Legal
Privacy Policy
Last updated: July 26, 2026 · Effective: July 26, 2026
Omnicial ("we", "us", or "our") operates omnicial.phira.tech and the Omnicial multi-platform advertising analytics service (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Service.
By accessing or using the Service, you agree to the terms of this Privacy Policy. If you do not agree, please discontinue use.
1. Information We Collect
1.1 Information You Provide Directly
We collect information you voluntarily provide when you:
- Connect advertising platform accounts via OAuth or another supported connection method
- Contact us for support or enquiries
1.2 Advertising Platform Data
When you connect an advertising platform account (such as Google Ads, Display & Video 360, Meta Ads, TikTok Ads, X Ads, or others), we access campaign performance data on your behalf via each platform's official API. This data includes:
- Campaign names, budgets, spend, and status
- Performance metrics (impressions, clicks, conversions, ROAS, CPC, CTR)
- Ad creative thumbnails and asset metadata
- Audience, device, and geographic breakdowns
- Account and ad group identifiers
Google Ads API data. When you connect Google Ads, we request the Google Ads OAuth scope and access the following raw Google user data for the Google Ads customers you select:
- OAuth access and refresh tokens, accessible customer resource names, customer and manager account identifiers, account name, and account currency
- Campaign and ad group identifiers, names, status, and campaign type
- Ad identifiers, type, status, final and display URLs, image URLs, and responsive-search-ad headlines
- Keyword text, match type, quality score, and search terms
- Age range, gender, device, advertising network, targeted location, and geographic location-of-presence segments reported by Google Ads
- Dates and performance fields including spend, impressions, clicks, conversions, conversion value, CTR, CPC, impression share, and related metrics
From that raw data, Omnicial calculates aggregated or derived dashboard data such as totals by date, campaign, ad group, ad, keyword, search term, device, network, region, age, and gender; prior-period trends; conversion rate; CPA; ROAS; and performance summaries. These aggregates remain associated with the Google Ads account and are not necessarily anonymous. We do not create or use anonymised Google Ads datasets for independent analytics, advertising, data brokerage, or unrelated purposes.
We use raw and aggregated or derived Google Ads data only to authenticate the connection, discover the accounts you can access, fetch and display the dashboard views you request, apply your selected filters and date ranges, and—only when you request the AI Intelligence Report—generate that user-facing report. We do not sell Google user data, use it to serve advertising, or use it to train a general-purpose AI model.
Omnicial's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. These commitments apply to raw data and data aggregated, anonymised, or derived from it.
Display & Video 360 data.When you connect Display & Video 360, we request Google's Display & Video 360 API and Bid Manager reporting OAuth scopes. We store the resulting OAuth access and refresh tokens for the active session and read the active partners and advertisers available to you, including their identifiers, names, status, currency, and timezone. For the advertiser you select, we read campaign, insertion-order, and line-item configuration used to explain delivery, including names, status, goals, flight dates, currency budgets, pacing, KPIs, bid-strategy labels, frequency caps, creative counts, and warning messages. We also create one-time Bid Manager reports containing dates; campaign, insertion-order, line-item, Floodlight activity, creative, app or URL, environment, format, device, exchange, and country dimensions; and advertiser-currency media cost, impressions, clicks, post-click and post-view conversions, attributed revenue, Active View measurability and viewability, modeled reach and frequency when available, and video completion milestones.
We use Display & Video 360 data only to authenticate the connection, discover advertisers, prepare and display the dashboard for the date range you request, and generate an AI Intelligence Report when you request one. For that requested report, we send Google Gemini the selected advertiser name and currency, date range, aggregated delivery and outcome metrics, flight budget and pacing summaries, warning text, limited campaign, insertion-order, line-item, Floodlight activity, creative, and app or URL names with performance, inventory breakdowns, and video-retention metrics. We do not send OAuth tokens, partner or advertiser identifiers, or raw report files to Gemini. Omnicial does not create or edit campaigns, insertion orders, line items, creatives, or budgets in Display & Video 360.
Meta and Facebook Platform data is accessed solely to display your own advertising performance within your Omnicial dashboard. This data is:
- Used only to provide and improve the Omnicial service to you
- Not sold, shared, or transferred to any third party except as required to deliver the service
- Not used for independent analytics, advertising, or any purpose unrelated to your dashboard
- Subject to the Meta Platform Terms and Meta Developer Policies
TikTok Ads data. When you connect TikTok Ads, we store the OAuth access token for the active session and access the following data for the advertiser account you select:
- Advertiser identifier, account name, currency, timezone, and account status
- Campaign and ad identifiers and names, campaign status, ad text, landing-page URL, video identifier, and temporary video-cover URL
- Date, device platform, country, age, and gender reporting dimensions supplied by TikTok
- Spend, impressions, reach, frequency, clicks, CTR, CPC, CPM, objective-aware results, cost per result, conversion rate, and compatible purchase ROAS
- Video plays, 2-second and 6-second views, 25%, 50%, 75%, and 100% completion counts, and average play time
- Subject to the TikTok Business Products (Data) Terms
We use TikTok Ads data only to authenticate the connection, discover advertiser accounts, display and filter the dashboard, and generate an AI Intelligence Report when you request one. For that requested report, we send Google Gemini the TikTok account name and currency, date range, aggregated account metrics and trends, limited campaign names and performance, device and regional performance, and video-retention metrics. We do not send the TikTok access token, advertiser identifier, ad landing-page URLs, or audience age and gender rows to Gemini. We do not sell TikTok Ads data or use it for unrelated advertising or independent analytics.
X Ads data. When you connect X Ads, we store the OAuth 1.0a access token and token secret for the active session and access the account you select, including its identifier, name, currency, timezone, and approval status; campaign identifiers, names, and status; active campaign placements; and reporting metrics for the date range you request. Reporting metrics include spend, impressions, engagements, link clicks, likes, reposts, replies, follows, engagement and link-click rates, cost per engagement and click, and video views and completion milestones. X may revise recent reporting and billing data after it first becomes available.
We use X Ads data only to authenticate the connection, discover the advertising accounts you can access, display and filter the X dashboard, and generate an AI Intelligence Report when you request one. For that requested report, we send Google Gemini the X Ads account name and currency, requested date range, aggregated account metrics and trends, limited campaign names and performance, placement performance, and video-retention metrics. We do not send the OAuth token, token secret, advertising account identifier, or X user credentials to Gemini. We do not sell X Ads data or use it for unrelated advertising or independent analytics. Use of X is also subject to the X Terms of Service and applicable X Ads terms.
You may revoke any platform connection at any time from your account settings or directly through the respective platform's authorization management page.
1.3 Usage and Technical Data
We collect anonymised usage data to improve the Service, including:
- Pages and features visited, session duration
- Browser type, operating system, and device type
- IP address and approximate geographic location
We use Umami Analytics, a cookie-free, privacy-preserving analytics platform. No personally identifiable information is stored by our analytics system.
2. How We Use Your Information
We use collected information to:
- Authenticate your account and maintain your session
- Fetch and display advertising performance data from connected platforms
- Generate AI-powered campaign analysis and insights
- Send transactional emails (account alerts, connection status)
- Detect and prevent abuse, fraud, or unauthorised access
- Improve Service features and performance
- Comply with legal obligations
We do not sell your personal data or advertising data to third parties.
3. Legal Basis for Processing (GDPR)
Where GDPR applies, our legal bases for processing include:
- Contractual necessity — processing required to provide the Service
- Legitimate interests — security, analytics, and service improvement
- Consent — where you have explicitly connected a platform account or opted in to communications
- Legal obligation — where required by applicable law
4. Data Sharing and Disclosure
We may share your data with:
- Infrastructure providers — cloud hosting and database services that store and process data on our behalf under data processing agreements
- AI providers — where you request an AI analysis report, the data described below is sent to Google Gemini solely to generate that report
- Legal authorities — where required by law, regulation, or court order
- Business transfers — in the event of a merger, acquisition, or asset sale
We do not share your advertising platform credentials or raw account data with any third party beyond what is described above.
4.1 Transfers of Google User Data
Our cloud hosting and cache/database processors process Google OAuth tokens, Google Ads and Display & Video 360 account identifiers, and related reporting data on our behalf only as needed to operate Omnicial. When you request an AI Intelligence Report, we transfer to Google Gemini the selected account or advertiser name and currency, requested date range, aggregated account metrics and trends, and limited entity names and performance breakdowns described in Section 1.2. We do not send OAuth tokens, Google Ads customer IDs, Display & Video 360 partner or advertiser IDs, search terms, ad URLs, Google Ads audience demographics, or raw Display & Video 360 report files to Gemini for this feature.
We may disclose Google user data to legal authorities when legally required or for security purposes such as investigating abuse. Google user data will be included in a merger, acquisition, or asset sale only after obtaining the affected user's explicit prior consent. We do not otherwise transfer Google user data to advertising platforms, data brokers, information resellers, or other third parties.
5. Data Retention and Deletion
Connected-platform OAuth tokens, selected advertising account identifiers, account names, and currencies are held in an active Omnicial session for no more than 24 hours. During OAuth account selection, tokens and accessible account identifiers are held in a temporary session for no more than 10 minutes and are deleted when consumed or allowed to expire. Most dashboard advertising API responses are processed only to answer the request. Normalised Display & Video 360 dashboard results are cached for up to 30 minutes, while the metadata needed to poll an in-progress one-time report may be retained for up to two hours. Completed report queries are deleted after Omnicial downloads and normalises their results.
AI report inputs are sent to Google Gemini only when you request a report. Omnicial caches only the resulting AI report for up to 30 minutes; the cache expires automatically. When you generate a PDF, Omnicial creates it on demand from the selected report configuration and returns it directly to your browser without retaining a separate permanent copy. We do not retain a separate permanent copy of the advertising data used to build the report.
Disconnecting through Omnicial immediately deletes the active session and all stored platform OAuth tokens and account connection data in that session. Any already-generated AI report expires within 30 minutes. You can also revoke access directly through the connected platform's authorization settings, including Google Account connections. To request deletion of any remaining data, email hello@phira.tech; we will complete verified deletion requests within 30 days unless retention is required by law, and will tell you if such an exception applies.
6. Data Protection and Security
We protect connected-platform data using HTTPS/TLS encryption in transit, restricted production credentials and environment secrets, access controls that limit data access to authorised personnel and service processors with an operational need, opaque random session identifiers, and automatic expiration of temporary and active session records. Our managed infrastructure providers protect stored data using their platform security controls. OAuth tokens are used only to fulfil the user-facing requests described above, are never exposed in dashboard API responses, and expire or are deleted as described in Section 5. We do not store your Google, Meta, TikTok, or X password.
7. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction or deletion of your data
- Disconnect any advertising platform from your account at any time
- Request export of your data in a portable format
- Object to or restrict certain processing activities
- Lodge a complaint with a supervisory authority
To exercise these rights, email us at hello@phira.tech. We will respond within 30 days.
8. Cookies
Omnicial uses strictly necessary session cookies for authentication. We do not use third-party advertising cookies or tracking pixels. Our analytics (Umami) are cookie-free.
9. Children's Privacy
The Service is not directed to individuals under 16. We do not knowingly collect data from children. Contact us immediately if you believe we have done so.
10. Changes to This Policy
We may update this Privacy Policy periodically. We will revise the "Last updated" date and notify registered users of material changes via email. Continued use of the Service constitutes acceptance.