How we use Google Ads data

Connecting your Google Ads account is optional and does one job: it lets us check that the clicks recorded on your site are clicks Google actually charged you for. This page is exact about what that involves, for you and for anyone at Google reviewing it.

Last updated 2026-09-19

What we read

Reporting for the accounts you connect, read once a day. Specifically:

Why

Anybody can add a fake click identifier to one of your URLs. Without a way to check, a competitor could manufacture hundreds of them against a single campaign until it looked like it was burning your budget for nothing — and you would pause a campaign that was working, on our advice.

Comparing against Google's own record is the only way to settle that with certainty. A click identifier that is not in Google's report was not a click, so it is excluded from your figures and reported to you as fabricated. The comparison also works the other way: a click Google charged you for that never became a visit is a click you paid for that never arrived.

What we never do

It changes two things in your account, and only when you switch them on in the plugin: it can add its tracking template to the account, and it can keep an account-level IP exclusion list of the visitors you blocked — never anybody you did not block, and never an exclusion you added yourself. Beyond those two, ClickHelm does not:

What Google's permission screen says

When you connect, Google shows a screen that reads “See, edit, create and delete your Google Ads accounts and data”. That wording is Google's, not ours, and it deserves an explanation rather than a glossing over.

The Google Ads API has a single permission covering the whole account. There is no read-only version of it, because Google does not offer one. Every tool that reads your campaigns has to ask for that same wide permission — ours included. What separates one tool from another is not what it was allowed to do, but what it actually does.

That permission has no limits of its own, so ours are set by what our server will send. It builds the two changes above itself — the template can only ever be ClickHelm's, and an exclusion only an IP address — and refuses any other kind of change before it reaches Google.

What is stored

Click identifiers, campaign names and cost figures for the periods your reports cover. Nothing about your advertising is shared with other customers, sold, or used to train anything. Access tokens are held encrypted and are only used to make the daily read described above.

Disconnecting

Disconnect from your ClickHelm account at any time, or revoke access directly from your Google account, and the daily read stops immediately. Everything else in the plugin carries on working — the connection improves accuracy and is not required for protection.