Legal

ConvDoctor Privacy Policy

Effective date: August 9, 2026
Last updated: August 24, 2026

1. Operator and contact

ConvDoctor is operated by IE Vasenov Maksym. Privacy questions and deletion requests: support@ggstore.com.ua.

2. Account and workspace data

The service stores registration information, a password hash, approval status, workspace membership and role, workspace name, language preference, settings, integration selections, and identifiers for connected resources. Plain-text passwords are not stored.

3. Google OAuth and synchronized data

After user-initiated OAuth authorization, the service may receive authorized Google Analytics 4 account metadata and reports; Google Ads accounts, campaigns, ad groups, keywords, queries, ads, assets, conversions, landing pages, segments, Performance Max data, recommendations, and change events; and Merchant Center accounts, products, performance, and issues. Availability depends on granted permissions and selected accounts.

Access and refresh tokens are stored in encrypted form to support synchronization. Explorer V1 uses these integrations for reading and does not modify Google Ads or Merchant Center.

4. Analytics, recommendations, Research, and plans

The service stores normalized reporting data, data-quality and freshness states, deterministic recommendations and evidence, Research projects, snapshots, selected ideas and campaign briefs, and Campaign Planner drafts, revisions, checks, and local decisions. These records support history, reproducibility, and human review.

5. AI processing

When AI features are enabled, bounded relevant context selected and sanitized by the server may be sent to OpenAI for generation. AI does not receive arbitrary database access, Google-account access, OAuth tokens, or provider-mutation tools.

AI output is advisory and can be inaccurate. ConvDoctor validates structure, evidence references, and the grounding of applicable claims; a response that fails validation may be rejected. We do not make unverified claims about an AI provider's retention or training practices.

6. AI and feedback storage

The application may store AI explanations, solutions, digests, action plans, strategies, Marketing Chat messages, Planner AI reviews, and AI-created plan revisions. It also stores usage metadata such as operation, model, provider request ID, token counts, latency, and outcome, but not the full internal prompt. User-submitted helpfulness feedback and an optional reason are also stored.

7. Logs, jobs, and audit records

The service processes job-queue records, safe error categories, synchronization logs, and audits of sign-ins, settings, connections, and important actions. Secrets, tokens, passwords, cookies, and session identifiers must not be written to logs.

8. Cookies and telemetry

The authenticated application uses an essential secure session cookie. The current implementation does not include third-party advertising analytics or profiling. We do not sell Google user data, share it for targeted advertising, or use it for third-party advertising profiles.

9. Sharing and processors

Information may be processed by providers needed to host and secure the service, operate Google integrations, and provide AI functionality. Information may also be disclosed when required by law or reasonably necessary to protect rights, safety, and service integrity.

10. Retention and deletion

The current product does not apply one fixed retention period to every data type. Historical reports, recommendations, plans, AI results, audit records, and related data may be retained for analysis, reproducibility, security, and legitimate recordkeeping. Expired temporary and rate-limit data may be removed under operational rules.

11. Disconnecting Google

Disconnecting an integration stops its future synchronization. The shared OAuth credential is deleted when the workspace's last Google integration is disconnected. Disconnecting does not automatically delete historical data already imported.

12. User requests

An authorized user may contact support@ggstore.com.ua to request access, correction, or deletion. We may verify identity and workspace authority and may retain limited records where required by law, security, or legitimate recordkeeping.

13. Google API Services User Data Policy

Use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including applicable Limited Use requirements.

14. Updates

An updated policy will be posted here with a revised date. Contact: IE Vasenov Maksym, support@ggstore.com.ua.