Privacy Policy
Last updated: July 21, 2026
1. Information We Collect
We collect minimal information required to provide our technical SEO and AI-readiness auditing services. This includes basic account profile data (such as name, email, and profile image) when you authenticate using Google OAuth.
2. Google OAuth and Search Console Data
We integrate Google OAuth to allow secure login as well as to enable the optional Google Search Console (GSC) integration.
Data Accessed
By connecting your Google Search Console account via the read-only scope (https://www.googleapis.com/auth/webmasters.readonly), Adticks accesses:
- Your list of verified sites and properties.
- Search analytics performance metrics, including clicks, impressions, CTR, and average position, broken down by date, page, query, country, device, and search appearance.
- Submitted sitemap metadata, warnings, and errors.
- Google URL Inspection status snapshots, indexing state, crawl freshness, robots.txt status, page fetch state, and canonical mappings (Google-selected vs. user-selected canonicals).
Purpose and Use
This data is accessed solely to show you your organic search performance dashboard, diagnose indexing and technical SEO risks, identify sitemap mismatches, discover orphan pages, and generate tailored, actionable SEO recommendations inside your Adticks workspace.
Limited Use Requirements
Adticks' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
3. Data Storage & Encryption
To safeguard your credentials, GSC OAuth access and refresh tokens are encrypted at rest using secure industry-standard AES encryption. They are stored securely in our private database and are never exposed to the frontend or third parties. Collected Search Console snapshots and analytics rows are securely cached to power your dashboard.
4. No Data Sharing & Privacy Safeguards
We maintain strict boundaries regarding your Search Console data:
- Not Sold: We never sell your Google Search Console data or account details to third parties.
- No Advertisers: We do not share your analytics data with advertisers, brokers, or external trackers.
- No AI Model Training: Your Search Console data is never used to train third-party AI models or LLMs.
5. Disconnect and Deletion Policies
You maintain full ownership of your data and can control the integration at any time:
- Disconnecting: You can disconnect your Google Search Console connection or revoke property mapping at any time via the Settings page.
- Sync Termination: Once disconnected, Adticks stops all scheduled background syncs and deletes your access/refresh tokens.
- Historical Data: Historical GSC performance metrics are retained in your workspace by default to preserve analytics continuity. You can permanently wipe all historical sync data and database snapshots by deleting your project or account.
6. Product analytics (GA, GTM, Amplitude)
When configured by the operator, Adticks may load first-party product analytics to understand product usage and reliability:
- Google Analytics 4 / Google Tag Manager: Loaded only when
NEXT_PUBLIC_GA_MEASUREMENT_IDand/orNEXT_PUBLIC_GOOGLE_TAG_MANAGER_IDare set. Empty values disable these scripts (default for local clones). Consent Mode defaults deny ad storage; analytics storage defaults may be set viaNEXT_PUBLIC_GOOGLE_ANALYTICS_CONSENT. - Amplitude: Optional product analytics via
NEXT_PUBLIC_AMPLITUDE_API_KEY. When unset, Amplitude SDKs do not initialize.
These tools measure product interactions (for example, page views or feature usage). They are separate from Google Search Console data you connect for SEO diagnostics. When analytics tags are configured, Adticks defaults analytics storage to denied until you accept via the on-site cookie banner (or until an operator explicitly sets NEXT_PUBLIC_GOOGLE_ANALYTICS_CONSENT=granted). Operators should ensure their deployment's privacy notice and consent flows match the analytics tools they enable.
7. AI visibility and third-party model providers
Optional AI Visibility features may send prompts and public URL context you configure to third-party model providers (for example OpenAI, Anthropic, or Google Gemini) solely to measure how those systems respond about your brand or URLs. Keys are held server-side. We do not sell this content. Provider retention is governed by each provider's terms; disable AI Visibility or remove API keys to stop outbound calls.
8. Cookies and Session Management
We use secure cookies to maintain your login session and verify your requests. These cookies are essential for security and platform operation and are not used to track your browsing activities across external websites.
9. Scan and Crawl Behavior
When you submit a domain scan request, our crawler fetches publicly available assets (such as HTML pages, robots.txt files, and sitemap XML files). We strictly adhere to your site's robots.txt directives unless you configure manual overrides. We do not attempt to access private, authenticated, or password-protected content.
10. Security and Support
We implement administrative, physical, and electronic security measures to safeguard your account metrics, tokens, and audit history. For any support or privacy-related questions, please email us at [email protected].