Llidfly.aiDeutsch
← Back to LidFly

Privacy and Google user data

Privacy Policy

This policy explains how the independent developer operating LidFly AI processes personal data and Google Ads data.

Last updated: 26 August 2026

1. Controller

Galina Savinykh

LidFly AI

Hofberg 4

09633 Halsbrücke

Germany

Email: info@lidfly.ai

Telephone/Fax: +49 3732 482103

2. Current product status

The LidFly platform foundation is online. The Google Ads integration is in development and production access is pending Google developer-token and OAuth approval. This policy also describes the processing that will begin only after a user connects Google Ads.

3. Website and account data

When the website is requested, technical data such as IP address, time, requested URL, user agent, and security events may be processed to deliver and protect the service. The legal basis is Article 6(1)(f) GDPR.

When a user signs in, LidFly processes the email address, account and workspace identifiers, language preference, session data, IP address, and user agent. One-time codes are valid for ten minutes and stored only in hashed form. Sessions normally expire after 30 days. Processing is based on Article 6(1)(b) GDPR and, for abuse prevention, Article 6(1)(f) GDPR.

Login and service emails are delivered through Resend. Support correspondence is processed to answer the request and maintain an appropriate record of the communication.

4. Google Ads data

A user will explicitly initiate Google OAuth and authorize access before LidFly accesses an account. LidFly will process only Google Ads accounts that are available to the authorizing user and only for user-facing Google Ads campaign creation, management, and reporting features.

  • Google Ads customer and manager account identifiers and the list of accessible accounts.
  • Campaign, ad group, keyword, ad, asset, audience, budget, bid, status, and configuration data needed for the requested feature.
  • Performance and reporting metrics, API request metadata, granted scopes, and connection status.
  • OAuth access and refresh credentials required to maintain the authorized connection.

5. Limited use of Google data

Google Ads data is used only to provide or improve the prominent user-facing features requested by the user, keep the connection secure, comply with law, and prevent abuse. It is not sold, used for unrelated advertising or retargeting, or transferred to data brokers. The planned initial integration does not upload Customer Match lists or customer lists.

OAuth credentials, authorization headers, and customer lists are never sent to an AI model. When a user deliberately asks an AI assistant to analyze or act on advertising data, the minimum campaign data and tool results required for that request may be returned to the AI client or model selected by the user. This transfer occurs only to perform that visible user-requested feature.

6. Storage, recipients, and international transfers

Provider credentials are referenced through encrypted secret storage and are separated from application records. Data may be handled by hosting, database, email-delivery, security, and user-selected AI providers only to operate the requested service and subject to appropriate contractual and security safeguards.

Some providers may process data outside the European Economic Area. Where required, LidFly relies on an applicable GDPR Chapter V transfer mechanism, such as an adequacy decision or standard contractual clauses. Further information can be requested at info@lidfly.ai.

7. Cookies

LidFly currently uses functional cookies only: a language-preference cookie for up to 12 months and authentication or security cookies needed for sign-in and sessions. The public website does not currently use advertising or cross-site tracking cookies.

8. Retention and deletion

Account and workspace data is retained while the account is active. Google OAuth credentials are retained until the connection is revoked, disconnected, expires, or the associated account is deleted. Cached Google Ads data is retained only while needed for the requested feature. Security and audit records may be retained for as long as necessary to protect the service, resolve disputes, and meet legal obligations.

Verified deletion requests are answered without undue delay and ordinarily completed within 30 days. Data that must be retained by law, or limited records needed to establish, exercise, or defend legal claims, may be kept for the applicable period.

9. Rights and complaints

Subject to the GDPR, users may request access, correction, deletion, restriction, portability, or object to processing, and may withdraw consent where consent is the legal basis. Requests can be sent to info@lidfly.ai.

Users may lodge a complaint with a competent supervisory authority. For a controller established in Saxony, the local authority is the Sächsische Datenschutz- und Transparenzbeauftragte, Maternistraße 17, 01067 Dresden, Germany, datenschutz.sachsen.de.

10. Changes

This policy will be updated before material new processing begins. The current version and its update date remain available at this URL.

Request data deletion →Email privacy contact →
Galina Savinykh · LidFly AIIndependent developer · Germany
PrivacyTermsImprintSupportData deletionSecurity