Last updated 1 October 2026
Privacy Policy
Analystic (“we”, “us”) is an analytics reporting workspace. It brings GA4, Search Console and Google Ads data for an agency's clients together in one place. This policy explains what information Analystic handles, why, and the choices you have.
1. Who can use Analystic
Analystic is not an open sign-up service. Only members of organizations that we have approved can open the application. Within an organization, admins connect Google accounts and manage configuration; members view clients, reports and configuration.
2. Information Analystic stores
- Account information. Your name, email address, organization membership and role, managed by our sign-in provider Clerk.
- Google connections. For each Google account an admin connects: the Google account ID and email address, the permissions that were granted, an encrypted refresh token, the connection status, and who connected it and when.
- Organization configuration. The organization's client list (client names, website domains, the organization's own client keys and categories) and which GA4 property, Search Console site and Google Ads account belongs to which client.
- Preferences. Favorite and recently viewed clients, per user.
- Import tokens. If an admin creates one for automated client imports: its name, a short prefix and a one-way hash. The token itself is shown once and not stored.
3. Google user data
When an admin connects a Google account, Google asks for consent to the permissions below. Analystic requests no other Google permissions: it has no access to Gmail, Google Drive, Google Sheets, Calendar or Contacts.
| Permission | What Analystic uses it for |
|---|---|
openid, email, profile | Identify which Google account was connected (its account ID and email address). |
analytics.readonly | List GA4 accounts and properties and read GA4 report data. |
webmasters.readonly | List Search Console sites and read search performance data. |
adwords | List Google Ads accounts and read campaign performance data. Analystic only runs reporting queries; it never creates or changes anything in Google Ads. |
tagmanager.readonly (optional) | Read Tag Manager accounts, containers and published versions for the tracking check. |
Report data is fetched, not stored. GA4, Search Console, Google Ads and Tag Manager data is requested from Google when a user opens a report, a list of accounts or a tracking check. It is shown to signed-in members of the organization and is not written to Analystic's database. To keep the application fast, responses may be held in server memory for up to 10 minutes and are then discarded.
Tokens. Google refresh tokens are encrypted (AES-256-GCM) before they are stored and are never sent to the browser. Short-lived access tokens are kept only in server memory until they expire.
4. Limited Use of Google data
Analystic's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. In practice:
- Google data is used only to provide the reporting features you see in Analystic.
- It is not sold, not used for advertising, and not used to build profiles.
- It is not used to train artificial intelligence or machine learning models.
- It is not transferred to anyone except as needed to run Analystic (see section 6), for security, or where the law requires it.
- People do not read it, except with your permission, to investigate a security issue or abuse, or where the law requires it.
5. Website checks
When a user starts a live website check for a client, Analystic loads public pages of that client's website, and the Google tag scripts they reference, to see which Google tags are installed. Only publicly available pages are requested; nothing is submitted to the site, and the pages are not stored.
8. Retention
- Google connections are kept until an admin disconnects them in Analystic, which deletes the stored token and connection details.
- Organization configuration and preferences are kept while the organization uses Analystic, or until deletion is requested.
- Google report data is not retained beyond the short in-memory caching described in section 3.
- Our hosting provider keeps standard technical request logs for a limited period.
9. Disconnecting, revoking and deleting
- Disconnect in Analystic. An organization admin can disconnect a Google account on the Connections page. The encrypted token and connection details are deleted from Analystic immediately.
- Revoke at Google. You can remove Analystic's access to your Google account at any time in your Google Account settings. Analystic then can no longer read data with that connection.
- Request deletion or a copy. To ask for your information, or your organization's configuration, to be deleted, corrected or exported, contact your organization's Analystic admin or us (see section 11). We handle requests without undue delay.
Depending on where you live, for example in the EU under the GDPR, you may also have the right to object to or restrict processing and to complain to your data protection authority.
10. Security
Access requires a signed-in member of an approved organization, and every request is checked against that organization. Google tokens are encrypted at rest and never reach the browser. No system is perfectly secure, but we work to protect the information we hold.
11. Changes and contact
If this policy changes, we update this page and its date. For questions or requests about privacy, contact rabe.goransson@gmail.com or through your organization's Analystic admin. See also the Terms of Service.