Privacy Policy
Last updated: August 2026
What we collect
Ninelytics is a privacy-first analytics platform. Data we collect on behalf of a customer belongs to that customer, is never sold, and is never combined across customers.
For visitors to a site running Ninelytics, and for visitors to this website, we collect:
- + Page views (anonymized, no personal data)
- + Referrer information
- + Country-level geolocation
- + Browser and device type
What we don't collect
- - No cookies
- - No personal identifiable information
- - No fingerprinting
- - No cross-site tracking
- - No data sold to third parties
Google user data
If you connect a Google account to the hosted service at dash.ninelytics.com, Ninelytics requests these scopes and uses them only for the feature named beside each one:
- +
analytics.readonly— to list your GA4 properties and read their reports so historical traffic can be shown alongside your Ninelytics data - +
webmasters.readonly— to list your Search Console sites and read search performance (queries, clicks, impressions, position) - +
indexing— to submit URLs from your own sitemap to the Google Indexing API when you ask us to
We request read-only access wherever a read-only scope exists. Ninelytics never writes to your Analytics or Search Console properties, and the indexing scope is used only for URLs belonging to sites you have added to your account.
How Google data is stored and shared
OAuth access and refresh tokens are encrypted at rest with AES-256-GCM and are readable only by the service that calls the Google APIs on your behalf. Reports we fetch are stored in your account so pages load without re-querying Google on every visit.
Google data is shared in exactly one case: if you use AI Insights, a summary of your analytics — which can include Search Console queries, clicks, impressions and positions — is sent to the AI provider serving your request (OpenAI, Anthropic or Google) so it can answer you. Nothing is sent unless you use that feature.
Ninelytics' use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, do not use it for advertising, and do not use it to train generalized AI or machine learning models.
Revoking access and deletion
You can disconnect Google at any time from Integrations in your dashboard. Doing so revokes the tokens with Google and deletes them, along with the GA4 property and Search Console site links, from our database. You can also revoke access from your Google account permissions page.
Reports already fetched are removed when you delete the website they belong to, or when the account is deleted. A closed account is purged 90 days after it stops being active.
Controller and processor
For the analytics you collect through Ninelytics, you are the data controller and we are the processor: we hold and process it on your instructions, and you remain responsible for your own privacy notice and for a lawful basis under GDPR, CCPA and equivalent laws. Built-in consent management is provided to help you meet that. Our Data Processing Agreement sets out the terms.
Data retention
How long raw page views are kept depends on your plan, from 30 days to unlimited. Aggregated figures outlive the raw rows. A closed account is purged 90 days after it stops being active.
Contact
For privacy-related questions, reach out at [email protected]