This page explains what data LightLead processes, for which purposes, who may receive that data, and how the User may exercise their rights regarding personal data.
The operator of the service and the party responsible for organizing data processing within LightLead is sole proprietor ABDURRAKHMAN ABBOEZITOVICH OZD OEV.
For privacy questions, deletion requests, and the exercise of data subject rights, please contact [email protected].
We process only the data necessary to operate the service, provide support, maintain security, and perform our obligations to the User.
LightLead processes data for authorization, integrations, report execution, synchronization, AI features, support, abuse prevention, security, contract performance, and compliance with legal obligations.
The legal grounds for processing may include contract performance, compliance with law, the Supplier’s legitimate interest in operating and securing the service, and consent where required by applicable law.
LightLead's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
LightLead requests the following Google OAuth scopes and no others:
spreadsheets.currentonly — access is limited to the single spreadsheet in which the user has opened the add-on. LightLead cannot see or open any other file in the user's Google Drive.userinfo.email and openid — sign-in identity, used to link the installation to a LightLead account and to enforce access control.script.container.ui, script.external_request, script.scriptapp — Google Apps Script runtime permissions required for the add-on interface, for calling the LightLead API, and for scheduled report refreshes.LightLead does not request access to Gmail, to Google Drive beyond the current spreadsheet, to Google Photos, or to Google Contacts.
LightLead does not sell Google user data, does not use it for advertising or ad targeting, does not transfer it to data brokers, and does not use it to train or improve any generalized or foundational machine learning or artificial intelligence model — whether our own or a third party's.
LightLead uses information received via the TikTok Marketing API.
We receive marketing metrics such as spend, impressions, clicks, conversions, campaign names, and ad group details.
This data is used solely for reporting, marketing analytics, and automations within your Google Sheets™.
We do not sell TikTok data, nor do we use it for advertising targeting or transfer it to third parties outside the product’s core functionality.
The User can revoke access at any time through TikTok for Business settings or by contacting our support to request data deletion from the service logs.
LightLead includes an optional AI assistant that answers questions about the advertising reports in the user's spreadsheet. This section explains exactly what that feature transmits, to whom, and under what terms.
When a user asks the assistant a question, LightLead sends to the AI provider:
No mailbox content, no file listing, no Google account credentials and no Google Photos data are transmitted, because LightLead never has access to them (see the scope list above). The assistant is only active when the user explicitly asks it a question; it does not run in the background.
| Processor | Role | Data policy |
|---|---|---|
| OpenRouter, Inc. (openrouter.ai) | API gateway. Receives the request and routes it to the inference provider below. Does not host the model. | Zero Data Retention enabled on our account. All prompt-training and prompt-publishing options are disabled at the account level. |
| DeepInfra, Inc. (deepinfra.com) | Inference provider. Executes the model. Reached only through OpenRouter. | Zero retention. No prompt training. |
| AkashML (akash.network) | Secondary inference provider, used only if the primary provider is unavailable. Reached only through OpenRouter. | Zero retention. No prompt training. |
The model used is DeepSeek V4, an open-weight model executed by the inference providers listed above. LightLead has no account, contract or API key with DeepSeek, and sends no data to DeepSeek's own services.
Data sent to these providers is used solely to generate the answer the user requested. It is not used to train, fine-tune or improve any machine learning model, and it is not retained by the providers after the response is returned. LightLead enforces this on every single request by restricting routing to a named list of zero-data-retention providers and by explicitly denying data collection; requests that cannot be served under those conditions fail rather than falling back to an unrestricted provider.
LightLead itself does not use Google user data to train or improve any machine learning or artificial intelligence model.
For clarity: LightLead does not operate a self-hosted or offline model. Requests are transmitted to the third-party providers named above. Compliance rests on their zero-retention and no-training terms together with the per-request restrictions described here, not on local processing.
To provide the service, data may be processed by or transferred to infrastructure, analytics, support, AI, payment, and integration providers where this is necessary for LightLead to function.
Because such providers and third-party platforms may operate in different jurisdictions, data may be transferred outside the User’s country. By using the service, the User agrees to such transfers to the extent required for product operation and contract performance.
Google user data is an exception to the general statement above. Data received from Google APIs is transferred only to the processors explicitly named in section 6, and only for the purpose described there. It is not transferred to any other AI or analytics provider, is not sold, is not used for advertising or ad targeting, and is not used to build user profiles or any generalized model. Where the general categories above conflict with this paragraph, this paragraph prevails for Google user data.
Payments are processed through WayForPay or another available payment method. The Supplier should not receive or store the User’s full payment card details; only the data necessary for payment confirmation, accounting, support, and fulfillment of service obligations may be processed.
Access tokens and API keys are stored in protected form using encryption and other reasonable organizational and technical security measures.
To answer questions without re-reading the spreadsheet on every request, LightLead stores a snapshot of the report sheets in its own database, on infrastructure operated by LightLead. Snapshots contain advertising metrics only — the same values the User's connected ad platforms wrote into the sheet.
When the User asks the AI assistant a question, LightLead also stores the question and the assistant's answer in order to maintain conversation context within a session. To keep a conversation coherent, a short window of recent turns from the same session — at most the last 12 messages, individually truncated and subject to an overall size limit — is included as context in subsequent requests to the inference providers named in section 6. Turns from other users, other sessions and other installations are never included.
The User can stop this at any time by sending a reset command to the assistant (/forget, /new, /reset, or an equivalent phrase such as "forget the conversation"). After that, no earlier turn is included in any future request. The reset command clears the conversation context; to have the stored records themselves erased, please send a deletion request to [email protected].
Snapshots and assistant history are deleted when the User requests deletion, and when the installation record is removed from our systems. Requests are accepted at [email protected] and are processed within the timeframe stated in section 10. Uninstalling the add-on from Google Sheets revokes LightLead's access to the spreadsheet immediately, but does not by itself erase previously stored snapshots — to have those erased, please send a deletion request.
The User may request access to personal data, correction, deletion, restriction of processing, or withdrawal of consent where such rights are granted by applicable law.
Deletion requests and other privacy requests are accepted at [email protected]. We may request additional information to verify identity and the scope of the request. Requests are handled within the timeframe required by applicable law or, if no explicit timeframe applies, within a reasonable period.
The official channel for privacy requests and other legal notices is [email protected].