Effective: July 13, 2026
1. Scope and data controller
This policy applies when you visit ease.analyticahouse.com, install or use Ease, connect a third-party source, create or schedule a report, run a forecasting or AI tool, manage a plan, or contact support.
AnalyticaHouse determines the purposes and means of processing described here unless a separate written agreement states that we act as a processor for an organization. An organization that provides your account may also control its own workspace, spreadsheet, and user-administration data.
2. Data we process
Account and identity data
Google identity claims and related information needed to authenticate the user and determine the acting principal, such as account email, display information, stable identifiers, domain or customer context, installation state, and authorization status.
Connected-source data
Provider account identifiers, selected properties or advertising accounts, granted scopes, encrypted or otherwise protected authorization credentials, connection state, and the marketing or analytics data requested for a report. Depending on the source, report data may include campaign names, dimensions, metrics, cost, conversion, revenue, attribution, and performance data.
Spreadsheet and reporting data
Spreadsheet and sheet identifiers, selected ranges or destinations, report definitions, filters, schedules, normalized report records, deterministic forecast inputs and outputs, cost-report configuration, run status, and generated artifacts. We do not claim ownership of your spreadsheet content.
AI action data
When you invoke AI Analysis or Explain this forecast, relevant raw or normalized report context, deterministic output, user instructions, generated response, model configuration, and associated operational metadata may be processed.
Plan, usage, and billing data
Trial dates, plan, entitlement scope, quota decisions, measured usage, exceptions, subscription status, Stripe customer or subscription references, invoice or checkout references, and limited billing metadata. Stripe—not this website—processes full payment-card details.
Operational and support data
Request and run identifiers, timestamps, service status, errors, security signals, audit and webhook records, IP address and user-agent data in infrastructure logs, plus information you provide in support, privacy, or billing communications.
3. How we use data
- Authenticate users, identify the principal, and maintain authorized sessions and source connections.
- Retrieve selected source data, create reports, write requested output, execute schedules, and generate forecasts and artifacts.
- Provide optional AI analysis and explanation when explicitly requested.
- Evaluate install or license state, trial or subscription entitlement, quota, manual exceptions, and permission to execute.
- Process subscription events, display Plan & Usage, prevent duplicate event processing, and provide billing support.
- Secure, operate, observe, debug, audit, improve, and protect the service from abuse, fraud, and unauthorized access.
- Respond to communications, enforce agreements, comply with law, and establish or defend legal claims.
We do not sell personal data for money. We do not use connected-source report data for unrelated behavioral advertising.
4. Google user data
Ease requests Google permissions required for its published features. Use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements, where applicable.
Google Sheets content is accessed or written only as needed to provide actions the user selects, maintain configured schedules, provide support authorized by the user, protect the service, or comply with law. You can revoke Google access through your Google Account security settings.
5. Legal grounds
Depending on your location and relationship with us, processing may be based on performance of a contract or steps you request before contracting; legitimate interests in providing, securing, supporting, and improving the service; compliance with legal obligations; establishment or defense of legal claims; or consent where consent is required and requested.
For users in Türkiye, processing is also governed by the Turkish Personal Data Protection Law No. 6698 (KVKK) and applicable secondary legislation. For EEA or UK users, relevant GDPR or UK GDPR rights may apply.
6. Service providers and disclosure
We disclose data only as reasonably needed for the purposes above, including to:
- Google: Google Workspace integration and Google Cloud infrastructure, including compute, task queueing, metadata storage, large-artifact storage, logging, and secret management.
- Stripe: hosted checkout, customer billing portal, subscription processing, invoices, tax or payment functions, fraud controls, and related webhooks.
- Connected-source providers: to authorize connections and retrieve the data selected by the user.
- AI API providers: when a user runs an optional AI feature, as explained on the AI Data Use page.
- Professional and legal recipients: auditors, advisers, insurers, authorities, courts, or transaction counterparties where reasonably necessary and lawful.
Each independent provider may process data under its own terms and privacy policy. We may also disclose data during a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality and legal safeguards.
7. AI processing
AI Analysis and Explain this forecast are optional, interpretive actions. Ease may transmit the context needed for that action to a configured API-based model provider. Forecast Builder calculations and authoritative connected-source reports remain separate from generated commentary.
Do not include unnecessary sensitive or personal information in a report range used for AI analysis. Review output before relying on it. Current configuration questions can be sent to data@analyticahouse.com.
8. International transfers
We and our providers may process data in countries other than yours. Where required, transfers are supported by recognized legal mechanisms, contractual protections, adequacy decisions, consent, or other lawful safeguards. Cloud region choices reduce unnecessary transfer but do not guarantee that all support, billing, provider, or security processing occurs in one country.
9. Retention
Retention depends on data type, account state, feature configuration, operational need, contract, security risk, dispute, and legal requirements. Connection credentials are retained while needed for authorized connections or schedules and should be removed or invalidated when disconnected. Run metadata and artifacts may be retained for service delivery, traceability, recovery, and configured archival behavior.
Billing, tax, fraud-prevention, security, event-idempotency, and legal records may be retained after account closure. Protected backups may contain data until overwritten under the backup lifecycle. When retention is no longer justified, data is deleted, anonymized, or aggregated.
10. Security
We use administrative, technical, and organizational safeguards appropriate to the nature of the service, including authenticated access, scoped authorization, encrypted transport, managed cloud controls, secrets management, least-privilege service identities, workload separation, status tracking, and operational logging.
No online service can guarantee absolute security. You are responsible for protecting your Google and source accounts, limiting spreadsheet sharing, reviewing requested permissions, and promptly reporting suspected compromise.
11. Your choices and rights
Subject to applicable law, you may have rights to access, correct, delete, restrict, object to, or obtain a copy of personal data; withdraw consent without affecting earlier lawful processing; and complain to a competent supervisory authority.
You can also disconnect sources, revoke Google access, avoid optional AI actions, cancel a paid subscription separately, and request deletion through the Data Deletion process. We may verify identity and authority before completing a request.
12. Children
Ease is a business reporting service and is not directed to children. We do not knowingly provide accounts to individuals who cannot lawfully agree to the service terms. Contact us if you believe a child provided personal information.
13. Changes to this policy
We may update this policy as the product, providers, law, or processing practices change. The effective date will be updated, and material changes will be communicated through an appropriate channel where required.
14. Contact
For privacy questions or rights requests, contact data@analyticahouse.com. Please do not include passwords, access tokens, API keys, full card numbers, or unnecessary sensitive report data.