Privacy Policy
Last updated: 16 September 2026
Brightstone Metrics shows publishers what their websites earn. To do that it reads figures from the advertising and analytics accounts you connect, stores them, and shows them back to you. This page says exactly what is read, why, where it goes, and how to get rid of it.
Who we are
Brightstone Metrics. The service runs at brightstone.app. For anything in this policy, including a request to delete your data, write to [email protected].
What we collect
Your account
Your name, email address, password (stored only as a bcrypt hash, never as text we can read), time zone, language and display currency. Billing is handled by Paddle, who act as the merchant of record — your card details go to them and never reach our servers.
Data from Google
When you connect a Google account, you are asked to grant two read-only permissions. We request nothing beyond them and cannot change anything in your Google accounts:
-
https://www.googleapis.com/auth/adsense.readonlyYour AdSense earnings, impressions, clicks and page views, by day and by site. This is the revenue the dashboard exists to show. -
https://www.googleapis.com/auth/analytics.readonlyGoogle Analytics 4 traffic for the properties you choose: page views, sessions, active users now, and your top pages. This is what lets the dashboard show earnings per thousand views rather than earnings alone.
We store the daily totals these return, plus the access and refresh tokens needed to keep fetching them. Tokens are encrypted at rest with your installation's application key. We never receive your Google password.
Data from other advertising networks
If you connect AdsKeeper or a similar network, we store the API key you provide — encrypted — and the same kind of daily revenue figures.
Data from your own websites
The optional WordPress connector posts a count of people on your site right now, and nothing else. It sends no personal data about your visitors, no IP addresses and no identifiers.
Ordinary service records
Server logs with IP address and browser, kept for up to 30 days for security and debugging. A session cookie so you stay signed in. We do not use advertising cookies and we do not track you across other sites.
How Google user data is used
Data obtained through Google APIs is used for one purpose: to show it to you, and to people you have invited to your own account. Specifically, Brightstone Metrics' use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. That means we do not:
- transfer or sell it to anyone, for advertising or anything else;
- use it for advertising, profiling or credit assessment;
- allow humans to read it, except where you have explicitly asked us to help with a support problem, where the law requires it, or where it is aggregated and anonymised for internal operations;
- use it to train machine learning or AI models.
Who else sees it
Nobody, beyond the processors that make the service run: our hosting provider, Paddle for payments, and an email provider for the messages the service sends you. Each sees only what its job requires. We have never sold customer data and the business does not depend on doing so.
We will disclose data if legally compelled to, and where we are allowed to tell you that has happened, we will.
How long it is kept
Daily revenue and traffic figures are kept for as long as your account exists, because a dashboard with no history is not worth much. Disconnect an integration and its tokens are deleted immediately; the figures already gathered stay until you delete the site or the account.
Delete your account and everything belonging to it — sites, integrations, tokens, figures, targets — is removed within 30 days, apart from records we are legally required to keep, such as invoices.
Taking it back
You can revoke our access to your Google data at any time, either from the integrations page in Brightstone Metrics or directly at myaccount.google.com/permissions. Revoking there stops all future access immediately.
Under the GDPR you may also ask for a copy of your data, ask us to correct it, ask us to delete it, or object to how we use it. Email [email protected] and we will answer within 30 days.
Security
Everything travels over HTTPS. Provider credentials and OAuth tokens are encrypted at rest. Passwords are hashed with bcrypt. Access to production is limited to the people who operate the service. No system is perfect, and if a breach ever affects your data we will tell you and the relevant authority without undue delay.
Children
The service is for businesses and is not directed at anyone under 16. We do not knowingly collect their data.
Changes
If this policy changes in a way that affects what we do with your data, we will email you before it takes effect. The date at the top always reflects the current version.