QueryAtlasWORKSPACE

Privacy & data access

QueryAtlas is operated by ChromeStats LLC. Google sign-in provides your verified identity, name, and email address. Connecting a reporting service separately authorizes access to that service. Ad Manager requires a broader Google permission to create reports. QueryAtlas uses it only to run reports and create fixed hidden measurement reports; it does not change ad serving settings.

What is stored

Dedicated Elasticsearch indices store your account, encrypted Google refresh tokens, connected resource identifiers and selections, hashed QueryAtlas access tokens, and session records. Query audit records contain the tool name, timestamp, and success status and are kept for up to 30 days. Google report results are fetched on demand and are not saved. Measurement reports created through QueryAtlas remain hidden in your Ad Manager network.

We also record page views in ClickHouse for service analytics. These events contain a fixed page name, time, temporary session identifier, browser details, and approximate location from request headers. The server derives a daily visitor identifier from the client address and browser user agent; it does not store the address itself. We do not put Google report data, account details, URL query strings, or referrers in these events. Raw events are retained for 30 days.

Sharing with AI clients

When you configure a QueryAtlas MCP token in an AI client, that client can receive reporting data for resources you enable. Its provider handles the results under its own terms and privacy practices. QueryAtlas does not itself send reports to a model provider or use them to train models.

Your controls

Newly discovered sources are selected by default when you connect or refresh an account. You can deselect individual sources or all sources under an account on the Connections page. Refreshing preserves existing deselections. MCP tokens can access all selected sources, including newly discovered ones.

You can disable resources, revoke MCP tokens, disconnect Google accounts, or delete your account. Account deletion disables access immediately and removes your saved identity and related records; failed or concurrent child-record deletions are retried hourly. An opaque account identifier and deletion timestamp remain to prevent stale requests from restoring access. Re-enrollment requires operator assistance. Removing a connection deletes its stored credentials; revoke the Google grant separately in your Google Account. Infrastructure backups follow the operator’s backup retention policy.

Use of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

For support, contact the operator who provided your QueryAtlas instance. Public launch requires a monitored support contact and applicable retention details.

Return to workspace