Paid Results Media
Privacy Policy
Last updated: 22 May 2026
This Privacy Policy explains how Results Media (ABN 54 660 443 676, "we", "us", "our") collects, uses, stores, and discloses information when you use Paid Results Media, the paid ads performance application available at paid.resultsmedia.au (the "Service").
We comply with the Australian Privacy Principles set out in the Privacy Act 1988 (Cth) and, where it applies to your use of connected Google services, with the Google API Services User Data Policy, including the Limited Use requirements.
1. Information we collect
1.1 Account information
When you create an account we collect your email address, a hashed password (we never store passwords in plain text), and a display name if you provide one. We log the IP address and user agent of sign-in requests for security and abuse prevention.
1.2 Project data you enter or upload
The Service lets you create projects, connect ad accounts, review paid media metrics, create ad copy drafts, generate image prompts, record audience ideas, and save notes. This content is stored against your account so you can return to it.
1.3 Google user data
If you choose to connect Google Ads through the in-app connector, the Service requests the following OAuth scope via Google's authorisation server:
https://www.googleapis.com/auth/adwords— access to Google Ads account data needed to retrieve reporting metrics through the Google Ads API.
This is a sensitive scope. We only request it after you press the "Connect" button inside an authenticated project, and only in order to display Google Ads metrics within the same project where you triggered the connection.
1.4 Usage analytics
We use PostHog to record product analytics events (for example which screens were viewed, which actions were taken) and limited session replays of authenticated app pages. We mask form inputs by default, strip email addresses from URLs before they are sent to PostHog, and honour the "Do Not Track" signal in supported browsers.
2. How Google user data is used
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Why we access it. To display Google Ads metrics for the ad accounts you connect, including campaign, ad group, and ad performance data inside the relevant project view.
- What we do not do. We do not sell Google user data. We do not use it for advertising, including retargeting, personalised advertising, or interest-based advertising. We do not use it to train, develop, or improve generalised or non-personalised artificial intelligence or machine learning models. We do not allow humans to read it, except (a) with your prior explicit consent for specific data, (b) where required for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) where the data is aggregated and used for internal operations in accordance with applicable privacy laws.
- No onward transfer. Google user data is not shared with third parties except the infrastructure providers listed in section 5 (acting as our processors) and Google itself.
3. Where data is stored
The Service runs on Cloudflare Workers. Account data, project data, cached ad metrics, and encrypted OAuth tokens are stored in Cloudflare D1 (a SQLite-compatible database) and Cloudflare R2 (object storage). Cloudflare may process the data on servers located anywhere in its global network. Google OAuth refresh tokens are encrypted at rest before being written to D1.
4. How long we keep your data
- Account + project data: for as long as your account exists. You can delete projects at any time inside the app. When you delete your account, the associated projects, connected account mappings, cached ad metrics, creative drafts, and saved notes are deleted within 30 days.
- Google OAuth tokens: kept while the connection is active. You can disconnect Google Ads at any time from the project's connections screen, which deletes the stored tokens and stops further API calls. You can also revoke our access from your Google Account permissions page.
- Cached Google metrics: metrics fetched from Google Ads are kept inside your project for historical reporting. They are removed when you disconnect the source or delete the project.
- Server logs: Cloudflare Workers request logs are retained by Cloudflare for a short period for operational and security purposes.
5. Third-party processors
We use the following service providers to deliver the Service. They act as our processors and are bound by their own privacy and security terms:
- Cloudflare, Inc. — Workers hosting, D1 database, R2 storage, KV, email routing, edge logs.
- Google LLC — Google Ads API reporting data and OAuth authorisation after you connect Google Ads.
- Meta Platforms, Inc. — Meta Marketing API Insights reporting data and OAuth authorisation after you connect Meta Ads.
- PostHog Inc. — product analytics and session replay for authenticated app pages, used to improve the Service.
6. Cookies and similar technologies
The Service uses first-party cookies and local storage to keep you signed in and to remember user-interface preferences. PostHog sets cookies and local storage entries to attribute analytics events to a consistent session. We do not use third-party advertising cookies.
7. Your choices and rights
- Access and correction. You can view and edit your account information from the in-app settings.
- Disconnect Google or Meta. Disconnect ad platform accounts from the project connections screen at any time. You can also revoke access from the relevant Google or Meta permissions page.
- Delete your account. Email contact@resultsmedia.au and we will delete your account and associated project data within 30 days.
- Opt out of analytics. Enable "Do Not Track" in your browser, or email us to request that we suppress your analytics capture.
- Complain. If you are not satisfied with our response to a privacy concern, you may contact the Office of the Australian Information Commissioner.
8. Security
We use TLS 1.2+ for all transport. Passwords are hashed with industry standard algorithms. OAuth refresh tokens are encrypted at rest before being written to the database. Access to production systems is restricted to authorised personnel using strong authentication. No system can be guaranteed completely secure; please notify us at contact@resultsmedia.au if you suspect unauthorised access to your account.
9. Children
The Service is not directed to children under 16 and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, please contact us so we can delete it.
10. International users
Results Media operates from Australia. By using the Service from outside Australia, you agree that your information may be transferred to and processed in Australia and in the regions where our infrastructure providers operate.
11. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page shows the most recent revision. Material changes will be highlighted inside the app or sent by email to your registered address.
12. Contact
Results Media (ABN 54 660 443 676)
Email: contact@resultsmedia.au
Victoria, Australia
