We never touch your login credentials

Here's exactly what access NarrateIQ requests for each platform, what we can see, and what we are permanently unable to do.

📊

Google Ads

Campaign performance data via the official Google Ads API
How we connect: NarrateIQ uses the official Google Ads API with OAuth 2.0 authorization. You authorize access through Google's own OAuth consent screen — your Google Ads password is never shared with us. We hold a read-only OAuth refresh token scoped to your account. You can revoke this token at any time from your Google account settings.

We can read

  • Campaign names, status, spend, and impressions
  • Clicks, CTR, conversions, CPA, and ROAS
  • Ad group and keyword-level performance
  • Budget pacing (spend vs. monthly budget)
  • 7-day rolling metrics for week-over-week comparison

We cannot

  • Run, pause, or modify any campaign
  • Change bids, budgets, or targeting
  • Access billing or payment information
  • Create or delete any asset in your account
  • Make any write operation of any kind
1
Campaigns: campaign name, status, channel type, budget amount, spend, impressions, clicks, conversions, CTR, average CPC, search impression share — queried via GoogleAdsService.SearchStream using GAQL.
2
Ad Groups: ad group name, status, spend, impressions, clicks, and conversions — for campaign-level drill-down in the report.
3
Keywords: keyword text, match type, impressions, clicks, cost, conversions, CTR, and average CPC — to identify top performers and underperformers.
4
Date range: The prior 7 calendar days, pulled once per week (Monday). No historical bulk exports. No creative assets, audience lists, or user-level data accessed.
📱

Meta Ads

Facebook & Instagram campaign data
How we connect: You add us as an Analyst in your Meta Business Manager. Analyst is the most restricted role Meta offers. It is read-only by design and cannot be upgraded without your explicit action.

We can

  • Read campaign spend, reach, and impressions
  • Read clicks, CTR, conversions, and ROAS
  • Read ad set and creative performance
  • View audience insights for reporting

We cannot

  • Edit, pause, or launch any campaign
  • Change budgets, bids, or audiences
  • Access your Facebook Page or Instagram account
  • View billing details or payment methods
📧

Klaviyo

Email marketing performance (optional)
How we connect: We use OAuth 2.0, the same secure standard used by "Sign in with Google." You click Connect Klaviyo, authorize in Klaviyo's own interface using read-only scopes, and we receive a token. Your Klaviyo password is never shared with us.

We can

  • Read campaign send stats (opens, clicks, revenue)
  • Read list growth and unsubscribe rates
  • Read flow performance metrics
  • Read aggregate audience metrics

We cannot

  • Send, schedule, or edit any email
  • Add, remove, or export contacts
  • Access or change your account settings
  • View individual subscriber profiles or PII
🐒

Mailchimp

Email marketing performance (optional)
How we connect: We use OAuth 2.0. You authorize via Mailchimp's own login screen, and we receive a read access token. Your Mailchimp password is never shared with us.

We can

  • Read campaign send reports (opens, clicks)
  • Read list/audience size and growth
  • Read unsubscribe and bounce statistics
  • Read e-commerce revenue per campaign

We cannot

  • Send or edit any email campaign
  • Add, remove, or export subscribers
  • Modify automations or templates
  • Access billing or account settings
How onboarding works, step by step
1
You fill out our onboarding form. We ask for basic info about your client: business name, industry, ad platforms used, and campaign goal. No credentials at this step.
2
You grant read-only access inside your own ad platforms. For Google and Meta, this takes 2 minutes. You invite us to your account. No passwords change hands.
3
If you use Klaviyo or Mailchimp, you connect via OAuth. One click in a secure link we send you. You authorize in Klaviyo or Mailchimp's own interface, and we receive a read-only token.
4
We run a test report and send it to you for approval before going live. You see exactly what your client will receive. Nothing is sent until you say it looks right.
Common questions

Can you see my clients' personal data or contact lists?

No. We only access performance metrics: aggregate numbers like open rates, click counts, and campaign spend. We do not read, download, or store individual subscriber profiles or any personally identifiable information (PII).

What happens if I want to revoke access?

For Google Ads and Meta, you remove us from your account inside their respective admin panels. It takes under 30 seconds and is entirely in your control. For Klaviyo and Mailchimp, you revoke the OAuth app from your account settings. Access is immediately terminated.

Where is my data stored?

Report data is stored on Railway (US infrastructure) and is used only to generate your weekly report. We do not sell, share, or license your data. See our Privacy Policy for full details.

Is my connection secure?

All connections use HTTPS/TLS encryption in transit. OAuth tokens and API credentials are stored encrypted at rest. We request only the minimum permissions needed to generate your report.

Do you share access with third parties?

No. Your data is accessed only by NarrateIQ's automated reporting pipeline and Claude (Anthropic's AI) to generate the written narrative. Anthropic's API does not train on your data. No other third parties receive your information.

Ready to get started?

Fill out the onboarding form and your first report runs automatically the following Monday.

Start Onboarding Have a question?