Trust & Legal Center

Privacy Policy

Detailed statement on data collection, tenant isolation, connected provider data handling, and Google API Services Limited Use compliance.

Last Updated: 2026-08-04Analytics Brain AI
Effective Privacy Principles
This Privacy Policy governs all analytics and workspace services provided by Analytics Brain AI. We do not sell tenant data or use connected API data for unauthorized targeting.

1. Service Operator & Scope

This Privacy Policy describes the policies and practices of Analytics Brain AI ("Platform", "we", "us") regarding the collection, processing, and protection of data from website visitors, account holders, organization members, and integrated third-party platforms.

Analytics Brain AI provides multi-tenant business intelligence for commercial organizations and business entities.

2. Information You Provide

We collect information provided directly by account administrators and organization members, including:

  • Account Contact Details: Full name, email address, and account registration credentials.
  • Organization & Workspace Information: Business entity name, organization identifiers, and workspace parameters.
  • Support Communications: Inquiries, tickets, and feedback submitted to technical or security teams.
  • Integration Choices: Resource selections, selected property IDs, and preferred display settings.

3. Authentication & Technical Data

To preserve system integrity, manage secure user sessions, and enforce tenant security boundaries, our infrastructure processes:

  • Cryptographic authentication identifiers and session tokens managed via Supabase Auth.
  • Short-lived anti-CSRF state verification cookies for Google, Meta, and Shopify OAuth flows.
  • Operational server logs, sync status snapshots, and diagnostic trace records.

4. Connected Platform Data

Upon explicit OAuth authorization, Analytics Brain AI connects to external business tools and processes specified data categories:

Shopify: Store identity, orders, line items, product catalogs, inventory levels, and fulfillment locations authorized via app scopes.
Meta Ads: Authorized ad account IDs, campaign structures, ad sets, creative assets, spend amounts, and aggregated performance metrics.
Google Search Console: Accessible site properties, search query performance, page impressions, clicks, and average ranking positions.
Google Analytics 4: Account summaries, property IDs, session metrics, active user counts, conversion events, and traffic source breakdowns.
Google Ads: Accessible customer account IDs, PMax/Search campaign metrics, ad costs, impressions, and conversion actions.

5. Future Connectors Framework

Our architecture maintains a public platform roadmap for upcoming connectors including TikTok, Snapchat, Microsoft Ads, LinkedIn Ads, Amazon, WooCommerce, Stripe, and Klaviyo.

We explicitly affirm that roadmap platforms are not accessed until fully implemented, documented, and authorized via individual user consent.

6. Purposes of Data Processing

We process collected and synchronized data strictly for the following purposes:

  • Authenticating user access, validating organization membership, and managing secure user sessions.
  • Executing scheduled background syncs to fetch and normalize sales and advertising metrics.
  • Populating unified analytics dashboards, channel comparisons, and metric breakdowns.
  • Powering AI advisor modules to generate budget optimization recommendations and diagnostic alerts.
  • Complying with applicable legal obligations, audit requirements, and infrastructure security.

7. Google API User Data & Limited Use Disclosure

Google API Limited Use Compliance
Analytics Brain AI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specific Disclosures Regarding Google API Data:

  • Explicit Authorization: Google data is accessed only after the user explicitly grants OAuth 2.0 authorization for specified scopes.
  • User-Facing Functionality: Google API data is used solely to provide user-facing analytics, performance reporting, cross-channel sync, and AI advisor insights.
  • No Data Sale: Google user data is never sold, leased, or commercialized to third parties.
  • No Targeted Advertising: Google API data is never used by Analytics Brain AI for serving targeted advertisements or retargeting profiles.
  • No Unauthorized Transfers: Google user data is not transferred to external parties except to secure infrastructure providers strictly necessary for hosting.
  • Restricted Human Access: Human employees cannot read Google user data unless required for technical support requested by the user, security incident resolution, or legal compliance.

8. Meta Platform Data Handling

Meta Ads data processing strictly follows granted business permissions:

  • Campaign performance metrics are fetched to present ad performance dashboards and creative breakdowns.
  • Meta ad metrics are never sold or shared with competing ad networks.
  • Users can revoke Meta permissions at any time via in-app disconnect or Meta Business Settings.

9. Shopify Integration Data Handling

Shopify store analytics are fetched using minimal authorized app scopes (read_products, read_orders, read_inventory, read_locations):

  • Sales data is processed to calculate net revenue, order volume, and inventory velocity.
  • Store merchants can uninstall the application or disconnect integration credentials via Shopify Admin.

10. Data Sharing & Infrastructure Providers

We share data exclusively with trusted technical infrastructure providers required to operate our service:

  • Supabase: Managed database hosting, Row Level Security enforcement, and authentication services.
  • Vercel: Application deployment, serverless execution, and global CDN routing.
  • Google Gemini API (@google/genai): AI analysis for generating natural language business advisor recommendations via Google Gemini API (@google/genai).

11. Security Architecture Summary

We enforce HTTPS/TLS 1.3 encryption in transit, AES-256-GCM credential encryption at rest, and Supabase Row Level Security (RLS) for complete multi-tenant database isolation.

12. Data Retention & Erasure

Integrated platform metrics are retained while the tenant account remains active. Upon disconnection or deletion request, tokens are invalidated and operational records are purged.

13. User Data Rights & Choices

Users reserve full rights to access, inspect, export, disconnect, or request permanent deletion of their business analytics data.

14. Children's Privacy Notice

Analytics Brain AI is designed exclusively for commercial business users and is not directed to children under 18.

15. Updates & Policy Contact

We may update this policy periodically. For privacy inquiries, contact our team at: ahmedomran12622@gmail.com