Privacy Policy
Last updated: August 26, 2026
GA4 Sensei ("GA4 Sensei", "we", "us", or "our") provides a Google Analytics 4 and Google Tag Manager auditing service (the "Service"). This policy explains what data we collect, why, and how it’s protected. It applies to ga4sensei.com and app.ga4sensei.com.
1. Information we collect
Account information
When you create an account, we collect your name, email address, and (if you sign up with a password rather than Google) a securely hashed password. If you sign in with Google, we receive your name and email from your Google profile.
Google account access
To audit your GA4 properties and Tag Manager containers, we request access to your Google account via OAuth. Depending on what you connect, this can include:
- Read-only access to your Google Analytics 4 configuration and reporting data
- Read-only access to your Google Tag Manager containers (tags, triggers, variables)
- Write access to Google Analytics and Tag Manager, requested separately and only when you explicitly choose to use an auto-fix feature. Every change is shown to you for review before anything is published live.
We store your Google OAuth tokens in encrypted form so we can keep auditing your properties without asking you to reconnect every time. We never see or store your Google account password.
Audit data
We store the results of each audit you run, including health scores, pass/warning/fail findings, and summaries of what we checked, so you can view your audit history over time. We do not permanently store the raw GA4 report data or GTM container contents beyond what’s needed to generate and display these findings.
Billing information
Paid subscriptions are processed by Razorpay. We do not store your card or payment details. Razorpay handles that directly, and we only store your plan, subscription status, and invoice history.
2. Cookies & local storage
To keep you signed in and make the app usable, we use a small number of cookies and browser-storage entries. All of them are strictly necessary for the Service to work; we do not use advertising or cross-site tracking cookies.
Cookies
| Name | Type | Expires | Purpose |
|---|---|---|---|
| ga4_access_token | HttpOnly, Secure, SameSite=Lax | 30 minutes | Keeps you signed in |
| ga4_refresh_token | HttpOnly, Secure, SameSite=Lax | 7 days | Silently renews your session |
Local storage (stays on your device)
| Key | Purpose |
|---|---|
| ga4_user | Cached name/email for display |
| ga4_logged_in | Sign-in status flag |
| ga4_theme | Light/dark mode preference |
| ga4_audit_cache | Cached recent audit results for faster loading |
| ga4_last_activity | Powers automatic sign-out after 30 minutes idle |
Session storage (cleared when you close the tab)
| Key | Purpose |
|---|---|
| oauth_state_nonce | Verifies Google sign-in redirects, prevents CSRF |
| A couple of short-lived flags | Used only during the in-progress GTM-connect / plan-upgrade flow, removed once that flow finishes |
You can clear cookies and site data at any time from your browser settings. Doing so will simply sign you out and reset your local preferences.
3. Google API Services User Data Policy
GA4 Sensei’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We only use the data we obtain from Google APIs to provide and improve the auditing features you see in the product. We never sell or rent it, never use it for advertising, and never use it to train generalized AI/ML models.
4. How we use your information
- To run the GA4/GTM audits you request and show you the results
- To send transactional emails: password resets, email verification, and monitoring/alert notifications you configure
- To process subscription payments and manage your plan
- To maintain and improve the reliability and security of the Service
5. Third parties we share data with
We rely on the following providers to operate the Service. Each only receives what it needs to do its job:
- Google: Analytics and Tag Manager APIs, and Google Sign-In
- Razorpay: payment processing for paid subscriptions
- Zoho Mail: sends transactional emails on our behalf
- Google Cloud Platform: application hosting and infrastructure
We do not sell your personal information to anyone, and we do not share it with third parties for their own marketing purposes.
6. Data retention
We retain your account and audit history for as long as your account is active, so you can track your GA4/GTM health over time. If you stop using the Service, your data remains until you request deletion (see below) or your account is inactive long enough that we archive it as part of routine housekeeping.
7. Your rights and choices
- You can disconnect your Google account or unlink a GTM container at any time from your dashboard.
- You can revoke GA4 Sensei’s access entirely from your Google Account permissions page.
- To request a copy of your data, or to request that we delete your account and associated data, email us at hello@ga4sensei.com. We handle these requests manually today and will confirm once it’s done.
8. Security
Google OAuth tokens and other sensitive credentials are encrypted at rest. All traffic to and from the Service is encrypted in transit (HTTPS). Access to production systems and secrets is restricted to the team operating the Service.
9. Children’s privacy
The Service is intended for business use and is not directed at children. We do not knowingly collect personal information from anyone under 16.
10. Changes to this policy
We may update this policy as the Service changes. If we make material changes, we’ll update the "Last updated" date above and, where appropriate, notify you directly.
11. Contact us
Questions about this policy or your data? Email hello@ga4sensei.com.
