Privacy
Policy

Last updated: August 26, 2026 — Version 1.0

This Privacy Policy explains how Blue Lotus (“we”, “us”) handles data, including what happens when you choose to connect a Google Ads or Microsoft Advertising account. Our use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We limit our use of Google user data to the purposes described below.

This policy describes how we collect, use, store, and share information in connection with our advertising analytics, summaries, alerts, and recommendations.

1. What Google data the product requests

If you choose to connect a Google Ads account, Blue Lotus requests access, via the Google Ads API, to:

  • Account structure: customer IDs and the campaign / ad group / ad hierarchy
  • Campaign data: names, status, budgets, bidding strategies, schedule, and targeting settings
  • Ad group and ad data: names, creatives, status, and labels
  • Spend and performance metrics: impressions, clicks, cost, conversions, conversion value, ROAS, and related signals

The product requests only advertising data. It does not request access to Gmail, Drive, or other non-advertising Google services.

2. What Microsoft data the product requests

If you choose to connect a Microsoft Advertising account, the product requests access to:

  • Account linkage and customer/account IDs
  • Campaign, ad group, ad, budget, and performance data similar to the Google Ads data above

3. Why we access this data

When you connect an account and select which advertiser accounts to analyze, the data is used to:

  • List the advertiser accounts your login can access and let you choose which to analyze
  • Generate summaries of recent performance, surface alerts for goals or pacing changes, and suggest possible next steps for you to review
  • Help apply an approved change to a campaign, ad group, ad, or budget after your review and approval
  • Present results for your review in the product and, when you enable email notifications, by email

4. How data is used — including AI assistance

Advertising performance data you have authorized is used to generate insights for you. Specifically:

  • Recent performance is aggregated (for example, over a recent period you select) and turned into a concise, readable summary and suggestions.
  • We use a self-hosted LLM to process advertising data and generate summaries, alerts, and optimization suggestions. We do not share your advertising data with external AI providers and do not use it to train general AI models.
  • We do not sell your Google or Microsoft advertising data.

5. Where and how data is handled

  • Service operation: Our website and services are provided with the help of service providers who host, secure, and deliver the service. Advertising data you authorize is processed only as needed to provide the features you use, and is not shared with external AI providers.
  • Encryption in transit: Connections to the product and to advertising platforms are encrypted in transit using HTTPS/TLS.
  • Credentials at rest: When the product stores OAuth access and refresh tokens after you connect, those tokens are encrypted at rest and are not stored in plaintext logs or code. They are transmitted only over HTTPS.
  • Access controls: Access to advertising data is limited to you and teammates you explicitly invite, with role-based controls and auditing. There is no public access to your advertising data.
  • Retention: Advertising performance data used to generate a summary or alert is handled transiently and is not retained long-term. Any temporary cache used for an analysis is deleted within 24 hours and immediately when you disconnect or revoke access. We do not store historical performance indefinitely. If we later offer opt-in long-term history, we will update this policy and request your consent before storing it.
  • On disconnect: When you disconnect an account or revoke access, the connection stops, tokens are deleted, and transient caches are purged. See Revocation and Retention.

6. Whether and whom we share data with

CategoryShared?Details
External AI APIsNoWe use a self-hosted LLM. Advertising data is not sent to external AI providers.
Email deliveryWhen enabled, as part of the serviceWhen email alerts are enabled, they are sent as part of the service to deliver the alerts you requested.
SMS deliveryNoneThe product does not send SMS.
Service providers (hosting, security, delivery)As needed to operate the serviceWe use service providers to host, secure, maintain, and deliver our website and services. These providers process information only as necessary to provide their services to us.
Analytics / tracking on this websiteNoneWe do not run Google Analytics, Meta Pixel, or similar on this website. If we introduce analytics in the future, we will update this section and request consent where required.
Sale of dataNeverWe do not sell Google or Microsoft advertising data.

If we engage a new sub-processor that would handle Google user data, we will update this policy and request your consent before sharing.

7. How you revoke access

You can revoke access at any time, without needing to contact us:

  • Google: Visit myaccount.google.com/permissions, find “Blue Lotus”, and remove access. You can also disconnect from within the product.
  • Microsoft: Visit your Microsoft account privacy settings for apps and services and remove “Blue Lotus”, or disconnect within the product.

After you revoke, the product stops syncing for that account, deletes stored tokens, and purges transient caches — typically within minutes and within 24 hours.

8. Data retention and deletion

  • Performance data: transient only; deleted within 24 hours and immediately on disconnect or revoke, unless you later opt in to longer retention after we update this policy and request consent.
  • Tokens: deleted immediately on disconnect or revocation.
  • Deletion requests: email privacy@bluelotustreasures.com — we confirm deletion within 30 days and sooner for Google user data where applicable.

9. Security measures

  • Encryption in transit and encrypted storage for credentials; no plaintext transmission or logging of tokens.
  • Access is limited to the advertising data needed to provide the features you use.
  • Access controls and auditing for advertising data.
  • Incident handling: if we detect unauthorized access, we revoke affected tokens, notify impacted users, and rotate affected secrets — see Security.

10. Non-Google / non-Microsoft data we collect

  • Account data: name, email, business name, and billing details if you subscribe.
  • Website usage: essential cookies only (see Cookie Policy). No advertising cookies by default.
  • Support correspondence.

11. Cookies and tracking

This website uses only essential cookies for security and load balancing. No analytics or advertising cookies by default. Details in Cookie Policy.

12. Children’s privacy

Blue Lotus is a business tool for advertisers and agencies. It is not directed to children under 13 (or 16 where applicable). We do not knowingly collect data from children.

13. Your rights — GDPR, CCPA/CPRA, and others

  • GDPR (EU/UK): Where applicable, lawful basis is performance of contract and your consent for the access you approve. You can access, correct, export, or delete your data, object to processing, and withdraw consent by disconnecting or emailing privacy@bluelotustreasures.com. We offer a Data Processing Agreement (DPA) on request — contact Contact.
  • CCPA/CPRA (California): Right to know, delete, correct, and opt out of sale (we do not sell data). Submit requests to privacy@bluelotustreasures.com; we verify and respond within 45 days.
  • We address applicable access/correction/deletion requests within 30 days.

14. Email alerts

When email alerts are enabled, they include accurate sender identification (“Blue Lotus”), a clear subject line, our mailing address, and a one-click unsubscribe link. Unsubscribing stops email alerts while leaving in-product notifications available unless you also disable those.

SMS: The product does not send SMS.

15. International transfers

Information is processed where we and our service providers operate. Where required, we apply appropriate safeguards as described in our DPA.

16. Changes to this policy

We will post updates here, change the “Last updated” date, and notify you in the product and by email for material changes. Continued use after the effective date constitutes acceptance.

17. Limited use disclosure (Google)

We affirm that our use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including Limited Use. We use Google user data only as described in this policy.

18. Contact

Privacy questions or requests: privacy@bluelotustreasures.com — or Contact page. For DPA requests, use the same address with subject “DPA Request”.

This policy is available at https://bluelotustreasures.com/privacy and is linked from every page on our website.