Conalytic icon logoConalytic
Terms of ServiceTermsSign in

On this page

Last updated 2026-07-16

Privacy Policy

Conalytic — transparency & trust

Conalytic operates Conalytic, a conversational analytics product that helps you connect authorized marketing and advertising accounts (such as Google Analytics 4, Google Search Console, Google Ads, and Meta Ads, where we support them) and interact with your data through AI-assisted chat, subject to the features available in your plan. We are based in Pune, Maharashtra, India. This Privacy Policy explains how we (“we”, “us”, “our”) collect, use, disclose, store, and protect personal data when you use our website, create or use an account, connect third-party platforms, or otherwise use the Service. It supports transparency under the EU and UK GDPR, India’s Digital Personal Data Protection Act, 2023 (where applicable), other applicable privacy laws, and the expectations of partners such as Google, Meta, and LinkedIn when you grant OAuth access.

1. Data controller and contact

The controller of personal data described in this policy is the entity identified below, unless we notify you that another entity is controller for a specific offering (for example, your employer under an enterprise agreement).

Conalytic

Conalytic Pune, Maharashtra 411006 India

Email: [email protected]

Representatives and processors

Where we act as a processor for a business customer (for example, processing end-user data solely on their documented instructions), that customer is typically the controller for that processing; our customer agreement and data processing terms govern those relationships. This policy still applies to personal data for which we are controller (such as account data on our systems and operational logs), unless a separate notice applies.

If we appoint an EU or UK representative or a data protection officer where legally required, we will publish their contact details here or in your contract documentation.

2. Scope and relationship to other notices

This policy applies to:

  • Visitors to our marketing site and authenticated users of the Service;
  • Individuals whose personal data we receive when they are invited or provisioned as users by an organization;
  • Personal data we process to provide OAuth-based integrations, billing, customer support, security, and product analytics.

Third-party sites, ad platforms, or social networks that we link to have their own policies. When you connect Google, Meta, LinkedIn, or other products, their terms and privacy notices also apply to data held on their systems.

3. Categories of personal data

We adhere to data minimization: we collect and process data that is adequate, relevant, and limited to what is necessary for the purposes in Section 4. Depending on your use of the Service, categories may include:

3.1 Account, identity, and profile

  • Name, email address, internal user identifiers, authentication data, and profile fields you provide (such as display name or avatar image).
  • Role, organization affiliation, subscription tier, and entitlement flags maintained for access control and billing.

3.2 Service usage, content, and inferences

  • Chat messages, prompts, refinements, attachments, and metadata (e.g. selected AI model, chat and message identifiers, timestamps).
  • Usage metrics such as token or cost estimates, feature usage, and in-product events used for billing, quotas, reliability, and product improvement.

3.3 Technical, device, and security data

  • IP address, approximate location derived from IP, device and browser type, operating system, referrer, session identifiers, and diagnostic logs.
  • Security signals such as failed logins, rate-limit events, and fraud-prevention telemetry.

3.4 OAuth, integrations, and marketing-platform data

  • OAuth tokens, refresh tokens where issued, granted scopes, connected account identifiers, and resource identifiers you select (e.g. GA4 properties, Search Console sites, ad account IDs).
  • Data retrieved from authorized third-party APIs to fulfill your queries (e.g. aggregated metrics, campaign metadata). This may include identifiers of individuals only where those platforms return such fields in the datasets you request — we process such data solely to provide the Service and as described here.

3.5 Billing and payments

  • Billing contact details, plan, invoices or receipt references, payment status, and payment-provider transaction IDs.
  • We do not store full payment card numbers on our infrastructure; card data is handled by certified payment processors (e.g. PayPal) under their terms.

3.6 Enterprise “bring your own key” (BYOK)

If enabled for your organization, API keys for AI providers may be stored in encrypted form so the Service can route inference requests. We do not use those keys for unrelated purposes.

3.7 Special categories and sensitive data

We do not intentionally collect special categories of data under GDPR Article 9 (such as health, biometric data for identification, or political opinions). You should not include such information in prompts, uploads, or connection scopes unless you have a clear legal basis and our prior agreement where required.

3.8 How we obtain data

  1. Directly from you when you register, connect integrations, use chat, upload files, correspond with us, or manage billing.
  2. Automatically through your device and our servers when you use the Service.
  3. From third parties such as authentication providers, payment processors, and marketing platforms you authorize via OAuth.
  4. From your employer or reseller when they provision accounts or share contact details for administration.

4. Purposes and legal bases (GDPR)

Where GDPR applies, we rely on one or more of the following legal bases under Article 6(1):

  • Contract (Art. 6(1)(b)). Providing the Service you request: account management, chat and analytics features, OAuth-based data retrieval, billing for paid plans, and essential service communications.
  • Legitimate interests (Art. 6(1)(f)). Securing the Service, preventing abuse, debugging, improving reliability and performance, internal reporting, and limited product analytics, balanced against your rights. You may object where applicable (Art. 21).
  • Legal obligation (Art. 6(1)(c)). Tax, accounting, regulatory compliance, and responding to lawful requests from authorities.
  • Consent (Art. 6(1)(a)). Where required for non-essential cookies, certain marketing, or specific optional features; you may withdraw consent at any time without affecting prior lawful processing.

Retention drivers

Purposes drive how long we keep data (see Section 10). We do not use personal data for automated decision-making that produces legal or similarly significant effects solely by automated means without human review. Billing and fraud checks may involve rules-based systems with human oversight where appropriate.

5. Artificial intelligence, models, and prompts

The Service may send your prompts, selected context (including retrieved marketing data and uploaded reference files), and system instructions to third-party model providers (such as OpenAI, Anthropic, or Google) to generate responses. Those providers act as subprocessors when we host keys, or may process data as independent controllers under their own policies when your organization supplies keys directly.

  • Outputs may be incorrect, incomplete, or outdated. They are not a substitute for professional advice or for verifying metrics in source systems.
  • Unless we expressly notify you and obtain consent where required, we do not use your content to train public foundation models for our own purposes.
  • We may log metadata (e.g. model, token counts, error codes) for reliability, billing, and security.

Human review

For high-risk decisions affecting individuals (for example, employment or credit), you must not rely solely on model outputs without appropriate human oversight and lawful grounds.

6. Cookies and similar technologies

We use cookies, local storage, and similar technologies for:

  • Strictly necessary. Session continuity, load balancing, security, and CSRF protection.
  • Functional. Preferences where you opt in or where essential to a feature you activate.
  • Analytics or performance. E.g. Vercel Analytics / Speed Insights or comparable tools if enabled, to understand aggregate performance.

Where non-essential cookies require consent under ePrivacy or local law, we will obtain it via a suitable mechanism before setting those cookies. You can control cookies through your browser; blocking strictly necessary cookies may break sign-in or core features. See also our Cookies Policy.

7. Recipients, subprocessors, and disclosures

We disclose personal data to:

  • Infrastructure and authentication. E.g. Google Firebase / Google Cloud (depending on configuration) for hosting, database, identity, and file storage.
  • Payments. PayPal (or other processors you enable).
  • AI inference. OpenAI, Anthropic, Google, or other providers corresponding to the models you use.
  • Edge and observability. E.g. Vercel for hosting, analytics, and logs.
  • Professional advisers. Lawyers, accountants, or auditors under confidentiality obligations.
  • Authorities. When required by law, court order, or lawful governmental request, or to protect rights, safety, and security.

Google user data. For information received from Google APIs (including how we access, use, store, share, transfer, or disclose that data, and the named parties involved), see Section 16A — Google user data: access, use, storage, and sharing.

We enter into data processing agreements or equivalent contractual terms with subprocessors where GDPR requires. A summary list of categories of subprocessors is available on request at [email protected]. We will notify business customers of material subprocessor changes where our agreements require.

8. Business customers and processor role

If your organization subscribes to Conalytic and we process personal data about your end users only on your documented instructions, we are a processor for that processing. Your organization is typically the controller. The applicable order form, data processing agreement (DPA), and security exhibit govern that relationship and prevail over conflicting terms in this policy to the extent permitted by law.

We assist controllers, as required by Article 28 GDPR, by implementing appropriate technical and organizational measures and by supporting requests from individuals where contractually agreed.

9. International transfers of personal data

We and our subprocessors may process data in the EEA, the UK, the United States, India, and other regions. Where GDPR applies and personal data is transferred to countries not subject to an adequacy decision, we implement appropriate safeguards such as the EU Standard Contractual Clauses (2021), supplemented by transfer impact assessments and, where relevant, the UK Addendum or International Data Transfer Agreement.

You may request a copy of relevant transfer mechanisms by contacting [email protected].

10. Retention

We retain personal data only as long as necessary for the purposes above:

  • Account data. For the life of the account and a reasonable period thereafter for backups, disputes, and legal claims unless a shorter period is required by law.
  • Chat and message content. According to product settings, your deletion actions, and backup cycles; some residual copies may persist for a limited time in encrypted backups.
  • OAuth tokens. Until you disconnect an integration, revoke access at the provider, delete your account, or we detect invalid tokens.
  • Billing records. As required by tax, accounting, and payment network rules (often several years).
  • Security logs. Typically a rolling window unless extended for incident investigation.

When retention ends, we delete or irreversibly anonymize data where feasible.

11. Security and personal data breaches

We implement technical and organizational measures appropriate to the risk, including encryption in transit, access controls, least-privilege administrative access, logging and monitoring, secure development practices, and vendor due diligence. No system is perfectly secure.

Personal data breaches

In the event of a personal data breach likely to result in risk to individuals, we will comply with applicable notification obligations to supervisory authorities and, where required, to affected data subjects, without undue delay, in line with GDPR Articles 33–34, the Digital Personal Data Protection Act, 2023 (where applicable), and other comparable laws.

12. Your privacy rights

Subject to applicable law, you may have the following rights regarding personal data we process as controller:

  1. Access. Obtain confirmation of processing and a copy of your personal data (GDPR Art. 15).
  2. Rectification. Correct inaccurate data (Art. 16).
  3. Erasure. Request deletion where grounds apply (Art. 17).
  4. Restriction. Limit processing in certain cases (Art. 18).
  5. Portability. Receive structured, machine-readable data you provided where processing is based on consent or contract and automated (Art. 20).
  6. Objection. Object to processing based on legitimate interests or to direct marketing (Art. 21).
  7. Withdraw consent. Where processing is consent-based (Art. 7(3)).
  8. Lodge a complaint. With your local supervisory authority (Art. 77).

To exercise rights, contact us at [email protected]. We may need to verify your identity. We typically respond within one month (or timelines required by applicable law), extendable where complexity permits under law. You may also use in-product tools (e.g. account deletion) where available.

India

Where India’s Digital Personal Data Protection Act, 2023 (DPDP Act) applies to our processing of your personal data, you may have rights such as obtaining information about processing, correction and erasure, grievance redress through Conalytic, and nomination, as described in that law and its rules. Use the contact details in Section 1 and Section 19 to reach us.

13. Marketing and service communications

We may send transactional messages (security alerts, billing receipts, policy updates where required) based on contract or legitimate interests. Marketing emails or in-product promotions, if any, are sent where permitted by law and, where required, only with your consent, with an unsubscribe option.

14. United States — state privacy rights (summary)

Residents of certain U.S. states (including California, Colorado, Virginia, and others with comprehensive privacy laws) may have rights to know, access, delete, correct, and opt out of certain processing, including “sale,” “sharing,” or targeted advertising as defined locally. We do not sell personal information for money. We may use analytics cookies or similar technologies as described in Section 6; where opt-out rights apply, we honor browser or platform signals if legally required.

California residents may use an authorized agent as permitted by the CCPA/CPRA. We will not discriminate against you for exercising privacy rights.

15. Children

The Service is not directed to children under 16 (or the age of digital consent in your jurisdiction). We do not knowingly collect personal data from children. If you believe we have, contact us at [email protected] and we will take appropriate steps to delete it.

16. Google, Meta, LinkedIn, and developer policies

When you connect third-party products, you authorize us to access only the scopes and data needed for features you use. You remain responsible for complying with each platform’s developer policies, brand guidelines, and acceptable use rules.

Google APIs

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Detailed disclosures on how we access, use, store, share, transfer, and disclose Google user data are in Section 16A below.

Meta

Meta integrations are subject to Meta’s Platform Terms, Developer Policies, and Marketing API terms. We access ad and insights data only as authorized by you and use it to power Conalytic features you request.

LinkedIn

LinkedIn integrations are subject to LinkedIn’s API Terms of Use and advertising policies. Disconnecting an integration in Conalytic or revoking access in LinkedIn stops new data pulls subject to caching and backup latency.

16A. Google user data: access, use, storage, and sharing

This section specifically discloses how Conalytic accesses, uses, stores, shares, transfers, and discloses Google user data obtained through Google APIs (including Google Analytics 4, Google Search Console, Google Ads, Google Tag Manager, Google OAuth / identity, and related Google API Services you authorize). It is intended to satisfy Google’s requirement that our Privacy Policy state with whom we share, transfer, or disclose Google user data.

What Google user data we access

  • OAuth tokens, refresh tokens (where issued), granted scopes, and connected Google account or resource identifiers you select (for example GA4 properties, Search Console sites, Google Ads customer IDs, or GTM containers).
  • Data retrieved from authorized Google APIs to fulfill your requests (for example aggregated metrics, campaign or property metadata, and related reporting fields returned by those APIs).
  • Basic Google account profile information needed for authentication when you sign in or connect with Google (such as name, email address, and profile identifiers), where applicable.

How we use Google user data

We use Google user data only to provide or improve user-facing features of Conalytic that you choose to use — including connecting your Google accounts, retrieving and displaying metrics, answering chat questions, generating summaries or visualizations, enforcing quotas and security, and troubleshooting reliability issues. We do not use Google user data for any purpose other than those disclosed in this Privacy Policy.

How we store Google user data

Google user data (including OAuth tokens and retrieved Integration Data) is stored on our production infrastructure with encryption in transit, access controls, and least-privilege administrative access. Storage locations may include systems operated by the infrastructure providers named below. OAuth tokens are retained until you disconnect the integration, revoke access in your Google Account, delete your Conalytic account, or we detect that tokens are invalid. Chat content that includes Google-derived metrics follows the retention rules in Section 10.

With whom we share, transfer, or disclose Google user data

We share, transfer, or disclose Google user data only to the following categories of recipients, and only as necessary to operate the Service you request or as required by law:

  1. Infrastructure subprocessors (on our behalf). Google Firebase / Google Cloud (hosting, database, identity, and file storage, depending on configuration) and Vercel (application hosting, edge delivery, and operational logs). These providers process Google user data solely to store and deliver Conalytic under our instructions.
  2. AI inference subprocessors (to generate responses you request). When you use AI-assisted chat or related features, selected prompts and context — which may include Google user data you asked us to retrieve (for example metrics or campaign metadata from Google APIs) — are sent to third-party model providers such as OpenAI, Anthropic, and/or Google (corresponding to the model you use). Those providers act as subprocessors when we host API keys. If your organization supplies its own keys (BYOK), the provider may process that data under its own terms as disclosed to you for that configuration. We send only what is needed to produce the Output you request.
  3. Users in your organization or workspace. Other authenticated users you invite or who share your Conalytic organization may access Google user data you authorize for shared chats, connections, or resources, subject to your role and access controls.
  4. Professional advisers. Lawyers, accountants, or auditors under confidentiality obligations, only when necessary (for example legal or compliance review).
  5. Authorities and legal process. Courts, regulators, or other competent authorities when required by applicable law, court order, or lawful governmental request, or to protect rights, safety, and security.
  6. Business transfers. In connection with a merger, acquisition, reorganization, or sale of assets, Google user data may be transferred to a successor entity, subject to this Privacy Policy and, where required by Google’s Limited Use rules, your explicit prior consent.

We do not sell Google user data. We do not share, transfer, or disclose Google user data to advertising platforms, data brokers, or information resellers. We do not use Google user data for serving ads (including retargeting, personalized, or interest-based advertising), for determining credit-worthiness or lending, or to create, train, or improve generalized machine-learning or AI models unrelated to providing Conalytic’s user-facing features for you.

Limited Use affirmation

Conalytic’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

You can revoke Conalytic’s access to your Google Account at any time in your Google Account permissions and/or by disconnecting the integration in Conalytic.

17. Your responsibilities

  • Provide accurate account information and keep credentials secure.
  • Ensure you have authority and lawful grounds to connect organizational accounts and to upload or describe personal data in prompts.
  • Comply with applicable marketing, advertising, and data-protection laws when acting on insights from the Service.
  • Promptly revoke OAuth access for departed employees or compromised accounts where your policies require.

18. Changes to this Privacy Policy

We may update this policy to reflect legal, technical, or business changes. We will post the revised version with an updated “Last updated” date and, where required, provide additional notice (e.g. email or in-product banner). Material changes affecting processing described here will be communicated in line with applicable law.

19. Contact

For privacy questions or to exercise your rights, contact Conalytic:

  • Email: [email protected]
  • Postal address: Conalytic Pune, Maharashtra 411006 India

Legal disclaimer

This Privacy Policy describes how Conalytic handles personal data in connection with Conalytic. It is not legal advice. You may wish to have qualified counsel review it if your use of the Service changes materially or if applicable law requires additional disclosures.

© 2026 Conalytic. Casting Spells of Clarity on Your Data