Privacy Policy

Last updated 5 September 2026

Falqor is a reporting tool for marketing agencies. An agency connects a client's Google Analytics or Search Console property, and Falqor collects the resulting statistics on a schedule and presents them as a report. This policy explains exactly what we store, why, and for how long. Falqor is operated by an independent developer, not a company.

What we collect

Account data. Your email address and a password, handled by our authentication provider — we never see the password in readable form. If you fill them in, we also store your agency name, brand colour and logo, and the names you give your clients.

Google data you connect. When you connect a property, Google gives us a token on your behalf and we store the property identifier plus the statistics we pull from it.

Site analytics. Our public marketing pages use Google Analytics and Vercel Analytics to count visits. The application itself (everything under /app) is not tracked this way.

Google user data: scopes and use

Falqor requests only read-only access, and only to the two scopes it actually needs:

  • analytics.readonly — to read Google Analytics 4 statistics for the property you choose.
  • webmasters.readonly — to list your verified Search Console properties and read their search statistics.

We cannot modify, create or delete anything in your Google account, and we never post on your behalf. The access is used for one purpose: building the reports you asked for.

Falqor's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we do not transfer this data to third parties except as needed to provide the service, we do not use it for advertising, we do not sell it, and no human reads it except where required for security or to comply with the law.

How we access, use, store and share Google user data

This section answers, in order, the four questions Google asks of any application that connects to a user's account.

Access.We access Google user data only after you have signed in to Google yourself and granted consent on Google's own screen. Access is limited to the two read-only scopes listed above, and only to the specific properties you choose. You can withdraw it at any time, without our involvement, from your Google account settings.

Use. The data is used for exactly one purpose: producing the performance report for the client you connected it to. It is not used to train models, to profile anyone, to advertise, or for any secondary purpose whatsoever.

Storage. Statistics are stored as daily aggregate totals in a managed Postgres database inside the European Union. The Google refresh token is encrypted with AES-256-GCM before it is written, and is never sent to a browser or written to a log.

Sharing. We do not sell Google user data, and we do not share it with advertisers, data brokers or any other third party for their own purposes. It is disclosed only to the infrastructure providers listed below, strictly so that they can run the service on our behalf, and to whoever you personally choose to send a report to.

Service providers we rely on

These companies process data on our behalf under their own contracts. They may not use it for their own purposes.

  • Supabase — database, authentication and file storage, hosted in the European Union.
  • Vercel — application hosting and delivery.
  • Resend — sending the report emails you schedule.
  • Google — the source of the analytics data itself, accessed through official read-only APIs.

Security

  • Google refresh tokens are encrypted with AES-256-GCM before storage; the key lives only in server configuration.
  • Separation between agencies is enforced by the database itself, not by application code, so one agency cannot read another's clients.
  • All traffic is served over HTTPS.
  • Background jobs hold no administrative database key; they authenticate with a separate shared secret.
  • Passwords are hashed by our authentication provider and are never visible to us.

What we store from your analytics

Only aggregate figures — never individual visitors. Falqor has no access to, and does not store, names, email addresses, IP addresses or any other identifier of the people who visit your clients' sites.

  • Daily totals: sessions, users, new users, key events, page views, engagement rate, average session duration.
  • Grouped summaries: traffic channels, top page paths, device categories and countries.
  • From Search Console: clicks, impressions, click-through rate, average position, top queries and pages.

How your Google token is protected

The refresh token Google issues is encrypted with AES-256-GCM before it is written to the database, using a key held only in server environment configuration. It is never sent to your browser, never written to logs, and is used solely to request a short-lived access token when a scheduled collection runs.

Where data is stored and who can see it

Data is held in a managed Postgres database and object storage provided by Supabase, hosted in the European Union, and the application runs on Vercel. These providers process data on our behalf in order to run the service; they are not permitted to use it for their own purposes.

Access is enforced at the database level: an agency can read only its own clients and their data. We do not sell data, and we do not share it with advertisers or data brokers.

Share links.You can generate a link that shows one client's report without a login. Anyone holding that link can view that report, so treat it as confidential. You can switch it off at any time, which immediately stops it working.

Retention and deletion

  • Disconnecting a source deletes the stored Google token for it.
  • Deleting a client deletes that client's collected statistics and any share link.
  • Deleting your account removes your agencies, clients, connections and collected data.
  • Backups held by our infrastructure providers may persist for a short period after deletion before being overwritten.

You can revoke Falqor's access to your Google account at any time, independently of us, at myaccount.google.com/permissions. Collection stops immediately when you do.

Your rights

You may request a copy of your data, ask for it to be corrected, or ask for it to be deleted, by writing to the address below. Reports can also be exported yourself at any time as PDF or CSV.

Children

Falqor is a business tool and is not directed at children. Accounts are intended for people old enough to enter into an agreement in their country.

Changes

If this policy changes materially we will update the date at the top of this page and, where the change affects how Google data is handled, notify account holders by email.

Contact

Questions, data requests or security reports: iskonpisko@gmail.com.