karaboga.dev

Privacy Policy

Effective 29 September 2026 · Last updated 29 September 2026

This policy explains what data is collected, how it is used, where it is stored and who it is shared with for two things run by Cihat Karaboğa (“I”, “me”), an independent software developer in Istanbul, Türkiye:

  • the website karaboga.dev, and
  • SaaS Idea Scout, a command-line market-research tool that signs in with Google to read keyword data from the Google Ads API.

Apps with their own privacy policy (for example those at mileage.karaboga.dev or pcos.karaboga.dev) are covered by that policy, not this one.

1. Who is responsible

The data controller is Cihat Karaboğa, Istanbul, Türkiye. For any privacy question or request, email cihat@karaboga.dev.

2. The karaboga.dev website

The website is a static page. It has no accounts, no forms, no advertising, no analytics and no tracking cookies.

  • Preferences on your device. Your theme (light/dark) and language (English/Turkish) choices are saved in your browser’s localStorage. They never leave your device and you can clear them in your browser settings.
  • Server logs. Like any web server, the server that hosts the site records standard request data — IP address, browser user agent, requested URL, referrer and time — to keep the service running and secure. These logs are not used to identify or profile visitors, are not shared, and are deleted on a rolling basis, normally within 30 days.
  • Fonts. Typefaces are loaded from Google Fonts, so your browser sends a request, including your IP address, to Google. See Google’s Privacy Policy.
  • Links. Links to GitHub, LinkedIn, X, the App Store or project sites take you to services with their own privacy policies. If you email me, I use your message and address only to reply.

3. SaaS Idea Scout and Google user data

SaaS Idea Scout runs entirely on your own computer. It asks you to sign in with Google so it can request keyword statistics from Google Ads Keyword Planner on your behalf. I do not operate a server for it: your Google data goes from Google’s servers straight to your computer and is never sent to me.

Data accessed

The tool requests one OAuth scope, https://www.googleapis.com/auth/adwords (Google Ads API). With it, the tool accesses only:

  • the OAuth access token and refresh token Google issues after you consent;
  • the Google Ads customer ID (and optional manager account ID) that you enter in the tool’s settings;
  • Keyword Planner results for the keywords you type in: average monthly search volume, competition level and top-of-page bid ranges, returned by the generateKeywordIdeas and generateKeywordHistoricalMetrics methods.

It does not request your name, email address, profile or contacts, and it does not read, create, change or delete campaigns, ads, budgets, billing or any other data in your Google Ads account.

How the data is used

Google user data is used for one purpose: to show you search demand and advertising cost for the keywords you ask about, as part of the market-research report the tool produces for you. It is not used for advertising, not used to build user profiles, not sold, and not used to develop, improve or train generalised AI or machine-learning models.

Storage and protection

  • The refresh token is written to ~/.saas-idea-scout/credentials-googleads.env on your computer, with owner-only file permissions (0600). The tool refuses to run if that file is readable by other users.
  • Access tokens are kept in memory only and are never written to disk, logs or reports.
  • Keyword Planner results are cached in ~/.saas-idea-scout/ for up to 30 days to avoid repeating identical requests, and are included in the reports the tool writes to your computer.
  • Sign-in uses Google’s OAuth 2.0 flow with PKCE and a local loopback redirect (127.0.0.1); all traffic to Google uses HTTPS.

Sharing

Google user data is not shared with, sold to or transferred to me or any third party. OAuth tokens and your customer ID are sent only to Google. The reports stay on your computer; what you do with them afterwards — including opening them in other software, such as an AI assistant you choose to run the tool from — is under your control and that software’s own terms.

Separately from Google data, the tool sends the keywords you enter (never your tokens or account IDs) to other public research sources to complete the report: Serper (Google search results), the Chrome UX Report, TrustMRR, Reddit, Hacker News (Algolia), Stack Exchange and Frankfurter (exchange rates). Each processes those requests under its own privacy policy.

Limited Use disclosure

SaaS Idea Scout’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Revoking access and deleting data

  • Revoke the tool’s access at any time at myaccount.google.com/permissions.
  • Delete everything the tool stored by removing the ~/.saas-idea-scout/ folder. Because I hold no copy of your data, nothing else remains to delete.

4. Your rights

Depending on where you live — including under Türkiye’s KVKK (Law No. 6698) and the EU/UK GDPR — you may have the right to access, correct, delete or restrict the processing of your personal data, to object to it, to data portability, and to complain to a data protection authority. Email cihat@karaboga.dev and I will reply within 30 days.

5. Children

The website and SaaS Idea Scout are not directed at children under 16, and I do not knowingly collect their data.

6. Changes

If this policy changes, the new version is published on this page with a new “last updated” date. If a change affects how Google user data is used, it will be made clear here before the change applies.

7. Contact

Cihat Karaboğa · Istanbul, Türkiye · cihat@karaboga.dev