Billing
Payments are processed by Stripe. Your card details go to Stripe directly and never touch our servers; we store the subscription state and Stripe's customer reference.
3. Cookies
The app uses a single first-party session cookie (httpOnly, secure) to keep you signed in. No advertising or analytics cookies, no fingerprinting.
4. Where data lives and how it's protected
Data is stored on servers in the EU/US, encrypted in transit (TLS) everywhere, with secrets and OAuth tokens encrypted at rest. Access is workspace-scoped: no customer can ever see another customer's data, and neither can a request that isn't authenticated to your workspace.
5. Your rights
Email ops@leakstop.dev to access, correct, export, or erase your data. Erasure requests are honored within 30 days. If you're in the EU/EEA/UK, this includes your GDPR rights (access, rectification, erasure, restriction, portability, objection); you may also lodge a complaint with your local supervisory authority.
6. What we will never do
- Sell or rent your data, or share it with data brokers.
- Use your Google Ads data to advertise to anyone.
- Mix one customer's account data into another customer's results.
- Modify your ad account behind your back — v1 has no write path at all.
7. Changes
If this policy changes materially, we'll note it here with a new effective date and — if you have an account or an active email sequence — tell you by email before it takes effect.
8. Contact
LeakStop · ops@leakstop.dev