Legal
Privacy Policy
The German version of this document is the operative one. This English translation is provided for convenience; where the two differ, the German text governs.
The short version
netrics shows your metrics on dashboards and screens. To do that we store your account, your workspaces and the numbers your data sources deliver, and nothing beyond that. We do not sell data, show ads or build profiles. Credentials for your data sources are stored encrypted. Data we receive from Google is used only to show your own Search Console metrics in your workspace.
1. Controller
The controller within the meaning of Art. 4 (7) GDPR for this website and for the hosted service at app.netrics.so is Lab80 – Florian Preusner, Freester Weg 10c, 13503 Berlin, Germany. netrics is operated as a sole proprietorship under the business name Lab80. For any privacy matter, write to privacy@netrics.so.
We are not required to appoint a data protection officer, because the thresholds in Art. 37 GDPR and § 38 BDSG are not met.
netrics is open source and can be self-hosted. If you use a netrics installation run by someone else (for example your employer), that operator is the controller for it, and this policy covers only this website and the hosted service we run.
2. Overview of processing
We process the following categories of personal data:
- Account data: name, email address, the hash of your password, your workspace memberships and roles.
- Workspace data: dashboards, tiles, data source connections and their settings, invitations (the invitee's email address), paired screens.
- Metric data: the figures your connected data sources deliver, for example page views from Vercel Web Analytics or clicks and search queries from Google Search Console. These are mostly aggregates about your websites and apps, not about individual people.
- Credentials: API tokens and OAuth tokens for your data sources, stored encrypted.
- Usage and security data: sign-in sessions with IP address and browser (user agent), security events such as sign-ins and changes to connections, and short-lived server logs.
- Website visits: anonymous page view statistics without cookies (section 5).
- Correspondence: what you send us by email.
The data subjects are users of the hosted service, people invited to a workspace, visitors of this website and people who write to us. The purposes are providing the website and the service, security, communication with you, and meeting legal obligations.
3. Legal bases
We rely on the following legal bases:
- Art. 6 (1)(b) GDPR (performance of a contract): your account, workspaces, connections, dashboards, paired screens and the emails the service sends you (invitations, password resets).
- Art. 6 (1)(f) GDPR (legitimate interests): hosting and delivering this website, anonymous page view statistics, security logs and abuse prevention. Our interest is running the website and the service reliably and safely and understanding which pages are read; the measures are designed to keep the intrusion small.
- Art. 6 (1)(c) GDPR (legal obligation): where law requires us to retain or disclose something.
Connecting a data source is your choice: you decide which accounts and properties netrics may read. Where we need your consent under Art. 6 (1)(a) GDPR we ask for it, and you can withdraw it at any time with effect for the future.
4. What we never do
We do not sell or rent personal data. We do not show advertising, use advertising trackers or set tracking cookies. We do not use your data or data from your connected sources to build profiles, to train AI or machine learning models, or for any purpose other than providing netrics to you. There is no automated decision-making, including profiling, within the meaning of Art. 22 GDPR.
5. This website
This website (netrics.so) and the pairing address netrics.tv are hosted by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. When you open a page, the server processes the data your browser sends (IP address, date and time, requested page, referrer, browser and operating system) to deliver it and to protect the site against attacks. These logs are kept for at most 7 days.
We use Vercel Web Analytics to count page views. It works without cookies and without storing anything on your device. Visitors are told apart only within one day by a hash of the request data that Vercel discards daily, so we see aggregate figures (pages, referring sites, countries, device types), never individual visitors. Page addresses are reported without query strings. The legal basis is Art. 6 (1)(f) GDPR; our interest is knowing which pages are read. You can object at any time (section 14).
The site loads no fonts, scripts or images from third parties and embeds no social media plugins.
6. The hosted service
To use app.netrics.so you need an account. We process the data you enter when you sign up or are invited, and the data that arises when you use the service. Your password is stored only as a hash. Workspaces are kept strictly apart: members of one workspace cannot see another workspace's data.
When you sign in we create a session and store its IP address and browser (user agent), and we record security events (sign-ins, changes to members, connections and screens) with the same information. This protects your account and lets us investigate misuse. The legal basis is Art. 6 (1)(b) GDPR for the account and Art. 6 (1)(f) GDPR for the security records.
You must be at least 16 years old to create an account.
7. Data sources and credentials
When you connect a data source, netrics stores the credential that lets it read your figures: an API token you create (for example for Vercel) or the OAuth tokens a provider issues when you sign in with it (Google, section 8). Credentials are encrypted with AES-GCM and bound to the connection they belong to; they never appear in logs, error messages or API responses. Connector code can reach only the provider addresses it needs.
netrics then fetches figures on a schedule and stores them in your workspace so dashboards and screens can show them. Deleting a connection deletes its credentials and the figures fetched through it.
8. Google user data (Search Console)
If you connect Google Search Console, you sign in with Google and grant netrics these permissions:
- View Search Console data for your verified sites (
https://www.googleapis.com/auth/webmasters.readonly), read-only. netrics reads the list of Search Console properties your Google account can access, so you can choose one, and for the chosen property its search performance: clicks, impressions, click-through rate and average position per day, optionally broken down by page, search query, country and device, for up to the last 16 months. - Your Google account's identity and email address (
openid,https://www.googleapis.com/auth/userinfo.email), to know which Google account a connection belongs to: we store Google's account ID and email address, show "Connected as …" on the connection and make sure a reconnection uses the same account.
netrics cannot change anything in Search Console or in your Google account, and it reads no other Google data.
Use. We use this data only to show your own Search Console metrics in the dashboards of the workspace in which you created the connection, to that workspace's members and on the screens paired with it, and to keep that connection working. We do not use it for advertising, do not sell it, do not use it to train AI or machine learning models and do not let people read it, except with your permission, where needed for security or to comply with the law.
Sharing. We do not transfer Google user data to third parties. It is processed only by the hosting provider that runs the service on our behalf (section 11).
Storage and protection. Google's refresh and access tokens are stored encrypted (section 7) in our database in the EU; the fetched metrics are stored in your workspace in the same database.
Retention and deletion. We keep the tokens and the fetched metrics for as long as the connection exists. When you delete the connection in netrics, its tokens and metrics are deleted at once, and netrics revokes its access at Google unless another netrics connection still uses the same Google account. You can also remove netrics' access at any time at myaccount.google.com/permissions; netrics then stops fetching and asks you to reconnect, and the figures already fetched stay in your workspace until you delete the connection. Deleting your account or workspace deletes all of it (section 13).
netrics' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
9. TVs, the Apple TV app and netrics.tv
To show a dashboard on a TV, you pair the screen with your workspace: the Apple TV app or a browser in kiosk mode shows a code, and you approve it in netrics at netrics.tv or by scanning the QR code. netrics.tv only forwards you to the approval page of the hosted service; the pairing code is not recorded in analytics.
For a paired screen we store its name, when it was paired and last seen, and a periodic status report (app version, uptime and the last error) so you can see in netrics whether it is working. The screen receives only the dashboards of its workspace. The Apple TV app contains no analytics or advertising code. Apple processes data when you download the app under its own privacy policy. The legal basis is Art. 6 (1)(b) GDPR. You can remove a screen in netrics at any time; its access ends immediately.
10. Email and contact
The service sends transactional emails, for example invitations and password resets, through Twilio SendGrid. SendGrid processes the recipient's address and the message to deliver it.
When you write to us by email, we process your message and your address to answer it. Our mailboxes are hosted by Microsoft (Microsoft 365). The legal basis is Art. 6 (1)(b) GDPR where your request concerns a contract, and Art. 6 (1)(f) GDPR otherwise.
11. Recipients and processors
We use the following service providers, each bound by a data processing agreement under Art. 28 GDPR:
- Railway Corporation (USA): hosting of the service, its database and its logs, in data centers in the EU (Amsterdam region).
- Vercel Inc. (USA): hosting of this website and of netrics.tv, page view statistics.
- Twilio Inc. (SendGrid, USA): delivery of the service's transactional emails.
- Microsoft Ireland Operations Ltd. (Ireland): our email (Microsoft 365).
Data sources you connect (such as Vercel or Google) are not our processors: netrics reads your data from them on your instruction, and they process it under their own terms. Beyond the providers above we disclose personal data only where the law requires it.
12. Transfers to third countries
The service's servers and database are in the EU. Railway, Vercel and Twilio are established in the United States, so personal data may be transferred to or accessed from the US. Such transfers are based on the EU adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR) where the provider is certified under it, and otherwise on standard contractual clauses (Art. 46 (2)(c) GDPR).
13. Retention and deletion
We keep personal data only as long as we need it:
- Account and workspace data, connections and metrics: for as long as the account or workspace exists. A deleted connection takes its credentials and metrics with it at once.
- Sessions: until you sign out or the session expires.
- Security events: 12 months.
- Server logs: at most 7 days.
- Emails: as long as needed to deal with the request, and longer only where commercial or tax law requires it.
To delete your account, write to privacy@netrics.so from the address of your account. We then delete your personal data, and every workspace in which you are the only member, within 30 days, except where statutory retention obligations require us to keep something longer.
14. Your rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR) and data portability (Art. 20 GDPR). Under Art. 21 GDPR you may object at any time, on grounds relating to your particular situation, to processing we base on a legitimate interest. You can withdraw a consent at any time with effect for the future (Art. 7 (3) GDPR). Write to privacy@netrics.so.
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR); for us that is the Berliner Beauftragte für Datenschutz und Informationsfreiheit.
15. Changes to this policy
We update this policy when the website or the service changes. If a change matters for the hosted service, we tell account holders by email before it takes effect. The date at the top shows the current version.