AdAlert Privacy Policy
日本語AdAlert (the "Service") is an ad delivery monitoring service operated by KIYONO Inc. ("we"). It continuously monitors the delivery status of ad accounts managed by advertising agencies, detects anomalies in delivery, and notifies the responsible staff.
The Service retrieves data through the APIs of advertising platforms only for the ad accounts that a user has explicitly authorized. What we retrieve is performance and configuration data; we do not collect information that identifies individual viewers of the ads.
This policy covers matters specific to the Service. Our handling of personal information as a company is governed by the KIYONO Inc. Privacy Policy.
1. Operator
- Operator:
- KIYONO Inc.
- Address:
- Akasaka Maple Hill 7F, 6-9-17 Akasaka, Minato-ku, Tokyo 107-0052, Japan
- Website:
- https://www.kiyono-co.jp
2. Access Restrictions
The Service is invitation-only. There is no publicly available sign-up form.
- We issue accounts only to corporate customers with whom we have entered into a service agreement
- Users within each organization are added by invitation from an administrator of that organization
- Data is never visible across organizations, except where a user has explicitly configured sharing, in which case the receiving organization can view the shared data
3. Authentication and Data Access
Signing in to the Service
- We support authentication with an email address and password
- Users may optionally sign in with a Google or Microsoft account (SSO). In that case, the only information we receive is the email address, the name, and the account identifier issued by the provider to link the sign-in
Connecting advertising platforms
- When a user initiates a connection, the authorization screen of the advertising platform is presented. Authorization takes place on the platform's own screen, and we never obtain the user's credentials (such as passwords) for that platform
- The supported platforms are Google Ads, Meta Ads, LINE Yahoo Ads and TikTok Ads
- Access tokens obtained through authorization are stored encrypted
Information retrieved through the APIs
- Names, identifiers and delivery status of ad accounts, campaigns, ad groups and ads
- Performance figures such as impressions, clicks, spend and conversions
- Ad review status
- The email address of the account that granted the authorization
For Google Ads and Meta Ads, we perform read operations only. We do not create, modify, pause or delete ads on those platforms.
4. Purposes of Use
We use the information we obtain solely for the following purposes.
- Monitoring ad delivery status and detecting delivery anomalies (zero impressions during a scheduled delivery period, impressions after a scheduled stop, large fluctuations in performance, deviation in budget consumption, ad disapproval, payment errors and the like)
- Notifying users of detected anomalies by email and chat tools
- Providing, maintaining, supporting and troubleshooting the Service
- Responding to inquiries from users
We do not use the information we obtain for advertising, targeting, profiling or any other advertising purpose. We do not sell, rent, redistribute or license it.
5. Retention, Sharing and Deletion
Retention periods
- Hourly delivery performance data is retained for 90 days from collection and is then deleted automatically
- Retention periods for other data follow the periods set out in the service agreement
Subprocessors
We entrust the handling of information to the following providers in order to operate the Service.
- Google LLC (Google Cloud Platform) / servers, database and cache / Japan and the United States
- Twilio Inc. (SendGrid) / delivery of notification emails / the United States
Sharing with monitoring organizations
The Service allows a user to grant view access to its own ad accounts to a separate organization that specializes in monitoring.
- The receiving organization is granted view access only, and cannot create or modify ads
- Where this feature is used, the user is responsible for obtaining and maintaining the advertiser's consent to that disclosure, in written or otherwise documented form
Deletion
- When an ad account is disconnected, we delete the credentials (access tokens and the like) associated with that account and revoke any sharing with monitoring organizations. We also delete the campaign, ad group, ad and delivery performance data under that account (this operation requires organization administrator privileges)
- When a service agreement ends, we delete that customer's data
- To request deletion, disconnect the account from the "Ad accounts" screen in the Service, or contact us at the address in Section 9
Other than as described above, we do not provide information to third parties without the user's consent, except where required by law.
6. Compliance with the Google API Terms
AdAlert's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- Information obtained from the Google Ads API is used solely to provide the monitoring, anomaly detection and notification features of the Service
- We do not use that information for advertising purposes
- We do not sell, transfer or redistribute that information to third parties
- Humans do not read that information, except where the user gives explicit consent, where it is necessary for security purposes, where required by law, or for internal operations on aggregated or anonymized data
7. Compliance with Other Advertising Platform Terms
- Information obtained from Meta Ads is handled in accordance with the Meta Platform Terms. We do not sell, license or use that information for advertising purposes
- Information obtained from the LINE Yahoo Ads API is handled in accordance with the LINE Yahoo Ads API terms of use
- Information obtained from TikTok Ads is handled in accordance with the TikTok API for Business terms of service
8. Data Protection Measures
- Communications are encrypted (HTTPS)
- Advertising platform access tokens are stored encrypted
- Access to the database is limited to personnel who require it for their work
- Data is separated per organization, so that no organization can access another organization's data
- Data is managed on Google Cloud Platform, with the primary storage location in Japan (Tokyo region)
9. Contact
For inquiries about this policy or about how information is handled in the Service, please contact us at the address below. Inquiries about the handling of personal data, and requests for deletion of data, are also received at the same address.
- Contact form:
- https://www.kiyono-co.jp/contact-us
Last updated: August 19, 2026