Privacy Policy
This policy explains how Ultrametrics collects, uses, stores, and protects your information, including data accessed through Google and Meta advertising APIs.
Last updated · October 8, 2026
About Ultrametrics
Ultrametrics connects your advertising accounts — Meta Ads and Google Ads — reads their performance data into one workspace, and provides reporting and AI-assisted analysis on top of it. This Privacy Policy explains what information we collect, how we use it, the third parties involved, and the choices and rights you have.
This policy applies to the Ultrametrics web application and related services. By creating an account or connecting a data source, you agree to the practices described here.
Information We Collect
We collect the following categories of information:
- Account information — your name, email address, profile picture and sign-in identifiers when you create an account.
- Workspace data — workspace names, who belongs to them, their roles, and the settings you configure.
- Advertising data from accounts you connect — campaign, ad set, ad and performance figures from Meta Ads and Google Ads, and — if you enable the export — the name and id of the Google Sheet you choose. These are the only sources that can be connected today. We collect no analytics or e-commerce data, because no such connector exists yet.
- Billing information — your subscription plan and payment status. Card details are handled by Razorpay and never reach us.
- Activity and diagnostic records — actions taken in your workspace — a campaign created, an asset generated — together with what each AI request cost, and error messages when something fails. These are shown back to you in your own timeline and used to operate and bill the service. They are not analytics, they are not shared, and no third-party tracking product receives them.
Google OAuth Data
When you connect a Google account, we use Google OAuth 2.0 to obtain a scoped access token. We request only the read scopes required for the connector you enable, and we never receive or store your Google password. Tokens are encrypted at rest and used solely to retrieve the data you authorize.
Ultrametrics's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can revoke access at any time from your Google Account permissions page or by disconnecting the connector in Ultrametrics.
How We Share Google User Data
This section answers one question directly: who, other than you, receives data we obtain from Google on your behalf.
We do not sell Google user data. We do not use it for advertising or to build advertising profiles. We do not transfer it to data brokers, and we do not transfer, share, or disclose it for any purpose other than providing the features you asked for. We do not use it to train any AI model.
The complete list of recipients, and what each one does:
- Supabase (database and authentication hosting) — stores your workspace, which Google accounts you connected, and your Google OAuth tokens in encrypted form. Supabase hosts this data on our behalf and does not use it for its own purposes.
- Vercel (application hosting) — runs the application that makes requests to Google on your behalf, so Google user data passes through Vercel's infrastructure in transit. Diagnostic messages about failures may appear in Vercel's platform logs.
- Anthropic (the AI assistant) — receives Google Ads performance figures only when you ask the assistant a question that requires them, and only the figures needed to answer it. This is the one case in which Google user data leaves our systems for an AI provider. Anthropic processes it to return an answer and does not use it to train its models.
- Google (back to you) — if you enable the Google Sheets export, we write your Google Ads figures into the one spreadsheet Ultrametrics created in your own Google account, at your instruction. It is the only file we can open.
Just as important, here is who does not receive it. Google user data is never sent to OpenAI or Replicate — the AI providers we use for image generation and editing receive only the creative material you upload and your brand settings, never advertising data from Google. It is never sent to Meta, never sent to our payment processors, and we run no third-party analytics, advertising, or error-reporting service that could receive it.
Google Ads performance data is not stored in our database. It is read from Google when you ask for it, held briefly in memory (at most five minutes) to avoid repeating the same request, and then discarded. What we do keep is the connection itself: which Google account you connected, the account identifiers, your export settings, and your OAuth tokens in encrypted form.
Human access. We do not read your Google user data as a matter of course. A small number of authorized personnel can access production infrastructure where necessary to operate the service, investigate a fault, or respond to a security issue. Every decryption of a stored Google credential is written to an access log we retain for 90 days.
Limited Use. Ultrametrics's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can end this at any time. Disconnect the connector in Ultrametrics, or revoke access from your Google Account permissions page. Either stops all further retrieval immediately. To have the stored connection and tokens deleted, follow Data Deletion or write to privacy@ultrametrics.in.
Google Ads API Usage
With your authorization, Ultrametrics accesses the Google Ads API to read campaign, ad group, keyword, and performance reporting data for the ad accounts you select. This data is used to populate your dashboards, reports, and AI analysis within your workspace.
- We request read-only reporting access; we do not create, edit, pause, or delete campaigns.
- Google Ads data is used only to provide the features you request and is never sold.
- Data is associated with your workspace and isolated from other customers.
- You may disconnect Google Ads at any time, which stops further data retrieval.
Meta Ads API Usage
When you connect Meta (Facebook and Instagram) advertising accounts, Ultrametrics uses the Meta Marketing API with the ads_read scope to retrieve the ad account insights you authorize, and the ads_management scope to carry out changes you explicitly approve in the app.
- We never change your account automatically. Every write — pausing or resuming a campaign, changing a budget, or publishing a creative — requires your explicit approval on that specific action inside Ultrametrics.
- A publish starts paused unless the screen you approve says it starts active — the test bench does, because a paused test measures nothing, and it states the daily spend on the button before you press it. Anything else we publish defaults to paused.
- On that one screen the words are on the control itself: the button says it starts ACTIVE, and a line above it says the test begins delivering and spending as soon as Meta accepts it.
- Every executed action is recorded in an audit log with its result, and reversible actions can be rolled back from the app.
- The optional pages_show_list scope is used only to list your Facebook Pages so you can choose one when publishing.
Use of Meta data complies with the Meta Platform Terms and Developer Policies. You can revoke access from your Meta account settings or by disconnecting the connector.
Google Sheets Integration
If you enable the Google Sheets integration, Ultrametrics creates one spreadsheet in your Google Drive and writes the synced datasets you configure into it. We request a single Google permission for this — drive.file, which Google describes as “see, edit, create, and delete only the specific Google Drive files you use with this app”.
That is a technical limit, not only a promise: Ultrametrics can open the file it created and nothing else. We cannot list the files in your Drive, read their names, or open any other spreadsheet — including ones you own. If you delete or move that file, we lose access to it and make a new one at your instruction. You control which data is exported and when, and you can disconnect at any time.
Payments (Razorpay)
Subscription billing is processed by Razorpay Software Private Limited. Payment details are entered directly with Razorpay and are never stored on Ultrametrics servers. We retain only non-sensitive billing metadata such as your plan, subscription status, and the subscription identifier needed to manage your account. Razorpay's handling of payment data is governed by Razorpay's own privacy policy.
AI Processing
Ultrametrics provides AI-assisted analysis of your connected marketing data. We use three AI providers, and we name them rather than describing them as a category:
- Anthropic — answers your questions about your accounts. It receives the metrics needed for the question you asked, which can include Google Ads figures.
- OpenAI — generates and edits images, and reads frames of video creative you provide. It receives your brand settings, your prompt, and the creative material itself.
- Replicate — separates a product from its background in reference images you upload, when that feature is enabled. It receives only those images.
- AI features operate on the data already present in your workspace.
- We do not use your private workspace data to train third-party foundation models, and our providers do not train on it.
- AI output is advisory. It can propose an action (for example pausing a campaign or moving budget), but nothing reaches your ad account until you approve that specific action yourself.
Data Storage
Your data is stored using Supabase (PostgreSQL) infrastructure with row-level security that isolates each workspace. Data is logically separated per customer and accessible only to authenticated members of the relevant workspace.
Where it is stored. Your workspace and all synced advertising data are held in our Supabase database in the Asia Pacific (Singapore) region. Generated and uploaded creative is held in Supabase Storage in the same region. Our web application runs on Vercel, also in Singapore; Vercel does not hold a copy of your advertising data, though diagnostic messages about failures are written to its platform logs and can contain identifiers such as a workspace or account id.
Where it is processed. Storage of your advertising data is in Singapore and does not move. Two other places can be involved. Our job queue runs in Mumbai, India, and holds identifiers only. Our background worker service is configured on Railway in the United States (US West), and while a worker is deployed there it decrypts your stored access token and reads your advertising data in that region. We name every region here rather than only the ones currently in use, so that this page stays accurate whether or not a worker is deployed at the moment you read it.
Our job queue. Scheduled work is queued through Upstash, a managed Redis service, on AWS in the Mumbai, India (ap-south-1) region. The queue carries only identifiers — a workspace id, a connector id and a timestamp — and never your advertising figures, account names, creative or tokens. Queued items stay until they are processed; they are not deleted on a schedule, and they are not encrypted at rest — see Encryption below.
Background workers. Some scheduled work is designed to be carried out by a worker process running outside our web application. A worker of this kind reads jobs from the queue and, to do the work, decrypts your stored access token and calls the advertising platform on your behalf. Whenever such a worker is deployed, the platform hosting it — Railway, in the United States (US West) — processes your advertising data in the same way our web application does, under the same obligations, and it is listed as a sub-processor below. Whether one is deployed at any moment is an operational detail rather than a difference in how your data is handled; the connector settings screen states whether scheduled syncs are actually taking place.
Encryption
In transit. Everything travels over TLS — between you and us, and between us and Google, Meta, and every service listed below.
At rest. Your workspace, your synced advertising data and your creative are encrypted at rest in our Supabase database and file storage. OAuth tokens get a second layer on top of that: we encrypt them ourselves with AES-256-GCM before they are written, so a copy of the database alone does not yield a usable token. Every decryption is written to an access log.
One exception, and we would rather name it than narrow the sentence above. Our job queue runs on a plan where encryption at rest is not enabled, so what it holds is not encrypted on disk. It holds only identifiers — a workspace id, a connector id and a timestamp. No tokens, no advertising figures, no account names and no creative are ever placed in the queue, which is why we are willing to run it that way and to tell you so.
Security
We apply administrative, technical, and organizational safeguards to protect your information, including:
- Row-level security and per-workspace access boundaries.
- Least-privilege OAuth scopes: read-only for Google Ads; on Meta, write access is limited to the actions you explicitly approve.
- Encrypted credential storage and access logging.
- Regular dependency and platform updates.
No method of transmission or storage is completely secure, but we work to protect your data and to promptly address any vulnerabilities we identify.
Data Retention
We retain your workspace and connected data for as long as your account remains active or as needed to provide the service. When you disconnect a connector, retrieval from that source stops immediately and we delete the stored access token, so we no longer hold the means to read that account; the data already synced is retained with your workspace until you delete the workspace or account, or ask us to. When you delete your account or request deletion, we remove your personal data and synced datasets within 30 days, except where retention is required to comply with legal, accounting, or security obligations.
Third Party Services
We rely on the following sub-processors and service providers to operate Ultrametrics. Each entry says whether it receives Google user data and whether it receives Meta Platform Data — see How We Share Google User Data for the detail.
- Google (Google Ads API, Google OAuth, Google Sheets) — the connected data sources you authorize. Google user data: yes — it originates here, and is written back only to the single spreadsheet Ultrametricscreated for you. Meta Platform Data: only if you turn on the Google Sheets export, which writes your Meta advertising rows into that same spreadsheet in your own Drive.
- Supabase — authentication, database and file hosting, in the Asia Pacific (Singapore) region. Google user data: yes — connection details and encrypted OAuth tokens. Google Ads performance rows are not stored. Meta Platform Data: yes — your Meta ad account id and name, campaign and ad set ids and names, daily aggregate figures, campaign configuration, and encrypted OAuth tokens.
- Vercel — application hosting and runtime, in the Asia Pacific (Singapore) region. Google user data: in transit, plus failure messages in platform logs. Meta Platform Data: in transit, plus the same failure messages.
- Anthropic — the AI assistant that answers questions about your accounts. It receives the figures needed for the question you asked — spend, impressions, clicks, campaign objectives and which days were measured — and does not use them to train its models. Google user data: yes, only when you ask a question that requires it. Meta Platform Data: yes, on the same basis. This is the one case in which your advertising data leaves our systems for an AI provider.
- OpenAI — image generation, image editing, and analysis of creative you provide. It receives your brand settings, your prompt and the creative itself. Google user data: no. Meta Platform Data: no.
- Replicate — product segmentation of reference images you upload. Configured in our code but not enabled in production, so it currently receives nothing. Google user data: no. Meta Platform Data: no.
- Meta Platforms (Marketing API) — the connected advertising data you authorize. Google user data: no. Meta Platform Data: yes — it originates here.
- Railway (background worker hosting) — runs our background worker, in the United States (US West). While a worker is deployed it decrypts your stored access token and reads your advertising data to do the work it was given. Google user data: yes, when a worker is deployed. Meta Platform Data: yes, on the same basis.
- Upstash (job queue) — queues scheduled work, on AWS in the Mumbai, India (ap-south-1) region. It holds only identifiers — a workspace id, a connector id and a timestamp — which remain queued until processed, and which are not encrypted at rest. Google user data: no. Meta Platform Data: no — no advertising figures, names, creative or tokens are placed in the queue. This is true of the QUEUE; a worker that reads from it handles both, and is described under Data Storage.
- Razorpay — subscription and payment processing. It receives no advertising data of any kind. Google user data: no. Meta Platform Data: no.
Your Meta advertising data is never sent to Google except into your own spreadsheet when you turn that export on, and never to our payment processor. We use no third-party analytics, advertising, attribution, or error-reporting service — no SDK of any kind — so none exists that could receive your data.
User Rights
Depending on your jurisdiction, you may have the right to access, correct, export, restrict, or delete your personal data, and to withdraw consent for processing. You can exercise many of these rights directly in the app by editing your profile, disconnecting connectors, or deleting your workspace.
To make a formal request, contact us at privacy@ultrametrics.in.
Delete Data Requests
You can delete your data in two ways:
- In-app — delete your workspace or account to remove your personal data and your synced advertising data. This happens immediately, not on a schedule. If you have an active paid subscription we cannot delete the account until you cancel it first, because we cannot cancel it for you; the app says so and links you to Billing.
- Two things survive deletion and we would rather say so than imply otherwise: payment records held by our payment processor, which a merchant may not destroy, and encrypted database backups until they age out on their own schedule.
- Disconnecting a connector stops all further retrieval immediately and deletes the stored access token, so we no longer hold the means to read that account. It does not erase the performance history already synced — that history is what your reports are built from, and it is removed when you delete the workspace or account.
- By request — email privacy@ultrametrics.in with the subject "Delete My Data" from your account email address.
We process deletion requests within 30 days and confirm completion by email. Revoking access through Google or Meta also stops further data collection immediately.
Contact
For privacy questions or requests, contact us at privacy@ultrametrics.in. For general support, email aryan@ultrametrics.in.