GrowthLens Back to Audit

Privacy Policy

Last Updated: June 19, 2026 · Effective Date: June 19, 2026 · growthlens.aidoralabs.in

GrowthLens is a product by Aidora Labs. We prioritize the security and privacy of your website analytics and search data. This policy explains how we collect, use, and protect your information when you connect Google Search Console and Google Analytics 4 to our services.

Have questions? Email us directly at support@aidoralabs.in. We are always here to help.

1. Read-Only Access

GrowthLens requests strictly read-only access to your Google Search Console (GSC) and Google Analytics 4 (GA4) profiles. Our integration is programmed to only read performance metrics (clicks, impressions, position, page paths, engagement rates, and session durations). We cannot modify, delete, or write any settings in your accounts.

We only ask for read-only permissions to load your dashboard stats. The application cannot modify, delete, or publish information on behalf of users.

2. How We Use Your Data

When you connect your accounts or run an audit, we process your metrics in a secure environment:

  • We analyze search performance and organize key metrics for your site dashboard.
  • AI Processing: GrowthLens uses AI services to generate plain-English insights and recommendations from analytics metrics. Only the minimum information necessary to generate user-requested outputs is processed. Google credentials, OAuth tokens, and personally identifying information are never transmitted to AI providers. AI-generated processing is used solely to provide requested functionality and is not used to train generalized artificial intelligence or machine learning models.
  • We save report snapshots to Firestore (your own account) so you can view past insights.
  • Account Authentication Data: When you sign in to GrowthLens using Google Sign-In, we receive your Google account name and email address solely for the purpose of creating and identifying your GrowthLens account. This information is stored in Firebase Authentication and is used only to authenticate your sessions and associate your analytics reports with your account. We do not use your name or email for marketing without your explicit consent.

We do not use your analytics data to train machine learning models, nor do we store raw data outside of your own reports.

No Sale or Sharing: GrowthLens does not sell, rent, or share Google user data with advertisers or unrelated third parties.

No AI/ML Model Training: Google user data obtained through Google APIs is used solely to provide GrowthLens services. Google API data is never used to train generalized artificial intelligence or machine learning models.

User Data Deletion: Users may request deletion of their account and associated data. Users may also revoke GrowthLens access at any time from their Google Account permissions page.

GrowthLens does not store Google OAuth access tokens or refresh tokens in server-side databases or logs.

Data Retention: We retain your custom account settings and generated report snapshots in your private database profile as long as your account remains active. You can delete report logs, disconnect your Google account, or completely delete your profile at any time. Triggering account deletion immediately and permanently purges all custom settings, report snapshots, and account records from our live database systems.

3. Data Security & Protection Mechanisms

We treat your data like we would want our own treated. We implement robust technical and organizational safeguards to protect user information, OAuth credentials, and Google API data.

  • Encryption in Transit: All communications between users, GrowthLens servers, and Google APIs are encrypted using HTTPS and Transport Layer Security (TLS 1.2 or higher).
  • Encryption at Rest: Configuration data, user preferences, and saved SEO reports stored in Firebase Firestore are protected using AES-256 encryption and Google's managed infrastructure.
  • Access Control & Isolation: Firestore Security Rules are used to isolate user records. Authenticated users can only access data associated with their own Firebase User ID.
  • Token Management: GrowthLens does not store Google OAuth access tokens or refresh tokens in server-side databases or logs. Access tokens are handled securely and are used only for the duration necessary to provide requested functionality.
  • Dependency & Infrastructure Auditing: Application dependencies, third-party libraries, and cloud infrastructure configurations are reviewed on a periodic basis. Security patches and updates are applied promptly upon release. Known vulnerabilities in dependencies are remediated as part of our standard development workflow. Access to production systems is restricted and monitored to help prevent unauthorized access.
  • Breach Notification: In the unlikely event of a security incident, affected users and regulatory authorities will be notified in accordance with applicable laws and regulations.

4. Data Sharing & Third Parties

Your credentials, API keys, and website analytics data are strictly confidential. We never sell, trade, rent, or monetize your website data or business metrics with any third parties.

We use trusted service providers, including Google Firebase, for authentication and secure data storage. These providers process data only as necessary to provide GrowthLens services and are subject to their own privacy and security obligations.

AI Processing Providers: When AI insight generation is enabled, GrowthLens may share aggregated analytics metrics with AI service providers selected by the user, including Google Gemini and OpenRouter, solely for the purpose of generating user-requested insights and recommendations. Only the minimum information necessary to generate the requested output is processed. Google credentials, OAuth tokens, passwords, and personally identifying information are never transmitted to these providers. These providers process data solely to provide the requested AI-generated outputs and are subject to their own privacy and security policies. GrowthLens does not permit AI providers to use Google API data for advertising purposes or to train generalized artificial intelligence or machine learning models.

OpenRouter's privacy policy is available at: https://openrouter.ai/privacy

5. Google API Data & Usage

Google API data obtained through Google Search Console and Google Analytics is accessed only after explicit user consent through OAuth 2.0.

  • OAuth Scopes Requested: GrowthLens requests only the following OAuth scopes:
    • https://www.googleapis.com/auth/webmasters.readonly — Read-only access to Google Search Console performance data (clicks, impressions, average position, page paths).
    • https://www.googleapis.com/auth/analytics.readonly — Read-only access to Google Analytics 4 metrics (sessions, engagement rates, page views, traffic sources).

    No write, edit, delete, or administrative scopes are requested. If additional scopes become necessary in the future, users will be prompted to re-consent before access is granted.

  • GrowthLens requests only the minimum scopes necessary to provide the requested functionality.
  • Google API data is used exclusively to deliver analytics, reporting, AI-generated insights, and growth recommendations requested by users.
  • GrowthLens does not store Google OAuth refresh tokens or access tokens in any database or server-side logs.
  • GrowthLens does not use Google API data for advertising purposes.
  • GrowthLens does not sell or share Google API data.
  • GrowthLens does not use Google API data to train generalized artificial intelligence or machine learning models.
  • Google API data is used exclusively to provide and improve user-requested functionality within GrowthLens.
  • Limited Use Compliance: GrowthLens complies with the Google API Services User Data Policy, including the Limited Use requirements, as follows:
    • Data obtained from Google APIs is used solely to provide GrowthLens features visible and prominent in our user interface (your analytics dashboard and AI-generated SEO reports).
    • We do not transfer Google API data to any third party except as necessary to provide GrowthLens services (AI insight generation), for security purposes, or as required by law.
    • We do not allow humans to read your Google API data except where you have explicitly requested support assistance or where required for security investigation. Access to user data is restricted to authorized processes and systems required to deliver GrowthLens functionality.
    • We do not use Google API data for advertising, data brokering, credit assessment, or any purpose beyond delivering your GrowthLens audit results.

6. Data Control & Revocation

You retain absolute ownership and control of your data. You may delete any past generated audit reports or settings inside the application dashboard at any time. Additionally, you can completely revoke GrowthLens's access to your Google account at any time through the Google Account Permissions page.

7. Data Retention

User data is retained only as long as necessary to provide GrowthLens services.

Users may request deletion of their account and associated information at any time. Account deletion requests may be initiated directly from the GrowthLens dashboard or by contacting support@aidoralabs.in.

8. Contact Information

For any questions or concerns regarding this Privacy Policy or your data, please feel free to reach out to us: