Knowledge base › Security
What a tool may do in your Google Ads account
How a connection through Google works, which permissions you actually hand over, how to revoke them, and what to check before granting access.
Your ad account is an account with money running through it. Giving something or someone access is a decision, not a formality. Here is what happens technically and what to look for.
What a connection through Google is
Serious tools connect through OAuth, Google's official sign-in method. You click connect in the tool, you land on a Google screen, you sign in there and you see which permissions are being requested. Agree, and the tool receives a key for those permissions.
What matters here:
- Your password never reaches the tool. You type it at Google.
- The permissions are bounded. Read access to your advertising data is not the same as permission to make changes.
- The key is revocable. You keep the keyring.
If you are asked to enter your Google password into a screen belonging to the tool itself, stop. That is not a connection, that is handing over your account.
Revoking access, step by step
- Go to your Google account and then to Security.
- Find the section with third-party apps and services that have access to your account.
- Select the tool and remove its access.
From that moment nothing more comes in. Data already retrieved stays with the provider until the retention period expires or you request deletion. That varies per party and belongs in their privacy statement.
For an agency working through a manager account it works differently: there you revoke access through the user settings of the Google Ads account itself.
What to check before granting access
Does the tool ask only for what it needs. An analysis tool requesting write access to your entire account is asking for more than necessary.
Is it clear who is behind it. A company name, a chamber of commerce number, an address and a phone number. If you cannot call anyone when something goes wrong in an account with thousands of euros a month running through it, that is the real risk.
Is it clear what happens automatically. Can the tool make changes on its own, and if so which, and can you undo them. Vaguely worded automation is an invitation for surprises.
Is anything said about retention and processors. If a language model runs on your account data, that belongs in the privacy statement, including which provider it runs at.
How AdWarp does it
The connection runs through the official Google Ads API with a developer token approved by Google. During the free audit, access is read-only: nothing in your campaigns is changed. If you then want Warp to execute as well, you decide per type of change where the line sits. Tidy-up work that is instantly reversible it may do on its own; anything touching your budget or your reach waits for your approval.
Every change appears in the change history with who made it, you or Warp, and when. And you revoke access through your own Google account, without having to ask us anything.
What exactly is read and how long it is kept belongs in the privacy statement. That has not been legally established yet, and it says so.