Privacy Policy
Effective Date: May 12, 2026·Last Updated: September 7, 2026
1. Introduction
Analyst Zero is an AI growth analyst for early-stage startups. To deliver the Service, we collect a small set of information from you, generate written analyses called “reads,” and store the results so you can return to them. This policy explains what we collect, why, and the rights you have over it.
This policy applies to users worldwide and is intended to align with the principles of the General Data Protection Regulation (GDPR), the UK GDPR, and applicable US state privacy laws.
2. What Data We Collect
Account information
- Email address (required for login)
- If you sign in with Google: the name and profile image associated with your Google account
- Authentication metadata (login timestamps, session tokens)
Business context you provide
- The information you share during onboarding about your business
- Anything you later add or edit in your memory vault
- Notes you paste in, and documents you upload. We accept text and PDF files up to eight megabytes. The file is read once by our AI subprocessor to pull out the handful of facts worth keeping, and is never stored. Only those short notes are kept.
Data we read on your behalf
When you connect your Google Analytics 4 property, we use Google’s read-only Analytics scope to fetch the standard metrics and dimensions needed to produce your reads over a recent time window.
If you also connect Google Search Console, we use Google’s read-only Search Console scope to fetch search performance data for the site you select over a recent time window.
We do not write to any property you connect. We do not access any Google service beyond the ones you explicitly connect.
Payment data we read on your behalf
If you connect a payment provider, we read completed transactions for your account: the amount, the currency, whether it was refunded, and the email or reference attached to the sale. We use it for one thing, which is putting the money next to the channel that earned it. We never take a payment method or a card number.
Data collected by our measurement script
If you put our script on your website, it records what happens there and sends it to us. You choose to install it. We use what it sends to write your reads, and for nothing else.
Here is everything it records:
- The address of the page someone visited. We strip out order numbers, account ids and anything like them before we store it.
- The website they came from, and any campaign tags in the link they clicked.
- Whether they were on a phone, a tablet or a computer.
- The country someone visited from. We work it out once, when they first arrive, and keep two letters. If we cannot work it out, we keep the visit with no country on it.
- Events you send us yourself, such as a signup or a purchase, and any value you attach to them.
- A random number we generate, kept in a cookie on your own domain, so we can tell a returning visitor from a new one.
- An email address, but only if you choose to send us one when someone signs up or buys. This is off unless you add that line yourself. It is what lets us tell you which channel earned a specific sale.
Here is what it never records:
- An IP address. Our server sees one, the way every server does, and we read it to work out the country. It is never stored, never written to a log, and never sent to anyone.
- Anywhere more precise than a country. No city, no region, no coordinates.
- Anything typed into a form. We never read form fields, keystrokes or page content.
- Keystrokes, mouse movements, or recordings of anyone’s screen.
- What a person does on a website that is not yours. The random number we generate means nothing anywhere else.
The country lookup runs on our own servers, against a copy of the free IP-to-country database published by DB-IP and used under the Creative Commons Attribution 4.0 International licence.
In legal terms, you are the controller of this data and we are your processor. In plain terms: it is your data, and we only touch it to do the job you hired us for.
Two things are yours to handle. You need the right to add the script to that website. And if the law where you operate says you must tell your visitors their visit is measured, that call is yours, not ours.
You can stop whenever you want. Remove the script, tell us, and we delete what we hold for that site.
Usage telemetry
- Pages you visit in the app
- Clicks on findings inside a read
- Feedback you submit on individual findings (was this useful, was this wrong)
- Errors and performance metrics needed to keep the app running
Emails we send you
When we email you a read, that email contains a single invisible image, one pixel wide. If your mail app loads it, we record that the email was opened and how many times. That is all it records. It does not tell us where you are, what you clicked, or what device you used, and the links in the email go exactly where they say they do.
Most mail apps block or route these images by default, so an email you did read often looks unopened to us. We treat the number as a rough floor, never as a measure of you. If you would rather it never load, turn off remote images in your mail app and nothing about your read changes.
Billing information
If you upgrade to Pro, Stripe collects your payment method directly. We do not see or store your full card number. We receive your subscription status so we know which plan you are on.
3. How We Use Your Data
We use your data to:
- Generate your reads, which involves sharing the relevant context with our AI subprocessor
- Display your reads and the data you provide inside the app
- Authenticate you and keep your account secure
- Process payments and manage your subscription
- Send transactional emails (login links, billing receipts, account notifications)
- Email you a read. We look at your site on a recurring basis and write only when something has changed enough to be worth saying, which is at most about once a week. Tell us and we will stop sending them.
- Improve the product through aggregate, anonymized analysis (for example, “what percentage of accounts hit the free-tier limit”). Individual user data is not used to develop unrelated features, and is never sold.
- Respond to your support requests
- Comply with legal obligations and enforce our Terms
We do not:
- Sell your data to anyone
- Share your data with advertisers
- Submit your data for training third-party AI models
- Profile you for purposes outside delivering the Service
- Send you marketing emails without your explicit opt-in
Legal bases (GDPR / UK GDPR)
Where GDPR applies, we rely on the following legal bases:
- Contract. Most processing is necessary to provide the Service you signed up for.
- Legitimate interest. Aggregate analytics, security monitoring, and product improvement.
- Consent. Anything optional, such as marketing emails (when offered), where we will ask you first.
- Legal obligation. Tax, accounting, and law enforcement requests where required.
Anonymous benchmarks
We may combine measurements from across the sites we read into anonymous benchmarks. That is what lets a read tell you whether a number is good or bad, instead of just telling you the number.
A benchmark is a total across many sites. It never names you, your business, another customer, or a single visitor. We do not sell benchmarks, and we do not offer them as a separate product.
4. Where Your Data Is Stored
Your data is stored with a third-party provider operating on commercial cloud infrastructure, and is encrypted in transit and at rest. If you are located in a jurisdiction with cross-border transfer rules (such as the EU or UK), your data may be processed outside your country of residence under the data-protection frameworks our providers maintain.
5. Third-Party Processors
We use a small set of third-party processors to operate the Service. Each one only receives the data needed to do its job.
| Category | Role |
|---|---|
| Database & authentication provider | Stores your account and the data you provide; handles login |
| AI inference provider | Generates your reads |
| Google (Analytics, Search Console) | Source of the analytics and search data you connect |
| Payment processor | Billing for the Pro tier (card details handled directly by the processor) |
| Hosting provider | Runs the application |
| Transactional email provider | Sends login links, receipts, and account notifications |
The full subprocessor list is available on request. Email us at support@analystzero.co if you need it for a vendor or procurement review.
Our AI subprocessor’s standard terms exclude API inputs and outputs from model training by default, and we do not opt in to any training-data program on your behalf.
We run two analytics scripts on the Analyst Zero marketing site and app: our own first-party measurement script, and Google Analytics 4 with IP anonymisation enabled. We use GA4 only as an independent check on our own measurement while it is new. We do not run any third-party advertising tracker, and we do not use either script to build advertising audiences or to sell or share data with anyone.
How Google user data flows through the Service
When you connect a Google service (Google Analytics, Google Search Console), the data we receive from Google (your metrics, dimensions, search performance data, and the OAuth credentials that grant read-only access) is treated as follows:
- It is stored in our database and authentication provider for the duration of your active account, so we can render your past reads and read fresh data on your behalf.
- The relevant portion (the metrics, dimensions, and search performance data for the property or site you selected) is sent to our AI inference provider to generate each read. The OAuth credentials themselves are never sent to the AI provider.
- It is processed by our hosting provider as part of running the application servers that handle your requests.
- It is not shared with any other party. We do not sell it, transfer it for advertising, or disclose it to anyone for purposes outside delivering the Service to you.
- No employee or contractor reads your Google user data except for limited support, debugging, or operations work, and only when necessary.
You can revoke Google’s access at any time at https://myaccount.google.com/permissions. When you do, we lose the ability to read fresh data. Existing reads stored in your account remain visible until you delete them.
6. Your Rights
You have the following rights over your data. Several are formally guaranteed under regional privacy law (such as GDPR in the EU, UK GDPR, and CCPA / CPRA in California). We extend them to every user, regardless of where you live.
- Access. You can view what we have on you. Most of it is visible inside the app (account, business context, memory vault, read history). For anything else, contact us.
- Correction. You can edit your business context and memory vault directly in the app. For other corrections, contact us.
- Deletion. You can request full account and data deletion by contacting us, and we will remove your records from our database. Backups containing your data are overwritten on our standard rotation.
- Portability. You can export the data we hold on you at any time from your account, as a single structured file.
- Restriction or objection. You can ask us to pause processing of your data while a question is resolved.
- OAuth revocation. You can revoke our Google access (Analytics, Search Console, or both) at any time at https://myaccount.google.com/permissions, independent of your Analyst Zero account.
- Withdraw consent. Where we rely on consent (for example, marketing communications, when offered), you can withdraw it at any time.
- Lodge a complaint. EU and UK residents have the right to complain to their local data protection authority.
To exercise any of these rights, email support@analystzero.co. We respond within 30 days.
7. Data Retention
- Active accounts. We retain your data for as long as your account is active.
- Cancelled subscriptions. If you cancel your subscription but do not delete your account, your data stays in place so you can pick up where you left off. You can request deletion at any time.
- Deleted accounts. If you request full account deletion, we remove your data from our active systems immediately. Backups containing your data are overwritten on our standard rotation, after which the data is gone.
- Billing records. We retain billing records for the period required by applicable tax and accounting law, even after account deletion.
- Data from your website. We keep what the measurement script sends for as long as you keep the script installed and your account open, because a read that compares this month to last month needs both months. Ask us to stop and we delete all of it for that site, in one action, including every visitor record. Nothing is archived elsewhere.
- Legal holds. If we are required to preserve data for a legal proceeding, we will retain only what is required for that purpose.
8. Cookies and Tracking
We use the minimum number of cookies needed to run the Service:
- Authentication session cookie. Set when you log in. Required for the app to know who you are.
- Measurement cookies on your own site. Two, both first party. One marks a returning visitor and lasts twelve months. One marks a single visit and expires after thirty minutes of inactivity.
- Functional preferences. Small cookies or local storage entries that remember your settings within the app.
If you install our measurement script on your own website, it sets two more cookies there. One holds the random number that tells a returning visitor from a new one. The other marks the visit someone is on right now. Both belong to your domain, only your site can read them, and neither one follows anybody to another website.
Emails we send you carry one invisible image that tells us the email was opened. It sets no cookie, it does not follow you anywhere, and section 2 explains what it does and does not record.
We do not set third-party advertising cookies. We do not use trackers from advertising networks. We do not sell or share data with ad-tech vendors.
9. Security
We protect your data with:
- TLS encryption for all data in transit
- Encryption at rest, provided by our infrastructure providers
- Encrypted storage of authentication tokens
- Access controls limiting which team members can view production data, and only when necessary for support, debugging, or operations
- Regular security review of our application code
No system is perfectly secure. If we discover a breach affecting your data, we will notify you and the relevant authorities within the timeframes required by law.
10. Children
The Service is not intended for users under 18 years old. We do not knowingly collect data from anyone in that age group. If we learn that we have collected data from a minor, we will delete it.
11. Changes to This Policy
We may update this policy as the product evolves. If we make material changes, we will notify you by email and post the updated policy in the app before it takes effect. Continued use of the Service after the effective date means you accept the updated policy.
The “Last Updated” date at the top of this policy reflects the most recent revision.
12. Contact
For privacy questions, data requests, or anything else covered by this policy:
support@analystzero.co