Privacy Policy
Last updated: 13 July 2026
Verdikt is an independent ad-spend auditor. It connects to your advertising and analytics accounts to produce an honest verdict on your spend. This policy explains exactly what we access, how we store it, and how you stay in control.
What we access
When you connect an account, you grant Verdikt read-onlyaccess to that platform's advertising or analytics data:
- Google Ads — campaign, ad-group, keyword and metric data (spend, impressions, clicks, conversions). Scope:
adwords(read-only use). - Google Analytics 4 — aggregate conversion/transaction totals. Scope:
analytics.readonly. - Meta Ads — campaign and ad-set insights (spend, results, conversions). Scope:
ads_read.
We never request write access. We do not change your campaigns, budgets, or settings. We do not access personal messages, contacts, or any data beyond the advertising/analytics scopes above.
How we use Google user data
Verdikt accesses Google Ads (adwords scope) and Google Analytics 4 (analytics.readonly scope) data solelyto read your connected brand's own campaign performance and funnel metrics, in order to produce an ad-spend audit that grades that brand's campaigns and identifies wasted spend — for that same brand, and no other purpose. This access is read-only: Verdikt never creates, edits, or deletes campaigns, ad groups, budgets, or any other setting on your Google Ads account. We do not use Google user data for advertising or marketing, we do not sell it, and we do not use it to train AI or machine-learning models.
Verdikt's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How we share, transfer & disclose Google user data
We do not sell Google user data, and we do not share, transfer, or disclose it to any third party for their own purposes. It is processed only by the infrastructure providers (sub-processors) strictly necessary to run Verdikt on your behalf:
- Vercel — hosts the Verdikt web application.
- Neon — hosts our Postgres database, where encrypted OAuth tokens and audit results are stored.
- Railway — runs the audit engine that reads your connected accounts and computes your verdict.
- Anthropic— Verdikt's AI translator (Claude) rewrites each audit finding's explanation into plain language before it is shown to you. It receives only the computed finding text (e.g. “CTR 0.50% is below the 2.00% benchmark”) — never your OAuth tokens or Google account credentials.
Beyond these sub-processors, we do not disclose Google user data to any other party, except where required by law (for example, a valid legal order).
Data protection
Concrete measures that protect your Google user data and other connected-account data:
- OAuth tokens are encrypted at rest using AES-256-GCM before being written to our database — never stored in plaintext.
- All data in transit — between your browser, Verdikt, and Google's APIs — is encrypted over TLS/HTTPS.
- Access is restricted to the account owner: each brand's data is isolated at the database level (row-level security), so only you can view your brand's data.
- Tokens are revocable at any time— see “How access is revoked” below.
- Data is deleted on request — see Data Deletion below.
The audit results we compute (your metrics and the resulting verdict) are stored so you can view them. We do not sell your data, and we do not share it with advertisers or agencies.
How access is revoked
You can disconnect any platform at any time from the connect screen — this deletes the stored token immediately. You can also revoke Verdikt's access directly in your Google account permissions or Meta business integrations. Revoking access stops all future data reads.
Contact form data
If you use our contact form, we store the name, email, company, and message you submit, and email them to our team so we can reply. That information is used only to respond to you.
Service access
Verdikt's team may access your audit results to provide support and improve the service. We never sell your data, and our team never accesses your connected-account credentials — those stay encrypted and are used only to run your audits.
Data requests & deletion
You can request a copy of, or the deletion of, any data we hold about you. Email privacy@anandpathak.com and we will action it. Disconnecting your accounts removes the stored tokens; on request we will also delete your account, stored OAuth tokens, and all audit data within 30 days and confirm by email. Full steps are on our Data Deletion page.
Contact
Questions about this policy or your data: privacy@anandpathak.com. See also our Terms of Service.