Privacy Policy
Last updated 13 July 2026
1. Who we are
Ad Manager is a Google Ads auditing and reporting tool operated by Neurobox ("we", "us", "our"), based in the United Kingdom. Neurobox is the data controller for the personal data described in this policy. You can contact us about anything in this policy at hello@neurobox.co.uk.
Ad Manager is an internal tool. Accounts are provisioned by Neurobox for its own team; there is no public sign-up.
2. What data we collect
Account data
For each provisioned user we hold a name, work email address, a role, and a password. Passwords are stored only as one-way cryptographic hashes — we cannot read them.
Google Ads data
When an administrator connects a Google Ads account, we access it through the official Google Ads API with read-only scope. We store:
- Campaign performance and budget snapshots (spend, clicks, conversions and similar metrics);
- Search terms that triggered ads, with their performance figures;
- The account's change history (what changed, when, and whether the change was made by a person or by Google automation);
- Google's optimisation recommendations for the account.
The OAuth refresh token that authorises this access is encrypted at rest. We never receive or store the Google account password.
Reports
The application generates audit reports from the data above and may email them to provisioned users.
Technical data
Standard server logs (IP address, browser user agent, timestamps of requests) are kept for security and troubleshooting.
3. How we use Google user data (Limited Use disclosure)
Ad Manager's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Google Ads data is used only to provide the auditing and reporting features described here — analysing spend, changes, search terms and recommendations for the connected account.
- We do not sell Google user data, use it for advertising, or transfer it to third parties except as needed to provide these features (see section 5), to comply with law, or as part of a merger or acquisition with prior notice.
- Humans do not read this data except with the account owner's permission, where necessary for security or to comply with law, or when aggregated for internal operations.
- Google user data is not used to develop, improve, or train generalised artificial-intelligence or machine-learning models.
4. Why we process data and our lawful bases
| Purpose | Lawful basis (UK GDPR) |
|---|---|
| Providing user accounts and authenticating sign-ins | Legitimate interests — running an internal business tool |
| Fetching and analysing the connected Google Ads account | Legitimate interests — auditing our own advertising spend |
| Generating and emailing audit reports | Legitimate interests |
| Security logging and backups | Legitimate interests — keeping the service secure and recoverable |
5. Who we share data with
We do not sell personal data. We share data only with the service providers (processors) that run the application:
| Provider | Purpose |
|---|---|
| Railway | Application and database hosting |
| Amazon Web Services | Transactional email (SES), encrypted backups and log storage (S3), and AI model inference (Bedrock — see section 6) |
| The Google Ads API, which we call to read the connected account |
Where these providers process data outside the UK, transfers are protected by the providers' standard contractual safeguards (such as the UK International Data Transfer Addendum or equivalent mechanisms).
6. AI-assisted reports
Report narratives are drafted with the help of a large-language model accessed through AWS Bedrock. Campaign metrics and related account data are sent to the model to produce the report text. Under AWS Bedrock's terms, this data is not used to train or improve the underlying models. Every AI-drafted report is reviewed by a person before decisions are made on it.
7. Security
- All traffic is served over TLS (HTTPS).
- Google OAuth refresh tokens are encrypted at rest; passwords are hashed.
- Access to Google Ads data is read-only — the application cannot change anything in the ads account.
- Access to the application is restricted to provisioned users; administrative access is limited to named staff.
8. Retention
Account data is kept while a user's account exists and deleted when the account is removed. Google Ads snapshots and reports are kept while the connected account remains active, so audits can compare periods over time. Encrypted database backups and shipped logs are rotated on a rolling schedule. If a Google Ads connection is revoked, we stop syncing immediately and delete the stored refresh token; you can also revoke access at any time from your Google account permissions page.
9. Your rights
Under the UK GDPR you have the right to access, correct, delete, or receive a copy of your personal data, to restrict or object to our processing of it, and to withdraw consent where processing is based on consent. To exercise any of these rights, email hello@neurobox.co.uk. You also have the right to complain to the UK Information Commissioner's Office (ico.org.uk).
10. Cookies
The application sets only the cookies strictly necessary for it to work: a session cookie and a CSRF protection token. There are no advertising, analytics, or third-party tracking cookies.
11. Changes to this policy
If we change this policy we will update this page and the "Last updated" date above. Material changes will be communicated to provisioned users directly.