Privacy Policy
Last updated 18 August 2026
This policy explains what Report Rabbit collects, why we collect it, how we store it, and the choices you have. It covers our website, our application, and the data we access on your behalf from Google Analytics and Google Search Console. We have written it to be read, not to be skimmed past — if anything here is unclear, email us at [email protected].
Who we are
Report Rabbit is a reporting tool for agencies and freelancers. You connect your clients' Google Analytics properties and Search Console sites, and we turn that data into dashboards and scheduled email reports. We are the data controller for the information described in this policy. Where you use Report Rabbit to process data belonging to your own clients, you are the controller of that data and we act as your processor.
Information we collect
Account information
When you register we collect your name, email address, and a securely hashed password. If you create or join a team, we store the team name and your role within it. We never store your password in a form we can read.
Project and client information
We store the projects you create, the site URLs you enter, the dashboards and widgets you build, and the email addresses you nominate as report recipients.
Billing information
Subscriptions are handled by our payment processor, Polar. We receive and store your subscription status, plan, and billing period. We never see or store your full card number — card details are entered directly with the payment processor.
Third-party API credentials
If you connect an additional API as a custom data source, we store the credentials you supply so we can make those requests on your behalf. These are encrypted at rest.
Technical information
Our servers record standard log information — IP address, browser type, pages requested, and timestamps — for security, debugging, and abuse prevention. Our public marketing pages ask whether you are willing to allow Google Analytics, which sets cookies in your browser. It is switched off until you accept, declining costs you nothing, and you can change your mind at any time using the "Cookie settings" link in the footer. This measurement runs only on those marketing pages — it is not present inside the application — and it is entirely separate from the Google Analytics data you connect as a customer.
Google user data
This section describes exactly what we access through Google APIs, and is the part of this policy most relevant if you are connecting a Google account.
Scopes we request, and why
| Scope | Why we need it |
|---|---|
| openid, userinfo.email, userinfo.profile | To identify which Google account you connected, so you can tell several connected accounts apart and disconnect the right one. |
| analytics.readonly | To list the Google Analytics properties you have access to, and to read traffic, page, device, and country metrics for the property you select. |
| webmasters.readonly | To list the Search Console sites you have access to, and to read search performance data — clicks, impressions, queries, and pages — for the site you select. |
Every scope we request is a read-only scope. Report Rabbit cannot create, edit, or delete anything in your Google Analytics or Search Console accounts, and cannot access Gmail, Drive, Calendar, Contacts, or any other Google service. We request the narrowest scopes that let the product work.
What we store
When you connect a Google account we store the email address and display name of that account, the identifiers of the property and site you select, the scopes you granted, and OAuth access and refresh tokens. Tokens are encrypted at rest and are used only to make the read-only API requests described above. We also cache the metrics we retrieve so dashboards load quickly and monthly reports can be assembled.
Limited Use
Report Rabbit's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In plain terms, this means we do not sell Google user data, we do not use it for advertising, we do not transfer it to data brokers or information resellers, and we do not allow humans to read it except with your explicit permission, where it is necessary for security purposes or to comply with applicable law, or where the data is aggregated and anonymised for internal operations. We do not use Google user data to train generalised artificial intelligence or machine learning models.
How we use information
- To provide the service: building the dashboards you configure and sending the reports you schedule.
- To authenticate you and keep your account and team secure.
- To bill you, and to send service messages about your subscription.
- To respond to your support requests.
- To diagnose faults, prevent abuse, and keep the service running reliably.
- To comply with our legal obligations.
We do not sell your personal information, and we do not use your data or your clients' data to serve advertising.
Legal bases for processing
If you are in the United Kingdom or the European Economic Area, we rely on the following legal bases: performance of a contract to provide the service you subscribed to; consent for connecting a Google account, which you may withdraw at any time; legitimate interests in securing the service, preventing abuse, and improving the product; and legal obligation where the law requires us to retain records.
How we store and protect information
All traffic to Report Rabbit is encrypted in transit with TLS. OAuth access tokens, refresh tokens, and any third-party API credentials you supply are encrypted at rest in our database using AES-256, so that a copy of the database alone does not expose them. We apply technical and organisational measures appropriate to the sensitivity of the data we hold.
Data within Report Rabbit is scoped to your team. Members of your team can see the projects, connected accounts, and reports belonging to that team; members of other teams cannot. No security measure is perfect, and we cannot guarantee absolute security, but we work to protect your information using measures appropriate to its sensitivity.
How long we keep information
We keep your account and project data for as long as your account is open. When you disconnect a Google account, we delete its stored tokens and profile details immediately. When you delete your account, we delete your personal data and your teams' project data within 30 days, except where we are required to keep records — for example invoices for tax purposes — for longer. Residual copies may persist in routine backups for a short period after deletion.
Revoking access and deleting your data
You are in control of the Google connection and can end it at any time, in either of two places:
- Inside Report Rabbit, disconnect the Google account from your team's connections page or your project's settings page. This deletes the stored tokens straight away.
- From your Google account directly, at myaccount.google.com/permissions, where you can remove Report Rabbit's access to your data.
To delete your whole account and everything in it, email us at [email protected] and we will action the request within 30 days.
Your rights
Depending on where you live, you may have the right to access the personal information we hold about you, to correct it, to delete it, to object to or restrict how we process it, to receive it in a portable format, and to withdraw consent you previously gave. If you are in California, you additionally have the right not to be discriminated against for exercising these rights; note that we do not sell personal information.
To exercise any of these rights, email [email protected]. We will respond within the time limit the applicable law sets. If you believe we have handled your data improperly, you may also complain to your local data protection authority.
International transfers
Our service providers may process information in countries other than your own, including the United States. Where personal information is transferred out of the United Kingdom or the European Economic Area, we rely on the safeguards that applicable law requires for such transfers.
Children's privacy
Report Rabbit is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact us and we will delete it.
Changes to this policy
We may update this policy as the product changes or the law requires. When we do, we will update the date at the top of this page, and we will give you notice of material changes where the law requires it. If we begin requesting a new Google scope, you will be asked to grant it on Google's own consent screen before we can use it.
Contact us
Questions, requests, or complaints about this policy or your data can be sent to [email protected] and we will get back to you.