Policies

Privacy

Identity, Google data access, and AI-client permissions are separate.

Pre-launch policy draft. Public launch requires the operator to approve these policies, publish their legal identity and support contact, and confirm retention and backup schedules.

What the service stores

Google provides sign-in. When you sign in we receive and store your Google account subject identifier, your email address and whether Google has verified it, and your display name. Your identity comes only from the openid, email, and profile permissions; signing in by itself grants no access to Analytics or Search Console data. Sign-in sessions are kept in our database as a keyed hash of a random token stored in an HttpOnly cookie; a session ends after 7 days of inactivity, 30 days at most, or when you sign out.

The application also stores workspace and project settings, source identifiers, consent and grant records, Pro requests, security audit events, and transactional notification delivery records. Once sending is approved, the outbox stores recipient/sender addresses and controlled message content for reliable delivery retries. Google sign-in alone does not authorize analytics access.

Read-only Google data

When Google data authorization is enabled, the Google sign-in screen also asks for read-only access to Google Analytics and Search Console. You can untick those permissions and still sign in, then connect them later from onboarding or Connections. Data access granted while signing in is used only if your workspace has no active Google connection; it never replaces or widens an existing one. Access is always read-only: the service never creates, changes or deletes anything in your Google accounts. Provider refresh tokens are encrypted before storage. Reports are retrieved to answer your requests; they are not presented as live data when a source is unavailable.

Teams

A workspace owner can invite people by email as admins or viewers. An invite stores the invited email address and a hash of its single-use link, and expires after 7 days. Members sign in with their own Google account and read the owner's analytics through the owner's read-only Google connection; their own Google data is never requested for the shared workspace. Members see each other's names, email addresses and last activity. Removing a member, or a member leaving, ends their access and revokes the AI clients they connected to that workspace.

AI clients and other providers

Each AI client requires a separate project-scoped grant. Data returned to an authorized client is then subject to that client provider’s policies. Google processes sign-in and data-access requests. Resend is the selected transactional email provider, but delivery is not yet activated or verified. Once approved, Resend processes account and Pro-review messages and recipient addresses, not analytics report payloads.

Revocation and deletion

Use Connections to revoke available connections and client grants. An account deletion request ends all sign-in sessions, disables workspace access, clears stored Google refresh tokens, and revokes client grants. It does not currently promise immediate deletion of all audit records or backups. The disabled account record, including your Google subject identifier and email address, is retained so the deletion notice can be sent and the account cannot be silently re-created; it is not promised to be erased immediately. Google third-party permissions can also be revoked in your Google account. Data already received by an AI client is not recalled by revocation.

Logs and retention

Request logs record generated correlation identifiers, methods, status codes, and timing. They exclude request URLs, query strings, credentials, cookies, and analytics request and response bodies. Audit records can contain internal record identifiers. Retention periods, backup expiry, deletion handling, and a support contact remain launch approval gates.

Your controls

See Account for your account controls and Docs for permission boundaries and troubleshooting.