Privacy Policy

Last updated: May 2026

1. Introduction

MetriQuill ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data. By using MetriQuill, you agree to the practices described in this policy.

2. Information We Collect

Account Information:

  • Email address (used for login and communications)
  • Password (stored as a secure hash — we never see it in plain text)
  • Subscription plan and billing status

Advertising Data You Upload:

  • CSV files exported from Meta Ads Manager or other ad platforms
  • Campaign names, spend, impressions, clicks, and other performance metrics
  • Client names and agency names you enter manually

Usage Data:

  • Number of reports generated
  • Feature usage (PDF exports, AI insights)
  • Browser type and general location (country level, via Vercel analytics)

3. How We Use Your Information

  • To provide, operate, and maintain the Service
  • To generate reports and AI insights from your uploaded data
  • To process payments and manage your subscription
  • To send transactional emails (account confirmations, receipts)
  • To improve the Service based on usage patterns
  • To comply with legal obligations

4. AI Insights and Third-Party Processing

When you use the AI Insights feature, your campaign metrics (spend, CTR, ROAS, CPA, etc.) are sent to Google's Gemini API to generate analysis. We send only numerical performance data — not personal information about your clients or end users. Google's use of this data is governed by their API Terms of Service and Privacy Policy.

5. Data Storage and Security

Your data is stored in Supabase (PostgreSQL database hosted on AWS infrastructure). We implement industry-standard security measures including encrypted connections (HTTPS/TLS), hashed passwords, and row-level security policies to ensure you can only access your own data. No security system is 100% foolproof, and we cannot guarantee absolute security.

6. Data Sharing

We do not sell your data. We share data only with the following service providers necessary to operate MetriQuill:

  • Supabase — database and authentication
  • Vercel — hosting and deployment
  • Paddle — payment processing and subscription management
  • Google (Gemini API) — AI insights generation
  • Resend — transactional email delivery

7. Data Retention

We retain your account data and saved reports for as long as your account is active. If you delete your account, we will delete your personal data within 30 days. Aggregated, anonymized usage statistics may be retained indefinitely.

8. Your Rights

Depending on your location, you may have the following rights:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data ("right to be forgotten")
  • Export your data in a portable format
  • Object to or restrict certain processing

To exercise any of these rights, email us at support@metriquill.com.

9. Cookies

MetriQuill uses only essential cookies necessary for authentication (session tokens). We do not use advertising cookies or third-party tracking cookies.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email. Continued use of the Service after changes constitutes acceptance of the updated policy.

11. Contact

For privacy-related questions or requests, contact us at support@metriquill.com.