Security & data handling

Caybl.ai only does what you explicitly allow it to. Access is granted through Google’s standard consent screen, credentials are encrypted at rest, and you can revoke access at any time by disconnecting. This page is a plain-language walkthrough - for the formal policy, see our Privacy Policy.

Scoped by design

Caybl.ai requests Google’s Analytics scope, which covers running reports plus two narrow write actions - marking a GA4 event as a key event, and linking a Google Ads account to your property. It cannot change any other GA4 settings, delete anything, or touch your website. Connecting Google Ads is separate and optional: read access works on its own, and write access - creating or changing campaigns, budgets, keywords, and ads - only switches on for an account when you explicitly turn it on in your dashboard.

No tokens to handle

You connect Google Analytics through Google’s own “Sign in with Google” consent flow - the same one you’d see for any trusted app. Caybl.ai never receives your password, and you never paste an API key or config file. The access Caybl.ai receives is stored encrypted at rest and used only to fetch the data you ask for.

Your AI, your data path

Caybl.ai connects to the AI agent you choose - Claude or ChatGPT. The reasoning runs on your own agent under your own terms; Caybl.ai’s job is only to fetch the Google Analytics data needed to answer a question. Your analytics isn’t sent anywhere it doesn’t need to go.

EU hosting & minimal processing

Caybl.ai runs in the EU (eu-west-1). It doesn’t warehouse your analytics - data is fetched on demand to answer a question and not retained beyond that. Usage tracking, which powers the “questions this month” view in your dashboard, records metadata only (which tool ran, when, how many rows, success or failure) - never the contents of your reports.

Disconnect anytime

You’re in control of the connection. Disconnecting in your dashboard removes the stored connection and revokes Caybl.ai’s access to your Google Analytics.

Caybl.ai is a separate product with its own infrastructure. Nothing about your connection is shared with unrelated services.

What we collect

To run Caybl.ai we store: your account email (from Google or the email you sign up with), an encrypted Google Analytics access credential once you connect a property, and metadata about each question your agent asks (tool name, timestamp, row count, success/failure, latency). We do not store the analytics data returned by a query, or the content of your questions.

Who we share it with

Google Analytics data is fetched from Google on demand and passed to the AI agent (Claude, ChatGPT, or another MCP-compatible client) that you connected and are actively using - that agent processes it under your own account with that provider. Our infrastructure runs on Amazon Web Services (eu-west-1); AWS acts only as our hosting provider and does not use your data for its own purposes. We do not sell data or share it with advertisers.

Google API Services User Data Policy

Caybl.ai's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Retention & deletion

Your encrypted Google Analytics credential is kept until you disconnect, at which point it and Google's grant are deleted immediately. Usage metadata is kept for as long as your account is active so your dashboard can show recent activity, and is deleted with your account. You can request account and data deletion at any time by contacting us below.

Contact

Questions about this page, or requests to access or delete your data: support@caybl.ai. For the terms that govern using Caybl.ai, see our Terms of Service; for the full legal Privacy Policy, see here; for a Data Processing Agreement, see here.

No tokens, revoke anytime

Connect Google Analytics and ask questions in the AI you already use.

Get started free

FAQ

Can Caybl.ai change my Google Analytics or my website?

Mostly no. Caybl.ai requests Google's Analytics scope, which lets it report on your data and perform two specific actions - marking a GA4 event as a key event, and linking a Google Ads account to your property - when your agent asks for them. It cannot change any other GA configuration, audiences, or your site.

Can Caybl.ai spend my Google Ads budget?

Only if you connect a Google Ads account and explicitly turn on write access for it. Read access works immediately and by itself. With write access on, changes can be dry-run first and anything newly created that could serve is paused by default - but you're in control of the switch, per account.

Do you store my Google password or tokens I can see?

No. You authorize Caybl.ai through Google's own consent screen. The resulting access is stored encrypted; you never see or handle a token, and Caybl.ai never receives your Google password.

Where is my data processed?

Caybl.ai runs in the EU (eu-west-1) and processes only what's needed to answer your question. Analytics data isn't warehoused - it's fetched on demand.

What happens when I disconnect?

Disconnecting removes the stored connection and revokes Caybl.ai's access to your Google Analytics.