Privacy Policy
Last updated: July 28, 2026
What we collect
To run your Ploxir workspace we store:
- Account data — email, name, password hash (bcrypt), and the workspace you created.
- Connector credentials — API keys, OAuth tokens, and webhook secrets for the third-party services you connect. These are encrypted at rest with AES-256-GCM using a key only the server holds.
- Snapshots — the data your connectors return (revenue, visitors, etc.). Stored in your workspace, accessible only to you and your invited members.
- Operational logs — IP, user agent, and timestamps for sign-in, webhook events, and errors. Retained 30 days for debugging and abuse prevention.
What we don't collect
- We do not sell or share your data with advertisers.
- We do not run third-party tracking scripts on the dashboard.
- We do not read or store your customers' personal data beyond what the connector returns for aggregate widgets.
Third-party processors
- Stripe — payments. We never see your full card number; Stripe handles PCI.
- Resend — transactional emails (signup confirmation, password reset).
- Your own connectors — Stripe, Shopify, GA4, etc. send their own data to Ploxir over HTTPS. We only ever fetch what their API or webhook delivers.
Google user data (OAuth)
When you connect a Google account to Ploxir (Google Analytics, Google Ads, YouTube, AdSense, or Google Play Console), Ploxir's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, Ploxir:
- Uses Google user data only to provide and improve user-facing dashboard features the user explicitly authorized — rendering analytics, ads, revenue, and channel widgets the user added to their own workspace.
- Does not transfer Google user data to third parties except as necessary to provide the user-facing features (e.g. the hosting infrastructure that stores their dashboard), to comply with applicable law, or as part of a merger / acquisition / sale of assets with notice to affected users.
- Does not use Google user data to serve advertisements, including retargeted, personalized, or interest-based advertising.
- Does not allow humans to read Google user data except (a) with the user's affirmative consent for specific data; (b) as necessary for security purposes such as investigating abuse; (c) to comply with applicable law; or (d) where the data is aggregated and de-identified for operational analytics.
- Does not sell Google user data, and does not use it to train generalized AI or ML models.
What we access via OAuth, per connector:
- Google Analytics — sessions, key events, traffic sources, pageviews (scope:
analytics.readonly). - Google Ads — spend, clicks, impressions, conversions, campaign performance (scope:
adwords). - YouTube — channel subscriber count and total view count (scope:
youtube.readonly); revenue, watch time, and monetization data (scope:yt-analytics-monetary.readonly); non-monetary analytics (scope:yt-analytics.readonly). - AdSense — earnings, page RPM, impressions (scope:
adsense.readonly). - Google Play Console — app reviews, vitals (crash rate, ANR, slow rendering) (scopes:
androidpublisher,playdeveloperreporting).
All Google OAuth scopes Ploxir requests are read-only. Ploxir does not call any write endpoint (POST/PUT/PATCH/DELETE) on a connected Google account under any circumstance.
You can revoke Ploxir's access at any time from your Google account at myaccount.google.com/permissions, or by disconnecting the data source from inside your Ploxir workspace. On disconnection, the associated OAuth tokens are deleted immediately and any cached snapshots are removed within 7 days.
Where data lives
Ploxir runs on a self-managed VPS located in Canada. Encrypted at rest, transported over TLS 1.2+ only.
Your rights
You can export, delete, or modify your workspace data at any time from the settings page. Account deletion permanently removes your workspace, encrypted credentials, and snapshots within 7 days.
Contact
Questions? Email [email protected].
