Privacy policy
Effective 23 September 2026
MetricDeck reads marketing data from accounts you connect, works out what changed, and shows it back to you. This page describes exactly what it reads, where that data goes, and how to get rid of it.
Who we are
MetricDeck operates metricdeck.app. For anything in this policy, including a request to delete your data, write to support@metricdeck.app.
What we collect
- Your account. The email address and password you sign up with. Passwords are handled by our authentication provider and never stored by us in readable form.
- Your Google identity. When you connect a Google account we store the name, email address and profile picture Google returns, so you can tell connected accounts apart.
- Google marketing data. For each source you attach to a project, we read and store: Search Console clicks, impressions, click-through rate, average position, and top search queries and pages; Google Analytics sessions, engaged sessions, new users, key events, revenue and traffic by channel; Google Ads campaign names, cost, impressions, clicks, conversions and conversion value.
- Site checks. For a project with a website we record its HTTP response, TLS certificate expiry, and Google Lighthouse scores for performance, accessibility, best practices and SEO.
We do not collect anything from your Google accounts beyond the read-only scopes you grant, and we never write to, change or spend from them.
How we use it
Connected data is used to calculate the metrics, charts and reports shown in your account, and nothing else. We do not sell it, we do not share it with advertisers, and we do not use it to build profiles or train our own models. No human at MetricDeck reads your connected data except where you ask us to investigate a problem, or where the law requires it.
Google user data, and the Limited Use requirements
MetricDeck's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can revoke our access at any time from your account's Connections page, or from your Google account permissions.
Who else processes it
We use a small number of service providers, each processing data only on our instructions and only to run the product:
- Hosting and database. The application and its database are hosted by Vercel and Supabase.
- AI briefs. When you generate a brief, the figures our code has already calculated — together with your project name, the names of the connected properties and your top search queries — are sent to Anthropic's API to be written up. Anthropic processes this as a service provider and does not use API inputs to train its models. Briefs are generated only when you ask for one.
- Google, for site checks. A project's website address is sent to Google's PageSpeed Insights API to measure it, and to Google's favicon service to show the site's icon.
We do not sell personal information, and we have no advertising or analytics trackers on this site.
How it is protected
The tokens that let us read your Google accounts are encrypted at rest with AES-256-GCM, are only ever decrypted on the server, and are never sent to your browser. Every record in the database is scoped to a single workspace, and the database is not reachable from the public internet API. Data is transmitted over TLS.
How long we keep it, and how to delete it
- Disconnecting a source deletes the data we synced for it, and we ask Google to revoke the token.
- Deleting a project deletes its sources and all of their data.
- To delete your account and everything in it, email support@metricdeck.app and we will do so within 30 days.
Your rights
You can ask us for a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it. Write to support@metricdeck.app. Depending on where you live you may also have the right to complain to a data protection authority.
Children
The service is for businesses and is not directed at anyone under 18.
Changes
If this policy changes in a way that affects you, we will update the effective date above and tell you in the app before the change applies to data we already hold.