Privacy Policy

Last updated: September 20, 2026

Metrifact ("Metrifact," "we," "us," or "our") provides a connector that lets you access and manage your own Google Ads, Google Analytics 4, Meta Ads, Search Console, and Shopify data through AI assistants that support the Model Context Protocol (MCP), such as Claude, ChatGPT, and Cursor.

1. Information we collect

  • Account information: your name and email address when you sign up.
  • Platform connection data: when you connect a Google Ads, GA4, Meta Ads, Search Console, or Shopify account, we store an OAuth access token, the connected account's ID and display name, and the scopes you granted. We never store your Google, Meta, or Shopify password. Tokens are encrypted at rest.
  • Activity logs: which tool was called, when, and whether it succeeded — used for your own visibility and for security monitoring. Retained for a limited period and deleted automatically after 90 days.
  • Billing information: if you subscribe, checkout and card entry happen on our payment processor's hosted page (Dodo Payments). We send it your email address and receive back a customer ID, your plan and subscription status, and your renewal date. Your card details are entered with the processor and are not received or stored by us.
  • Product usage and error data: events such as signing up, connecting or removing a platform, and changing plan, tied to your account ID, plus technical error reports. Some events that happen before you sign in, such as a rate limit or a failed sign-in, are tied to your IP address instead.
  • Security logs: records of security-relevant events, such as a failed sign-in, a rate limit, a two-factor change, or an admin action, with the related account ID or IP address. We keep them to monitor for abuse and to investigate incidents.
  • Emails we send you: service emails about your account and subscription, for example a welcome message, a payment problem, a connection that needs reconnecting, a plan change, a renewal reminder, or a security change such as a new API key or a password change.
  • Website visits: when you visit metrifact.com, Google Tag Manager measures how the site is used and may set cookies in your browser. You can block or delete cookies in your browser settings.

2. How we use platform data

Data retrieved from a connected platform — Google Ads, GA4, Meta Ads, Search Console, or Shopify — is used only to answer the specific request you make through your AI assistant, at the time you make it. It is retrieved live for each request and is not copied into a separate database of its own. We do not sell this data, share it with third parties other than the service providers described in Section 7 acting on our behalf, or use it to train any AI/ML model. Section 8 adds the commitments that apply specifically to Google user data.

3. Write access

On Google Ads and Meta Ads, Metrifact can make changes to a connected account, such as creating or updating campaigns, budgets, or settings, but only after you explicitly approve the specific change in your conversation with your AI assistant. Nothing is changed silently or automatically. GA4, Search Console, and Shopify are read-only.

4. Data retention and deletion

You can disconnect any platform account at any time, which immediately revokes our access. You can delete your account entirely by contacting us at privacy@metrifact.com. When we delete an account, we delete its connections, API keys, and account information. We may keep limited billing records where the law requires it, and our payment processor keeps its own records under its own policies.

5. Your rights

Depending on where you live, you may have some or all of the following rights over your personal data. To exercise any of them, contact privacy@metrifact.com — we aim to acknowledge requests within 2 business days and resolve them within 30 days.

  • Access — request a copy of the personal data we hold about you (primarily your account information and platform-connection metadata; see Section 2 for why platform data itself isn't retained separately).
  • Correction — ask us to correct inaccurate account information.
  • Deletion — request deletion of your account and its associated data, as described in Section 4.
  • Portability — request your account and connection data in a portable format.
  • Restriction and objection — ask us to limit or stop a particular use of your data; disconnecting a platform account has the same practical effect for that platform's data.
  • Withdraw consent — disconnect any connected platform account at any time, with immediate effect.
  • Lodge a complaint — if you're in the EEA, UK, or another jurisdiction with a data protection authority, you may file a complaint with your local supervisory authority in addition to contacting us directly.

We do not sell your personal information, and have not done so in the preceding 12 months.

6. Security

OAuth tokens are encrypted at rest. We support two-factor authentication on your account. All traffic is encrypted in transit (HTTPS). We do not store your platform passwords under any circumstance.

7. Service providers

We use the following providers to run Metrifact. Each processes only what its role needs, on our behalf. We do not sell your personal information to any of them or to anyone else.

  • Google Cloud: hosts the Service. Our servers run in Google Cloud's Mumbai, India region.
  • Supabase: our database and sign-in system. It holds your account information, your encrypted platform connection tokens, connection metadata, subscription status, and our logs.
  • Cloudflare: network, security, and hosting for our website and app. Traffic to and from them passes through Cloudflare.
  • Dodo Payments: subscription billing and card processing, through its hosted checkout and billing portal. It receives your email address and the payment details you enter with it.
  • Resend: sends our service emails. It receives your email address and the content of each email.
  • PostHog: product analytics. It receives usage events tied to your account ID, and for some events before you sign in, your IP address.
  • Sentry: error monitoring. It receives technical error reports, and we configure it not to send personal data by default.
  • Google Tag Manager: measures traffic on our marketing website, as described in Section 1.

8. Google user data

Metrifact's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

When you connect Google Ads, GA4, or Search Console, you give Metrifact read access to GA4 and Search Console, and access to Google Ads that lets us read data and apply the changes you approve. We use that Google user data only to provide and improve the features you use directly, such as answering your questions in your AI assistant. We do not use it for advertising, we do not sell it, and we do not use it to develop, improve, or train any AI or machine learning model. We do not allow people to read it except with your permission, where needed for security (for example to investigate abuse), to comply with the law, or in aggregated and anonymized form. You can revoke access at any time by disconnecting the account in Metrifact or from your Google Account's third-party access settings.

9. Where data is processed

Our servers run in Mumbai, India, and our service providers may process data in other countries. Where the law requires a transfer mechanism, we rely on our providers' own mechanisms, as described in our Data Processing Agreement.

10. Changes to this policy

When this policy changes, we update the date at the top of this page and, for material changes, notify account holders.

11. Contact

Questions about this policy: privacy@metrifact.com