Privacy Policy
Frugle ("Frugle", "we", "us") is a free, read-only tool that lets you view and export your own Google Ads spend history. Frugle is operated by Fernlabs (fernlabs.xyz). This policy explains what we access, how we use it, and your choices.
Information we access
When you sign in with Google, Frugle requests permission to access:
- Basic profile — your name, email address, and profile
picture (via the
openid,userinfo.email, anduserinfo.profilescopes), used only to show who is signed in. - Google Ads data (read-only) — via the
https://www.googleapis.com/auth/adwordsscope. Frugle issues only read (SELECT) queries. It reads the Google Ads accounts and manager-account hierarchy you can access (account ID, account name, currency, whether an account is a manager, and direct client-account relationships). For a selected client account, it reads campaign ID, campaign name, campaign status, advertising channel type, Performance Max serving channel, month, monthly cost, impressions, clicks, conversions, and conversion value. Frugle never creates, edits, pauses, or deletes campaigns or any other data in your account.
How we use it
We use this information solely to display your spend history back to you as charts and tables, and to generate the CSV you choose to download or email. We do not sell it, share it, use it for advertising, use it to train machine-learning models, or use it for any purpose beyond providing this feature to you.
Storage and retention
- Tokens. Your Google access and refresh tokens are stored only in a signed, HTTP-only session cookie in your browser. They are not written to our servers, disk, or any database, and the session expires after 24 hours.
- Encrypted handoff links. An authorized operator can create an encrypted handoff link containing a recipient name, recipient address, optional note, optional expiry time, and random identifier. A link may be created without an expiry; it then remains valid until the encryption key is rotated. Frugle does not create a database record for the link. The encrypted token is preserved in your signed, HTTP-only session cookie while you complete Google sign-in. Anyone who has a valid handoff link can start this flow, so treat it as confidential. Frugle redirects to a clean address after validating the link, but the original encrypted URL may remain in browser history or the systems used to share it. Links cannot be revoked individually without adding server-side storage; rotating the encryption key invalidates every link.
- Your Ads data. Frugle does not retain your Google Ads spend data on its servers. It is fetched live, shown to you, and discarded when your session ends. CSV files are generated on demand and downloaded directly to your device. The one exception is the emailed export, below.
- Emailed exports. If you choose to email a CSV to yourself or someone else, that export leaves our control. The CSV — which contains your Google Ads spend data — is transmitted to our email delivery provider along with the recipient address, the email address of the signed-in Google account, and any optional note, then onward to the recipient's mail server. A handoff link can preselect the recipient, but Frugle always shows a final disclosure and requires your approval before sending. Copies may be retained in delivery logs, outbound mailboxes, and provider caches after sending, and we cannot recall a message once it has been sent. Use this feature only if you are comfortable with that. If you never use it, no Ads data leaves Frugle.
If we ever introduce optional server-side storage of your spend history, we will update this policy first and it will be used only to display your own data back to you.
Third parties
- Google — authentication (OAuth) and the Google Ads API, governed by Google's own privacy policy.
- Fly.io — hosts the application. Standard request logs may contain IP addresses and request metadata for operating the service.
- Our email provider — used only by the "email this CSV" feature to relay the export to the address you give it. It receives the CSV, the recipient address, the signed-in account's email address, and any optional note, and is instructed to use them only to complete that delivery. It is not used anywhere else in the app and receives nothing if you do not use that feature.
Security
Traffic is served over HTTPS. Session cookies are signed and HTTP-only. No Google credentials are logged or stored server-side. No system is perfectly secure, but we aim to minimise what we hold — largely by holding nothing.
Your choices
- Sign out at any time to clear your session.
- Revoke Frugle's access entirely at myaccount.google.com/permissions.
- Because Frugle does not retain your data, signing out or revoking access generally leaves nothing for us to delete.
- Deletion requests. If you have used the email export feature, copies may persist in our delivery provider's logs and caches as described above. Email accounts@fernlabs.xyz and we will delete any data we still hold about you, including anything cached on our side from emailed exports. We cannot delete a message that has already reached the recipient's mailbox.
Changes
We may update this policy; material changes will be reflected by the "Last updated" date above.
Contact
Questions? Email privacy@fernlabs.xyz. For data deletion requests, email accounts@fernlabs.xyz.