Privacy Policy

Privacy policy

Effective date: June 23, 2026

Summary (plain English)

  • AdHelm connects to Google Ads using OAuth. We never ask for your Google password.
  • Google Ads connection credentials are encrypted before storage, and connected account data is scoped to your workspace.
  • Do not submit protected health information (PHI) into AdHelm. The product is designed for marketing performance and operational workflow signals.
  • We do not sell customer data or Google user data.

Information we collect

  • Account information: name, email, workspace membership.
  • Google Ads data you authorize: account identifiers, campaign, keyword, and performance metrics.
  • Google Ads connection credentials: OAuth tokens needed to maintain the connection you authorize.
  • Product usage data: feature usage and action logs for auditability.
  • Billing data: subscription status and billing identifiers from Stripe.

How we use information

  • Provide audits, recommendations, previews, and explainable insights for the ad accounts and workspaces you connect.
  • Maintain your connected Google Ads workspace and account access.
  • Run safety guardrails and action logging, including rollback metadata.
  • Communicate account and billing notifications.
  • Improve product quality and reliability.

How we protect Google Ads and other sensitive data

  • OAuth access: you authorize Google Ads access through Google OAuth. AdHelm does not ask for or store your Google password.
  • Encryption in transit: data is transmitted over HTTPS/TLS.
  • Encrypted credential storage: Google Ads refresh tokens are encrypted before storage using AES-256-GCM.
  • Scoped access controls: workspace data is tenant-scoped and access is enforced server-side.
  • Limited access: access to customer data is limited to authorized workspace users and to personnel or service providers who need it to operate, secure, bill for, or support the service.
  • Logging and investigation support: we maintain logs around account changes, product actions, and operational events to investigate bugs, abuse, and support requests.

Cookies and analytics

  • Staying signed in. We set one essential cookie, __session, which keeps you logged in. The product does not work without it.
  • Your cookie choice. The choice you make in the cookie banner is saved in your browser's local storage. It is not sent to us.
  • Clicks on our public pages. When you click a button or link on a marketing page, we record the event: which page you were on, which button you clicked, and where it pointed. No name, no email address, and nothing about your health is attached to it.
  • Where those events go. They are passed to Google Analytics and Google Tag Manager when a tag is loaded on the site. Optional analytics tags load only if you choose “Accept all” in the cookie banner. Choose “Essential only” and they do not load.
  • What we do not do with it. We do not sell it, and we do not use it to build an advertising profile of you. It tells us which pages people read and which buttons they press.

Private pilot messaging

Some private pilot features may involve business messaging workflows for specific invited customers. When that happens, message frequency varies based on the customer's interaction with the practice, and message and data rates may apply.

Mobile opt-in data and consent records are used only to deliver the requested messaging service for that practice. We do not sell mobile numbers or messaging consent data, and we do not share that information with third parties for their own marketing purposes.

Messaging choices and controls

Patients can stop text communication at any time by replying STOP. For assistance, they can reply HELP or contact the practice directly. Practices are responsible for collecting appropriate consent before using messaging with a patient or prospective patient.

PHI and HIPAA

AdHelm is an advertising tool. It does not ask for clinical data and does not store any: no symptoms, no diagnoses, no treatment history, no test results, no clinical notes. Do not type any into it. We do not offer a BAA and we hold no HIPAA certification. If your practice needs either, tell us before you buy — today the answer is no.

Questions about this go to support@ad-helm.com.

Sharing

We do not sell customer data or Google user data, and we do not use Google user data for unrelated advertising. We share information with service providers only as needed to host, secure, bill for, and support the product.

Service providers (subprocessors)

  • Hosting and infrastructure: Google Cloud / Firebase (to run the application and store tenant-scoped data).
  • Billing: Stripe (to manage subscriptions, invoices, and payment processing).
  • Email and notifications: providers used to deliver product email (weekly reports, billing notices, and critical alerts).

We restrict access by role and scope, and we share only what is needed to deliver the service.

Retention and deletion

We retain data for as long as needed to provide the service and maintain action logs for accountability. If you disconnect the product or request deletion, we delete or de-identify data when reasonably possible, subject to billing, security, fraud-prevention, and legal retention needs. You can request deletion by contacting support@ad-helm.com.

Your responsibilities

You are responsible for ensuring that any data you input is appropriate for this product and compliant with your own obligations. Do not enter PHI or patient records.