Legal
Privacy Policy
Last updated: 9 July 2026
Who we are
Swishiy is an independent marketing measurement service operated by Qudees Kiani. Contact: hello@swishiy.com.
What we collect
Website: pages you visit, referral source, and anonymised device data via standard analytics.
Contact & audit forms: the email address and business URL you submit, plus the audit results generated from your Google Ads data.
Google Ads Auditor: when you sign in with Google we request read-only access to your Google Ads account (https://www.googleapis.com/auth/adwords) and read your Search Terms report for the last 90 days. We also receive your basic Google profile (name, email) so we can identify the session.
How we use it
Google Ads data is used solely to generate your audit and display the results back to you in the browser. We do not use it to build advertising profiles, we do not sell it, and we do not share it with third parties beyond the infrastructure providers listed below.
Google API Services User Data Policy
Swishiy's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, we do not allow humans to read it (except with your explicit permission for support, to comply with the law, or for security purposes), and we do not transfer it to third parties except as strictly necessary to provide the audit you requested.
OAuth scopes we request
When you sign in with Google we request the minimum scopes required to run the audit. Nothing else is requested, and no scope grants us the ability to modify your Google Ads account.
| Scope | Why we need it |
|---|---|
https://www.googleapis.com/auth/adwords | Read-only access to your Google Ads account so we can query the Search Terms report for the last 90 days and list accessible customer accounts. We never write, edit, pause, or spend anything. |
openid email profile | Basic profile (name, email) so we can identify the session and email your report to the correct address. |
Storage and retention
Your Google OAuth refresh token is stored encrypted at rest in our backend (Supabase / Lovable Cloud, EU region) and is used only to fetch data during your session. All data in transit between your browser, our backend, Google's APIs, and our subprocessors is encrypted using HTTPS/TLS 1.2+. Sessions expire after 24 hours. Audit outputs are retained for 90 days so you can revisit results, then deleted.
You can revoke Swishiy's access at any time in two ways:
- Click Disconnect Google inside the Google Ads Auditor. This revokes the token server-side and deletes your session immediately.
- Or open myaccount.google.com/permissions and remove Swishiy from your list of connected apps.
Access controls
Access to production systems that store Google user data (refresh tokens, audit outputs) is restricted to the Swishiy founder (Qudees Kiani) on a strict need-to-know basis, protected by unique accounts, strong passwords, and two-factor authentication. No third party, contractor, or automated system accesses Google user data except the subprocessors listed below acting on our behalf under contract.
Subprocessors
We rely on: Supabase (backend & database, EU), Lovable (hosting), Anthropic (search-term classification, only search-term strings are sent, no account identifiers or metrics), Klaviyo (email delivery), HubSpot (CRM), and Google (OAuth and Ads API).
Anthropic does not use this data to train its models. Requests are made under Anthropic's standard commercial API terms, not a consumer product, which prohibit training on customer inputs and outputs by default.
Your rights
You may request access, correction, or deletion of your data at any time by emailing hello@swishiy.com. We respond within 30 days.
Changes
We may update this policy; material changes will be announced on this page with a new "last updated" date.