Privacy Policy
Last updated: July 2026
1. General Information
measurementIQ ("we", "our" or "the service") is an audit tool for Google Tag Manager (GTM) that uses artificial intelligence to analyze your container configurations.
This privacy policy describes how we collect, use and protect your information when you use our service.
2. Data We Collect
2.1 Google Tag Manager Data
When you authorize access to your Google account, we request read-only permissions to:
- List the GTM accounts and containers you have access to
- Export the configuration of the selected container (tags, triggers, variables)
Important: We cannot create, modify or delete any elements in your GTM account.
2.2 Authentication Data
We use Google OAuth 2.0 for authentication. We receive:
- Your name and email address (to identify you in the session)
- A temporary access token to communicate with the GTM API
2.3 Technical Data
We collect minimal technical data necessary for service operation:
- Error logs for troubleshooting
- Session information for authentication
3. How We Use Your Data
- Deterministic analysis: Most of the audit runs as rule-based checks on our servers, in memory.
- AI analysis: A summarized view of your container structure is processed in real time by third-party AI model providers to generate recommendations. We may route between providers for reliability, quality and cost. We send only the container structure summary and your audit context (site category, audit motive) — never your name, email or Google account data. Your data is not used to train models.
- Report generation: Downloadable reports (spreadsheet, PDF) are generated inside your browser and are not stored on our servers.
- Service operation: We keep audit metadata (container ID and name, date, scores, issue counts) to manage your audit credits, prevent abuse and monitor service health.
We do not use your Google data for any purpose other than providing the audit functionality you requested.
measurementIQ's use and transfer of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
4. Storage and Retention
We never store your full GTM container configuration.
- Container data is processed in memory during the audit session and discarded when the audit completes. We do not keep copies of your tags, triggers or variables.
- Your reports are generated in your browser and are not stored on our servers. If you use the optional "send by email" feature, the report is relayed through our email provider to your inbox and is not retained by us.
- Access tokens live in an encrypted session cookie, expire automatically and are not stored persistently on our servers.
What we do store, and why:
- Audit metadata (container ID and name, date, scores, issue counts, analysis cost): needed to manage your audit credits, prevent abuse and monitor service health. This is metadata about the audit, not the contents of your container.
- Aggregated, non-identifying check statistics:which audit rules fired and how many elements they affected, plus tag counts per platform type (e.g. "5 analytics tags, 2 advertising pixels"). These are rule IDs and numbers only — never the names, values or configuration of your tags. We use them to measure and improve the accuracy of the audit engine.
- A temporary analysis cache: to avoid charging you twice for auditing the same unchanged container, we keep the analysis result (which references the names of affected tags, triggers and variables, plus short structural excerpts used as evidence) for up to 7 days, keyed to a fingerprint of the container version. It is deleted automatically after that period.
- Waitlist emails: used only to notify you about access, auto-deleted after 30 days.
5. Third-Party Sharing
We rely on a small number of infrastructure providers, only as necessary to provide the audit functionality:
- AI model providers: for the AI part of the analysis, in real time. We may route between providers for reliability, quality and cost; your data is not used to train models, and we do not permit providers to retain it beyond real-time processing wherever the provider offers that control.
- Cloud hosting and managed database providers: to run the service. They process data only on our behalf.
We do not sell, share, or use your Google data for advertising, analytics, marketing, or any purpose beyond providing the core audit service.
6. Security
We implement security measures including:
- Encrypted connections via HTTPS
- Short-lived access tokens
- Full container configurations are never persisted
- HTTP security headers
7. Your Rights
You have the right to:
- Revoke access at any time from your Google account
- Request information about the data we process
- Request deletion of any stored personal data
To exercise these rights, contact: support@measurementiq.com
8. Cookies & Analytics
We use only essential cookies required for service operation (authentication session). For product analytics we run Google Analytics via Google Tag Manager in cookieless mode (Google Consent Mode with storage denied by default): it sends aggregated, non-identifying usage pings and sets no analytics or advertising cookies. We do not use tracking or advertising cookies.
9. Changes to This Policy
We may update this privacy policy occasionally. We will notify you of significant changes by posting the new policy on this page.
10. Contact
If you have questions about this privacy policy, contact us at:
Email: support@measurementiq.com