Privacy Policy
Last updated: March 2026
What we collect
When you sign in with Google, we receive your name, email address, and a read-only OAuth token scoped to your Google Analytics 4 properties. We do not receive your Google password or any write access to your accounts.
How we use your data
We use your GA4 data to generate, deliver, and support your weekly briefs. Kulma stores report content and supporting analytics payloads required to generate reports, display report details in your account, and retain report history for your team.
Data sharing
We do not sell, rent, or share your personal data with third parties except as required to operate the service (e.g., our email delivery provider for sending your reports). We use an AI language model to generate report narratives; the GA4 metrics payload is sent to this model but is not used to train future models under our data processing agreements.
Data retention
Reports and supporting analytics payloads remain available in your account until you delete them or request account deletion. Access to stored data is limited to service operation and support workflows. You may request deletion of your account data at any time, and we process deletion requests within 30 days.
Cookies and tracking
We use a session cookie to keep you signed in. We do not use third-party advertising trackers or analytics cookies on this application.
Security
All data is transmitted over HTTPS. OAuth tokens are stored encrypted at rest. We use read-only GA4 scopes and never request write permissions to your Google account.
Changes to this policy
We may update this policy from time to time. Material changes will be communicated via email to registered users.
Contact
Questions about this policy? Email privacy@kulma.co.