Google API Services User Data Disclosure
The short, public statement of how Lumetry uses Google user data. This is the page we will point Google’s OAuth reviewers at.
01What Lumetry is
Lumetry is a marketing analytics application at lumetry.ai. It lets a business connect its own Google Analytics, Search Console, Google Ads, Merchant Center, and Business Profile accounts so the team can see verified dashboards and briefs. Connecting Google is optional and happens only when someone in the workspace clicks Connect.
This page is the public disclosure of how we handle Google user data. The full Privacy Policy and Terms of Service apply as well.
02Limited Use
Lumetry's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- Google user data is used only to provide or improve user-facing features that are prominent in Lumetry: the Analytics, Search Console, Google Ads, Merchant Center, and Business Profile boards, plus verified answers, briefs, and scheduled reports you turn on.
- We do not sell Google user data.
- We do not use Google user data for advertising or retargeting.
- We do not use Google user data to train generalized AI or ML models.
- We do not transfer Google user data except to subprocessors that operate the product (hosting, database, OAuth token broker, cache, email, and the model router used to draft briefs), under contracts that restrict their use.
- Lumetry staff do not read Google user data unless you ask for support, we are investigating abuse or a security issue, law requires it, or the data is aggregated.
03Scopes we request, and why
Each scope is requested only when you connect that product. We do not request extra scopes for features that do not exist yet.
- analytics.readonly — Read GA4 property reports so the Analytics board can show sessions, users, conversions, revenue, and acquisition, and so answers can cite those figures.
- webmasters.readonly — Read Search Console search analytics so the Search Console board can show queries, pages, countries, devices, and search appearances.
- adwords — Read Google Ads performance (campaigns, keywords, spend, clicks, conversions). We do not mutate campaigns. This is the Ads API’s reporting scope.
- content — Read Merchant Center accounts, products, and product statuses for the Merchant Center board. We do not write to the feed.
- business.manage — List Business Profile accounts and locations and read listing details, hours, and review summaries. Google does not publish a read-only Business Profile scope; we do not edit listings or reply to reviews.
04How data is stored
OAuth access and refresh tokens are stored encrypted by our connection broker (Composio), scoped to one Lumetry workspace. Lumetry stores the connection id, the property or account you selected, and short-lived cached report results used to render boards.
We do not store your Google password. Cached payloads expire and are replaced on refresh. Tokens are used only to call the Google APIs you authorized.
05How to revoke and delete
In Lumetry: open Integrations and disconnect the Google product. That revokes the brokered grant and queues deletion of associated Google user data.
In Google: open Google Account permissions and remove Lumetry (or the OAuth client you authorized). We treat that as a revocation.
Associated Google user data is deleted from our systems within 30 days of disconnect or a verified deletion request, except for minimal records we must keep for law or security. Email privacy@lumetry.ai from your account address with the subject “Request Data Deletion.”
06Contact
privacy@lumetry.ai for data requests. legal@lumetry.ai for legal notices. security@lumetry.ai for security issues.