Privacy Policy
Effective date: 2026-10-08. Last updated: 2026-10-10.
This policy covers the public pages, the owner's private web tool at 91sks.com/app/, and the retained Windows application. The tool supports pre-launch product research and keyword preparation for possible future Google Ads campaigns. The owner has not yet registered a Shopify store. Contact: lh56b02@gmail.com.
1. Access
The public homepage and policies can be read without signing in. The query API requires the owner's website access code and a server-side signed session. No ChatGPT sign-in is required. It does not offer public keyword queries. Live web queries require completed secure server configuration and approved Google Ads API access. The browser interface does not request a Google password or accept service account key files.
2. Information used
The tool processes entered keywords, an optional public URL for related-keyword expansion, selected country, language and historical period, the authorized Google Ads customer identifier and currency, service account credentials used by the backend, and historical metrics, aggregate device counts, related keywords and concept annotations returned by Google. The tool verifies a randomly generated website access code using its server-side SHA-256 value. It sets a Secure, HttpOnly, SameSite=Strict session cookie for up to seven days; the code itself is not saved in browser storage.
TXT and CSV files are parsed in the browser. Keyword text and query settings are submitted to the backend; the original file is not uploaded or retained. Use ordinary research terms and public URLs, without confidential personal information, login credentials, or private access tokens.
3. Processing and sharing
For a web query, the browser sends keywords, an optional URL for related-keyword expansion, and query settings over HTTPS to the hosted backend. The backend authenticates with Google and sends those query inputs, the customer identifier, and required authorization information to Google Ads API. If a public URL is supplied, Google may read that webpage to generate related keywords. Google processes requests under its Privacy Policy and applicable API terms.
This website runs on Cloudflare Workers in the owner's Cloudflare account. Cloudflare processes requests to run the application. See the Cloudflare Privacy Policy. The application does not use ChatGPT identity or connected apps to authorize keyword queries.
The operator does not sell Google data, profile visitors using keyword results, or train AI models using Google data. Use and transfer of Google API information will follow the Google API Services User Data Policy, including Limited Use where applicable.
4. Storage and retention
Once configured, the hosted service account credential stays in server-side secret configuration. It is not embedded in the public page, browser script, source repository, downloaded results, or knowledge-base notes. Google access tokens are used only by the backend.
Single historical and related-keyword queries are held in the current page. When the owner starts a research task, its input clues, public source references, fixed settings, classification rules, returned keyword metrics, query dates, page progress and errors are saved in the owner's Cloudflare D1 database. Records remain until the owner deletes the task. The same website authentication protects creation, reading, continuation and deletion. Only a preference for the last opened task ID is stored in the browser; the database is the authoritative record. Research pagination checkpoints remain server-side. Image files are not uploaded; image-based research starts with keywords identified by the owner or an authorized assistant.
The owner retains a local migration backup of saved research tasks and their page results. Backup copies remain under the owner's control until manually deleted. Deleting an online task does not automatically delete existing local backups. During migration, the original database may also remain with the previous hosting service until the owner removes it.
The retained Windows version encrypts configuration with Windows DPAPI for the current Windows user and keeps results in running memory. Original keys, input files, and exports remain under the owner's control.
The operator does not add logging of keyword lists, credentials, or complete Google response bodies. Google and the hosting provider may retain normal account, request, operational, and security information under their own policies and retention periods.
5. Website delivery and sign-in
The operator adds no analytics or advertising scripts. The hosting provider may process IP addresses, URLs, browser details, and access times for delivery and security. A necessary first-party session cookie keeps the owner's website login. Signing out clears the current browser's cookie. Rotating the server session signing key invalidates all issued sessions. The operator adds no advertising cookies. Anonymous visitors cannot query the API; the backend verifies the website session and same-site submission.
6. Control and revocation
The owner can delete saved research tasks from the private tool, sign out, delete local files and exports, remove the hosting secret and apply the updated hosting configuration, revoke the service account's Google Ads access, or disable/delete its key in Google Cloud. Deleting a local key copy does not revoke a Cloud key.
For privacy questions contact lh56b02@gmail.com. Do not email passwords, private keys, or tokens. Material changes to functionality, hosting, authorization, and data handling will be reflected here before the changed flow is used.