Privacy Policy
Grapebox is a connector that lets AI assistants work with your Google Ads account on your instruction. This policy explains what information Grapebox accesses, why, and what it does not do. Contact us at admin@grapebox.ai with any question.
1. Information Grapebox accesses
Google Ads account data. When you authorize Grapebox, it requests access to your Google Ads account using the Google Ads API scope https://www.googleapis.com/auth/adwords. Through that access, Grapebox can read and, where you instruct it, change data such as campaigns, ad groups, ads, keywords, budgets, bidding settings, conversion action settings, performance metrics, and account change history.
This data describes your advertising activity. It is not, in general, personal information about an individual. The change history can include the email addresses of the people on your own team who made changes in the account.
Authorization credentials. To keep the connection working, an OAuth refresh token is held for each account you connect. [CONFIRM BEFORE PUBLISHING: where tokens are stored — on your own device, or encrypted on Grapebox-operated servers — and how they are protected.]
Usage information. [CONFIRM: whether Grapebox keeps any logs of tool requests, what they contain, and for how long. If none are kept, say so here.]
2. How Grapebox uses it
Only to provide the service you asked for: returning your reports and carrying out the changes you instruct. Grapebox does not sell your data, does not use it for advertising, and does not use it to build profiles or train models.
Google API Services User Data Policy. Grapebox's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
3. Who data is shared with
- Google, necessarily, because Grapebox works through the Google Ads API.
- The AI assistant you use (for example Claude). Grapebox returns your account data to the assistant you connected so it can answer you. How that assistant provider handles the conversation is governed by its own terms and privacy policy, which you should read.
- No one else, unless required by law.
4. Your customers' personal data
Grapebox does not process, store, or transmit the personal data of your own customers. This covers offline conversion uploads (names, emails, phone numbers matched to ad clicks) and Customer Match audience lists. This is a policy, not a missing feature. If you ask for help with these, Grapebox will tell you so and guide you through Google's own import tools, so that your file goes directly from you to Google and not through Grapebox.
5. Retention and deletion
[CONFIRM: how long tokens and any logs are kept, and how deletion works.] You can revoke Grapebox's access at any time at myaccount.google.com/permissions. Revoking access stops Grapebox from reading or changing your account immediately. To ask us to delete any information we hold about you, email admin@grapebox.ai.
6. Security
[CONFIRM AND DESCRIBE THE ACTUAL PRACTICES: how credentials are protected, who can access them, and how access is controlled. Avoid claims that are not yet true.]
7. Your rights
Under Singapore's Personal Data Protection Act, you can ask what personal data we hold about you, ask us to correct it, and withdraw consent to our use of it. Email admin@grapebox.ai and we will respond within a reasonable time. [CONFIRM: Data Protection Officer contact, if appointed.]
8. Children
Grapebox is a business tool and is not directed at children. We do not knowingly collect information from children.
9. International transfers
Google and your AI assistant provider operate internationally, so information may be processed outside Singapore. [CONFIRM once hosting is decided.]
10. Changes to this policy
If we change this policy, we will update the effective date above and, for material changes, notify connected users by email.
11. Contact
[LEGAL ENTITY NAME] · admin@grapebox.ai