Garimpeitor
Legal · Garimpeitor

Privacy Policy

How Garimpeitor, the internal keyword research tool operated by SESTEC, handles the data it accesses — including data received from Google APIs.

Effective date: 15 August 2026 · Last updated: 15 August 2026

1. Who we are

Garimpeitor ("the application", "the tool") is an internal software application built and operated by SESTEC — Soluções em Tecnologia ("SESTEC", "we", "us"), a company based in Florianópolis, Santa Catarina, Brazil, operating since 2005.

SESTEC is the data controller for the processing described in this policy. For any question about this policy, contact topafiliado@sestec.com.br.

2. Scope of this policy

Garimpeitor is an internal tool. It has no public interface, no sign-up, no user accounts, and it is not offered, sold or licensed to third parties. It is operated exclusively by authorised SESTEC personnel.

Because there is no public interface, Garimpeitor does not collect personal data from members of the public. It does not use cookies, analytics, advertising pixels, fingerprinting, or any other tracking technology. This website, which describes the tool, is a set of static pages and likewise sets no cookies and runs no analytics.

3. Data the application accesses

The application accesses only the following categories of data:

  • Google account credentials of our own operator. A single Google account belonging to SESTEC authorises the application through OAuth 2.0. The application receives and stores an OAuth refresh token and access tokens for that account. It does not request access to any other person's Google account.
  • Google Ads API data. Aggregated, non-personal keyword metrics — average monthly searches, monthly search volume series, competition, competition index, average CPC and top-of-page bid range — retrieved for keywords we submit, plus the list of Google Ads customer IDs accessible to our own account.
  • Affiliate offer catalog data. Product names, categories, commission rates and programme terms retrieved from the affiliate networks SESTEC is a member of. This is commercial product data, not personal data.
  • Publicly available search trend data. Aggregated, non-personal relative interest data used to establish whether demand for a term is rising or falling.

The application does not access, request or receive Gmail, Google Drive, Google Contacts, Calendar, Photos, location data, or any other Google user data beyond what is listed above.

4. Google API scopes and how we use them

Scope requested
https://www.googleapis.com/auth/adwords
Why we need it
This is the only scope the Google Ads API offers for reading keyword planning data. We use it solely to call two read methods: CustomerService.ListAccessibleCustomers (once at startup, to confirm the credential is valid) and KeywordPlanIdeaService.GenerateKeywordHistoricalMetrics (to retrieve historical search metrics for our candidate keywords).
What we never do with it
We never create, modify, pause, delete or otherwise manage campaigns, ad groups, ads, keywords, budgets, bids or conversions. The application contains no write path to the Google Ads API. It never accesses Google Ads accounts belonging to third parties.
Accounts involved
A single Google Ads account owned by SESTEC. No client accounts, no manager accounts belonging to others, no delegated access.

5. Limited Use disclosure for Google user data

Garimpeitor's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, we affirm that data obtained from Google APIs is:

  • used only to provide and improve the internal research function described on this site;
  • never transferred to, sold to, or shared with any third party, except as strictly required by law;
  • never used for advertising targeting of any kind;
  • never used to train, fine-tune or evaluate generalised artificial intelligence or machine learning models;
  • never read by a human, except where we have the account owner's affirmative agreement (the account owner is SESTEC itself), where it is necessary for security purposes such as investigating abuse, or where required by law.

6. Storage, retention and deletion

  • OAuth tokens are stored encrypted at rest on infrastructure controlled by SESTEC, are never written to logs, and are never transmitted anywhere other than to Google's own authentication endpoints. They are revoked and deleted when the tool is decommissioned or when an operator leaves the team.
  • Google Ads API responses are cached locally for up to 30 days, because the underlying historical metrics refresh monthly. This cache exists specifically to reduce the number of requests we send to Google. Cached entries are deleted automatically when they expire.
  • Decision records — the internal spreadsheet of verdicts and the reasons behind them — are retained for as long as they remain commercially useful for auditing our own advertising decisions, and contain no personal data.

7. Sharing and disclosure

We do not sell, rent, trade, redistribute or publish any data the application accesses. Data obtained from the Google Ads API is never displayed publicly, never included in any product or report offered to others, and never shared with affiliate networks, advertisers or any other third party.

The only circumstance in which we would disclose data is where we are legally compelled to do so by a valid order from a competent authority.

8. Security

Access to the application and to its credentials is restricted to authorised SESTEC personnel. Credentials are held in an encrypted secret store, transport to all APIs is over TLS, and access to the machine that runs the weekly job is protected by individual authentication. We review access periodically and revoke it promptly when it is no longer needed.

9. Your rights

The application does not process personal data belonging to members of the public, so in ordinary operation there is no personal data about you for us to hold. If you nevertheless believe we hold personal data relating to you, you may request access, correction, anonymisation, portability or deletion under Brazil's Lei Geral de Proteção de Dados (LGPD, Law No. 13.709/2018), and equivalent rights under the GDPR where it applies. Write to topafiliado@sestec.com.br and we will respond within the period required by the applicable law.

10. Children

Garimpeitor is an internal business tool. It is not directed at children and is not accessible to them.

11. Changes to this policy

If we change how the application handles data, we will update this page and revise the "Last updated" date above. Material changes to the scopes we request or to the purposes of processing will be reflected here before the change takes effect.

12. Contact

SESTEC — Soluções em Tecnologia
Florianópolis, Santa Catarina, Brazil
Email: topafiliado@sestec.com.br
Website: sestec.com.br

← Back to overview · Terms of Service