Privacy Policy
Last updated: 7 October 2026.
This policy explains what Megametrics ("we") collects when you use the service at megametrics.app, why, who helps us process it, and what you can do about it. Questions: aslansakov@gmail.com.
What we collect
- Account. Your email address, an optional name, your interface language and how you sign in (an email link, Google, Microsoft or your organization's SSO). We keep the IP address of sign-in link requests for up to two days to stop abuse.
- Workspace and team. Workspace names, time zone, members and their roles, and the email addresses you invite.
- Connected accounts. Access tokens for the platforms you connect (for example Google Ads, Google Analytics 4, Search Console, YouTube, Google Sheets, Meta, TikTok, Microsoft Advertising, LinkedIn, Yandex Direct and Yandex Metrica), and the IDs and names of the accounts you pick. Tokens are encrypted at rest.
- Marketing data. Campaign statistics (impressions, clicks, spend, conversions), website traffic totals by channel, source and campaign, and search and video statistics that we load from those platforms at your request, plus the files, spreadsheets and database tables you import. We request totals, not data about individual website visitors.
- Your work in the service. Projects, saved queries, exports and their recipients, schedules, load and export logs, and usage counts for your plan.
- AI analyst. Your questions, the answers and the query results shown under them.
- Billing. Your plan, its status and the Stripe customer and subscription IDs. Card details go to Stripe and never reach us.
Cookies and local storage
We use three cookies, all needed for the service to work: mm_session keeps you signed in, mm_workspace remembers the workspace you chose and mm_tz passes your time zone to a new workspace. Your browser also keeps the theme, the language and the last opened project. We use no advertising or analytics cookies.
Why we use it
- To provide the service you signed up for: load your data, show reports, run exports and schedules (performance of a contract).
- To keep the service secure and stop abuse (legitimate interest).
- To bill you and keep accounting records (contract and legal obligation).
- To send emails the service needs: sign-in links, invitations, exports, load failures, trial and billing notices, renewal reminders and cancellation confirmations. We don't send marketing emails without your consent.
Who processes data for us
- Hetzner (Hetzner Online GmbH, Germany) — the server that runs the service; the database and its daily backups are stored in Falkenstein, Germany.
- Stripe — payments and subscriptions.
- Resend — email delivery.
- Anthropic — writes the AI analyst's answers, unless your workspace connects its own AI provider, which then does it instead. The provider receives your question and the results of queries on your project's data; account tokens and passwords are never sent.
When you sign in with Google or Microsoft, connect a platform or export to Google Sheets, we call that platform's API on your behalf; its own privacy policy applies to what you do on its side.
The database stays in Germany. Stripe, Resend and Anthropic are based in the USA, so the data they process for us may leave the European Economic Area; these transfers rely on the European Commission's Standard Contractual Clauses in our agreements with them.
Google user data
When you sign in with Google or connect a Google account, Megametrics asks only for the access the feature you chose needs, and uses what it receives only for features you see in the service:
- Sign-in (
openid,email,profile): your email address and name, to create your account and sign you in. We don't store your profile photo. - Google Analytics (
analytics.readonly): the list of your GA4 properties and, for the properties you pick, sessions and key events by date, channel, source, medium and campaign. - Google Ads (
adwords): the list of your ad accounts, statistics of the campaigns in the accounts you pick and, only when you press the button for it on a board, a change of a campaign's status or daily budget. - Search Console (
webmasters.readonly): queries, pages, countries and devices with clicks, impressions and positions for the sites you pick. - YouTube (
youtube.readonly,yt-analytics.readonly): your channel, its most viewed videos and their statistics. - Google Sheets (
spreadsheets.readonly,drive.file): the spreadsheet you choose to import, and the spreadsheets Megametrics creates for your exports. We can't open your other Drive files.
This data is stored in your workspace and shown only to its members, as their roles allow. We don't sell it, don't use it for advertising and don't use it to train AI models. We transfer it only to provide the features you use: to the processors listed above that run the service and, when you ask the AI analyst about your data, to the AI provider that writes the answer, which may not use it to train its models. People at Megametrics don't read your Google data unless you ask us to, it is needed for security or the law requires it.
Disconnecting a Google account in Sources deletes its tokens at once and stops new loads; data already loaded stays in your project until you delete it, the project, the workspace or your account. You can also revoke access at any time in your Google Account.
Megametrics uses YouTube API Services: by connecting YouTube you agree to the YouTube Terms of Service, and the Google Privacy Policy applies to your data on Google's side.
Megametrics' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How long we keep it
We keep your data while your account exists. When you delete a workspace or your account, access closes at once and the data is erased within 30 days. Sign-in links expire after 15 minutes. Backups are kept for up to 30 days and then deleted. Billing records are kept as long as the law requires.
Your rights
You can see and correct your profile in the service, download any query as CSV or Excel, and delete your account and data yourself under Account → Delete account. You can also ask us for a copy of your data, for corrections, for restriction or erasure, or object to processing by writing to aslansakov@gmail.com. If you are in the EU or the UK, you can complain to your data protection authority.
Security
Connections are encrypted (HTTPS), platform tokens are encrypted at rest, each workspace sees only its own data, and members get only what their role allows.
Children
Megametrics is a business tool and isn't meant for anyone under 16.
Changes
If we change this policy in a way that matters, we will email account owners at least 30 days before the change takes effect.