Privacy

Privacy Policy

Last updated: July 2026

This page explains what data LightLead processes, for which purposes, who may receive that data, and how the User may exercise their rights regarding personal data.

1. Who Is Responsible for Data Processing

The operator of the service and the party responsible for organizing data processing within LightLead is sole proprietor ABDURRAKHMAN ABBOEZITOVICH OZD OEV.

For privacy questions, deletion requests, and the exercise of data subject rights, please contact [email protected].

2. What Data We Process

We process only the data necessary to operate the service, provide support, maintain security, and perform our obligations to the User.

  • Google™ account data, including the email address required for authorization and service operation;
  • OAuth tokens, technical access keys, and connection data for ad platforms, CRM systems, and other sources;
  • technical logs, report settings, error records, queue data, and alert settings;
  • payment and transaction data related to service payments through WayForPay or another available payment method;
  • support requests and message history if the User voluntarily provides them;
  • AI assistant conversation history — questions the User asks the assistant and the answers returned, stored to maintain context within a session (see sections 6 and 9).

3. Purposes and Legal Grounds

LightLead processes data for authorization, integrations, report execution, synchronization, AI features, support, abuse prevention, security, contract performance, and compliance with legal obligations.

The legal grounds for processing may include contract performance, compliance with law, the Supplier’s legitimate interest in operating and securing the service, and consent where required by applicable law.

4. Google user data and Limited Use

LightLead's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

LightLead requests the following Google OAuth scopes and no others:

  • spreadsheets.currentonly — access is limited to the single spreadsheet in which the user has opened the add-on. LightLead cannot see or open any other file in the user's Google Drive.
  • userinfo.email and openid — sign-in identity, used to link the installation to a LightLead account and to enforce access control.
  • script.container.ui, script.external_request, script.scriptapp — Google Apps Script runtime permissions required for the add-on interface, for calling the LightLead API, and for scheduled report refreshes.

LightLead does not request access to Gmail, to Google Drive beyond the current spreadsheet, to Google Photos, or to Google Contacts.

LightLead does not sell Google user data, does not use it for advertising or ad targeting, does not transfer it to data brokers, and does not use it to train or improve any generalized or foundational machine learning or artificial intelligence model — whether our own or a third party's.

5. TikTok Marketing API Data Usage

LightLead uses information received via the TikTok Marketing API.

We receive marketing metrics such as spend, impressions, clicks, conversions, campaign names, and ad group details.

This data is used solely for reporting, marketing analytics, and automations within your Google Sheets™.

We do not sell TikTok data, nor do we use it for advertising targeting or transfer it to third parties outside the product’s core functionality.

The User can revoke access at any time through TikTok for Business settings or by contacting our support to request data deletion from the service logs.

6. AI-powered features and third-party processing

LightLead includes an optional AI assistant that answers questions about the advertising reports in the user's spreadsheet. This section explains exactly what that feature transmits, to whom, and under what terms.

What is transmitted

When a user asks the assistant a question, LightLead sends to the AI provider:

  • the user's question;
  • a bounded slice of the advertising-report sheet the user is asking about — no more than 20 sample rows per request, consisting of advertising metrics such as spend, impressions, clicks and leads;
  • the structural description of the report (column names, date range);
  • a short window of recent turns from the same conversation — at most the last 12 messages, truncated — so that the assistant can follow up coherently (see section 9).

No mailbox content, no file listing, no Google account credentials and no Google Photos data are transmitted, because LightLead never has access to them (see the scope list above). The assistant is only active when the user explicitly asks it a question; it does not run in the background.

Who processes it

Processor Role Data policy
OpenRouter, Inc. (openrouter.ai) API gateway. Receives the request and routes it to the inference provider below. Does not host the model. Zero Data Retention enabled on our account. All prompt-training and prompt-publishing options are disabled at the account level.
DeepInfra, Inc. (deepinfra.com) Inference provider. Executes the model. Reached only through OpenRouter. Zero retention. No prompt training.
AkashML (akash.network) Secondary inference provider, used only if the primary provider is unavailable. Reached only through OpenRouter. Zero retention. No prompt training.

The model used is DeepSeek V4, an open-weight model executed by the inference providers listed above. LightLead has no account, contract or API key with DeepSeek, and sends no data to DeepSeek's own services.

No training on your data

Data sent to these providers is used solely to generate the answer the user requested. It is not used to train, fine-tune or improve any machine learning model, and it is not retained by the providers after the response is returned. LightLead enforces this on every single request by restricting routing to a named list of zero-data-retention providers and by explicitly denying data collection; requests that cannot be served under those conditions fail rather than falling back to an unrestricted provider.

LightLead itself does not use Google user data to train or improve any machine learning or artificial intelligence model.

Not a self-hosted model

For clarity: LightLead does not operate a self-hosted or offline model. Requests are transmitted to the third-party providers named above. Compliance rests on their zero-retention and no-training terms together with the per-request restrictions described here, not on local processing.

7. Data Recipients and Cross-Border Transfers

To provide the service, data may be processed by or transferred to infrastructure, analytics, support, AI, payment, and integration providers where this is necessary for LightLead to function.

Because such providers and third-party platforms may operate in different jurisdictions, data may be transferred outside the User’s country. By using the service, the User agrees to such transfers to the extent required for product operation and contract performance.

Google user data is an exception to the general statement above. Data received from Google APIs is transferred only to the processors explicitly named in section 6, and only for the purpose described there. It is not transferred to any other AI or analytics provider, is not sold, is not used for advertising or ad targeting, and is not used to build user profiles or any generalized model. Where the general categories above conflict with this paragraph, this paragraph prevails for Google user data.

8. Payments and Security

Payments are processed through WayForPay or another available payment method. The Supplier should not receive or store the User’s full payment card details; only the data necessary for payment confirmation, accounting, support, and fulfillment of service obligations may be processed.

Access tokens and API keys are stored in protected form using encryption and other reasonable organizational and technical security measures.

9. Data Retention and Deletion

To answer questions without re-reading the spreadsheet on every request, LightLead stores a snapshot of the report sheets in its own database, on infrastructure operated by LightLead. Snapshots contain advertising metrics only — the same values the User's connected ad platforms wrote into the sheet.

When the User asks the AI assistant a question, LightLead also stores the question and the assistant's answer in order to maintain conversation context within a session. To keep a conversation coherent, a short window of recent turns from the same session — at most the last 12 messages, individually truncated and subject to an overall size limit — is included as context in subsequent requests to the inference providers named in section 6. Turns from other users, other sessions and other installations are never included.

The User can stop this at any time by sending a reset command to the assistant (/forget, /new, /reset, or an equivalent phrase such as "forget the conversation"). After that, no earlier turn is included in any future request. The reset command clears the conversation context; to have the stored records themselves erased, please send a deletion request to [email protected].

Snapshots and assistant history are deleted when the User requests deletion, and when the installation record is removed from our systems. Requests are accepted at [email protected] and are processed within the timeframe stated in section 10. Uninstalling the add-on from Google Sheets revokes LightLead's access to the spreadsheet immediately, but does not by itself erase previously stored snapshots — to have those erased, please send a deletion request.

  • OAuth tokens and connection data are stored while an integration remains active and are deleted or anonymized upon disconnection unless continued storage is needed for security or legal compliance;
  • technical logs, task queues, and system events are typically retained for up to 12 months unless a longer period is needed to investigate an incident or comply with law;
  • support request history may be retained for up to 24 months after ticket closure;
  • payment and accounting records are retained for the period required by applicable law.

10. User Rights and Deletion Requests

The User may request access to personal data, correction, deletion, restriction of processing, or withdrawal of consent where such rights are granted by applicable law.

Deletion requests and other privacy requests are accepted at [email protected]. We may request additional information to verify identity and the scope of the request. Requests are handled within the timeframe required by applicable law or, if no explicit timeframe applies, within a reasonable period.

11. Contacts and Supplier Details

The official channel for privacy requests and other legal notices is [email protected].

  • Supplier: Sole proprietor ABDURRAKHMAN ABBOEZITOVICH OZD OEV
  • Tax ID (RNOKPP / DRFO): 3560015636
  • Legal address: Ukraine, 08147, Kyiv region, Kyiv-Sviatoshyn district, Sofiivska Borshchahivka village, Soborna street, building 126/13, apartment 106
  • Actual address: Ukraine, 08147, Kyiv region, Kyiv-Sviatoshyn district, Sofiivska Borshchahivka village, Soborna street, building 126/13, apartment 106
  • Official email: [email protected]