Privacy Policy
Last updated: 18 September 2026 · Deutsche Fassung
SpliceMule pulls advertising reports from ad platforms and writes them into Google Sheets. This policy explains what personal data is involved.
1. Controller
Prociro LLC, — Strasse und Hausnummer —, — PLZ, Ort —, Vereinigte Staaten von Amerika
Email: datenschutz@splicemule.com
EU representative under Art. 27 GDPR: — Name des EU-Vertreters nach Art. 27 DSGVO —, — Anschrift in der EU —
2. Data we process
- Account: email address, name, company name, password hash, two-factor secret and recovery code hashes, IP address of sign-in attempts.
- Connected ad accounts: the access token you grant through the platform's own consent dialog, the account label, the connecting account's name or email address, the platform user ID (Meta only, so deletion requests can be matched), and the token's validity. Tokens are stored encrypted with AES-256-GCM.
- Advertising reports: fetched, written to your spreadsheet, and then discarded. They are not stored. What remains is a run log: timestamp, duration, row count, and any error message.
- Billing: handled by Stripe. We never see or store card details.
3. Read-only access
SpliceMule requests read-only permissions exclusively — for example ads_read on Meta. It cannot create, modify, pause, or delete campaigns, because it never requests the permissions that would allow it. It surfaces only the ad accounts the connecting user can already access.
4. Google API Services — Limited Use disclosure
SpliceMule's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, data obtained from Google APIs is:
- used only to provide and improve the data flows you configure;
- not transferred to third parties except as necessary to run your data flow, with your explicit consent, or where required by law;
- not used for advertising, not sold, and not used to train AI or ML models;
- not read by humans, unless you explicitly request support, it is required for security, or it is required by law.
| Scope | Why we need it |
|---|---|
spreadsheets | Writing rows into the sheet tab you specify |
drive.file | Access limited to the spreadsheets you point SpliceMule at |
adwords | Reading reports from your Google Ads accounts |
userinfo.email | Showing which Google account is connected |
You can revoke access at any time at myaccount.google.com/permissions.
5. Meta, TikTok, and LinkedIn
The same principles apply: read-only scopes, used solely to run your data flows, never sold, never used for advertising, never used to train models. Revoke access in your Meta settings under “Apps and Websites”, in LinkedIn under “Privacy → Other applications”, or in your TikTok Business account settings.
6. Recipients
The ad platforms you connect, Google Sheets as your destination, Stripe for billing, Hetzner as our hosting provider, and Cloudflare for bot protection. See subprocessors. We do not sell data.
7. Retention
- Account and data flow configuration: until the account is deleted
- Access tokens: until disconnected or revoked at the platform
- Advertising reports: not stored
- Run log: 90 days · Server logs: 14 days
- Invoices: as required by statutory retention periods
8. International transfers
The application runs on servers in Germany. Transfers to the United States occur where you connect US platforms and through Stripe, based on the European Commission's Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.
9. Your rights
You have the right to access, rectification, erasure, restriction, portability, and objection under the GDPR. Contact datenschutz@splicemule.com. For deletion, see Data deletion. You may also lodge a complaint with a supervisory authority.
10. Security
TLS in transit, AES-256-GCM for tokens at rest, bcrypt for passwords, optional two-factor authentication, rate-limited sign-in. Report vulnerabilities to security@splicemule.com; we respond within five business days.