MetricFabric.io — Privacy Policy Version 1.0 · 8 September 2026
MetricFabric.io

Privacy Policy

Effective 10 September 2026 · Last updated 8 September 2026 · Version 1.0

MetricFabric.io is a subscription service that copies performance data from the Google accounts you authorise — Google Search Console, Google Analytics 4 and Google Ads — into a private data store held for you, so that you keep a longer history than Google's own consoles retain, can query all three sources together, and can read that store from reporting tools and from an AI client of your choosing over the Model Context Protocol (MCP).

This policy explains what we collect, why, who else touches it, how long we keep it, and how you get rid of it. It applies to the MetricFabric.io website, the web application and the hosted MCP endpoint.

1. Who we are

The data controller for your account information is Platform Foundry Ltd, 128 City Road, London EC1V 2NX, United Kingdom, registered in England and Wales.

For the performance data we ingest from your Google accounts, you are the controller and we act as your processor. Those arrangements are set out in our Data Processing Addendum, which forms part of your contract with us. Contact for all privacy matters: [email protected]. [If a Data Protection Officer or EU/UK representative is appointed, name them here.]

2. Data we collect

Account data. Your name, email address, workspace names, password hash or federated sign-in identifier, and your notification preferences. Provided by you when you register.

Google service data. Performance data retrieved from the Google accounts and properties you explicitly select, listed in section 4, together with the OAuth refresh and access tokens needed to retrieve it.

Billing data. Subscription plan, billing email, country, VAT identifier and invoice history. Card details are collected and held by Stripe; we never see or store them.

Service and technical data. Authentication events, ingestion job logs, MCP tool-call logs (which tool, which workspace, which client, when), error traces, and IP address and user agent for security purposes.

We do not use advertising cookies or third-party analytics trackers on MetricFabric.io. Cookies are limited to what is needed for sign-in and to remember your interface preferences.

3. Google API Services — Limited Use disclosure

MetricFabric.io's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, and without qualification:

  • We use Google user data only to provide and improve the user-facing features described in this policy and visible in your own account.
  • We do not transfer or sell Google user data to third parties for advertising, market research, credit assessment or any similar purpose.
  • We do not use Google user data to serve advertisements of any kind.
  • We do not use Google user data to develop, train, retrain, fine-tune or improve any generalised or generative artificial-intelligence or machine-learning model, and we do not permit our sub-processors to do so.
  • No human reads your Google user data except where you have given specific consent (for example, when you ask our support team to investigate a problem in your account), where it is necessary for security or to comply with applicable law, or where the data has been aggregated and de-identified for internal operations such as capacity planning.

Transfers to third parties are limited to (a) the sub-processors listed in section 8, who process the data only on our instructions and under contract, and (b) destinations you yourself direct the data to, as described in section 6.

4. Scopes we request, and why

We request the narrowest scopes that make the features work, and only when you connect the corresponding source. Every scope below is read-only in effect: MetricFabric.io contains no feature that creates, edits, pauses or deletes anything in your Google accounts.

Scope What we read Feature it enables
webmasters.readonly Search Analytics rows — query, page, country, device, date, clicks, impressions, CTR, position The warehouse itself: 16-month backfill on connect and daily incremental collection, so you retain history beyond Google's window
webmasters.readonly
(sites list)
The list of properties you have access to, and your permission level on each Letting you choose which properties to ingest, instead of guessing or asking you to type URLs
analytics.readonly GA4 aggregate report data — sessions, engaged sessions, conversions and key events by landing page, channel and date Joining organic impressions to outcomes on the same URL, and content-decay detection
adwords Campaign, ad group, keyword and search-term reports: match type, impressions, clicks, cost, conversions, budget-lost-impression-share The paid × organic overlap report, wasted-spend audits and match-type audits. Read operations only; we issue no mutate calls

If you decline a scope, the features that depend on it are unavailable and the rest of the product continues to work. You may disconnect any single source at any time from Connections in the app, or revoke our access entirely at myaccount.google.com/permissions.

5. How we use your data

6. AI clients and the MCP endpoint

This section matters, so we will be plain about it.

MetricFabric.io does not send your data to any AI provider on its own initiative. What we operate is an MCP server: a read-only interface onto your store, protected by an access token that you create and can revoke. Nothing flows through it until you configure a client — for example Claude or ChatGPT — with that endpoint and token, and then ask that client a question. At that point your client requests specific rows and we return them to your client. The transfer is made at your instruction and to a recipient you selected, and the terms of your relationship with that AI provider govern what they then do with it.

Consequences worth understanding: we cannot control or retract data once your client has received it; the provider you chose may retain it under their own policy; and if you connect a consumer-tier AI account, that provider's default training settings — not ours — apply. If you are connecting on behalf of clients, review the AI provider's terms first. We log which tool was called, by which client and when, so you can audit exactly what left your workspace.

Where the product narrates an analysis in prose using a language model, the analysis itself is produced by our deterministic rules and only the resulting summary figures are passed to the model for wording. We do not permit that provider to train on the content, and we do not use your Google data to train models of our own. Any change to this arrangement will be announced before it takes effect.

7. Legal bases for processing

Where the UK GDPR or EU GDPR applies, we rely on: performance of a contract for account data, Google service data and the delivery of the service; legitimate interests for security monitoring, fraud prevention, service improvement and aggregate operational metrics; legal obligation for accounting and tax records; and consent for optional marketing email, which you can withdraw at any time. Your authorisation of a Google scope is the mechanism by which you instruct us to process that data under the contract.

8. Sub-processors

We use a deliberately short list. Each is contractually bound to process data only on our instructions, with confidentiality and security obligations, and none is permitted to use your data for their own purposes or for model training.

Sub-processor Purpose Location
Hetzner Online GmbH Application servers, database and object storage — where your ingested data lives Germany (EU)
Cloudflare, Inc. DNS, TLS termination, CDN and DDoS protection. Configured for EU-region processing where the setting is available EU points of presence; US company
Stripe Payments Europe Ltd Subscription billing, payment processing and invoicing. Receives billing identity only — never Google service data Ireland (EU), with US affiliate access
Resend, Inc. Transactional email — sign-in links, alerts and scheduled report delivery. Receives your email address and report contents you have chosen to email United States
Anthropic, PBC · OpenAI, L.L.C. and other MCP clients you connect User-directed recipients, not our sub-processors. They receive data only in response to requests you initiate from a client you configured, per section 6 United States or as set by that provider

The current list is published at metricfabric.io/sub-processors. We give at least 30 days' notice by email before adding a sub-processor that processes ingested Google data, and you may terminate without penalty if you object.

9. International transfers

Your ingested Google data is stored and processed in Germany. Transfers outside the UK and EEA arise only for the Cloudflare, Stripe and Resend functions described above, and are covered by the UK International Data Transfer Addendum and the European Commission's Standard Contractual Clauses, supported by transfer risk assessments we keep on file. Transfers to an AI client you connect are made at your instruction under section 6 and are not covered by those clauses — you choose the recipient and the terms.

10. How long we keep it

Ingested Google performance dataKept for as long as your subscription is active — the retained history is the point of the product. Deleted in full 90 days after cancellation or account closure, and exportable at any time before then.
OAuth refresh and access tokensDeleted immediately when you disconnect a source, delete your data or close your account.
Account and workspace data90 days after account closure.
MCP call logs and ingestion job logs90 days.
Security and authentication logs12 months.
Invoices and accounting records7 years, as required by tax law.
Encrypted backups35 days on a rolling cycle, after which deleted data cannot be recovered.

You can trigger immediate deletion yourself from Settings → Data & privacy, which erases all ingested rows and revokes our Google tokens in the same action.

11. Security

Data is encrypted in transit with TLS 1.2 or better and at rest with AES-256. OAuth tokens are held in a dedicated secrets store with envelope encryption and are never written to logs. Every workspace is isolated at the row level, with tenant identity enforced in the data layer rather than in application code alone. Access to production is limited to named administrators using multi-factor authentication and is logged. We run dependency and vulnerability scanning continuously, keep an incident response procedure, and will notify you without undue delay — and within 72 hours where the GDPR requires it — of any breach affecting your data. Full technical and organisational measures are listed in Annex B of the DPA.

12. Your rights

Subject to applicable law you may request access to your personal data, correction, erasure, restriction of processing, portability in a machine-readable format, and objection to processing based on legitimate interests. You may also withdraw consent where we rely on it. Most of these you can exercise yourself in the app; for anything else, write to [email protected] and we will respond within one month.

If you are unhappy with our response you may complain to your supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk); in the EEA, the data protection authority of the country where you live or work.

13. Children

MetricFabric.io is a business tool and is not offered to anyone under 16. We do not knowingly collect data from children.

14. Changes to this policy

We keep a version history at metricfabric.io/privacy. For material changes — new categories of data, new purposes, new sub-processors handling ingested Google data — we email account holders at least 30 days before the change takes effect. Continued use after that date constitutes acceptance; if you would rather not accept, cancel and export your data.

15. Contact

Platform Foundry Ltd, 128 City Road, London EC1V 2NX, United Kingdom

[email protected] · Terms of Service · Data Processing Addendum