by Clouds Creation

APIMCC · privacy

Privacy Policy

Information pages, hosted demo and local desktop client.

Last updated: October 2, 2026.

1. Scope and contact

CLOUDS CREATION LLC (Clouds Creation) operates APIMCC, an internal Google Ads campaign management prototype. This policy describes APIMCC's informational website, hosted sample-data demonstration and local desktop client. It does not describe all company services; the company's other website services have a separate company privacy policy.

APIMCC privacy questions: [email protected]. Postal contact: 109 East 17th ST, Cheyenne, WY 82001.

2. Current development status

The hosted demo uses fictional data and makes no Google API calls. It stores demo state in the user's browser local storage.

The separate desktop client implements Google OAuth authorization, but successful live authentication and Google Ads reads have not yet been verified. The current owner setup disables campaign mutations. The following sections explain what the implemented client would access and retain if a connection succeeds; they do not claim that a Google connection or API approval has already been obtained.

3. Google permission and data accessed when connected

The desktop client requests the Google Ads permission https://www.googleapis.com/auth/adwords. This is a broad permission to view and manage Google Ads data, even when the current app configuration disables changes. Google presents the authorization request separately from these information pages.

When connected, the client's queries request accessible account resource names; the selected customer's ID, name, currency, time zone and test-account flag; and campaign IDs, names, statuses, advertising channel types and budgets. The current queries do not request performance metrics, audiences or user profiles.

This data supports account selection and campaign viewing in the local interface. The implementation can create, update or remove campaigns with confirmation when mutations are enabled, but those actions are disabled in the current owner configuration.

4. Processing and storage on the operator's device

The local client holds access tokens, discovered accounts, selected account metadata and pending operations in its running server's memory. Live campaign results are displayed in the local browser interface; the implementation does not maintain a database cache of those results. Refresh tokens are discarded and automatic token refresh is not implemented.

A local SQLite database persists simulated campaigns and audit events. Audit entries can include the timestamp, demo or live mode, action, target ID, outcome and an optional Google request ID. A successful live operation can therefore leave Google Ads customer IDs in the audit history.

Audit records have no automatic age-based deletion or fixed retention period in the current implementation. Showing the last 100 entries is a display limit, not a deletion rule. Information remains subject to the operator's device access, local storage and backups.

5. Disconnecting, deletion and revocation

The client's Disconnect control clears its current token, authorization state, discovered accounts, selected account metadata and pending operations. It does not revoke the Google account's authorization grant or delete local audit history. It also does not remove the OAuth client secret stored in the local configuration.

To revoke Google's authorization, review your Google Account third-party connections and remove APIMCC's access. Stop the local application to release its running memory state; this is not a guarantee of secure memory erasure.

There is no in-app automatic audit deletion feature. The device operator can stop APIMCC and remove its local SQLite database and any copies or backups when the associated audit and simulated records are no longer needed. This removes that local history and does not remove provider records or revoke Google's grant. Contact us for help identifying APIMCC's local data files before deleting them.

For the hosted fictional-data demo, use your browser's site-data controls to clear its local storage. This does not delete hosting-provider logs or messages sent by email.

6. Network destinations and sharing boundaries

The desktop client's Google authorization and API requests go to accounts.google.com, oauth2.googleapis.com/token and googleads.googleapis.com. Its browser interface calls the application on the local device. No analytics integration or code path for sending Google data to advertising services or AI training was found in the reviewed client implementation.

The implemented local access checks restrict requests to the local host and check session, request origin and request tokens. These checks are not staff identity verification or role-based access control. This prototype does not provide a verified multi-user permission system.

7. Website and hosted-demo visits

The APIMCC information pages are static and contain no contact form or analytics script. Requests to the website or hosted demo are handled by their hosting providers, which may process technical information such as IP address, browser information, requested URL and request time.

The hosted demo uses ChatGPT Sites. That platform may require authentication for invited access and handles its own account information and technical logs under OpenAI's Privacy Policy. This policy does not set hosting-provider retention periods.

8. Questions and changes

Email [email protected] about APIMCC data handling or a request concerning information you have provided. Emailing sends your address and message to Clouds Creation and its email service; avoid sending credentials or confidential account records. Local data deletion and Google grant revocation require the separate steps described above.

This policy will be revised when APIMCC's actual data handling changes. The date above identifies the current version.