Effective 10 September 2026 · Last updated 8 September 2026 · Version 1.0
MetricFabric.io is a subscription service that copies performance data from the Google accounts you authorise — Google Search Console, Google Analytics 4 and Google Ads — into a private data store held for you, so that you keep a longer history than Google's own consoles retain, can query all three sources together, and can read that store from reporting tools and from an AI client of your choosing over the Model Context Protocol (MCP).
This policy explains what we collect, why, who else touches it, how long we keep it, and how you get rid of it. It applies to the MetricFabric.io website, the web application and the hosted MCP endpoint.
The data controller for your account information is Platform Foundry Ltd, 128 City Road, London EC1V 2NX, United Kingdom, registered in England and Wales.
For the performance data we ingest from your Google accounts, you are the controller and we act as your processor. Those arrangements are set out in our Data Processing Addendum, which forms part of your contract with us. Contact for all privacy matters: [email protected]. [If a Data Protection Officer or EU/UK representative is appointed, name them here.]
Account data. Your name, email address, workspace names, password hash or federated sign-in identifier, and your notification preferences. Provided by you when you register.
Google service data. Performance data retrieved from the Google accounts and properties you explicitly select, listed in section 4, together with the OAuth refresh and access tokens needed to retrieve it.
Billing data. Subscription plan, billing email, country, VAT identifier and invoice history. Card details are collected and held by Stripe; we never see or store them.
Service and technical data. Authentication events, ingestion job logs, MCP tool-call logs (which tool, which workspace, which client, when), error traces, and IP address and user agent for security purposes.
We do not use advertising cookies or third-party analytics trackers on MetricFabric.io. Cookies are limited to what is needed for sign-in and to remember your interface preferences.
MetricFabric.io's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, and without qualification:
Transfers to third parties are limited to (a) the sub-processors listed in section 8, who process the data only on our instructions and under contract, and (b) destinations you yourself direct the data to, as described in section 6.
We request the narrowest scopes that make the features work, and only when you connect the corresponding source. Every scope below is read-only in effect: MetricFabric.io contains no feature that creates, edits, pauses or deletes anything in your Google accounts.
| Scope | What we read | Feature it enables |
|---|---|---|
| webmasters.readonly | Search Analytics rows — query, page, country, device, date, clicks, impressions, CTR, position | The warehouse itself: 16-month backfill on connect and daily incremental collection, so you retain history beyond Google's window |
| webmasters.readonly (sites list) |
The list of properties you have access to, and your permission level on each | Letting you choose which properties to ingest, instead of guessing or asking you to type URLs |
| analytics.readonly | GA4 aggregate report data — sessions, engaged sessions, conversions and key events by landing page, channel and date | Joining organic impressions to outcomes on the same URL, and content-decay detection |
| adwords | Campaign, ad group, keyword and search-term reports: match type, impressions, clicks, cost, conversions, budget-lost-impression-share | The paid × organic overlap report, wasted-spend audits and match-type audits. Read operations only; we issue no mutate calls |
If you decline a scope, the features that depend on it are unavailable and the rest of the product continues to work. You may disconnect any single source at any time from Connections in the app, or revoke our access entirely at myaccount.google.com/permissions.
This section matters, so we will be plain about it.
MetricFabric.io does not send your data to any AI provider on its own initiative. What we operate is an MCP server: a read-only interface onto your store, protected by an access token that you create and can revoke. Nothing flows through it until you configure a client — for example Claude or ChatGPT — with that endpoint and token, and then ask that client a question. At that point your client requests specific rows and we return them to your client. The transfer is made at your instruction and to a recipient you selected, and the terms of your relationship with that AI provider govern what they then do with it.
Consequences worth understanding: we cannot control or retract data once your client has received it; the provider you chose may retain it under their own policy; and if you connect a consumer-tier AI account, that provider's default training settings — not ours — apply. If you are connecting on behalf of clients, review the AI provider's terms first. We log which tool was called, by which client and when, so you can audit exactly what left your workspace.
Where the product narrates an analysis in prose using a language model, the analysis itself is produced by our deterministic rules and only the resulting summary figures are passed to the model for wording. We do not permit that provider to train on the content, and we do not use your Google data to train models of our own. Any change to this arrangement will be announced before it takes effect.
Where the UK GDPR or EU GDPR applies, we rely on: performance of a contract for account data, Google service data and the delivery of the service; legitimate interests for security monitoring, fraud prevention, service improvement and aggregate operational metrics; legal obligation for accounting and tax records; and consent for optional marketing email, which you can withdraw at any time. Your authorisation of a Google scope is the mechanism by which you instruct us to process that data under the contract.
We use a deliberately short list. Each is contractually bound to process data only on our instructions, with confidentiality and security obligations, and none is permitted to use your data for their own purposes or for model training.
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Application servers, database and object storage — where your ingested data lives | Germany (EU) |
| Cloudflare, Inc. | DNS, TLS termination, CDN and DDoS protection. Configured for EU-region processing where the setting is available | EU points of presence; US company |
| Stripe Payments Europe Ltd | Subscription billing, payment processing and invoicing. Receives billing identity only — never Google service data | Ireland (EU), with US affiliate access |
| Resend, Inc. | Transactional email — sign-in links, alerts and scheduled report delivery. Receives your email address and report contents you have chosen to email | United States |
| Anthropic, PBC · OpenAI, L.L.C. and other MCP clients you connect | User-directed recipients, not our sub-processors. They receive data only in response to requests you initiate from a client you configured, per section 6 | United States or as set by that provider |
The current list is published at metricfabric.io/sub-processors. We give at least 30 days' notice by email before adding a sub-processor that processes ingested Google data, and you may terminate without penalty if you object.
Your ingested Google data is stored and processed in Germany. Transfers outside the UK and EEA arise only for the Cloudflare, Stripe and Resend functions described above, and are covered by the UK International Data Transfer Addendum and the European Commission's Standard Contractual Clauses, supported by transfer risk assessments we keep on file. Transfers to an AI client you connect are made at your instruction under section 6 and are not covered by those clauses — you choose the recipient and the terms.
| Ingested Google performance data | Kept for as long as your subscription is active — the retained history is the point of the product. Deleted in full 90 days after cancellation or account closure, and exportable at any time before then. |
| OAuth refresh and access tokens | Deleted immediately when you disconnect a source, delete your data or close your account. |
| Account and workspace data | 90 days after account closure. |
| MCP call logs and ingestion job logs | 90 days. |
| Security and authentication logs | 12 months. |
| Invoices and accounting records | 7 years, as required by tax law. |
| Encrypted backups | 35 days on a rolling cycle, after which deleted data cannot be recovered. |
You can trigger immediate deletion yourself from Settings → Data & privacy, which erases all ingested rows and revokes our Google tokens in the same action.
Data is encrypted in transit with TLS 1.2 or better and at rest with AES-256. OAuth tokens are held in a dedicated secrets store with envelope encryption and are never written to logs. Every workspace is isolated at the row level, with tenant identity enforced in the data layer rather than in application code alone. Access to production is limited to named administrators using multi-factor authentication and is logged. We run dependency and vulnerability scanning continuously, keep an incident response procedure, and will notify you without undue delay — and within 72 hours where the GDPR requires it — of any breach affecting your data. Full technical and organisational measures are listed in Annex B of the DPA.
Subject to applicable law you may request access to your personal data, correction, erasure, restriction of processing, portability in a machine-readable format, and objection to processing based on legitimate interests. You may also withdraw consent where we rely on it. Most of these you can exercise yourself in the app; for anything else, write to [email protected] and we will respond within one month.
If you are unhappy with our response you may complain to your supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk); in the EEA, the data protection authority of the country where you live or work.
MetricFabric.io is a business tool and is not offered to anyone under 16. We do not knowingly collect data from children.
We keep a version history at metricfabric.io/privacy. For material changes — new categories of data, new purposes, new sub-processors handling ingested Google data — we email account holders at least 30 days before the change takes effect. Continued use after that date constitutes acceptance; if you would rather not accept, cancel and export your data.
Platform Foundry Ltd, 128 City Road, London EC1V 2NX, United Kingdom
[email protected] · Terms of Service · Data Processing Addendum