Privacy

Last updated 6 August 2026

What we collect

Two things: the account details you give us (name, email, company, timezone), and the analytics figures we retrieve from the providers you connect. We do not use tracking cookies beyond the session cookie that keeps you signed in.

Provider access

When you connect a provider we store an access token and, where the provider issues one, a refresh token. Both are encrypted at rest. We request read-only scopes exclusively — Koometrics has no permission to publish, edit or delete anything in your accounts, because that permission is never granted.

Disconnecting a provider deletes its tokens and the metrics we stored for it immediately. You can also revoke our access from the provider's own settings at any time; the next sync will simply fail and we will mark the connection as needing attention.

What we do with it

We use your data to render your reports and to keep your account working. We do not sell it, share it with advertisers, or use it to train anything. Aggregate, non-identifying counts (for example, how many workspaces connect Instagram) inform what we build next.

Retention

Metrics are retained for as long as your plan's history window allows, and older rows are pruned nightly. If you cancel, your workspace becomes read-only for 30 days and is then deleted along with everything in it.

Sub-processors

Koometrics runs on DigitalOcean infrastructure. Transactional email is sent through our mail provider. We do not send your analytics data to any third party beyond these.

Contact

Questions, exports or deletion requests: privacy@koometrics.com.