Privacy policy

Last updated 8 July 2026

Draft — pending legal review. This is a working draft, not yet reviewed by a solicitor. It will be finalised before launch and before any customer connects client data.

Who we are and our role

MetricScout is a platform for SEO and marketing agencies. When an agency connects a client’s data (for example Google Analytics or Search Console), the agency and its client are the data controllers and MetricScout acts as their data processor under UK GDPR — we process that data only to provide the service. For our own account holders’ details we are the controller.

What data we process

  • Account and billing details of our direct users
  • OAuth tokens for connected Google accounts (encrypted at rest)
  • Google Analytics and Search Console metrics you connect
  • Website crawl data and technical, SEO and accessibility findings
  • Generated insights, opportunities and risks
  • Timeline events and client context you enter

Google user data

With your permission we access read-only Google Analytics and Search Console data for the properties you connect. We use it solely to generate the marketing insights and reports you connected it for. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically:

  • We use Google data only to provide and improve the features you connected it for
  • We do not use it for advertising
  • We do not sell it
  • We do not allow humans to read it except where you ask us to, where it is necessary for security, or where the law requires it

Where insight wording is refined by our AI provider (OpenAI), only the text needed to phrase the insight is sent; that data is not used to train AI models, and the AI cannot introduce any figure not already in the evidence. See the sub-processor list.

How we store and protect data

  • Encryption in transit and at rest; OAuth tokens encrypted with managed keys
  • Agency-level tenant isolation enforced on every query
  • Least-privilege internal access and audit logging of sensitive operations

Sharing

We share data only with the sub-processors needed to run the service, listed on our sub-processors page. We do not sell personal data.

Retention and deletion

We retain data per our data retention & deletion policy and delete it when the client or account it belongs to is removed.

Your rights

You have the rights afforded by UK GDPR, including access, correction and erasure. To exercise them, or to ask a question about this policy, contact us.