Privacy Policy
Last updated: 2026-08-24
What we collect. Account details (email, business name), the business data you submit for analysis, data we retrieve from third-party accounts you explicitly connect, and usage/operational logs needed to run and secure the service.
How we use it. To provide the product, run the AI pipeline on your data, meter usage against your plan, secure the platform, and email you about your account. We do not sell your data.
Processors. We use infrastructure and AI providers (hosting, database/auth, and LLM inference) to operate the service; your data is processed by them solely to deliver it.
Connected accounts
What connecting does. You may connect third-party marketing accounts — Google (Search Console, Analytics, and in future Business Profile and Ads), Meta, LinkedIn and TikTok. Connecting is always initiated by you, is never required to use the product, and can be undone at any time.
We only read. We retrieve performance measurements — impressions, clicks, sessions, rankings and similar metrics — so the product reports what your marketing actually did instead of estimating it. We do not post, publish, edit, delete or change anything in a connected account, and we never run or modify advertising campaigns.
Where a permission looks larger than what we do. Some providers publish no read-only permission for the data we need. Google Business Profile offers only a single manage permission, and LinkedIn page analytics are available only under a permission labelled “manage organization pages.” Where that is the case, the provider's consent screen will describe more access than we use. Our commitment is unchanged: we read, and nothing else. For Google Ads you can additionally grant our connection the Read only role in your Google Ads account, which makes any change technically impossible rather than merely promised.
How credentials are stored. Access and refresh tokens are encrypted with AES-256-GCM before they are written to our database, are bound to your account so they cannot be used in another tenant's context, and are never displayed in the product, logged, or sent to any third party.
Revoking. Disconnect any provider from the Connections screen in the product; we delete the stored credential and, where the provider supports it, revoke it upstream too. You can also revoke us directly at myaccount.google.com/permissions for Google, or in the equivalent settings for other providers. Revoking stops all future retrieval immediately.
Google user data
What we access. With your consent we read Search Console performance data for sites you select and Google Analytics reporting data for properties you select, plus your Google account's basic identity (name, email address) solely to label the connection so you can see which account is connected.
Limited Use. Perpetual Marketing's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not transfer or sell Google user data to third parties for advertising, market research or credit assessment; we do not use it to serve advertisements; we do not allow humans to read it except with your explicit consent, where required for security or to comply with law, or where the data has been aggregated and anonymised; and we do not use Google user data to develop, improve or train generalised AI or machine-learning models.
Retention. Metrics we retrieve are kept while your account is active so the product can show change over time. Disconnecting a provider deletes its stored credential immediately; deleting your account deletes the retrieved data.
General
Email. We send transactional account emails (e.g. confirmation). You can contact us to manage communications.
Retention & deletion. We keep your data while your account is active. Contact us to request export or deletion.
Tenant isolation. Each business's data is isolated at the database layer; other tenants cannot access it.
Contact. hello@perpetual.marketing. See also our Terms.