GEN1 InsightsInsightsBack to home

Legal

Privacy Policy

Last updated: 28 August 2026

Overview

GEN1 Insights is an analytics interpretation platform. It connects to your Google Analytics 4 (GA4) account, with your explicit permission, and turns the reporting data in that account into plain-English trends and recommendations. This policy explains exactly what the application accesses, what it stores, and how you can remove that access.

Information we collect and store

  • Account details. When you create an account we store your email address and, if you provide it, your name. If you sign in with Google, the sign-in provider supplies your email address and basic profile information, which we store in the same way.
  • Business context you enter. During onboarding we store your business name, website address, a short description of what your business does, and the goals you select.
  • Google Analytics connection records. When you connect Google Analytics we store, server side: your Google OAuth access and refresh tokens (encrypted), their expiry time, the granted scope, the email address of the Google account used to authorise (where Google returns it), the connection status and any last error message, the time of the last successful data fetch, and a list of the GA4 properties that Google account can access (property ID, property name and account name), plus which property you selected.
  • Analytics report data. Each time your dashboard loads we request aggregated reports from the GA4 Data API for your selected property: active users, total users, new users, sessions, engaged sessions, engagement rate, average session duration, page views and conversions/key events, both for the selected period and the preceding comparison period, broken down by day, acquisition channel, page path/title, device category and conversion event name. A copy of the most recent normalised result is stored against your workspace for each date range as a record of what was reported.
  • Generated insights. The written interpretations shown in the app are stored against your workspace, along with their category, severity, the date range they relate to and whether you have marked them as actioned or dismissed.

We do not collect payment card details through this application, we do not buy or sell personal data, and we do not use tracking or advertising cookies on this site.

Google Analytics access

The application requests one Google scope: https://www.googleapis.com/auth/analytics.readonly. This is read-only. GEN1 Insights can list the GA4 properties your Google account can access and read reports from the property you select. It cannot modify, delete or create anything in your Google Analytics account, and it cannot access Gmail, Drive, Contacts or any other Google service.

After authorisation we make one call to Google's userinfo endpoint to record which Google account was connected, so the app can display it on the connection screen. Where Google does not return that address, no email is stored for the connection.

GA4 report data is aggregated by Google before we receive it. We do not request user-level identifiers and we do not attempt to identify individual visitors to your website.

GEN1 Insights' use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How we use your information

  • To authenticate you and keep your workspace separate from other customers' workspaces.
  • To retrieve and display your GA4 metrics, trends and period comparisons in the dashboard.
  • To generate written interpretation and recommendations (see below).
  • To operate, secure and troubleshoot the service.

We do not use your analytics data for advertising, and we do not use it to build or train products for other customers.

AI processing

Insights are written by an AI model (currently Google Gemini) accessed through the Lovable AI Gateway. What we send is limited to your business name and a structured, aggregated summary of the GA4 report: the date range, the current and previous period totals, the channel breakdown, your top eight pages by traffic, conversion event names and totals, and the device breakdown. No OAuth tokens, no account credentials, no email addresses and no website content are sent. If the AI service is unavailable or returns an unusable response, the app falls back to a rules-based engine that runs entirely on our own servers.

Storage and security

Data is stored in a managed PostgreSQL database (Supabase, provided through Lovable Cloud) with row-level security policies, so a workspace's records are only readable by members of that workspace. Google OAuth access and refresh tokens are encrypted with AES-256-GCM before they are written to the database and are only decrypted server-side when a report is requested. Tokens and the Google client secret are never sent to the browser. All traffic is served over HTTPS.

Retention, caching and deletion

  • Report copies. The stored copy of each date range's report is overwritten each time fresh data is fetched. It is not used to serve the dashboard — the dashboard always requests live data from Google — and it currently has no automatic expiry, so the latest copy is retained until the record is deleted.
  • When you disconnect Google Analytics. The stored OAuth tokens, connection record and the list of GA4 properties are deleted immediately, and the workspace stops requesting data from Google. Previously stored report copies and generated insights are not automatically removed at that point; email us if you want them deleted too.
  • Account deletion. There is currently no self-service delete button in the app. Email us and we will delete your profile, business context, connection records, stored report copies and generated insights.
  • Otherwise. Account, business context, report copies and insights are retained for as long as your workspace is active.

Disconnecting and revoking access

You can remove GEN1 Insights' access to your Google Analytics data at any time:

  • Inside the app, open Data source and disconnect the Google Analytics connection. This deletes the stored tokens and property list, as described above.
  • Or revoke access directly from your Google Account at myaccount.google.com/permissions.

Once revoked, the application can no longer retrieve new data from your Google Analytics account.

Third parties that process your data

  • Google. OAuth 2.0, the Google Analytics Admin API (property list), the Google Analytics Data API (reports) and the userinfo endpoint (connected account email).
  • Supabase, via Lovable Cloud. Managed authentication and the PostgreSQL database where all of the above is stored.
  • Lovable. Application hosting, and the AI Gateway that routes insight requests to the model provider.
  • Google Gemini (through the Lovable AI Gateway). Generates the written insight text from the aggregated summary described above.

These providers process data to deliver the service and on our instructions.

Your rights

Depending on where you live, you may have the right to access, correct, export or delete the personal data we hold about you, and to object to or restrict certain processing. Contact us and we will respond within the time required by applicable law.

Changes to this policy

We may update this policy as the product develops. Material changes will be reflected in the "last updated" date at the top of this page.

Contact

Questions about this policy or your data? Email info@gen1digital.co.uk.

See also our Terms of Service.