Privacy Policy
Last updated: September 8, 2026
This policy explains what AdRevFlow collects, why, and the choices you have. It applies to the website and the signed-in dashboard.
What We Collect
Account data: when you sign in with Google, we receive your name, email address and profile picture.
Platform credentials: when you connect AdSense we store the OAuth tokens Google issues; for Adsterra we store the API token you paste. All credentials are encrypted at rest with AES-256-GCM and are never sent to your browser.
Synced metrics: revenue, impressions, clicks and related reporting data for your sites, ad units and countries, fetched from the platforms you connect.
How We Use It
We use this data only to operate the service: authenticating you, syncing your metrics, and rendering your dashboard. We do not sell your data, do not share it with advertisers, and do not use your metrics for any purpose other than showing them back to you.
Third-Party Processors
We rely on a small set of processors to run the service: Google (sign-in and the AdSense Management API), Adsterra (reporting API), Neon (database hosting), Vercel (application hosting) and, when you buy a paid plan, our Merchant of Record as the seller and payment processor. Each processes data under its own privacy policy.
Cookies
We use only the cookies required for sign-in and security. We do not use advertising or cross-site tracking cookies.
Retention and Deletion
We keep your data while your account is active. Disconnecting a platform deletes its stored credentials immediately. Deleting your account removes your profile, connections and all synced metrics; residual copies in backups expire within 30 days.
Your Rights
You can view your data in the dashboard, export your metrics to Excel, correct your profile in Settings, and delete your account at any time. If you are in the EEA, UK or another region with data-protection law, you also have the right to lodge a complaint with your local authority. For any request, contact support@adrevflow.com.
Security
All platform API calls happen server-side, tokens are encrypted at rest, and access to synced metrics is scoped to your account. No method of storage is perfectly secure, but we design for the minimum data needed to run the service.
Changes
We may update this policy as the service evolves. The current version is always posted on this page with its revision date.
Contact
Privacy questions and requests: support@adrevflow.com.