Security & trust
Built to be trusted with your accounts.
RunPPC reads sensitive advertising data, and applies the changes you approve in your Google Ads account, so the security posture is part of the product,
not an afterthought. Here is exactly how it works.
Nothing changes without your approval
We connect via Google OAuth (scope adwords) and read your account structure and cost metrics, to build your plan and compute CPL. The agent proposes what to change and shows you the change in full: you can edit any part of it, or reject it. When you approve that exact version, RunPPC applies it in your Google Ads account. Nothing in your campaigns, bids or budgets moves without that approval, and that includes launching a new campaign, which RunPPC does for you.
Ads tokens encrypted at rest
Google (and, later, Microsoft) OAuth tokens are encrypted at rest with AES-GCM and never stored in plaintext. Access is least-privilege and limited to operating the Service.
Tenant isolation by workspace
Every query is scoped by workspace_id. One workspace is the boundary between your clients, so data never leaks across tenants.
The snippet never blocks your page
Personalization runs locally from URL parameters. Telemetry is sent fire-and-forget (sendBeacon or fetch keepalive). The snippet is designed to fail safe and minimize what it collects.
We share data only with vetted providers acting on our behalf. The current list is also kept
in our DPA.