Last Updated: 19 Aug 2026
This Privacy Policy explains how Waterbe.,Co.,Ltd collects, uses, and protects personal data when you use our Service.
1. Data Controller
Waterbe.,Co.,Ltd (operating the Spool platform — referred to in this policy as “Spool”, “we”, “us”, or “our”)
Registered Address: 524, Bongeunsa-ro, Gangnam-Gu, Seoul, South Korea
Email: privacy@spool.marketing
2-A. Information We Collect
We may collect:
- Account information (name, business email, company name)
- Billing details (processed securely by Paddle)
- Usage data (log data, device information, IP address)
- Communications sent to us
2-B. Information We Collect
When you choose to connect a third-party advertising account (such as
Google Ads, Meta Ads, Naver Search Ads, or Kakao Ads) to Spool, we
access certain data on your behalf to provide our analytics features.
For Google Ads specifically, we access:
- Google Ads campaign performance metrics, including impressions, clicks, cost, cost-per-click, conversions, and conversion value
- Campaign, ad group, and ad metadata (names, status, type)
- Google Ads customer (account) IDs and their hierarchy, so that you can pick which accounts to import into Spool
- The email address of the Google account you authenticate with, used solely to display the connected account in your Spool integrations page
We request the following Google OAuth scopes:
- https://www.googleapis.com/auth/adwords — read access to your Google
Ads campaign data - openid and https://www.googleapis.com/auth/userinfo.email — to identify the Google account you connected, for display in Spool
We never modify, create, pause, or delete your Google Ads campaigns. Spool’s access is read-only for the purpose of analytics and reporting.
OAuth refresh tokens received from Google are stored encrypted at rest in our database. Tokens are used only by Spool’s backend systems to fetch your campaign data on schedule and on demand from within your
Spool dashboard.
For Meta Ads (Facebook and Instagram) specifically, we access :
- Meta Ads campaign performance metrics, including impressions, clicks, cost, cost-per-click, and reach Campaign and ad set metadata (names, status, objective).
- The list of ad accounts you have access to (ad account IDs, names, currency, and time zone), so you can choose which accounts to import into Spool.
- The name of the Meta account you authenticate with, used solely to display the connected account on your Spool integrations page.
We request the following Meta permissions:
- ads_read — read-only access to your Meta Ads campaign performance data
- business_management — to list the ad accounts you can access, so you can choose which to import We never create, modify, pause, or delete your Meta Ads campaigns, ad sets, ads, budgets, or audiences.
- Spool’s access is strictly read-only for analytics and reporting.
- Meta access tokens are stored encrypted at rest and are used only by Spool’s backend to fetch your campaign data on schedule and on demand.
- Meta access tokens are stored encrypted at rest and are used only by Spool’s backend to fetch your campaign data on schedule and on demand.
- Meta does not issue a permanent refresh token; the long-lived token is securely re-extended by our systems before expiry and is deleted when you disconnect.
For YouTube specifically, we access:
- YouTube channel metadata (channel ID, title, and public statistics such as subscriber and video counts)
- YouTube Analytics reports for channels you own or manage — including views, watch time, average view duration, likes, comments, and shares
- The list of YouTube channels your Google account owns or manages, so you can select which channel to connect
- The email address of the Google account you authenticate with, used solely to display the connected account on your Spool integrations page
We request the following Google OAuth scopes:
- https://www.googleapis.com/auth/youtube.readonly — read-only access to your YouTube channel and video metadata
- https://www.googleapis.com/auth/yt-analytics.readonly — read-only access to your YouTube Analytics reports openid and
- https://www.googleapis.com/auth/userinfo.email — to identify the connected Google account for display in Spool
We never upload, modify, or delete videos, comments, playlists, or any content on your YouTube channel. Spool’s access is strictly read-only for analytics and reporting. OAuth refresh tokens received from Google are stored encrypted at rest, are used only by Spool’s backend to fetch your YouTube data on schedule and on demand, and are deleted when you disconnect.
3. Purpose of Processing
We process personal data to:
- Provide and operate the Service
- Manage subscriptions and billing
- Communicate service updates
- Ensure security and prevent fraud
- Comply with legal obligations
4. Legal Basis (GDPR)
Processing is based on:
- Performance of a contract
- Legitimate business interests
- Legal compliance
- Consent (where applicable)
5. Data Sharing
We may share data with:
- Payment processors (e.g., Paddle)
- Cloud infrastructure providers
- Legal or regulatory authorities if required by law
We do not sell personal data.
6. Data Retention
We retain personal data only as long as necessary to fulfill contractual and legal obligations.
7. Data Security
We apply technical and organizational measures to protect all personal data, and we apply them specifically to the sensitive data we access through Google APIs — including YouTube channel metadata and YouTube Analytics reports — as well as the advertising data accessed through Meta, Naver, and Kakao.
Encryption in transit: All data exchanged between your browser, our servers, and third-party APIs — including all Google and YouTube API data — is encrypted using TLS 1.2 or higher (HTTPS).
Encryption at rest: OAuth tokens, refresh tokens, and connected-account credentials are protected with application-level field encryption using Fernet (AES-128 in CBC mode with HMAC-SHA256 authentication); plaintext tokens are never written to disk or to application logs. All stored data — including the YouTube channel and analytics data and the advertising performance data we retrieve on your behalf — is held in managed PostgreSQL databases (AWS RDS) with encryption at rest enabled.
Access controls: Access to the Service requires authentication through our identity provider, and all connected-account data and sensitive Google user data is scoped to your organization. Internal access to production systems and stored data is limited to authorized personnel on a need-to-know basis.
Data minimization: We request only read-only scopes and access only the data required to provide analytics and reporting features.
Retention and deletion: Sensitive Google API data is retained only as long as necessary to provide the reporting features you use. When you disconnect an account or request deletion, we delete stored OAuth tokens immediately and remove the associated stored data as described in Sections 10 and 11.
8. Your Rights
Depending on your jurisdiction, you may have rights to:
- Access, correct, or delete personal data
- Restrict or object to processing
- Data portability
Requests may be submitted to privacy@spool.marketing.
9. International Transfers
If data is transferred outside the EEA, appropriate safeguards (such as standard contractual clauses) are applied.
10. Google API Services User Data Policy (Google API Services User Data Policy Compliance)
Spool’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, data we access from Google APIs is :
- only used to provide and improve the user-facing features described in this Privacy Policy (campaign analytics, performance dashboards, and scheduled reports);
- Never used for advertising purposes, including retargeting, personalized advertising, or interest-based advertising;
- Never sold, rented, or transferred to data brokers, information resellers, or any other third party for commercial purposes;
- Never read by any human, except: (a) where you have given us affirmative consent to access specific records, (b) where necessary for security investigations, abuse prevention, or compliance with applicable law, or (c) where data has been aggregated and anonymized so that it cannot be associated with any individual user or Google account;
- Not used to develop, improve, or train generalized or non-personalized
artificial intelligence or machine learning models.
You can revoke Spool’s access to your Google data at any time by: - Clicking “Disconnect” on the Integrations page within your Spool account, which immediately revokes the OAuth refresh token and removes our access; or
- Visiting https://myaccount.google.com/permissions and removing Spool from the list of apps with account access.
When you disconnect, we stop fetching new data from Google APIs and delete the stored OAuth tokens. Historical analytics already saved in your Spool account remain available until you delete the relevant
campaigns or close your Spool account.
11. Data Deletion
You can delete the data Spool holds from your connected advertising accounts at any time: Click “Disconnect” on the Integrations page within your Spool account. This immediately deletes the stored OAuth access tokens for that account and stops Spool from fetching any further data from it.
To request deletion of your entire Spool account and all associated data, email privacy@spool.marketing. We will process verified deletion requests within 30 days.
For Meta (Facebook and Instagram), you can also remove Spool directly from your Facebook settings at https://www.facebook.com/settings?tab=business_tools, which revokes Spool’s access to your Meta data.
For Google, you can also remove Spool at https://myaccount.google.com/permissions.
When you disconnect or request deletion, we stop fetching new data and delete the stored OAuth tokens. Historical analytics already saved in your Spool account remain available until you delete the relevant campaigns or close your Spool account.
12. Updates
We may update this Privacy Policy from time to time. Continued use of the Service constitutes acceptance of the updated policy.