Review Mosaic

Privacy Policy

Last updated: September 16, 2026

Overview

Review Mosaic respects reader privacy. This policy covers reviewmosaic.com, correspondence with us, and Review Mosaic Ads API, our desktop keyword research tool. The website and the desktop tool have separate data flows: visiting the website does not connect your Google Ads account or upload the desktop tool's credentials or results.

Information you provide

If you email us, we receive the address, name, message, and other information you choose to include. Contact and newsletter forms on this site open your own email application; the website does not silently submit the contents to a separate database.

Information processed automatically

Our hosting provider may process standard technical logs such as IP address, browser type, requested page, timestamp, and security signals to deliver and protect the site. Review Mosaic does not activate optional advertising or behavioral analytics in this release.

Cookies and local storage

The site uses essential browser storage to remember whether you dismissed the cookie notice. See the Cookie Notice for details.

Affiliate links

If partner links are introduced, merchants and affiliate networks may process referral information after you choose to follow a clearly identified link. Their privacy practices are governed by their own policies.

How information is used

We use messages to respond, correct content, evaluate suggestions, protect legal rights, and maintain the publication. We do not sell personal information.

Retention and rights

We retain correspondence only as long as reasonably needed for the purpose, legal obligations, or security. Depending on location, you may have rights to access, correct, delete, restrict, or object to certain processing.

Review Mosaic Ads API: Google user data

The desktop tool is used by authorized Google Ads account users for internal keyword research. After you explicitly grant Google OAuth consent, it processes OAuth access and refresh tokens, accessible Google Ads account IDs, the manager and customer account IDs you configure, keywords you import from Excel, and keyword historical metrics returned by Google Ads. Metrics may include average and monthly search volumes, competition, competition index, and top-of-page bid ranges. The tool does not request access to Gmail messages, Google Drive files, contacts, or payment-card details.

Purpose and permissions

The tool uses Google Ads access to discover accessible accounts and request historical keyword metrics for the keywords you choose, display and filter the results, and export them to a local Excel file for internal analysis. This workflow does not create, edit, or delete Google Ads accounts, campaigns, ad groups, ads, bidding settings, or budgets. Google Ads API uses the https://www.googleapis.com/auth/adwords OAuth scope; the tool's implemented workflow is read-only even though Google's consent description covers broader capabilities.

Sharing, transfers, and disclosure of Google user data

The desktop tool sends authorization credentials to Google's OAuth services and authenticated account IDs and keyword requests to Google's Google Ads API, as necessary to provide the features you select. Google is the external recipient of these requests. The application does not send OAuth tokens, Google Ads account IDs, imported keywords, or returned metrics to the Review Mosaic website, Cloudflare Pages, affiliate networks, advertisers, analytics providers, AI services, or other third parties. Review Mosaic does not sell Google user data, use it for personalized advertising, or use it to train AI models.

Retrieved data is available locally to the authorized operator using the tool and to anyone the operator grants access to the device or exported files. Exporting saves a file to a location selected by the operator; it is not an automatic upload or third-party sharing feature. If the operator selects a cloud-synchronized folder or separately sends an exported file, that transfer is controlled by the operator and the selected service, not performed by the tool. We do not routinely disclose Google user data. If legally compelled to provide records already in our possession, we disclose only what is required by applicable law; there is no central application database of desktop credentials or results.

Data protection mechanisms and local-storage limitations

Communication with Google's OAuth and Ads API services uses HTTPS with certificate verification enabled by the HTTP libraries, protecting credentials and requests in transit. OAuth authorization occurs in Google's browser consent flow; the tool does not collect your Google password, passkey, or verification codes. The authorization callback is bound to the local loopback address 127.0.0.1, not a public application server. Tokens are used for authenticated API requests and are not included in Excel exports or displayed as credential contents in the interface.

Account IDs and credential file paths are saved in local settings. The refresh token is saved in a local JSON file, and the OAuth client configuration remains in the local file selected by the operator. Query results are held in process memory unless you explicitly export them. The application does not implement its own encryption at rest for credential JSON or exported Excel files, and a local file is not automatically confidential. Operators must protect these files with operating-system access controls, a secured device account, and device or disk encryption where available; they must not place credentials in public folders, shared repositories, screenshots, or email attachments. The tool's lack of a central upload service and its limited data collection reduce exposure but do not eliminate risks from device compromise, backups, or operator sharing.

Retention, revocation, and deletion of Google data

There is no central server retention of the desktop tool's Google data. Results held only in memory are no longer retained by the application after it closes. Credential JSON, account settings, imported files, and exported Excel files remain on the operator's device until the operator deletes them; the tool does not automatically expire or erase these files. To stop access, revoke Review Mosaic Ads API in your Google Account's third-party connections settings, close the tool, and delete the local refresh-token file. Deleting a token file alone does not revoke the authorization at Google. Delete local settings and exported files when they are no longer needed, and remove any copies from the recycle bin, backups, or synchronized services according to those services' controls. Do not delete an OAuth client file if it is required by another authorized application.

For assistance with access, correction, deletion, or other privacy requests concerning Google data in our possession, contact google-ads-api@reviewmosaic.com. Do not send us passwords, tokens, or credential files. Google controls retention of its own service records under its policies; revoking this application does not delete your Google Ads source account or its data.

Google API Services User Data Policy

Review Mosaic Ads API's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google data is used only to provide the tool's described user-facing keyword research features, not for unrelated purposes.

Contact

Website privacy requests can be sent to hello@reviewmosaic.com. Questions or privacy requests concerning Review Mosaic Ads API can be sent to google-ads-api@reviewmosaic.com.