Data & security.
SynthBid handles advertising credentials and account data. We keep that surface small: least-privilege access, no resale of data, and a clear retention and audit posture.
Authentication
The tool connects to the Google Ads API using OAuth 2.0 with a single developer token. Credentials are held only in our operating environment and are never embedded in client-side code or exposed on this website. Refresh tokens can be revoked at any time from the Google account that granted them.
What data we touch
- Account & campaign data — structure, settings and performance metrics for the accounts we own, read to inform decisions in the review queue.
- Search-term and keyword reports — pulled to identify what to add, pause or exclude.
- No end-user personal data — SynthBid does not collect, store or process personal information about the people who see or click the ads.
Storage & retention
Operational data is stored only as long as it is useful for review and reporting, then rotated out. Reports are working artifacts, not a long-term data product. We do not sell, share or transfer account data to any third party.
Access control
Only named operators on our team can run the tool. Access follows least-privilege: the tool acts within our own manager account and its linked client accounts, and nothing else. There is no public sign-up and no external tenant.
Auditing & reversibility
Every write the tool applies — creates, edits, pauses, removals — is recorded with the account, the change and the approving operator. Because changes flow from a reviewed queue rather than an unattended process, they can be traced and rolled back.