Security

What we can reach, and what we cannot.

You are weighing whether an automated system might change something expensive while you are not looking. We read your account and write nothing back until you approve a specific operation.

Anything this page does not cover — security@goldbeater.ai

Read-only
until you approve an individual operation
0 keys
where the analysis runs. Your Google access stays on our server
0 rows
of your performance data kept after a review
Undo first
or the change is refused before anything is sent

The boundaries

Four boundaries, and the thing in the code that holds each one.

A claim without a mechanism is a promise, and a promise is not a control.

Boundary 01

We cannot read anyone else's account

The account a query runs against is attached by our own server, from a token minted for that run. The query language has nowhere to name an account, so no string the agent writes can reach a different one.

Boundary 02

Your credentials never leave our server

The analysis runs in a sandbox that holds no credential of any kind and can reach exactly one address: our own server. Your Google access and our developer key stay behind it.

Boundary 03

Nothing changes without a way back

A change set is a proposal until you accept operations inside it one at a time. We check it with Google first, refuse to send anything unless the undo has been written, then re-read the fields to confirm it did what it said.

Boundary 04

Nothing in your data can give us orders

Search terms are what members of the public typed into a search box, and some of it is written to be read by a model. It arrives as data, kept apart from the instructions the agent follows — and there is no write path without your approval, so the worst outcome is a proposal you reject. There will not be an autopilot mode.

What we hold

We keep the conclusions and the conversation. We never keep a copy of your account.

Every review reads the live account and lets what it pulled expire. What stays is the part you would want back — the findings, the scorecards, and your decisions.

WhatWhere it livesHow long
Performance rows pulled for a reviewWorking files in object storageExpire automatically after the run
Findings, scorecards and their historyOur databaseWhile your account is open
Change sets, the decisions you made, and the undo for eachOur databaseWhile your account is open
Conversation transcripts and tool callsObject storage, referenced from the databaseWhile your account is open
Google OAuth refresh tokenEncrypted under a managed keyUntil you disconnect the account
Your name, email, organizationOur databaseWhile your account is open
Card detailsStripe — never on our serversPer Stripe's retention
What is never stored
  • A copy of your Google Ads account — every review pulls its own.
  • Your Google password. Access is a grant you make at Google, and revoke there.
  • Raw performance rows beyond the life of the run that pulled them.
  • Any customer's data in a model provider's training set.

Subprocessors

Everyone who touches your data, and why.

This is the current list, and this page is where we keep it.

ProcessorWhat it doesRegion
CloudflareOur API, the agent, the database, storage and the analysis sandboxUnited States
VercelServes this website and the product front endUnited States
AnthropicThe model that reads the summarized account data and writes the analysisUnited States
GoogleThe Google Ads API — the origin of your account data, reached only through our proxyUnited States
StripeBilling and card handlingUnited States

What reaches a model provider is the summary the checks produced, not a copy of your account. It never trains their models.

Reporting

Found something? Tell us before you tell anyone else.

Write to security@goldbeater.ai. A human replies within two business days.