Privacy Policy

Effective date: July 15, 2026  ·  SyncMetrics (syncmetrics.io)

SyncMetrics connects your marketing and analytics accounts — Meta Ads (Facebook & Instagram), Facebook Pages, TikTok Ads & organic, LinkedIn Ads, Google Ads, Google Analytics (GA4), Shopify, and Google Sheets — to AI tools (Claude via MCP), reporting tools (Looker Studio), and Google Sheets (through our Sheets connector and the SyncMetrics Google Sheets add-on), so you can analyse your data in plain language. This policy explains exactly what data we access, how we use and protect it, and your rights.

1. Information We Collect

Account Information

When you create an account we collect your email address and a hashed password. We never store your password in plain text.

Ad Platform Tokens All platforms

When you connect an ad account, we store the OAuth access token issued by that platform. All tokens are encrypted at rest using Fernet authenticated encryption (AES-128-CBC with HMAC-SHA256). We never store your platform password.

Ad Performance Data All platforms

We fetch campaign performance data (spend, impressions, clicks, CTR, CPC, CPM, ROAS, etc.) on your behalf when you request it. We do not permanently store this data. It is fetched live from the platform API and returned directly to you or your connected tool (Claude, Data Studio). Nothing is cached or retained after the response is delivered.

Usage & Technical Logs

Standard server access logs (IP address, endpoint called, HTTP status, timestamp) are retained for up to 30 days for security and debugging. These are not shared with third parties.

2. Permissions We Request

Meta Ads Meta

We request only the minimum permissions needed. We do not request permission to create, edit, or delete ads, or to post on your behalf.

TikTok Ads TikTok

We request read-only access. We do not create, edit, or delete campaigns or post on your behalf.

LinkedIn Ads LinkedIn

We request read-only reporting scopes only. We do not create, edit, or delete ads or post on your behalf.

Google Ads Google

Reporting is the default. Any change to your account is opt-in and preview-first: SyncMetrics shows you the exact change and asks for your confirmation before it runs, and newly created campaigns are always created paused for your review. We never post publicly or act without your explicit request.

Google Analytics (GA4) Google

Read-only. We do not change your Analytics configuration. We access only the aggregated report metrics and dimensions returned by Google's Analytics Data API — not individual visitor identities.

Google Sheets Google

We access only the spreadsheets you explicitly connect to SyncMetrics. Writes are opt-in and happen only when you ask SyncMetrics to export or update a sheet. We do not browse or access other files in your Google Drive.

SyncMetrics Google Sheets Add-on Google

The SyncMetrics Google Sheets add-on is an installed Google Workspace add-on that runs inside your own Google account. When you install it and click "Connect SyncMetrics," it requests the following Google permissions and uses each one only for the feature described:

Your report definitions and refresh schedules are stored in the add-on's private storage inside your own Google account (Apps Script Properties) — not on SyncMetrics servers. Marketing data fetched for a report is written into your spreadsheet and is not retained by SyncMetrics after it is delivered. The add-on requires a SyncMetrics account; the OAuth token that authorises it to call the SyncMetrics API is stored, encrypted, only within your own Google account's add-on storage.

Google API Services disclosure (Limited Use): SyncMetrics's use and transfer of information received from Google APIs — including Google Ads, Google Analytics, Google Sheets, your Google Account email address, and data accessed by the SyncMetrics Google Sheets add-on — to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data — whether raw or in any aggregated or anonymized form — solely to provide and improve the user-facing SyncMetrics features you request. We do not sell it; we do not transfer it to data brokers, advertisers, or other third parties except the sub-processors listed in Section 4 that are strictly necessary to deliver the service; and we do not use it for advertising, credit, or any secondary purpose. We do not use Google user data to develop, improve, or train generalized AI/ML models. Where you ask SyncMetrics to answer a question using an AI assistant (Claude), only the data needed for that specific request is sent to generate your response, and — per Anthropic's API terms — it is not used to train their models.

3. How We Use Your Data

We do not: sell your data, use your ad data for advertising or profiling, share it with other users, or use it to train AI models.

4. Data Sharing

We share data only with the following sub-processors, solely to deliver the service:

We do not share your data with any other third parties. We do not sell data. We do not disclose data unless required by law.

5. Data Retention

6. Data Deletion

You can delete your data at any time:

7. Security

8. Cookies

We use only essential session cookies required for authentication. We do not use advertising cookies, tracking pixels, or third-party analytics cookies.

9. Children's Privacy

SyncMetrics is not directed at children under 16. We do not knowingly collect personal data from children.

10. Your Rights

You have the right to:

To exercise these rights, email support@syncmetrics.io.

11. Changes to This Policy

We may update this policy. We will notify you by updating the "Effective date" above and, for material changes, by email. Continued use of the service after changes constitutes acceptance.

12. Contact

Questions or concerns about this policy:
📧 support@syncmetrics.io
🌐 syncmetrics.io