First 200 users get the Growth plan for $19/mo.

Claim
Legal

Privacy policy

Last updated: July 18, 2026

1. Introduction

This privacy policy explains how overads ('we', 'us', 'our') collects, uses, and protects information when you visit our marketing site or use the overads product. By using overads you agree to the practices described here. It covers both the personal data we hold about you and the advertising, search, and customer data you connect to your workspace from third-party platforms.

2. Data we collect

We collect account information you provide directly (name, email, workspace name), authentication metadata from your identity provider, usage telemetry generated as you use the product, and ad-account data you authorize us to fetch via OAuth from supported platforms. We do not collect payment card numbers directly; payment processing is handled by our payments provider.

3. How we use data

We use the data we collect to operate the service, authenticate you into your workspace, sync metrics from connected ad platforms, generate AI suggestions, send transactional email, prevent abuse, and improve the product. We do not sell personal data and we do not train third-party foundation models on customer ad data.

4. Google user data and Limited Use

When you connect a Google account, we request the narrowest scopes that support the features you have enabled: read-only access to your Google Ads reporting data, and, where you enable Search Console reporting, read-only access to your Search Console performance data. We never request write access to your Google account, and we never request access to your Gmail, Drive, Contacts, Calendar, or Photos. overads' use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Concretely, this means we use Google user data only to provide and improve the reporting, analytics, and recommendation features you asked for; we do not use it for advertising, we do not sell it, and we do not transfer it to third parties except as necessary to provide the service, to comply with applicable law, or as part of a merger or acquisition with notice to you. No human at overads reads your Google user data except with your explicit consent for a specific support request, where it is necessary for security purposes such as investigating abuse, or where the law requires it. You can disconnect a Google account at any time from Settings, which revokes our stored access and refresh tokens; you can also revoke our access directly from your Google Account permissions page.

5. Data protection and security

We treat OAuth credentials and connected-platform data as sensitive, and protect them with specific technical controls rather than general assurances. Encryption in transit: all traffic to overads is served over HTTPS, and we set HTTP Strict Transport Security with a one-year max-age so browsers refuse to connect over plaintext. Encryption at rest: OAuth access and refresh tokens for every connected platform, including Google, are encrypted before they are written to the database using envelope encryption backed by a managed key service. Each ciphertext is bound to your workspace through an encryption context enforced by the key service, so a token belonging to one workspace cannot be decrypted in the context of another, even by someone holding database access. Production refuses to start without a configured encryption key, so plaintext credential storage is not a state the service can reach. Credential handling: we never log access tokens, refresh tokens, or passwords. Account passwords are stored only as bcrypt hashes, and password-reset and session tokens are stored only as SHA-256 hashes, so the stored value cannot be replayed. Access control: every request that touches workspace data is authenticated and authorized against your membership of that workspace before any query runs, roles limit what each member can do, and multi-factor authentication is available on your account. Administrative and security-relevant events are recorded to an audit log. We apply hardened HTTP security headers, including a restrictive content security policy, across the application. Deletion: see the retention section below, and the data deletion page for how to request erasure. No system is perfectly secure, and we do not claim otherwise, but if we become aware of a breach affecting your personal data we will notify affected customers and any required regulators without undue delay.

6. Sharing with third parties

We share data with a limited set of subprocessors that are essential to running the service (infrastructure, payments, AI inference, error tracking, transactional email). A full list of subprocessors is available in our Data Processing Agreement. We do not share customer data with advertisers or data brokers.

7. Cookies and similar technologies

We use a small number of first-party cookies for authentication, workspace switching, and basic product analytics. We do not use third-party advertising cookies on our application surfaces. Our marketing site may use lightweight, privacy-respecting analytics to understand aggregate page performance.

8. Your rights

Depending on where you live, you may have rights to access, correct, export, or delete the personal data we hold about you. You can exercise most of these rights from inside the product Settings. For anything else, write to privacy@overads.io and we will respond within thirty days.

9. GDPR (EEA, UK, Switzerland)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, we process personal data on the legal bases of contract performance, legitimate interest, and consent where applicable. We offer a Data Processing Agreement that incorporates the relevant Standard Contractual Clauses for international transfers.

10. CCPA (California)

If you are a California resident, you have specific rights under the California Consumer Privacy Act including the right to know what personal information we collect, the right to delete personal information, and the right to opt out of any sale of personal information. We do not sell personal information.

11. Data retention

We retain personal data and ad-platform data for as long as your workspace is active. Deletion is immediate rather than staged: when you delete your account or a workspace, those records are removed from our primary database as part of that request. There is no soft-delete window and no restore path, so export anything you need before you delete. Encrypted backups age out within ninety days. The data deletion page sets out exactly what is removed, and the few things that fall outside it.

12. Contact

Questions about this policy or our data practices can be sent to privacy@overads.io. For formal data protection inquiries from the EEA or UK, write to the same address with the subject prefix 'GDPR request'.