Security &
Data Handling

How Blue Lotus protects data when you connect an advertising account. For commitments that apply to personal data, see our Privacy Policy.

1. Encryption

  • In transit: All connections to the product and to advertising platforms are encrypted in transit using HTTPS/TLS. OAuth tokens are never transmitted in plaintext.
  • At rest: OAuth access and refresh tokens are encrypted at rest and never stored in plaintext logs or code.

2. Credential handling

  • OAuth tokens are stored only after you grant access via Google’s or Microsoft’s consent screen.
  • When you disconnect or revoke access, the product deletes stored tokens and immediately stops syncing for that account. See Privacy — Revocation.
  • OAuth tokens are stored securely on the server and are never logged, emailed, or exposed to the browser.

3. Data requested

The product requests only advertising data needed to provide the features you use. It does not request access to email, files, or other non-advertising services. Details of the data accessed when you connect are listed in our Privacy Policy.

4. AI assistance — no third-party sharing

We use a self-hosted LLM to process advertising data and generate summaries, alerts, and optimization suggestions. We do not share your advertising data with external AI providers and do not use it to train general AI models. If this approach changes, we will update our Privacy Policy and request your consent before any data is shared.

5. Service operation

Our website and services operate with the help of service providers who host, secure, and deliver the service. Advertising data you authorize is processed only as needed to provide the features you use. See Privacy — Sharing for the categories of processing involved.

6. Access controls

  • Access to connected advertising data is limited to you and teammates you explicitly invite. Role-based access (viewer or editor) is available where team access is offered.
  • Access by our team is limited, audited, and never allows browsing of other customers’ advertising data without your permission.
  • Support access, where offered, is gated by your explicit approval.

7. Retention

Advertising performance data used to generate a summary or alert is processed transiently and deleted within 24 hours and immediately when you disconnect. No indefinite history is kept without an opt-in you approve. See Privacy — Retention.

8. If something goes wrong

If we detect unauthorized access affecting connected accounts, we revoke affected tokens, rotate affected secrets, purge transient caches, and notify impacted users with a post-incident summary. To report a potential issue, contact security@bluelotustreasures.com. We acknowledge reports within 24 hours.

9. Your responsibilities

  • Keep your Google and Microsoft logins and notification email accounts secure.
  • Review any AI-assisted suggestion before deciding whether to apply it — suggestions are recommendations (see Terms).

Encrypted
At Rest

HTTPS
In Transit

No External AI
Sharing