Privacy Policy

Last updated: 31 July 2026

MetricPilot ("MetricPilot", "we", "us") is a reporting and analytics service operated from India at https://metricpilot.in. It lets agencies, freelancers, consultants and in-house teams connect their own advertising accounts and turn the performance data into dashboards, AI-written summaries and PDF reports. This policy explains, in plain language, what we collect, why we collect it, how we protect it and how you can remove it.

1. Information we collect

Account information. Your name, email address and the password hash held by our authentication provider (we never see your password). If you sign in with Google, we receive your name, email address and profile picture.

Workspace content. Your business name, logo and brand colour, the client records you create, and contact details you choose to add.

Advertising performance data. Aggregated reporting metrics retrieved from the accounts you authorise — for example campaign name, campaign type, campaign status, impressions, clicks, CTR, cost, conversions, conversion value, CPA, ROAS and the dates they relate to.

Authorisation credentials. OAuth access and refresh tokens issued by the platform you connect, stored encrypted.

Billing information. Plan, invoice history and GSTIN if you provide one. Card details are handled by our payment provider and never reach our servers.

Technical logs. Limited server logs (timestamp, request path, error details) used to keep the service running and diagnose faults.

2. Why we collect it

We use this information for one purpose: to operate the reporting features you asked for — authenticating you, fetching the metrics you authorised, generating dashboards, summaries and PDFs, supporting you, and billing paid plans. We do not use your data for advertising, we do not sell it, and we do not build user profiles from it.

3. Google user data and the Google Ads API

When you connect Google Ads, you authorise MetricPilot through Google's own OAuth 2.0 consent screen. We request a single scope:

https://www.googleapis.com/auth/adwords

This is the scope the Google Ads API requires to run reporting queries. We request no other Google user-data scopes (no Gmail, Drive, Contacts or Calendar access). We use this access only to read aggregated reporting metrics for the Google Ads accounts you select, and only to display them to you inside your workspace and in the reports you generate.

MetricPilot performs no campaign management of any kind. The product cannot create, edit, pause, resume or delete campaigns, ad groups, ads or keywords, cannot change bids or budgets, cannot create Google Ads accounts and cannot serve advertising.

MetricPilot's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not transfer Google user data to third parties except as necessary to provide or improve the service, to comply with law, or as part of a merger or acquisition; we do not use it for advertising; we do not sell it; and humans do not read it except with your explicit permission for support, for security purposes, to comply with law, or where the data is aggregated and anonymised.

4. Meta (Facebook and Instagram) data

How Meta Login works. When you connect Meta Ads, MetricPilot sends you to Facebook's own OAuth dialog on facebook.com. You review the permission being requested and approve it there. MetricPilot never asks for, sees or stores your Facebook password, and receives nothing until you approve.

Permission requested. A single read-only permission:

ads_read

This is the minimum permission the Meta Marketing API requires to list the ad accounts you can report on and to read their insights. We do not request ads_management, business_management, Pages, Instagram publishing, Commerce, Messenger, Leads or any other permission, and we do not request any permission the product does not actually use.

What Meta data we access. Your basic Facebook profile identifier returned by the login itself, the name and currency of the ad accounts available to you, and aggregated advertising reporting data for the ad account you select: campaign, ad set and ad names, status and objective, reach, impressions, clicks, CTR, CPC, CPM, frequency, amount spent, conversions, cost per result, ROAS where available, and the dates those figures relate to.

Why we access it. Solely to display your own advertising performance inside your workspace and to generate the dashboards, AI-written summaries and PDF reports you request. We do not use Meta data for advertising, we do not sell it, we do not share it with data brokers, and we do not use it to build profiles of people.

Read-only. MetricPilot performs no write operations on Meta. It cannot create, edit, pause, resume or delete campaigns, ad sets, ads or creatives, cannot change budgets, bids, audiences or targeting, cannot manage pixels, and cannot publish content to any Facebook Page or Instagram account.

How long it is stored. Encrypted Meta access tokens are stored only while the connection is active and are deleted the moment you disconnect. Reporting figures already pulled into a report stay in your workspace until you delete the report, the client or your account.

How to revoke access. Disconnect Meta Ads inside MetricPilot, which deletes the stored token immediately, or remove MetricPilot from Facebook settings → Business integrations, which invalidates our token instantly.

How to request deletion. Follow the steps on our Data Deletion page, or email contact@metricpilot.in from your registered address and we will delete the Meta-derived data we hold for you.

MetricPilot is an independent tool and is not affiliated with, endorsed or sponsored by Meta Platforms, Inc.

5. Storage and security

Google and Meta OAuth tokens alike are encrypted with AES-256-GCM before storage and are never sent to the browser; all Google Ads API and Meta Marketing API calls are made server-side. Data is encrypted in transit with HTTPS/TLS and at rest by our infrastructure provider. Row-level security policies restrict every record to the workspace that owns it. Full detail is on our Security page. No system is perfectly secure, but we work to industry-standard practices and will notify affected users promptly if a breach affecting their data occurs.

6. Cookies

We use strictly necessary cookies and browser local storage to keep you signed in and to remember interface preferences. We do not use advertising cookies and we do not run third-party ad trackers. Clearing this storage signs you out.

7. Third-party services

We share data only with the processors needed to run MetricPilot: our cloud hosting, database and authentication provider (application data and account records), our AI provider (aggregated, non-identifying performance figures used to draft report summaries), our payment provider (billing details), and the advertising platforms you connect (to request your data). These providers act on our instructions and are not permitted to use your data for their own purposes.

8. Retention

We keep your workspace data for as long as your account is active. Tokens are kept only while a connection is active. Billing records are kept for as long as Indian tax law requires. Everything else is deleted when you delete it or close your account.

9. Your rights and choices

You can access and correct your information in the app, export your reports as PDFs, disconnect any connected account at any time, and delete individual reports, clients or your entire account. You may also revoke MetricPilot's Google access at myaccount.google.com/permissions and your Meta access at Facebook business integrations. To exercise any right by email, write to contact@metricpilot.in from your registered address.

10. Data deletion

Disconnecting a source deletes its stored tokens immediately. Deleting your account removes your workspace, clients, connections, tokens and reports from live systems immediately, and from encrypted backups within 30 days. Step-by-step instructions are on our Data Deletion page.

11. Children

MetricPilot is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children.

12. Changes to this policy

If we make a material change we will update the date at the top of this page and notify account holders by email before the change takes effect.

13. Contact

MetricPilot — privacy queries and data requests: contact@metricpilot.in. We acknowledge requests within 2 business days.