Privacy policy
Last updated: 5 October 2026
What AuditRoger collects, why, who processes it for us, how cookies are used, and how to see, change or delete your data.
1. Who we are
AuditRoger is owned and operated by Roger Tech LLC, a Wyoming limited liability company based at 1309 Coffeen Avenue, STE 1200, Sheridan, Wyoming 82801 (“we”, “us”, “our”). We decide how the personal data described here is used, except for the information about other people that you add to AuditRoger, which we handle on your behalf (see section 3). Privacy questions go to hello@auditroger.com, and you can call us at +1 (307) 445-3601. Roger Tech LLC also operates “AuditRoger Social Studio”, its LinkedIn content tool, which this policy covers.
2. What we collect
- Your account. Your email address and name, when you confirmed the address and, if you sign in with a password, a one-way hash of it, never the password itself. We also keep your plan, credits and team, and any API keys you create, stored as a short prefix and a hash rather than the key. If you sign in with Google, Google shares your name, email address, whether Google has verified it and a link to your profile picture, which our sign-in provider Supabase keeps for sign-in. Signing in with Google gives AuditRoger no access to your Google Ads or Google Analytics accounts, and we never see your Google password.
- Connected ad accounts. The ID and name of each Google Ads, Google Analytics, Meta or Amazon Ads account you connect, and the access tokens the platform issues, which we encrypt before storing. With them we read campaigns, ad groups, ads, keywords, search terms, conversion settings and performance figures, and we keep the audits and reports built from that data.
- TikTok Ads, once it opens. TikTok Ads audits aren't available yet. When they are, connecting a TikTok Ads account gives us its advertiser ID and name and the access token TikTok issues, which we encrypt before storing. With it we read your campaigns, ad groups and ads with their settings and results, and your list of audiences: each audience's name, type, size and status. We receive only those details, not the people in an audience, and we never upload customer lists to TikTok. We also read the videos, images and text your ads use, with their results, to spot creatives that have stopped performing. We also read your Pixel and conversion event setup, such as which events are set up and whether TikTok is receiving them, to check that conversions are tracked. We don't receive the individual visitors those events record.
- LinkedIn Ads, once it opens. LinkedIn Ads audits aren't available yet. When they are, connecting a LinkedIn ad account gives us its ID, name and currency and the access tokens LinkedIn issues, which we encrypt before storing. With them we read your campaign groups and campaigns with their settings and results (impressions, clicks, spend, conversions, lead form opens, leads and approximate reach); the name, status and review status of each ad, with its results; your conversion setup and when each conversion and your Insight Tag last reported; and your list of audiences: each audience's name, type, status and approximate size. We receive counts, not the people behind them: not the members of an audience, and not the people who fill in your lead forms. We don't keep the text or images of your ads.
- Landing pages. The addresses of the landing pages your ads send people to, which we test for speed.
- Uploaded reports. Amazon search term reports you upload are read for the audit and not stored.
- Information about other people that you add. Leads you enter or import for client reports (a name, a phone number or email address, the date, form, channel, status, value and notes); the name and email address of a client you send a pre-flight link to, and their answers; the email addresses you schedule reports to; and the email addresses of team members you invite.
- Payments. Stripe takes payment. While your account exists we keep your Stripe customer ID and a record of what you bought. Card details stay with Stripe and never reach us.
- Usage and technical data. A record of events on your account, such as payments, refunds and credit changes, and the IP address of each request, which we use to limit how often sign-in and other actions can be tried. Our hosting providers also keep technical logs of requests.
- Analytics, only if you agree. If you choose Accept analytics, Google Analytics records the pages you visit and how you use the site. See cookies and local storage.
- LinkedIn, if you connect it. Your LinkedIn member ID and basic profile (name, headline and profile photo link), and the access tokens LinkedIn issues, which we encrypt before storing; the posts, comments and replies we publish for you, and their IDs; statistics for your own posts and for the Page you manage (impressions, members reached, reactions, comments, reshares, saves, sends, link clicks, profile views and followers gained); and, to let you answer them, the comments other members leave on those posts, with the commenter's name and member ID.
3. Why we use it, and our legal bases
- To provide AuditRoger (performing our contract with you). Running audits and client reports, Roger AI, team seats and the API; billing; and the emails the service sends, such as the link to confirm your email address, alerts, scheduled reports, invitations, password resets and billing notices.
- To keep it secure and working (our legitimate interests). Rate limits and preventing abuse, investigating errors, and understanding from our own records how the product is used so we can improve it.
- Analytics (your consent). Google Analytics runs only if you accept it, and you can withdraw that consent at any time.
- To meet legal obligations. Responding to lawful requests. Invoices and payment records are kept by Stripe, which processes our payments.
Information about other people that you add (leads, pre-flight answers, report recipients, team invitations): you decide what goes in and why, and we process it on your behalf to provide the service. You need a lawful basis to share it with us. Someone whose details a customer has added can contact that customer, or us, and we'll help.
We don't sell personal data, use your advertising data for advertising, or use it to train AI models.
4. Access to your ad accounts and LinkedIn
AuditRoger reads your advertising accounts. It never creates, changes, pauses or deletes your campaigns, ads or budgets, never combines one advertiser's data with another's, and never shows your data to anyone outside your AuditRoger account except through a share link you create. AuditRoger Social Studio, our LinkedIn tool, is different: it publishes to LinkedIn, but only content you have approved. What each permission can do, and what we use it for:
- Google Ads: Google's Ads permission (
adwords) does not come in a read-only version, so Google's consent screen says an app with it could manage your campaigns. AuditRoger uses it only to read, and contains no code that writes to the Google Ads API. - Google Analytics: read-only access (
analytics.readonly), which can't change your properties. Google asks for both Google permissions whenever you connect a Google account. - Meta:
ads_read, to read your ad accounts and their results, andbusiness_management, to see which business each ad account belongs to. Meta's business permission can also be used to manage a business; AuditRoger only reads with it. We do not request Meta's ad management permission. Meta Ads audits aren't open to customers yet. - Amazon Ads: you can upload a search term report, which is read for the audit and not stored. If you connect an Amazon Ads account directly (not yet open to all customers), you sign in with Login with Amazon and grant Amazon's advertising permission (
advertising::campaign_management). Like Google's, it has no read-only version; AuditRoger uses it only to read your advertising profiles, campaigns and reports, and never changes them. We do not ask for your Amazon profile, and we never see your Amazon password, orders or payment details. - TikTok Ads: TikTok Ads audits aren't open to customers yet. When they open, you connect a TikTok Ads account through TikTok for Business and approve AuditRoger's access. We ask only for TikTok's reporting, ads, creative, audience and measurement permissions. TikTok's ads, creative, audience and measurement permissions also allow changes; AuditRoger uses them only to read your results, the settings of your campaigns, ad groups and ads, your ad creatives, your audience list, and your Pixel and event setup, so an audit can check creatives that have stopped performing, retargeting, exclusions, lookalike audiences and conversion tracking. It never creates, changes or deletes your campaigns, ads, creatives, audiences or Pixels, and never uploads customer lists. You can disconnect it at any time in Settings → Integrations, which deletes the stored access token.
- LinkedIn Ads: LinkedIn Ads audits aren't open to customers yet. When they open, you sign in with LinkedIn and approve AuditRoger's access. We ask only for
r_ads, to read your ad accounts, campaigns, ads, conversions and audiences, andr_ads_reporting, to read their results. Both are read-only: AuditRoger can't create, change or delete anything in your LinkedIn ad accounts. This is separate from AuditRoger Social Studio, below, and uses a different LinkedIn app. As LinkedIn's terms require, we use this data only to show you, and the team members you invite, your own audits. We don't send it to an AI provider: a LinkedIn Ads audit's analysis is written from the audit itself, and Roger AI doesn't read it. We don't create public share links for LinkedIn Ads audits, and we don't sell the data or use it for anything else. You can disconnect it at any time in Settings → Integrations, which deletes the stored access tokens. - LinkedIn: AuditRoger Social Studio is Roger Tech's tool for publishing and managing LinkedIn content for the AuditRoger LinkedIn Page and for the personal LinkedIn profiles of Roger Tech team members who connect it. It is not offered to AuditRoger customers yet. It asks for
w_member_socialandw_member_social_feed, to publish posts, comments and reactions as you; we publish only content you approved, one item at a time.r_member_postAnalytics, to read the statistics of your own posts.r_organization_social,r_organization_social_feed,w_organization_social,w_organization_social_feedandrw_organization_admin, only when you connect a Page you administer, to publish on the Page, read and reply to comments on its posts, and read Page statistics.r_member_socialandr_member_social_feed, only if LinkedIn grants them, to read comments on your own posts so you can reply to them. We never send connection requests or messages, never scrape LinkedIn, never post without your approval, and never use LinkedIn data for advertising, for selling or to train AI models.
Google user data. What AuditRoger receives from Google APIs, through the Google Ads permission (adwords) and read-only Google Analytics (analytics.readonly), is used only to provide the features you use: your audits, client reports, monitoring alerts and Roger AI's answers about them. It is only read, never used to change your accounts. To write the analysis in audits and client reports, and Roger AI's answers, audit findings and report figures built from it are sent to our AI provider, Anthropic, which processes them to generate that text; Anthropic does not train its models on data sent through its API. We don't sell Google user data, use it for advertising, or use it to train AI models.
AuditRoger's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can stop our access at any time by disconnecting an account in Settings → Integrations, which deletes the stored access token, or by removing AuditRoger from your Google, Facebook or Amazon account. On Amazon, that is Your Account → Manage your data → Manage apps & services with data access. You can disconnect LinkedIn in AuditRoger at any time, or remove AuditRoger Social Studio in LinkedIn under Settings & Privacy → Data privacy → Permitted services. LinkedIn Ads access is removed the same way: remove AuditRoger from that list.
5. Who processes your data for us
These providers run parts of AuditRoger. Each receives only what its part needs.
- Supabase, for sign-in and the database that holds your account, connected accounts, audits and reports
- Railway, which hosts the service that runs audits
- Vercel, which hosts the website
- Stripe, for payments, subscriptions and invoices
- Resend, which sends AuditRoger's emails
- Anthropic (Claude), which writes the analysis in audits and client reports and answers Roger AI. It receives audit findings and report figures; the names and contact details in lead lists are not sent. To draft a reply for you to review, it also receives the text of a LinkedIn comment and the post it is on. It never receives LinkedIn Ads data. Anthropic does not train its models on data sent through its API.
- Google APIs: the Google Ads API and Google Analytics APIs, to read the accounts you connect, Google sign-in to connect them, and the PageSpeed Insights API, which receives your landing page addresses to test their speed
- Google Analytics, for analytics on this website, only if you accept it
- Amazon Ads API and Login with Amazon, for Amazon Ads accounts you connect directly
- Meta Marketing API, for Meta ad accounts you connect, once Meta Ads audits open
- TikTok Marketing API (TikTok API for Business), for TikTok Ads accounts you connect, once TikTok Ads audits open
- LinkedIn Marketing APIs (Community Management API), to publish to and read from the LinkedIn profile or Page you connect
- LinkedIn Marketing APIs (Advertising API), to read the LinkedIn ad accounts you connect, once LinkedIn Ads audits open
6. International transfers
Roger Tech LLC is based in the United States, and so are the providers above, so your data is processed in the United States and wherever those providers operate, even if you live elsewhere. Where the law requires a safeguard for transferring personal data out of your country, such as from the EU or the UK, we rely on the transfer safeguards these providers offer, such as the European Commission's Standard Contractual Clauses.
7. How long we keep it
- Your account, audits, reports and the information you add are kept for as long as your account exists, so each audit can be compared with the ones before it. They are not deleted on a schedule, except LinkedIn Ads audit reports, below.
- Disconnecting an ad account deletes its stored access token straight away. Audits you already ran stay until you ask us to delete them.
- For LinkedIn, we follow LinkedIn's data storage requirements. Profile data of other members (for example, people who comment) is cached for at most 24 hours and not stored. The content of other members' comments and posts is kept for at most 48 hours. Statistics for your posts and Page are kept for up to one year. IDs of posts, comments and members are kept while LinkedIn stays connected. Disconnecting LinkedIn deletes the stored access token at once, and we delete your LinkedIn data when you ask.
- For LinkedIn Ads, we follow LinkedIn's data storage requirements. A LinkedIn Ads audit's report, analysis and score are deleted automatically one year after the audit ran; the audit stays in your history with its date. Disconnecting a LinkedIn ad account deletes its stored access tokens at once.
- Password reset links expire an hour after they are sent.
- To have everything deleted, email hello@auditroger.com from the address on your account. We remove your account, connected accounts and their tokens, every audit and report, client reports and their lead lists, pre-flight answers, team seats and API keys, and your sign-in, and confirm by email within 30 days. We keep a one-way fingerprint of the deleted email address, with nothing else about you, as a record that the request was carried out. Deleting your account doesn't cancel a subscription, so cancel it first under Billing & credits → Manage billing. Step-by-step instructions are on our data deletion page.
- Deleting your account also deletes our own records of your payments, plan and credits. Stripe, which processes payments, is separate: Stripe keeps its own payment and invoice records, under its own privacy policy, for as long as the law requires.
- Our providers keep backups and logs for their own periods, so deleted data can remain in those copies until they expire.
8. Your rights
Under data protection laws such as the GDPR in the EU and the UK GDPR, and similar laws elsewhere, you can ask us to:
- give you a copy of the personal data we hold about you (access);
- correct anything that is wrong (correction);
- delete it (deletion);
- give it to you in a machine-readable form to take elsewhere (portability);
- stop using it where we rely on our legitimate interests, or limit how we use it (objection and restriction);
- and you can withdraw consent, such as for analytics, at any time. Withdrawing doesn't affect what happened before.
To exercise any of these, email hello@auditroger.com from the address on your account; we may need to confirm the request is yours. Deletion is explained on the data deletion page. Some you can do yourself: disconnect accounts in Settings → Integrations, export audits as PDF or PowerPoint and client reports as PDF or CSV, and change your analytics choice with Cookie settings.
If you're unhappy with how we've handled your data, you can complain to a data protection supervisory authority: in the EU, the authority in the country where you live or work; in the UK, the Information Commissioner's Office (ICO). Please tell us too, so we can try to put it right.
9. Cookies and local storage
AuditRoger uses no advertising cookies. This is what the site keeps in your browser:
- Staying signed in (necessary). When you sign in, Supabase keeps your session in your browser's local storage, and the app keeps a few entries beside it: your user ID, name, email address and plan, and choices such as the account and date range you picked. A cache of screens you've opened is kept in session storage, which the browser clears when you close the tab.
- Your cookie choice (necessary). Your answer to the cookie banner, and when you gave it, stored in local storage as
ar_consent_v1so we don't ask again. - Google Analytics (only with your consent). Until you choose Accept analytics, its script isn't loaded at all. If you accept, Google Analytics sets its cookies (
_gaand_ga_followed by an ID) and records the pages you visit. We send page addresses without their query strings, send nothing from private links (shared audits, client reports, pre-flight forms, team invitations and password resets), and turn off Google signals and ad personalisation. - Stripe. Checkout and the billing portal are pages on Stripe's own site, where Stripe's cookies and privacy policy apply.
You can change your choice at any time with Cookie settings in the footer of this site's public pages, with the button below, or, once you're signed in, in Settings → Privacy. If you withdraw consent, analytics stops, the Google Analytics cookies on this site are deleted, and it doesn't load again.
10. Security
Access tokens for your ad accounts are encrypted before they are stored, passwords and API keys are kept only as hashes, and connections to the website, the service and its database are encrypted. Only you and team members you invite can see your audits and reports; team members see lead names and contact details masked. Share links are signed, expire and can be revoked, and client report links leave out lead names and contact details.
11. Children
AuditRoger is a business tool for people aged 18 or over, as our terms of service require. We don't knowingly collect data from children. If you think a child has given us personal data, email us and we'll delete it.
12. Changes to this policy
We'll update this policy as AuditRoger or the law changes, and change the “Last updated” date above. For material changes, we'll tell account holders by email or in the app before they take effect.
13. Contact us
For privacy questions and requests, email hello@auditroger.com. Our terms of service and contact page have more about Roger Tech LLC.
Roger Tech LLC, 1309 Coffeen Avenue, STE 1200, Sheridan, Wyoming 82801.
Phone: +1 (307) 445-3601
