跳到主要内容
AdsDesk.ai
能力工作方式平台说明服务条款
返回首页 ↗

PRIVACY · LIMITED USE · USER CONTROL

AdsDesk 隐私政策

说明 AdsDesk.ai 如何处理经用户明确授权的 Google Ads 相关数据,以及用户如何撤销授权或提出删除请求。

DOCUMENT STATUS

生效及最后更新
2026 年 7 月 22 日

访问的数据使用目的共享与披露存储与安全保留与删除Google API 政策政策更新联系我们English version

AdsDesk 是由武汉得鹿网络科技有限公司(以下简称“我们”)运营的内部 Google Ads 管理工具。本政策说明 AdsDesk 如何处理经用户明确授权的 Google Ads 相关数据。

1. 我们访问的数据

当授权用户连接 Google 账号时,AdsDesk 通过 Google OAuth 和 Google Ads API 的 https://www.googleapis.com/auth/adwords 范围访问完成投放管理所必需的数据:

  • OAuth 授权信息及识别已授权账号所需的基本账户信息;
  • 用户有权管理的 Google Ads 客户账号信息;
  • 广告系列、广告组、广告、关键词、预算、出价及相关配置;
  • 广告效果、搜索字词和报告数据;
  • 关键词规划及账户管理所需的其他 Google Ads 数据。

AdsDesk 不会索取用户的 Google 账号密码。

2. 数据使用目的

上述数据仅用于用户授权范围内的 Google Ads 账号管理,包括创建和管理广告系列、生成报告、分析广告效果及进行关键词规划。所有可能改变广告账号的操作均须由有权人员在执行前审核确认。我们不会出售 Google 用户数据,也不会将其用于个性化广告或与上述目的无关的用途。

3. 数据共享与披露

我们不会向第三方出售或出租 Google 用户数据。只有在提供服务所必需、受保密和数据保护义务约束的基础设施服务商,或法律法规、司法及监管机关依法要求时,才可能进行必要披露。

4. 数据存储与安全

我们仅保存提供 AdsDesk 功能所必需的授权信息和业务记录。OAuth 访问令牌、刷新令牌、OAuth 客户端密钥和 Google Ads 开发者令牌均不显示在 AdsDesk 界面或报告中,也不会被有意写入应用日志。Web 审核环境不请求或保存刷新令牌;短期访问令牌仅在服务端使用,并以 AES-GCM 加密后存入带有 HttpOnly、Secure 和 SameSite=Lax 属性的会话 Cookie,最长保留 55 分钟。桌面运行环境中的长期凭据仅保存在本机配置目录,文件权限限制为该系统用户可读写。Web OAuth 回调及与 Google OAuth、Google Ads API 的通信全部使用 HTTPS;桌面演示在适用时使用本机回环回调(127.0.0.1)。对 Google 用户数据的访问仅限履行工作职责的授权人员,并采用最小权限、访问控制和凭据隔离措施。

5. 数据保留与删除

当用户停止使用服务、撤销 Google OAuth 授权或提出删除请求后,我们将在 30 天内删除相关授权信息和受本政策约束的 Google 用户数据;法律法规要求保留的记录除外。

用户可在 Google 账号的第三方应用访问设置中随时撤销 AdsDesk 的授权,也可发送邮件至 [email protected]提出访问、更正或删除请求。

6. Google API 数据政策

AdsDesk 对从 Google API 获取的信息的使用和向其他应用的传输,将遵守 Google API Services User Data Policy,包括其中的 Limited Use 要求。

7. 政策更新

如本政策发生重大变化,我们将在本页面发布更新并修改“最后更新日期”。

8. 联系我们

武汉得鹿网络科技有限公司
隐私与数据删除联系邮箱:[email protected]

AdsDesk Privacy Policy

Effective and last updated: July 22, 2026

AdsDesk is an internal Google Ads management tool operated by Wuhan Delu Network Technology Co., Ltd. (“we,” “us,” or “our”). This policy explains how AdsDesk handles Google Ads data accessed with a user's explicit authorization.

Data we access and how we use it

Through Google OAuth and the Google Ads API using the https://www.googleapis.com/auth/adwords scope, AdsDesk may access OAuth authorization information, basic information needed to identify the authorized account, Google Ads customer accounts the user is permitted to manage, campaign settings, ads, keywords, budgets, bidding data, performance reports, search terms, and keyword-planning data. We use this data only to create and manage campaigns, produce reports, analyze performance, and perform keyword planning within the user's authorization. Any operation that changes an advertising account requires review and confirmation by an authorized person before execution.

Sharing, security, and retention

We do not sell or rent Google user data, use it for personalized advertising, or use it for unrelated purposes. Data may be disclosed only to infrastructure providers subject to confidentiality and data-protection obligations when necessary to provide the service, or when legally required. We retain only the authorization information and operational records needed to provide AdsDesk. OAuth access tokens, refresh tokens, OAuth client secrets, and Google Ads developer tokens are not rendered in the AdsDesk interface or reports and are not intentionally written to application logs. The web review environment does not request or store refresh tokens. Its short-lived access token is used only on the server and is stored in an AES-GCM-encrypted session cookie with HttpOnly, Secure, and SameSite=Lax attributes for no more than 55 minutes. Long-lived credentials used by the desktop environment are stored only in a local configuration directory with file permissions limited to that system user. The web OAuth callback and all communication with Google OAuth and Google Ads API endpoints use HTTPS; the desktop demonstration uses a local loopback callback (127.0.0.1) when applicable. Access to Google user data is limited to authorized personnel with a work need, using least-privilege access controls and credential isolation.

After a user stops using the service, revokes Google OAuth access, or requests deletion, we delete the relevant authorization information and Google user data covered by this policy within 30 days, except where retention is legally required. Users may revoke access in Google Account permissions or contact [email protected].

Google API Services User Data Policy

AdsDesk's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Contact

Wuhan Delu Network Technology Co., Ltd.
Privacy and deletion requests: [email protected]

AdsDesk.ai

武汉得鹿网络科技有限公司
Google 用户数据仅用于获授权的广告管理。

客户官网平台说明隐私政策服务条款
© 2026 AdsDesk.ai