Privacy Policy

Last updated September 1, 2026

ReportKite builds client reports for marketing agencies from the analytics data their clients already own. This policy explains exactly what we collect, why, how long we keep it, and who else touches it.

Who we are

ReportKite (“ReportKite”, “we”, “us”) operates the website at reportkite.com and the reporting service available from it. For any privacy question, or to exercise the rights described below, write to privacy@reportkite.com.

Our customers are agencies. Where an agency connects an account belonging to one of its own clients, the agency is the controller of that data and ReportKite acts as its processor, following the agency’s instructions.

What we collect

  • Account data. The email address you sign up with, your agency name, and the branding you upload (logo, colors, sending address).
  • Client and report settings. The client names, website addresses, report templates and schedules you create.
  • Analytics data from Google. Read-only metrics pulled from the Google accounts you connect — see the next section.
  • Waitlist data. If you join our waitlist, your email address and which part of the page you signed up from.
  • Technical data. Standard server logs (IP address, browser, pages requested) kept for security and debugging. We do not run advertising trackers or third-party analytics on our marketing site.

Google user data

When you connect a Google account, ReportKite requests read-only access to Google Analytics 4 and Google Search Console. We request the narrowest scopes that let us build a report: analytics.readonly and webmasters.readonly.

  • How we access it. Through Google’s official APIs, using the authorization you grant on Google’s own consent screen. We never ask for your Google password.
  • How we use it. Solely to generate the reports you configure and deliver them to the recipients you choose. Metrics such as sessions, search queries, page performance and conversions are read at report time and rendered into your branded report.
  • How we store it. We store your OAuth tokens encrypted, along with the report figures needed to show month-over-month comparisons. We do not copy your full analytics history.
  • How we share it. We do not sell it, and we do not share it with anyone except the infrastructure providers listed below that operate the service on our behalf, and the report recipients you designate.
  • How to revoke it. Disconnect a client inside ReportKite, or revoke access at any time from your Google account permissions. Revoking stops all future data access immediately.

ReportKite’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to serve advertising, we do not sell it, and we do not use it to train generalized artificial intelligence or machine learning models.

Where a report includes a written summary generated by AI, only the aggregate figures already in that report (for example: total sessions and their percentage change) are sent to our AI provider to phrase the paragraph. That provider is contractually bound not to train models on the data. You can edit or switch off the summary before anything is sent.

Why we are allowed to process it

We process account and report data to perform the contract you enter into when you use ReportKite. We process technical logs on the basis of our legitimate interest in keeping the service secure and working. We process waitlist emails on the basis of your consent, which you can withdraw at any time by asking us to delete your address.

Who else touches your data

We keep the list short and name every provider that can technically reach customer data:

  • Vercel — hosting and content delivery for the application.
  • Supabase — the database where accounts, settings and report data are stored.
  • Resend — delivery of the report emails you schedule.
  • Polar — payment and subscription processing. Card details go to Polar and its payment processors; ReportKite never sees or stores your card number.
  • Anthropic — generation of the plain-English report summary, when that section is enabled.

We may also disclose data if the law requires it, or to protect the rights and safety of our users and the service. If ReportKite is ever sold or merged, we will tell customers before their data moves.

How long we keep it

Account, client and report data is kept for as long as your account is open. When you delete a client, its connections and report data are deleted within 30 days. When you close your account, everything is deleted within 30 days, except records we must keep for accounting or legal reasons. Server logs are kept for 30 days. Waitlist addresses are kept until launch, or until you ask us to remove yours.

Security

Data is encrypted in transit with TLS and at rest by our hosting and database providers. OAuth tokens are stored encrypted and used only by the server. Access to production data is limited to the people who operate the service. No system is perfectly secure, but if a breach affects your data we will notify you without undue delay.

Where your data lives

Our servers and database are hosted in the United States. If you are in the European Economic Area or the United Kingdom, this means your data is transferred outside your region; those transfers rely on the European Commission’s Standard Contractual Clauses entered into with our providers.

Your rights

Depending on where you live, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or send it to another provider. If you are a California resident, you can ask what personal information we collected and request its deletion. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of on that front.

Write to privacy@reportkite.com and we will answer within 30 days. You will never be treated differently for exercising these rights. If you are in the EEA or the UK and think we have handled your data badly, you can also complain to your local data protection authority.

Cookies

We use a small number of cookies that are strictly necessary: one to keep you signed in, and one to remember your workspace preferences. We do not use advertising or cross-site tracking cookies, so you will not find a consent banner here.

Children

ReportKite is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16.

Changes to this policy

If we change how we handle data in a way that affects you, we will update this page and email account holders before the change takes effect. The date at the top always shows the current version.

Questions? Write to hello@reportkite.com.